Search for what the European Accessibility Act costs an Irish business and you will be told, confidently and repeatedly, that the exposure is up to €100,000 or 4% of annual turnover. That figure is not in Irish law. It is not in S.I. No. 636 of 2023, the instrument that transposed the Directive here, and it is not in anything the CCPC has published. It seems to have been carried over from other member states and copied between vendor landing pages until it acquired the texture of a fact. The real Irish numbers are smaller, and criminal. And the thing most likely to put an Irish company in front of a judge is not the contrast ratio on its checkout button. It is a missing document.
TL;DR
- Ireland’s EAA penalties sit in Regulation 32 of S.I. 636/2023: a class A fine (up to €5,000) and/or 6 months on summary conviction, or up to €60,000 and/or 18 months on indictment. The €100,000 and 4%-of-turnover figures circulating online are not Irish law.
- Ireland took the criminal route rather than the administrative-fine route most member states chose, and Regulation 33 extends liability personally to directors and managers on consent, connivance, approval or wilful neglect.
- Most offences in Regulation 32 are documentation and cooperation failures rather than accessibility defects: no documented burden assessment, no notification that you rely on one, ignoring a direction, or misleading an authority.
- Disproportionate burden is not a shrug. It is a Schedule 4 assessment that must be documented, retained five years, renewed, notified and produced on request. Take external funding to improve accessibility and Regulation 15(8) removes the exemption entirely.
- Regulation 34 gives a due diligence defence and Regulation 30 lets a consumer skip the regulator and go straight to the Circuit Court. Your remediation record wins the first and survives the second.
The numbers, from the instrument itself
Regulation 32(6) sets the penalty for any offence under the Regulations: on summary conviction, a class A fine or imprisonment not exceeding 6 months or both; on indictment, a fine not exceeding €60,000 or imprisonment not exceeding 18 months or both. A class A fine, under the Fines Act 2010, is a fine not exceeding €5,000.
The custodial option is the part worth pausing on. Most of the EU transposed the Act into administrative penalty regimes, where a regulator assesses a fine and you appeal it. Ireland put it in the criminal law, so the process ends with a prosecution and a named defendant, and Regulation 33 can make that defendant a person rather than a company.
What is actually an offence
This is where the vendor guides stop reading. Regulation 32 does not say “an inaccessible service is an offence” and leave it there. It lists specific failures:
- 32(1): failure to comply with Regulation 5(1), the substantive duty to only provide compliant services or place compliant products on the market. It also names Regulations 15(4), 15(9), 17, 21(2) and 24(3).
- 32(2): CE marking failures under Regulation 19.
- 32(3): missing the period specified in a direction, or failing to comply with a court order under Regulation 29 or 30.
- 32(4) and 32(5): obstructing an authorised officer, or giving an authority information you know, or ought reasonably to know, to be false or misleading in a material respect.
The defect itself is in there, at 32(1) via Regulation 5(1), so nobody should conclude an inaccessible checkout is fine. But look at the balance. Most of that list concerns records, declarations and how you behave once a regulator is looking. Regulation 24(3) is a single sentence requiring an operator to “fully cooperate” with the compliance authority, and failing to do that is an offence in its own right, separate from whatever prompted the enquiry.
The disproportionate burden trap
Regulation 15 is the exemption everyone reaches for: the requirements apply only to the extent that compliance does not fundamentally alter the basic nature of the product or service, or impose a disproportionate burden. We usually hear it invoked as a verbal position in a planning meeting. It is nothing of the sort.
To rely on it you must carry out an assessment using the Schedule 4 criteria, which cost compliance as a ratio of both total expenditure and net turnover. Regulation 15(4) then requires you to document it, retain a written record for five years after the service was last provided, and produce a copy on request. Regulation 15(7) requires service providers to renew it whenever the service is altered and at least every five years. Regulation 15(9) requires you to tell the relevant authority you are relying on it at all.
Both 15(4) and 15(9) are named in Regulation 32(1). Failing to document, retain or notify is the offence. You can hold a perfectly reasonable view that full compliance would sink your product and still commit a criminal offence by never writing it down.
One clause deserves its own line. Regulation 15(8) removes the exemption entirely where an operator receives funding from any source other than its own resources, public or private, provided for the purpose of improving accessibility. Take a grant to improve accessibility and you have traded the exemption away. That should be a deliberate decision, not one discovered afterwards.
The phrase to read carefully, and the defence
Regulation 33(1) is standard Irish drafting, and broader than people expect. Where an offence by a body corporate is proven to have been committed “with the consent, connivance or approval of, or to be attributable to any wilful neglect on the part of” a director, manager, secretary or other officer, that person also commits the offence. Consent, connivance and approval all require somebody to have decided something. Wilful neglect does not. It reaches the manager who was told in writing, on a ticket, that a service was non-compliant and left it in the backlog for two years without a decision, an assessment or a plan.
Against that, Regulation 34 provides a due diligence defence: it is a defence to prove you exercised due diligence and took all reasonable precautions to avoid committing the offence. Regulation 32(7) then tells the court what to weigh in setting a penalty: the extent and seriousness of the failure, the number of units of products or services involved, and the number of persons affected.
Together those are the argument for treating accessibility as an engineering programme with an audit trail rather than a sprint before a deadline. A dated audit report, a triaged backlog, automated checks in CI, a written assessment where you genuinely cannot comply, and decisions recorded with names against them: that is “all reasonable precautions” in evidence.
Note the asymmetry. For the substantive defect, due diligence is a live argument, because reasonable effort is a matter of degree. For the Regulation 15 documentation offences it mostly is not: either the five-year record exists or it does not, and either you notified the authority or you did not. That is why the paperwork is the higher-risk half of the obligation, and it is the half that never appears in an accessibility audit quote.
It is not just the CCPC, and it is not only regulators
Guides routinely name the CCPC as the Irish enforcer. Regulation 4 splits the job six ways: the CCPC takes products, e-commerce services and e-books; ComReg takes electronic communications; Coimisiún na Meán takes access to audiovisual media services; the Central Bank takes consumer banking; and the Irish Aviation Authority and National Transport Authority split passenger transport. Regulation 35 lets all six bring summary proceedings within their own remit. Operate across sectors and you have several regulators, arriving at different times.
There is also a route involving no regulator at all. Regulation 30 lets a consumer who believes an operator is failing to comply apply directly to the Circuit Court for a compliance order, and Regulation 30(10) allows a representative organisation with a legitimate interest to act in support of them. Failing to comply with the resulting order then becomes an offence under Regulation 32(3). That is a private enforcement path with a criminal tail, and it does not require the CCPC to have any view at all.
What we would do first
- Settle scope in writing. E-commerce and consumer banking services catch far more B2C software than teams assume, and the microenterprise exemption in Regulation 5(4) covers services only: fewer than 10 employees and turnover or balance sheet not exceeding €2 million.
- Audit against WCAG 2.1 AA and date the findings. The dated report starts the due diligence record, whatever it says.
- Triage by number of persons affected, one of the three Regulation 32(7) factors. Authentication, checkout and support paths before marketing pages.
- Automate the regression check. Accessibility tests in CI are the difference between a backlog that shrinks and one that quietly refills.
- Write the Regulation 15 assessment where you rely on it, with retention and renewal dates, and notify under 15(9). Check 15(8) before taking accessibility funding.
- Name an owner. Regulation 33 makes that concrete rather than cultural.
None of this means anyone is going to prison over a colour contrast ratio. The custodial provisions exist for sustained refusal after formal enforcement, and a team making genuine, documented remediation effort is in a different position entirely from one ignoring directions. Saying that plainly matters, because the fear-selling around this Act has largely been built on a fine that does not exist. The real obligation is more boring and more manageable: build the thing properly, and keep the receipts.
REPTILEHAUS remediates interfaces to WCAG 2.1 AA, wires accessibility checks into CI/CD pipelines so compliance holds after launch, and helps teams build the evidence trail the Regulations ask for. If you are unsure whether you are in scope, or you know you are and have nothing written down, get in touch.
This article is general information about Irish law, not legal advice. Take advice on your own circumstances.
📷 Photo by Luke Caunt on Unsplash

