EAA compliance in Ireland: what directors need to know
Ireland is the only EU member state where EAA non-compliance can result in a criminal conviction. This guide explains what that means in practice.
The European Accessibility Act (EAA) has been enforceable in Ireland since 28 June 2025 under S.I. No. 636/2023, the European Union (Accessibility Requirements of Products and Services) Regulations 2023. Ireland's implementation goes further than most EU member states in one significant respect: it includes criminal penalties for serious or persistent non-compliance.
The four things EAA compliance requires
EAA compliance is not a single checklist item. It requires four things, all of which are mandatory:
- Technical conformance. Your digital products and services must meet EN 301 549, the harmonised European standard. In practice, that means WCAG 2.1 Level AA.
- A published accessibility statement. A mandatory public declaration of your current compliance position, what is not yet accessible, and your remediation plan. Irish regulators request this first in any complaint process.
- Active governance. A named owner for accessibility, a regular testing rhythm, and a process that survives a team change.
- Documentary evidence. Dated assessments, remediation records, and a compliance process that demonstrates the organisation was actively managing its obligations.
Criminal liability: who is at risk
Serious or persistent non-compliance (meaning organisations that knew and did not act) can be prosecuted as a criminal offence under the Regulations. For the most serious cases, prosecuted in the higher courts, the penalty is a fine of up to €60,000, imprisonment of up to 18 months, or both.
What makes this unusual is who is at risk. Where a company commits an offence under the Regulations, directors, managers, secretaries, and other officers of that company can be held personally liable. The liability does not stop at the corporate level. It follows the individuals whose decisions, actions, or neglect contributed to the non-compliance.
Ireland is the only EU member state with criminal penalties for EAA non-compliance. Across Europe, enforcement means fines: significant ones in some markets, but fines nonetheless. Ireland goes further.
Penalties at a glance
| Conviction type | Who | Maximum penalty |
|---|---|---|
| Summary conviction | Organisation or individual | €5,000 fine and/or 6 months imprisonment |
| Conviction on indictment | Organisation or individual | €60,000 fine and/or 18 months imprisonment |
| Director or officer liability | Named individuals personally | Same as above: personal, not corporate |
Enforcement in Ireland
This is not a theoretical risk. ComReg (the Commission for Communications Regulation) is already processing formal complaints, including one against Three Ireland. Enforcement has started.
The CCPC (Competition and Consumer Protection Commission) is the primary market surveillance authority, with services enforcement distributed across sector regulators: ComReg for electronic communications, the Central Bank for financial services, Coimisiún na Meán for audiovisual and media, and the National Transport Authority for transport.
Irish regulators review the accessibility statement early in any complaint process. It is typically the first document they request. An organisation without one starts any investigation at a disadvantage.
The due diligence defence
Irish law allows that a defendant who can demonstrate they exercised due diligence may have a case against the charge. In practice, that means documented evidence of active accessibility management: assessments, remediation records, and a compliance process that shows the organisation was not simply ignoring the obligation.
That evidence is exactly what a structured compliance programme produces. It is also, in most cases, the difference between a defensible position and a personal liability. The defence cannot be constructed retrospectively. Genuine accessibility work with no documentation cannot support it.
Which organisations are covered
The EAA applies to any organisation providing covered products or services to consumers in Ireland, regardless of where the organisation is headquartered. A US-based SaaS company with Irish enterprise customers, a Dutch e-commerce retailer selling to Irish consumers, and an Irish-headquartered FinTech all face the same obligations.
Microenterprises (fewer than 10 employees and annual turnover or balance sheet total not exceeding €2 million) may be exempt for some obligations, but should verify this with a qualified adviser before assuming exemption applies.
Common questions
Does the EAA apply to my Irish company?
If your organisation provides covered digital products or services to consumers in Ireland, it is in scope regardless of where it is headquartered. A US-based SaaS company with Irish enterprise customers, a Dutch e-commerce retailer selling to Irish consumers, and an Irish-headquartered FinTech all face the same obligations under S.I. No. 636/2023.
Can a director actually go to prison for EAA non-compliance?
Yes. On conviction on indictment, the maximum penalty for an individual director or officer is a fine of €60,000 and/or imprisonment of up to 18 months. Summary conviction carries a maximum of €5,000 and/or 6 months. The personal liability provision is explicit in S.I. No. 636/2023, Regulations 32 and 33. Ireland is the only EU member state where EAA non-compliance carries criminal sanctions for individuals.
Which authorities enforce the EAA in Ireland?
Enforcement is distributed across sector regulators: the CCPC is the primary market-surveillance authority, with the Central Bank for financial services, Coimisiún na Meán for media, the National Transport Authority for transport, and ComReg for electronic communications. These authorities process formal complaints, investigate organisations, and can refer cases for prosecution where non-compliance is serious or persistent. The competent authority requests the accessibility statement first in any complaint investigation.
What is the due diligence defence?
The due diligence defence is available to organisations that can demonstrate they took all reasonable steps to prevent non-compliance. It requires documented evidence of active accessibility management: assessments, remediation records, and governance processes. The defence cannot be constructed retrospectively. Genuine accessibility work without documentation cannot support the defence.
What happens when an EAA complaint is filed in Ireland?
A user who encounters an accessibility barrier contacts the organisation first through the mandatory feedback mechanism. If the response is inadequate, they can submit a formal complaint to the competent authority — the CCPC for most services, or the relevant sector regulator. The authority investigates, requests documentation starting with the accessibility statement, and can refer the matter for prosecution if non-compliance is found to be serious or persistent. One formal complaint is already being processed against Three Ireland.
Find out where you stand
If you'd like to understand what Ireland's criminal liability provisions mean for your specific organisation, our free assessment is the place to start.
Book your free assessment today