What is an accessibility statement, and how do you create one?
Public sector body, service provider or manufacturer: which document you owe depends on your role and your market. With templates for both routes.

Introduction
This Privacy Notice aims to clearly and transparently explain which personal data we collect when you visit our website, why we collect it, how we use it, and what Your rights are.
We process your personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national data protection laws. We are committed to ensuring that all processing activities are carried out in accordance with the principles of lawfulness, fairness, transparency, data minimization, integrity, and confidentiality.
Specifically, in this notice you will find information about:
-
which data we collect about you and for what purposes;
-
the legal bases on which we process such data;
-
who we may share your data with;
-
how long we retain your data;
-
your rights and how to exercise them.
While we sometimes need Your data for example, to respond to your requests or improve our website), we do so with respect, care and only when truly necessary.
Our Privacy Promises
-
We deeply value your privacy, and for this reason, we guarantee that:
-
We treat your data as if it were our own.
-
We use your data only for the purposes outlined in this notice.
-
We retain your data only for as long as strictly necessary.
-
We do not share your data with third parties without a valid legal basis or your explicit consent.
1. Who Processes Your Personal Data
The Data Controller — that is, the entity that determines the purposes and means of the processing of Your personal data — is AccessiWay S.a.S., with registered office at 7 Rue du Général Henrion Bertier, 92200 Neuilly-sur-Sein registered with the Nanterre Trade and Companies Register under number 914 022 595.
AccessiWay is part of the team.blue group and, in certain cases, acts as joint controller together with team.blue NV, with registered office at Skaldenstraat 121, 9042 Ghent, Belgium. In this context, Your personal data may be shared within the group for statistical, administrative, operational, and service improvement purposes.
AccessiWay and team.blue have defined their respective roles and responsibilities under a joint controllership agreement pursuant to Article 26 of the GDPR, ensuring full compliance with data protection regulations.
For more information regarding joint controllership or to exercise Your rights, you may contact AccessiWay via email at the following email addresses:
📧 legal.fr@accessiway.com or info@accessiway.com.
2. Who This Privacy Notice Applies To
This notice applies to:
-
users who browse the website www.accessiway.com,
-
individuals who contact us through the form available on the website or via email;
-
users who interact with tools we have implemented (e.g. widgets, cookies);
-
individuals who, through the website or other channels, access external platforms or third-party entities through which they may submit a job application (e.g. recruiting portals or employment agencies).
-
In such cases, the privacy notices of the third parties involved — independent from AccessiWay — also apply.
3. What Data We Process
To manage your interaction with our website, we may process the following categories of personal data:
-
Identification and contact details such as name, surname, company, job title, email address, and phone number.
-
These data may be partially processed through our customer relationship management (CRM) system.
-
Data relating to your interaction with our services such as information collected via the website or through Hubspot, such as communication history, preferences, requests, and commercial or technical notes.
-
Technical data such as IP address, device type, operating system, browser, access times, and other data automatically recorded by our systems or servers.
-
Browsing data and preferences such as collected via cookies or similar technologies, in accordance with the choices expressed through the cookie consent banner.
-
Application data such as personal information included in your CV or other documents submitted through third-party platforms (e.g. professional experience, education, contact details).
-
These data are processed by AccessiWay only after being transmitted by the third party, which remains autonomous in the initial processing.
4. Purposes and Legal Basis of Processing
We process Your personal data in compliance with Regulation (EU) 2016/679 (GDPR) and applicable national data protection laws. Your data may be processed for the following purposes:
-
Technical operation of the website
We process technical data, using technical cookies and similar tools, to allow You to access the site, view it correctly, and ensure it functions properly (e.g. browsing, content loading, storing preferences).
📌Legal basis: this processing is necessary to provide a service requested by the user, pursuant to Article 6(1)(b) of the GDPR. Your consent is not required for these cookies.
-
Handling contact or support requests
When you send us a request — via the contact form or by email — we process your data to respond and provide the information requested.
📌 Legal basis: this processing is necessary to take steps at your request prior to entering into a contract, pursuant to Article 6(1)(b) of the GDPR.
-
Compliance with legal obligations
In certain cases, we may need to process your data to comply with legal obligations, such as tax, accounting, or IT security requirements.
📌 Legal basis: this processing is based on compliance with a legal obligation, pursuant to Article 6(1)(c) of the GDPR.
-
Statistical analysis and website improvement
We use analytical tools (e.g. analytical cookies) to collect aggregated data in order to understand how the website is used and to improve its content and functionality.
📌 Legal basis: we process this data only with your freely given and specific consent, pursuant to Article 6(1)(a) of the GDPR.
-
Marketing and Profiling
If you authorize us to do so, we may use your data to send you promotional communications or provide personalized content (e.g. through profiling cookies).
📌 Legal basis: this processing is carried out only with your explicit consent, pursuant to Article 6(1)(a) of the GDPR. You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
-
Management of job applications through third parties
We may receive job applications via third-party platforms (e.g. job portals) or through recruitment agencies. In such cases, we process the submitted data to assess your suitability for the proposed role.
📌 Legal basis: this processing is necessary to take steps at your request prior to entering into a contract, pursuant to Article 6(1)(b) of the GDPR.
Note: the privacy policies of the third-party platforms or agencies involved also apply, independently of AccessiWay.
5. Cookies and Tracking Tools
This website uses a cookie management system provided by iubenda, which allows you to:
-
view a full and transparent list of the cookies in use;
-
modify or withdraw your consent at any time;
-
access the complete Cookie Policy, integrated in the cookie widget.
You can manage your preferences by clicking on the cookie widget icon located at the bottom left corner of every page on the site.
Technical cookies are necessary and therefore enabled by default. Other non-essential cookies (analytical, profiling) are only enabled with your consent.
For more information, please refer to the full Cookie Policy accessible from the cookie widget.
6. Use of accessWidget
This website integrates accessWidget, an automated accessibility tool developed by accessiBe Ltd. and distributed by AccessiWay. The widget allows users to personalize their browsing experience based on their needs.
When the user activates the widget, their IP address is technically transmitted, but:
-
it is not stored, tracked, or associated with identifiable individuals;
-
it is anonymized via a proxy located in the European Union;
-
it is not used for profiling or marketing purposes.
📌 Legal basis: provision of a service requested by the user (Article 6(1)(b) of the GDPR).
7. Data Security
We adopt appropriate technical and organizational measures to ensure the security, integrity, and confidentiality of the personal data we process. These measures are designed to prevent unauthorized access, loss, disclosure, or alteration of your data. In particular, we implement:
-
secure connections via HTTPS (SSL/TLS);
-
authentication systems and access control;
-
access limitation and internal access tracking mechanisms;
-
regular audits and verification procedures;
-
continuous updates to systems and security measures according to the level of risk.
8. Data Retention
Your personal data is stored only for the time strictly necessary to achieve the purposes for which it was collected. Specifically:
-
Contact data: up to 10 years if relevant for contractual or legal purposes;
-
Technical and browsing data: according to what is outlined in the Cookie Policy;
-
Marketing data: until consent is withdrawn.
9. Your Rights (Data Subject Rights)
As a data subject, you may exercise the rights provided under Articles 15–22 of the GDPR at any time. In particular, you have the right to:
-
Obtain confirmation as to whether or not your personal data is being processed and access such data (right of access);
-
Request the rectification of inaccurate personal data or the completion of incomplete data (right to rectification);
-
Request the erasure of your data, if the conditions set out in the GDPR are met (right to erasure);
-
Obtain restriction of processing where applicable (right to restriction);
-
Object to the processing of your data, in whole or in part, under certain circumstances (right to object);
-
Receive your data in a structured, commonly used, and machine-readable format, and, where technically feasible, have it transmitted directly to another controller (right to data portability);
-
Withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
📧 You can exercise Your rights at any time by contacting us at: legal.fr@accessiway.com.
🔗 If you are located in France and believe that the processing of your personal data violates applicable law, you have the right to lodge a complaint with the French Data Protection Authority (Commission Nationale de l’Informatique et des Libertés – CNIL) via the website: www.cnil.fr.
*If you have difficulty accessing our form, please feel free to contact us. Send an e-mail to info@accessiway.com
An accessibility statement tells users how well a digital service works for people with disabilities. In the EU, public sector bodies publish one by law, companies under the European Accessibility Act publish something different, and manufacturers issue a third document entirely. In the United States, no law requires any of them. Which document you owe depends on your role and your market.
Key points
Three routes, three documents. Public sector bodies publish an accessibility statement. Companies providing a covered service publish accessibility information. Manufacturers of a covered product issue an EU declaration of conformity. One template does not cover all three.
A statement does not make a service accessible. It records what an assessment found, and every claim in it needs evidence behind it.
The EU prescribes the content. The Commission's model statement sets the categories, and each member state adds its own rules on top.
The US requires no statement at all. What American buyers ask for instead is a VPAT completed into an Accessibility Conformance Report.
A public authority writes a formal accessibility statement with a compliance status, a list of barriers and an enforcement procedure. An online shop writes something shorter with a different structure and names a market surveillance authority. Both pages can carry the same title.
Scope reaches past websites. Apps, customer accounts, checkout and booking flows, documents and self-service terminals can all fall inside it.
This is general information rather than legal advice. Whether and how the rules apply depends on your organization, your service, your market and the national law that governs you.
Statement, conformance report or declaration of conformity?
Three documents get called the same thing, and telling them apart solves most of the confusion.
Document | What it is | Who reads it |
Accessibility statement | A public page describing current accessibility, known barriers, alternatives and how to complain | Users, regulators, journalists |
Accessibility Conformance Report, produced from a VPAT | A report mapping a product against WCAG, Section 508 or EN 301 549, criterion by criterion | Procurement teams and buyers |
EU declaration of conformity | A manufacturer's formal declaration that a product meets legal requirements, filed rather than published | Market surveillance authorities |
What do users get from the statement?
A good statement answers three questions in a few seconds:
Can I use this service? The compliance status, in plain words.
What will fail if I try? Named functions rather than general phrases, with a real alternative wherever something does not work.
Who do I tell? A contact route that works for someone who cannot use your standard form.
It is also read by people outside your audience:
Procurement teams, checking whether you can be bought from.
Auditors and regulators, checking whether the claims hold.
Journalists and competitors, because it is the one page where an organization states its own position on record.
Does a statement replace an accessibility audit?
No. Publishing changes nothing about how your service behaves. The statement is the visible output of work that happened earlier: an assessment against the Web Content Accessibility Guidelines and, in the European public sector, against EN 301 549.
In our analysis of 19 consumer-facing DAX company websites, 89 percent showed at least one digital barrier. Tested against nine selected WCAG 2.2 success criteria in May 2026, the sites missed more than three of the nine on average, and two met all nine. That analysis is a snapshot rather than a full conformance assessment, which is exactly the distinction a statement has to get right.
Who has to publish an accessibility statement?
Not every organization carries the same duty. The scope has to be checked for your specific service rather than for your sector.
Role | What generally applies | What to watch |
Public sector body in the EU | Formal accessibility statement under the Web Accessibility Directive as transposed nationally | Prescribed content, feedback mechanism, enforcement procedure |
Company providing a covered consumer service, for example e-commerce | Accessibility information under the European Accessibility Act | Separate minimum content, plus the competent market surveillance authority |
Company placing a covered product on the market | EU declaration of conformity and CE marking | A document for the authority, not a web page |
Organization operating in the United States | No statutory statement | WCAG still applies in practice through the ADA, Section 508 and procurement |
Any of the above selling into more than one market | More than one document | One assessment, several published pages, a different authority named on each |
Public sector bodies in the EU
Public sector bodies publish a statement for their websites and mobile applications. It names content that is not fully accessible, explains why, and points to accessible alternatives where they exist. It also offers an accessible feedback route that users can reach immediately, plus information about the enforcement procedure with a link to the responsible body.
Companies under the European Accessibility Act
The European Accessibility Act has applied since 28 June 2025. It covers defined consumer services, including e-commerce, banking, e-books, transport and telecommunications, rather than every commercial website. Providers of a covered service make information about that service's accessibility publicly available in accessible form.
Does the EAA apply to my online shop?
It turns on the service rather than on the fact that you run a website. E-commerce is one of the named categories, so a consumer-facing shop with an ordering process is a realistic candidate. Booking flows, customer accounts and payment steps belong in the same assessment. What this looks like in practice is covered in our overview of accessibility in e-commerce.
What about microenterprises?
The EAA's microenterprise exemption for services applies where a business has fewer than ten employees and either annual turnover or an annual balance sheet total of no more than two million euros. It covers services, not products across the board. It also does nothing about the orders an unusable checkout loses you.
Products rather than services: the EU declaration of conformity
A company placing a covered product on the market carries a third duty. Covered products include e-readers, ATMs, ticketing and check-in machines, self-service terminals and consumer devices with interactive computing. The manufacturer runs a conformity assessment, issues an EU declaration of conformity and applies the CE marking.
That declaration goes to authorities on request rather than onto a web page, and it is kept for five years. A company that manufactures a product and runs a shop carries both duties at once.
Which law applies to your digital service?
The Web Accessibility Directive and the EU model statement
Directive (EU) 2016/2102 created the duty for public sector bodies. The Commission set the form in Implementing Decision (EU) 2018/1523, which is where the recognized content categories come from. Member states transpose it, and they add the review cadence, the enforcement body and often extra requirements.
Why does the same duty look different in each member state?
The directives set the floor. National law decides what you actually publish, and the differences are not cosmetic.
Market | National framework | What is distinctive |
Germany | BGG and BITV 2.0 for public bodies, BFSG for companies | Federal public bodies explain the statement in Easy Language and sign language, and update it annually |
France | The statement carries a numerical conformance rate and sits alongside a multi-year plan and an annual action plan | |
Italy | Statements are filed through the national agency's own form rather than written freely | |
Austria | One central market surveillance body, and an extra duty for operators of self-service terminals | |
Switzerland | Outside the EU, so neither directive applies. Swiss companies selling into the EU are still covered by the EAA |
Tip: keep one findings record and generate each market's document from it. Four documents maintained separately drift apart within a couple of release cycles, and the oldest one is the one someone will quote back to you.
What applies in the United States?
No US law requires you to publish an accessibility statement. Three things matter instead.
ADA Title II. The 2024 Department of Justice rule sets WCAG 2.1 Level AA for state and local government web content. Deadlines moved in April 2026, to 26 April 2027 for entities serving 50,000 or more people and 26 April 2028 for smaller ones.
ADA Title III. No technical standard exists in regulation for private businesses. Courts have filled the gap, and WCAG 2.1 AA is the practical bar. Website accessibility lawsuits run into the thousands each year.
Section 508 and the VPAT. Federal agencies and their suppliers follow Section 508. Buyers request a VPAT completed as an Accessibility Conformance Report, which is the document US procurement actually asks for.
What has to be in an accessibility statement?
For public sector bodies, six elements make up the statement. Each becomes a section of the published page.
Scope. The service, the relevant URLs, and where applicable the app with its version and date.
Compliance status. Fully, partially or non-compliant, chosen on the basis of an actual assessment.
Non-accessible content. The concrete barriers, the reason, any applicable exception, the accessible alternative and a remediation plan where you have one.
Preparation and review. The creation date, the date of the last review, and whether the assessment was internal or third-party.
Feedback and contact. An accessible route to report a barrier or request information, and the unit that handles it. Make sure it works for the people most likely to need it.
Enforcement procedure. The correct procedure and contact details for your jurisdiction.
Three additions are worth making even though they are optional: a link to the assessment report, the remediation schedule, and a phone contact for people who cannot use a web form.
Tip: put a named owner and a response time on the feedback route. A statement that sends reports to a generic inbox tends to produce unanswered reports, which is precisely what the enforcement procedure exists to escalate.
How do I describe a barrier concretely?
Vague wording is the most common weakness in published statements. "Some areas are not yet accessible" tells a user nothing and gives your own team nothing to work from.
Example: In the checkout, the "choose payment method" step cannot be operated by keyboard. The selection fields respond only to mouse clicks, so screen reader users cannot complete an order. As an alternative we take orders by phone on [number]. The checkout is scheduled for revision by [month/year].
That version names the function, the barrier, who it blocks, the alternative and a timeline.
What do companies publish under the EAA?
Providers of a covered service make four things available, in accessible form and somewhere users can find them:
an accessible general description of the service;
the explanations needed to understand how the service is provided;
a description of how the service meets the relevant accessibility requirements;
the competent market surveillance authority.
The Act prescribes content rather than form, so no official template exists for this one. Put it behind a clearly labelled accessibility link in the header or footer rather than inside your terms and conditions. Do not carry the public sector enforcement section across, since it belongs to a different legal route.
How do I create an accessibility statement?
Six steps, in this order. The first two decide everything that follows, which is why the template comes fifth.
Step 1: Establish the legal route Public sector body, covered service provider, manufacturer, several of these or none. Then check the national law in each market you operate in.
Step 2: Define the scope Write down every touchpoint the statement will cover, and get it agreed before anyone starts testing.
Step 3: Run a real assessment Combine automated checks with manual testing of keyboard operation, screen reader compatibility, forms, contrast, heading structure, media alternatives and your central transaction paths. Audit and remediation covers what a team cannot reach in-house.
A compliance status written on the strength of an automated score is a claim your own assessment does not support.
Step 4: Document the findings precisely For each finding, record who owns it and what its remediation status is. That record feeds every document you publish.
Step 5: Draft the right page Use the public sector template or the service information structure below, and fill every placeholder with verified facts. Keeping it current over time is what the accessibility statement service is for.
Step 6: Publish and set a review date Assign an owner and a date before the page goes live.
Accessibility statement templates: which one do you need?
Two templates follow. The first is for public sector bodies and mirrors the Commission's model. The second is for companies providing a covered service. Neither is a substitute for an assessment, and using the wrong one produces a document that satisfies no rule at all.
Template: accessibility statement for public sector bodies
An editable structure rather than a guarantee of compliance. Check your national framework before publishing.
# Accessibility statement
## Scope
This accessibility statement applies to [name and URL of the service / name, version and date of the app].
## Compliance status
[Name of the organization] is committed to making [service] accessible in accordance with [applicable national legislation].
This service is [fully compliant / partially compliant / non-compliant] with [applicable requirements].
## Non-accessible content
The content listed below is non-accessible for the following reasons:
- [specific page, content or function]: [specific barrier], [reason], [accessible alternative], [planned remediation and timeframe, if any].
## Preparation of this statement
This statement was prepared on [date].
The assessment is based on [self-assessment / third-party assessment; method or basis of testing].
The statement was last reviewed on [date].
## Feedback and contact
Have you encountered barriers using [service]? Please tell us through [accessible contact form / email / phone].
Responsible for handling reports: [unit, contact details].
## Enforcement procedure
If you do not receive a satisfactory response within [applicable deadline], you can contact [competent enforcement body]: [link and contact details].
Check before publishing:
every placeholder replaced and every inapplicable option deleted;
"fully compliant" selected only where an assessment supports it;
the enforcement body for your jurisdiction named, not a default copied from elsewhere;
the page published as accessible HTML.
Tip: fill the dates last, and check them twice. Placeholder dates surviving into a published statement are the most common error in this document, and the easiest one for a regulator or a journalist to spot.
Template: accessibility information for a covered service
For providers of a covered consumer service, not for public sector bodies.
# Accessibility information
## About our service
[Short, accessible description of the service, for example an online shop for …]
## How to use the service
[The steps and information needed for ordering, booking, registration, payment or account management.]
## Accessibility of the service
[Description of how the relevant accessibility requirements are met, based on measures actually implemented and tested.]
## Competent market surveillance authority
[Name and contact details of the competent market surveillance authority.]
Where the scope or the claims are uncertain, legal and accessibility specialists should review it before it goes live.
Where should the statement sit, and does that include apps?
In the footer, on every page, labelled as plainly as your privacy policy. For public sector bodies the statement has to be reachable from the homepage and every other page. Mobile apps need the statement reachable from the app itself or from the download page, depending on the national rule.
HTML, PDF or both?
Accessible HTML is the better default. Assistive technology reads it directly, it adapts to display settings, and it stays current more easily. A PDF is not automatically non-compliant, but if you publish one it has to be accessible itself, and you then maintain two versions of the same facts.
How often does the statement need updating?
Public sector bodies review annually and after every substantial change. Everyone else should review after a redesign, a new checkout or booking path, a CMS migration, an app release, a document update or a newly identified barrier. Keeping several statements current by hand is where most of them go stale, which is the case for a continuous web accessibility solution rather than a one-off project.
Changing the review date without re-checking anything leaves you with a document that is current and wrong at the same time.
Frequently asked questions
We are a public sector body and a covered service provider. Do we need two documents?
In most cases yes. The duties sit on different legal bases and cover different things, so a merged page tends to satisfy neither. Publish the statement for the website or app, publish the service information for the covered service, and link the two.
Can private companies call their page an accessibility statement?
Yes. The title is not regulated, the content is. There is no statutory accessibility statement for private companies in the way there is for public sector bodies. What is required is the four pieces of information under the EAA. Many companies publish them under the more familiar heading, which is fine as long as the page claims no conformance an assessment cannot support.
Can I take a template or a generator output as it is?
No. A template gives you the structure. The content comes from your own assessment: your scope, your barriers, your dates, your contacts, your authority. An unedited template claiming full conformance is a documented false statement rather than a shortcut.
Does a statement protect us from a US lawsuit?
No. It creates no safe harbor. It can evidence good faith when backed by real work, and it can create a written admission when it overclaims. Both effects come from the same page, and the difference is whether an assessment sits behind it.
Does the EAA apply to a US company with no European entity?
It can. The EAA follows the market rather than the company's address. A US business offering covered services to consumers in the EU can fall within scope, and the microenterprise exemption turns on headcount and turnover rather than location.
Where to begin?
One assessment supports every document you need. Start there rather than with a template.
Run a free scan to see what an automated check already flags.
Count your obligations: one per market, per role. That number tells you how many documents you owe.
Decide who owns the findings record, because every document you publish will be generated from it.
Note: the US Title II extension moved a deadline, not an obligation. The duty to provide accessible services predates the rule, and private litigation under Title III was never affected by it.
Read next

Editorial Board
An accessible website ensures that all users, including people with disabilities, can perceive, operate, and understand digital content without assistance. By following WCAG guidelines, sites become easily navigable via keyboards and screen readers while providing readable contrast and proper text alternatives.
Digital Accessibility

Editorial Board
AI agents read a page through the same structure a screen reader does. Here's why digital accessibility drives AI visibility and makes your site more quotable.
Digital Accessibility

Author
An overlay changes what visitors see, not what the code says. Here's why every EU accessibility framework needs the hybrid model instead, and what it costs.
Digital Accessibility