Skip to content
Skip article header Engineering

European Accessibility Act Compliance

The European Accessibility Act never names WCAG or EN 301 549. This piece sorts a software company into the role that actually carries liability, and states plainly why the standard everyone cites carries no legal presumption here.

23 min read 18 views
Skip key takeaways

Key takeaways: European Accessibility Act compliance 5

Why the Act regulates five closed roles rather than software as a category, where software counts as a product versus a service, why a pure B2B vendor is reached anyway, what the microenterprise derogation actually covers and why the standard everyone cites carries no legal presumption here.

  • The Act regulates five roles, manufacturer, authorised representative, importer, distributor and service provider Article 3(21) closes the list at five roles and attaches nothing to a company occupying none of them, which is the usual position of a development agency.
  • Software is a product only in one narrow case; it is a covered service through two rows Software counts as a product only as a free-standing consumer operating system. It is a covered service only through the e-books and dedicated software row or the e-commerce row, and recital (43) makes a consumer-capable checkout in-scope regardless of what it sells.
  • A pure B2B vendor is outside the Act as an economic operator, but is reached anyway A pure B2B vendor sits outside the Act as an economic operator, but is reached anyway through a customer's own Annex I duty, through public procurement under Article 24(1) and through the customer's inability to shift the duty by subcontracting.
  • The microenterprise derogation is services-only Microenterprises dealing with products stay fully subject to the accessibility requirements, with only two procedural reliefs rather than an exemption.
  • No harmonised standard supports the Article 15(1) presumption of conformity for the EAA EN 301 549's Official Journal citation supports Directive (EU) 2016/2102, the public sector bodies directive, not the EAA. As at 2026-08-16, EUR-Lex searches and the Commission's own harmonised standards portal found no equivalent citation for Directive (EU) 2019/882, so the Article 15(1) presumption of conformity is not available under it, though the standard remains valid evidence.
See our UX and UI design services

European Accessibility Act compliance sounds like a single checklist until you read Directive (EU) 2019/882 and notice it never treats software as a regulated category, never mentions WCAG and never mentions EN 301 549. If a customer's procurement team has sent a questionnaire since the application date passed on 28 June 2025, the honest first move is to work out which of five named roles your company occupies, because most software companies occupy none of them and get the questionnaire anyway. What follows is a role test, not a summary of the Act, and it states the one finding almost nothing else in the field says out loud: the standard everybody cites for it is cited for a different directive.

In short: the European Accessibility Act regulates a closed list of five roles, manufacturer, authorised representative, importer, distributor and service provider, and attaches nothing to a company occupying none of them, typically a development agency. Software is a product in one narrow case only, a free-standing consumer operating system, and a service through two rows, e-books and dedicated software or e-commerce. A pure B2B vendor sits outside the Act as an economic operator, but is reached anyway through a customer's own duty, through public procurement or through its own consumer-capable checkout. No harmonised standard supports the Article 15(1) presumption of conformity: EUR-Lex searches found no citation for the EAA, and reading the Decision publishing EN 301 549 shows it is published for a different directive entirely.

Nobody can tell you whether you comply, and the drafting is why

Directive (EU) 2019/882 reads nothing like most EU directives once you reach its operative chapters. NIS2's every sentence reads Member States shall ensure. The EAA's Chapters III and IV are drafted as direct commands, manufacturers shall, service providers shall, which is seductive and does not change what the instrument is. Article 4(1) routes the whole of Annex I through the Member State first:

"1. Member States shall ensure, in accordance with paragraphs 2, 3 and 5 of this Article and subject to Article 14, that economic operators only place on the market products and only provide services that comply with the accessibility requirements set out in Annex I."

And Article 31 makes the reader's duty a creature of a national measure, not of the Directive itself:

"1. Member States shall adopt and publish, by 28 June 2022, the laws, regulations and administrative provisions necessary to comply with this Directive."

"2. They shall apply those measures from 28 June 2025."

There is no directly applicable EU regulation sitting alongside this directive the way Commission Implementing Regulation (EU) 2024/2690 sits alongside NIS2. Every obligation in this article reaches a reader through whichever national law transposed it, with no exception, which is why the correct sentence is never "the EAA requires you to" and is instead "the national measure transposing Article 13(2) requires".

Your own checkout puts you in scope for a reason unrelated to your product

Before any role test matters, check your own checkout, because it is the single most useful fact in the instrument for a company whose product never touches the Act at all. Article 2(2) covers a short list of services provided to consumers, and one of them, e-commerce services, is wider than its name suggests. Article 3, point (30) defines it:

"‘e-commerce services’ means services provided at a distance, through websites and mobile device-based services by electronic means and at the individual request of a consumer with a view to concluding a consumer contract;"

Recital (43) widens it past whatever you are selling

Four cumulative elements, and a B2B ordering portal fails the last one twice, no consumer and no consumer contract. Recital (43) then widens the row past the product being sold:

"The e-commerce services accessibility obligations of this Directive should apply to the online sale of any product or service and should therefore also apply to the sale of a product or service covered in its own right under this Directive."

It does not matter what you sell. A company whose product sits entirely outside the Directive can still run an in-scope e-commerce service the moment its own site accepts a consumer-capable order, and from that moment it owes the same Article 13(2) documentation duty as any other service provider, running from the same 28 June 2025 application date. Whether that reading extends to a checkout that has only ever produced business contracts is a fact about your own terms of sale, not something the text resolves, so treat this as a test to apply to your own checkout rather than a verdict. A retailer or marketplace building the same kind of checkout has this question settled from the start; our e-commerce software development coverage builds that surface directly.

The standard everybody cites is cited for a different directive

Article 15(1) offers a presumption of conformity, conditional on one thing:

"1. Products and services which are in conformity with harmonised standards or parts thereof the references of which have been published in the Official Journal of the European Union , shall be presumed to be in conformity with the accessibility requirements of this Directive in so far as those standards or parts thereof cover those requirements."

EN 301 549 genuinely is a harmonised standard with a real Official Journal citation. Commission Implementing Decision (EU) 2018/2048 publishes it:

"The reference to harmonised standard for websites and mobile applications drafted in support of Directive (EU) 2016/2102 listed in the Annex to this Decision, is hereby published in the Official Journal of the European Union ."

Read the directive it names. Directive (EU) 2016/2102 governs the websites and mobile applications of public sector bodies:

"this Directive aims to approximate the laws, regulations and administrative provisions of the Member States relating to the accessibility requirements of the websites and mobile applications of public sector bodies"

Four EUR-Lex searches, and what they actually found

Four EUR-Lex full-text searches run on 2026-08-16 looked for a citation reaching the EAA instead. Searching for the phrase "in support of Directive (EU) 2019/882" returned no results. Searching for "support of Directive 2019/882" returned no results. A control search for "in support of Directive (EU) 2016/2102" did return results, confirming the search method itself works. A fourth search for "EN 301 549" together with "2019/882" returned six documents, none of them an implementing decision, a regulation or any act publishing a standard reference, only evaluations and notices. The Commission's own harmonised standards portal carries an index page for Directive (EU) 2016/2102 and no equivalent page for Directive (EU) 2019/882.

As at 2026-08-16, no reference to a harmonised standard appears to have been published in the Official Journal in support of the European Accessibility Act, so the Article 15(1) presumption of conformity is not available under it. That is not a statement that EN 301 549 is irrelevant. It remains the obvious engineering target for evidencing Annex I, Section III(c), and conformity with it is real evidence a company can offer. It simply does not carry a legal presumption here the way it does for a public sector website under the other directive.

The Act names five roles, and software is not one of them

Article 3, point (21) closes a list of exactly five roles:

"‘economic operator’ means the manufacturer, the authorised representative, the importer, the distributor or the service provider;"

Every duty in the Directive attaches to one of those five and to nothing else. Article 2(1) applies to five product categories placed on the market after 28 June 2025, and the only one a normal software company plausibly sits on is:

"consumer general purpose computer hardware systems and operating systems for those hardware systems;"

Article 3, point (38) defines an operating system as software that:

"‘operating system’ means software, which, inter alia, handles the interface to peripheral hardware, schedules tasks, allocates storage, and presents a default interface to the user when no application program is running including a graphical user interface"

whether it ships as part of hardware or as free-standing software for consumer PCs, laptops, phones or tablets. That is a product, with technical documentation, an EU declaration of conformity and a CE marking attached. An application is not an operating system, and where the boundary sits for a shell, a launcher or a kiosk-mode wrapper is not resolved anywhere in the text.

How the Directive can hand you a role you never chose

Article 11 can also hand a role to a company without asking: white-labelling a covered product under your own name, or modifying one so that its compliance may be affected, makes you its manufacturer, with the full Article 7 chain attached. This applies to products only. There is no equivalent for services, and there is no CE marking for a service at all.

The six service rows, and the two words that decide everything

Article 2(2) is the services side, and it opens with a gate that settles the entire B2B question before anything else does:

"2. Without prejudice to Article 32, this Directive applies to the following services provided to consumers after 28 June 2025:"

The service provider carries that duty. The consumer named in the text is only the counterparty each row is tested against, not the party the duty attaches to.

The six rows are electronic communications services; access to audiovisual media services; five named elements of passenger transport by air, bus, rail and waterway; consumer banking services; e-books and dedicated software; and e-commerce services. Two of them catch most software companies that get caught at all: "e-books and dedicated software; and" "e-commerce services." The second is the row the checkout test above already covers.

The e-books and dedicated software row, narrower than its name suggests

Article 3, point (41) defines it as:

"‘e-book and dedicated software’ means a service, consisting of the provision of digital files that convey an electronic version of a book"

and continues to cover only the software used to access, navigate, read and use those files, the only place the word software appears in a service row, and it means reading software for books, not software in general.

Everything in Article 2(2) turns on the word consumer, defined exactly:

"‘consumer’ means any natural person who purchases the relevant product or is a recipient of the relevant service for purposes which are outside his trade, business, craft or profession;"

A service sold only to businesses fails that definition and is not a covered service. That is a scope answer, not a defense, and a later section explains why it rarely feels like one.

Building it for someone else does not move the liability to you

Recital (20) is the sentence quoted most often to prove a development agency is inside the Act. It says the opposite.

"Even if a service, or part of a service, is subcontracted to a third party, the accessibility of that service should not be compromised and the service providers should comply with the obligations of this Directive."

Read it in the direction it is written. It does not pull a subcontractor into the closed list of five roles. It keeps the duty exactly where it started, on the service provider, and makes it that service provider's problem if a subcontractor's work compromises accessibility. An agency building a banking app for a bank is not the manufacturer, importer, distributor or service provider of the bank's consumer banking service. It occupies no role in the Directive's list, so the Directive attaches nothing to it directly.

That is also why the requirement still arrives, just not through the Official Journal. The bank cannot discharge its own Article 13 duty by pointing at its vendor, so the accessibility clause lands in the contract instead. For a team building software for other companies, the correct answer to "does the EAA apply to us" is that it does not, and the correct next sentence is that the client's obligation is about to become the team's specification.

Selling B2B keeps you out, and puts you in the questionnaire instead

A software company selling only to businesses is outside the European Accessibility Act as an economic operator. Article 2(2) reaches only services provided to consumers, and the Directive's consumer definition requires a natural person acting outside trade, business, craft or profession. It is reached anyway, through three routes that never make the vendor an economic operator in its own right.

Through the customer's own duty over the products it uses

Recital (19) and Annex I, Section III, point (a) put the products used to deliver a covered service inside the service provider's own compliance obligation:

"In order to ensure the accessibility of the services falling within the scope of this Directive, products used in the provision of those services with which the consumer interacts should also be required to comply with the applicable accessibility requirements of this Directive."

Your software is not the addressee. It is the thing your customer has to be able to stand behind, and that is the mechanism that produces a procurement questionnaire regardless of whether your company is ever named in the Directive. What the questionnaire is really collecting is the evidence your customer needs to write its own Annex V description of how its service meets Annex I, the artifact its own Article 13(2) duty requires it to keep.

Through public procurement, and through the customer's inability to delegate

Article 24(1) makes Annex I a mandatory technical specification in public procurement law:

"1. As regards the products and services referred to in Article 2 of this Directive, the accessibility requirements set out in Annex I thereto shall constitute mandatory accessibility requirements within the meaning of Article 42(1) of Directive 2014/24/EU and of Article 60(1) of Directive 2014/25/EU."

A public buyer imports the whole Annex whether or not the Directive reaches the vendor. Recital (20), read the right way round, closes the third route: subcontracting cannot move the duty, so a customer cannot pass compliance to you contractually and then stop caring what your software does.

None of the three routes makes a B2B vendor a manufacturer, an importer, a distributor or a service provider. For that pure B2B product line, what it faces is a contract clause, a procurement scoring criterion or a lost deal, never an Article 23 assessment, an Article 30 penalty or a national authority's letter. That is a different question from the one covered above, where a vendor's own consumer-capable checkout makes it an in-scope e-commerce service provider in its own right, and can bring exactly that letter.

The one case the text leaves open, and how we plan around it

One case has no answer in the text: a product sold on identical terms to companies and to individuals acting privately. No recital addresses it. While that gap stays open, our engineering judgment, not a legal reading, is to plan against the stricter answer: treat the sale as though it brings the whole service into scope, and keep the same accessibility evidence a covered service would need, including a draft Annex V description of how the product meets Annex I. That costs little now and avoids a retrofit later if the stricter reading turns out to be right, and it costs nothing but paperwork if it turns out to be wrong.

The microenterprise fork, services out and products in

The EAA sizes microenterprises itself. Article 3, point (23):

"‘microenterprise’ means an enterprise which employs fewer than 10 persons and which has an annual turnover not exceeding EUR 2 million or an annual balance sheet total not exceeding EUR 2 million;"

That is not Recommendation 2003/361/EC by reference, unlike NIS2. Headcount is mandatory, joined by and, and either financial ceiling satisfies the rest. Whether a ten-person subsidiary of a larger group consolidates for this test is not settled by the text. Recital (53) gestures at the Recommendation's anti-circumvention machinery, but a recital is an interpretive aid, not an operative provision, and Article 3(23) states its own numbers with no cross-reference.

Services get a full exemption, products do not

Which half of a microenterprise you sit in decides everything. Providing services, the exemption is total:

"5. Microenterprises providing services shall be exempt from complying with the accessibility requirements referred to in paragraph 3 of this Article and any obligations relating to the compliance with those requirements."

Dealing with products, it is not. A microenterprise manufacturer, importer or distributor stays fully subject to the accessibility requirements. It gets exactly two procedural reliefs, not an exemption: under Article 14(4) it need not document its own Article 14 assessment, though the underlying facts still have to be supplied on request, and under Article 14(8) it need not notify the authority when relying on it. The Directive's own recitals use two different words in two adjacent recitals, recital (70) saying services "should therefore not apply", recital (71) saying products "should be lighter in order to reduce the administrative burden". A sentence that says microenterprises are exempt from the EAA without the word services is wrong, and applying that exemption to a company shipping a covered product is wrong twice.

What the law actually asks of a website, and where the boundary sits

For a covered website or app, the entire legal test is one sentence. Annex I, Section III, point (c):

"making websites, including the related online applications, and mobile device-based services, including mobile applications, accessible in a consistent and adequate way by making them perceivable, operable, understandable and robust;"

That duty falls on the service provider, and it has applied since 28 June 2025.

Four adjectives, no standard named, no version, no success criteria, no conformance level. Recital (47) explains where they come from: the four principles, as used in Directive (EU) 2016/2102, are "also relevant for this Directive", which borrows the framing without adopting that directive's standard, conformance level or accessibility statement duty. How a team designs and evidences perceivable, operable, understandable and robust interfaces is engineering practice, not law, and our UX and UI design services page covers that build process directly rather than repeating it here.

The extra clauses that reach a login, a payment step and a language setting

Annex I, Section IV, point (g) adds two requirements once identification, security or payment is delivered as part of a service rather than baked into a product:

"ensuring the accessibility of the functionality for identification, security and payment when delivered as part of a service instead of a product by making it perceivable, operable, understandable and robust;"

A neighbouring point extends the same test to identification methods, electronic signatures and payment services. Together they reach the parts of a checkout most teams treat as third-party and therefore untouched: login, two-factor prompts, CAPTCHA, e-signature flows and the payment step itself. The consumer banking row goes further and caps language complexity at level B2 of the Common European Framework of Reference for Languages, a content constraint rather than a UI one, and our banking software development coverage is the better place to read it against actual account flows.

The document that has to travel with a service, and it is not an accessibility statement

Article 13(2) sets the service-side documentation duty:

"2. Service providers shall prepare the necessary information in accordance with Annex V and shall explain how the services meet the applicable accessibility requirements. The information shall be made available to the public in written and oral format, including in a manner which is accessible to persons with disabilities. Service providers shall keep that information for as long as the service is in operation."

The phrase accessibility statement appears nowhere in this instrument. It appears eleven times in Directive (EU) 2016/2102, whose Article 7(1) requires public sector bodies to publish one:

"Member States shall ensure that public sector bodies provide and regularly update a detailed, comprehensive and clear accessibility statement on the compliance of their websites and mobile applications with this Directive."

What Annex V actually requires instead

The EAA's own artifact lives somewhere else. Annex V requires the description to sit in the general terms and conditions or an equivalent document, and that description has to explain how the service actually meets the specific accessibility requirements in Annex I, not simply assert that it does:

"The service provider shall include the information assessing how the service meets the accessibility requirements referred to in Article 4 in the general terms and conditions, or equivalent document."

Three details trip most implementations. The information has to be published in written and oral format, not written alone. It has to be itself accessible. And it has to be retained for as long as the service operates, not for a fixed archival period. None of that is self-certifying, because it has to describe how the service actually meets Annex I, which means someone has to have tested it against that Annex before the sentence can be written honestly. Our QA services coverage is where that testing discipline lives, not this article.

Disproportionate burden is a priced calculation with a retention period

Article 14 offers two defences, and both are scoping limits rather than exits:

"does not require a significant change in a product or service that results in the fundamental alteration of its basic nature; and"

"does not result in the imposition of a disproportionate burden on the economic operators concerned."

Using the second one is not a declaration. Article 14(2) and (3) require an economic operator to assess disproportionate burden against the Annex VI criteria, document that assessment and keep the results for five years from the last time the product or service was made available. Article 14(5) requires renewing the assessment at least every five years for services, and Article 14(8) requires notifying the relevant authority when relying on it. It forfeits the defense entirely if it took accessibility funding:

"6. Where economic operators receive funding from other sources than the economic operator's own resources, whether public or private, that is provided for the purpose of improving accessibility, they shall not be entitled to rely on point (b) of paragraph 1."

Annex VI prices the assessment, and a recital closes the shortcut

Recital (66) closes the obvious shortcut:

"Lack of priority, time or knowledge should not be considered to be legitimate reasons."

Annex VI's own cost criteria name the work explicitly. Criterion 3 asks for a ratio:

"Ratio of the net costs of compliance with accessibility requirements to the net turnover of the economic operator."

and its underlying cost elements include, as printed in that criterion, "one off costs of understanding the legislation on accessibility" among five organisational costs, plus four ongoing production costs including testing the product or service for accessibility. A vendor that has decided compliance is disproportionate and written nothing down has not used Article 14. It has simply not complied. Pricing that assessment against a real engineering plan is the part our design cost coverage models, and it is not repeated here.

The dates that did not end on 28 June 2025

Treating 28 June 2025 as the only date in the instrument produces two mistakes, one in each direction. The first extends a real deferral to software that was never covered by it. Article 31(3) lets a Member State defer only one obligation:

"3. By way of derogation from paragraph 2 of this Article, Member States may decide to apply the measures regarding the obligations set out in Article 4(8) at the latest from 28 June 2027."

Article 4(8) is the answering of 112 emergency communications by the most appropriate public safety answering point. It has nothing to do with commercial software, and a page presenting 28 June 2027 as a general grace period has misread this clause.

The second mistake: assuming no transition exists at all

The second mistake denies that any transition exists at all. Two do, both narrower than a blanket delay. Products already in lawful use to provide a service get five more years:

"1. Without prejudice to paragraph 2 of this Article, Member States shall provide for a transitional period ending on 28 June 2030 during which service providers may continue to provide their services using products which were lawfully used by them to provide similar services before that date."

The same Article 32(1) also lets service contracts agreed before 28 June 2025 continue without alteration until they expire, capped at five years from that date. Self-service terminals get a separate, optional carve-out under Article 32(2):

"2. Member States may provide that self-service terminals lawfully used by service providers for the provision of services before 28 June 2025 may continue to be used in the provision of similar services until the end of their economically useful life, but no longer than 20 years after their entry into use."

That grandfathering is real, and it is not automatic. It only exists where a Member State chose to provide for it, capped by two independent limits, economic life and twenty years. A separate, permanent exclusion sits alongside this and should not be confused with it: third-party content nobody funds, develops or controls, and genuine archives frozen before the application date, sit outside a covered service with no transition clock attached at all.

Who comes asking, and it may be a customer rather than a regulator

There is no EU-level fine anywhere in this instrument. Article 30 hands the number to national law:

"2. The penalties provided for shall be effective, proportionate and dissuasive. Those penalties shall also be accompanied by effective remedial action in case of non-compliance of the economic operator."

Any specific figure circulating online is a national number, and Article 30(5) removes public procurement from the penalties article entirely, since Article 24(1) already covers it. Enforcement also runs privately, which most summaries skip. Article 29(2) gives standing to a consumer directly, and separately to public bodies and associations with a legitimate interest:

"provisions whereby a consumer may take action under national law before the courts or before the competent administrative bodies to ensure that the national provisions transposing this Directive are complied with;"

So the letter that arrives may come from a customer's legal team or a consumer body rather than a regulator, and it will cite your Member State's transposing law, not the Directive.

What the transposition count does and does not tell you

As at 2026-08-16, the EUR-Lex collection of national transposition measures for Directive (EU) 2019/882 lists at least one communicated measure for every one of the 27 Member States, with counts ranging from one to fifty-nine. That is a count of documents filed, not a statement that any Member State's transposition is complete or correct. What survives all of that uncertainty is the part that does not change by country: which of the five roles you occupy, and what your own contracts already commit you to regardless of which national authority eventually asks.

Sources: Directive (EU) 2019/882 (European Accessibility Act), Articles 2, 3, 4, 7, 11, 13, 14, 15, 24, 29, 30, 31 and 32; Annexes I, IV, V and VI; recitals 19, 20, 43, 47, 53, 66, 70 and 71; via EUR-Lex (CELEX 32019L0882). Commission Implementing Decision (EU) 2018/2048, consolidated, Article 1 and Annex, via EUR-Lex (CELEX 02018D2048-20220212). Directive (EU) 2016/2102, the Web Accessibility Directive, Articles 1(1) and 7(1), via EUR-Lex (CELEX 32016L2102). EUR-Lex national transposition measures collection for Directive (EU) 2019/882, read 2026-08-16. This is engineering guidance, not legal advice, and it does not state what any single Member State's transposing law requires.

FAQ

Last updated:

Quick answers to common questions about custom software development, pricing, process and technology.

  • Copy link Copies a direct link to this answer to your clipboard.

    Not as an economic operator. Article 2(2) reaches only services provided to consumers, and Article 3(22) defines a consumer as a natural person acting outside trade, business, craft or profession.

    A pure B2B vendor fails that gate. It is reached anyway through its customer's own Annex I duty over the products used in its service, through Article 24(1) if the customer procures publicly and through the customer's inability to shift the duty by subcontracting under recital (20). None of these make the vendor a regulated economic operator.

  • Copy link Copies a direct link to this answer to your clipboard.
  • Copy link Copies a direct link to this answer to your clipboard.

    Only if they provide services. Article 4(5) exempts microenterprises providing services from the Annex I Section III and IV requirements and from any related obligations.

    Microenterprises that deal with products, as a manufacturer, importer or distributor, remain fully subject to the accessibility requirements and get only two procedural reliefs: no duty to document the Article 14 assessment, and no duty to notify the authority under it.

  • Copy link Copies a direct link to this answer to your clipboard.

    Not directly. Article 3(21) closes the list of five regulated roles at manufacturer, authorised representative, importer, distributor and service provider, and a development agency typically occupies none of them for its client's consumer-facing service.

    Recital (20) keeps the compliance duty on the service provider even when work is subcontracted. The requirement still reaches the agency, through the client's contract rather than through the Official Journal.

  • Copy link Copies a direct link to this answer to your clipboard.

    28 June 2025 is the application date for the Directive's substantive requirements. 28 June 2027 is not a general deadline, it is an optional deferral limited to Article 4(8), the answering of 112 emergency communications.

    28 June 2030 covers products already used to provide a service before the application date, and service contracts signed before that date running to expiry, capped at five years. Self-service terminals may be grandfathered at Member State option, up to economic life and no more than twenty years from entry into use.

  • Copy link Copies a direct link to this answer to your clipboard.

    Recital (43) states that the e-commerce accessibility obligations apply to the online sale of any product or service, and Article 3(30) requires the sale to be at the individual request of a consumer with a view to a consumer contract. A vendor whose checkout can produce a genuine consumer contract runs an in-scope e-commerce service regardless of what it sells, even where its core product is entirely outside the Act.

    This turns on the vendor's own terms of sale rather than on a settled legal test, and should be treated as a question to check rather than an assumption either way.

  • Copy link Copies a direct link to this answer to your clipboard.

    Not an EU-level one. Article 30 requires penalties to be effective, proportionate and dissuasive and leaves the actual figures to national transposing law, and Article 30(5) disapplies the penalties article to public procurement procedures entirely.

    Article 29(2) additionally gives standing to a consumer, and separately to public bodies and associations with a legitimate interest, to bring action under national law, so enforcement can arrive through a private claim as well as through a national authority.

I work with startup founders who need a dedicated software development team but don’t want to gamble on hiring, random outsourcing, or opaque delivery.
Most founders face the same problem sooner or later.
Early technical and team decisions lock the product into tech debt, slow delivery, missed milestones and constant re-hiring. By the time this becomes visible, fixing it is already expensive.

As a CTO and software architect, I help founders design, build and run dedicated development teams that work as a true extension of the startup. Not as a black-box vendor.

My focus is on complex products where mistakes are costly:

  • Web3 and blockchain platforms
  • FinTech and regulated products
  • High-load startup systems
  • MVP → scale transitions

We don’t do body-shopping.
We don’t sell generic outsourcing.

Instead, we help founders:

  • build the right team structure from day one
  • keep technical ownership and transparency
  • scale delivery without losing control
  • avoid vendor lock-in and hidden risks

Teams are aligned with the product roadmap, business goals and long-term architecture. Not just short-term velocity.

Dmytro Nasyrov, Founder and CTO at Pharos Production
Dmytro Nasyrov Founder & CTO Let's work together!

Your business results matter

Achieve them with minimized risk through our bespoke innovation capabilities

Your contact details
Please enter your name
Please enter a valid email address
Please enter your message
* required

We typically reply within 4 hours. Prefer email? hello@pharosproduction.com

What happens next?

  1. Contact us

    Contact us today to discuss your project. We're ready to review your request promptly and guide you on the best next steps for collaboration

    Same day
  2. NDA

    We're committed to keeping your information confidential, so we'll sign a Non-Disclosure Agreement

    1 day
  3. Plan the Goals

    After we chat about your goals and needs, we'll craft a comprehensive proposal detailing the project scope, team, timeline and budget

    3-5 days
  4. Finalize the Details

    Let's connect on Google Meet to go through the proposal and confirm all the details together!

    1-2 days
  5. Sign the Contract

    As soon as the contract is signed, our dedicated team will jump into action on your project!

    Same day