Regulation
BFSG warning letter received: What specifically to do now
A BFSG warning letter requires a swift but controlled response. Check the sender, the claim, and the deadline, do not sign a cease-and-desist declaration without reviewing it, and simultaneously begin documenting the remediation of the accessibility barriers raised.

Figures, methodology and reuse terms: see the citable data →
The short answer
Stay calm, retain the complete letter, and note the specified deadline. Ask a lawyer experienced in competition law to assess whether the sender is entitled to bring the claim, whether the allegation is sufficiently specific, and whether the demand for costs is justified. Do not sign the enclosed cease-and-desist declaration without first having it reviewed. At the same time, analyze and remedy the accessibility barriers identified, document every change, and have the affected functions retested using both automated and manual methods.
Formal notice and regulatory BFSG inspection are two different procedures
The Barrierefreiheitsstärkungsgesetz, or BFSG for short, transposes the requirements of the European Accessibility Act into German law for covered products and services. The relevant requirements have generally applied since 28 June 2025. They may also cover electronic commerce services, provided that no statutory exemption applies.
However, a formal notice is not a regulatory sanction. It is an instrument of private enforcement, usually based on the Gesetz gegen den unlauteren Wettbewerb, or UWG for short. A competitor or another legally authorised entity may use it to challenge disputed conduct out of court and demand a cease-and-desist undertaking backed by a contractual penalty.
The competition law allegation requires legal assessment
Whether a specific breach of the BFSG also constitutes a competition law infringement that may be challenged through a formal notice is not a purely technical question. In particular, the decisive factors may include whether the breached provision qualifies in the specific case as a market conduct rule within the meaning of Section 3a UWG, whether the sender is entitled to bring a claim under Section 8 UWG, and whether a relevant commercial practice actually exists. This assessment should be entrusted to a lawyer.
Public law market surveillance is separate from this. The competent authorities and the Marktüberwachungsstelle der Länder für die Barrierefreiheit von Produkten und Dienstleistungen, or MLBF for short, may inspect compliance with the BFSG within the scope of their statutory powers. The law also provides for fines of up to 100,000 euros for certain infringements. A private formal notice is neither an administrative fine notice nor proof that an authority has established an infringement.
| Procedure | Typical purpose |
|---|---|
| Competition law formal notice | Out-of-court assertion of private law claims for injunctive relief |
| Regulatory market surveillance | Inspection and enforcement of statutory BFSG requirements |
| Court proceedings | Binding decision on asserted claims or interim measures |
The first steps after receiving the letter
The wrong response is either panic or inaction. A short deadline does not automatically make the claim valid, but it must not simply be allowed to expire. If no response is provided, the sender may consider taking legal action, such as applying for a preliminary injunction. Whether the requirements for such action are met depends on the individual case.
Preserve evidence and check the deadline
- Save the letter, attachments, email headers and, where applicable, the envelope in full.
- Record the exact date of receipt and every deadline stated in the letter.
- Preserve the version of the website in question, screenshots and any existing audit reports without delaying remediation.
- Forward the letter internally only to those directly involved and to the appointed lawyer.
- Do not spontaneously make any legal or factual admission to the sender.
There is no standard response deadline that applies equally to every BFSG warning letter. The primary considerations are the deadline specified and whether it is reasonable in the particular context. A lawyer can assess whether to request an extension, prepare a rejection or choose another response.
Technical work must begin in parallel. This is not an admission of the claim being asserted, but a sensible way to limit risk. For an online shop, critical ordering steps, sign-in, search, forms, product information, payment processes and support channels deserve particular priority.
Check legitimacy, legal standing, and costs
Not every formally worded letter is well founded. A robust review examines the sender, their claimed entitlement to bring the claim, the alleged violation, and the requested legal remedies separately. A professional letterhead is no substitute for legal reasoning.
Who is entitled to bring the claim?
In the case of a competitor, it must be determined whether a specific competitive relationship exists and whether the statutory requirements for entitlement to bring the claim are met. Separate requirements apply to associations, qualified entities, or chambers. Even a lawyer’s letter must make clear on whose behalf the lawyer is acting and which claim is being asserted.
Legal standing must be considered separately from the substantive issue. Even a sender who is generally entitled to bring a claim must describe the alleged violation in sufficient detail for it to be assessed from both a legal and technical perspective. A mere collection of general accessibility terms does not indicate which function, page, or requirement is allegedly affected.
What should raise concerns about a demand for costs?
- Does the letter clearly explain the statutory basis on which the costs are being claimed?
- Are the subject matter, calculation, and scope of the lawyer’s work consistent with one another?
- Are multiple similar letters or unrelated claims apparent?
- Are there indications that the claim is being asserted abusively within the meaning of § 8c UWG?
Such warning signs do not, on their own, prove abuse, nor do they automatically invalidate a deadline. However, they provide specific points for a lawyer to examine. Do not pay merely because a demand is worded assertively, and likewise do not reject it without legal review.
Never sign a cease-and-desist declaration without careful review
The enclosed cease-and-desist declaration is often the most consequential part of a warning letter. Signing it may create an independent cease-and-desist agreement that remains effective for a long time. In the event of a subsequent culpable breach, a contractual penalty may be claimed, regardless of whether the original legal position has since been assessed differently.
Why a modified declaration is considered
A pre-formulated declaration may extend beyond the alleged infringement. It may contain unclear terms, an excessively broad substantive scope, unfavorable contractual penalty provisions, or additional acknowledgments. A lawyer therefore examines whether a declaration should be submitted at all and whether its content must be drafted more narrowly and with greater legal certainty.
Modified does not mean cosmetically altered. If the declaration is intended to eliminate the risk of recurrence, it must be serious and sufficient. Wording that is too narrow may fail to achieve its purpose, while wording that is too broad creates unnecessary obligations. A declaration drafted by the company itself may also create significant risks.
- Do not sign under time pressure without legal review.
- Do not remove individual sentences on your own in the belief that this resolves the risk.
- Clarify which websites, functions, brands, and actions the text actually covers.
- Align the legal declaration with the technically feasible remediation plan.
A lawyer experienced in competition law should always be consulted before signing or submitting a cease-and-desist declaration. This article is intended solely for general information and does not constitute legal advice. The appropriate response depends on the specific letter, the business model, and the documented condition of the offering.
Reduce technical risk at the source
A legal response will not stop a faulty checkout. Likewise, a technical correction does not replace the legal response to the letter. Both workstreams must be coordinated: assess the claim, manage the deadline, identify barriers, address root causes, and document the results in a traceable manner.
Start with a reproducible assessment
An automated scan can quickly provide objective evidence of which machine-testable WCAG requirements are violated on the page in question. Inclaria can analyze a page in a real browser and rank findings by severity. Such a report provides evidence of the work performed, but it is not complete proof of compliance because many requirements call for human assessment and user testing.
Prioritization should not be based solely on the number of findings. A missing accessible name on a key button, an inoperable selection control, or an unclear error message can block a core process. Recurring errors in navigation, components, or templates should be corrected at their common source rather than concealing each visible occurrence individually.
The Inclaria 2026 study found that 94.5% of the 55 websites analyzed from a French e-commerce panel had at least one critical or serious non-conformity. The result cannot be readily extrapolated to German online stores. However, within the scope examined, it shows why a structured assessment is more appropriate than assuming that a visually functional store is accessible.
Why an overlay is not a reliable substitute for evidence of remediation
An interface added after the fact does not necessarily modify the underlying source code, semantic structure, or every interaction. It therefore proves neither that the specific reported root causes have been addressed nor that all applicable requirements have been met. What matters is verifiable corrections to components, content, and processes, together with appropriate manual testing.
- Map each allegation to a specific page, component, and requirement.
- Record the initial finding, responsibility, and selected correction.
- Document the code change, deployment, and retesting in a traceable manner.
- Additionally test key workflows using a keyboard and appropriate assistive technologies.
- Add any remaining findings to a controlled remediation plan, including the rationale and target date.
How to Create a Robust Remediation Record
Good documentation should be reproducible rather than as extensive as possible. It shows what was challenged, how the finding was reviewed, which cause was identified, and which change was deployed. It distinguishes automatically confirmed results from manual assessments and unresolved issues.
Which Evidence Belongs Together
- The unaltered formal notice, including attachments and proof of receipt.
- A dated baseline scan and manual findings concerning the affected user journeys.
- Tickets, commit references, or change logs linked to each finding.
- A new scan and documented manual retesting after deployment.
- Approvals, known remaining deviations, and the plan for further action.
A single passing test does not guarantee compliance across the entire website. Changes to templates, third-party components, content, or ordering processes can create new barriers. The follow-up review should therefore cover the same URL, the same process, and, wherever possible, the same testing conditions, before transitioning into continuous monitoring.
The documentation can help legal counsel assess the actual situation and determine an appropriate response. Whether and which evidence is disclosed to the sender or an authority is a legal and strategic decision. An internal remediation record should not be sent without prior review.
After the acute phase: systematically preventing recurrence
A formal warning often reveals that responsibilities and approval processes were not sufficiently defined. Accessibility should therefore become part of the development process rather than being assessed only at the end of a publication cycle. Design, editorial, development, quality assurance, and legal teams need a shared workflow.
A robust control cycle
- Define who is responsible for findings, deadlines, approvals, and evidence.
- Assess reusable components before deploying them widely.
- Combine automated controls with manual assessments of key user journeys.
- Assess changes to the online shop, content, and integrated services before publication.
- Maintain the legally required accessibility information based on the actual assessment status.
Automation is particularly useful for identifying regressions and recurring machine-detectable errors at an early stage. It can neither determine the legal applicability of the BFSG nor assess every issue related to perception, comprehension, and operation. A robust process explicitly acknowledges this limitation.
The objective is not to create a defence file without improving the product. The most effective risk reduction occurs when legal review, technical root-cause analysis, and continuous quality assurance work together. This turns a one-off response into a traceable process for accessible digital services.
Frequently asked questions
Do I have to respond to a BFSG warning letter?
A specified deadline should not be ignored, even if the claim appears questionable. Have a lawyer review the letter promptly and coordinate further communications. This does not mean that the claim, costs, or cease-and-desist undertaking must be accepted.
Should I sign the enclosed cease-and-desist undertaking?
Not without review by a lawyer experienced in competition law. A cease-and-desist undertaking can create a long-term binding agreement carrying the risk of contractual penalties. Whether it should be rejected, modified, or answered in another form depends on the individual case.
Can any online shop receive an accessibility warning letter?
That depends on whether the specific offering falls within the scope of the BFSG, whether an exemption applies, and whether the alleged violation can be pursued under competition law. The sender’s standing to bring the claim must also be examined. A general statement based solely on the shop system used would not be reliable.
Is an automated scan sufficient as evidence of BFSG compliance?
No. A scan covers only requirements that can be tested automatically and can support technical prioritization and documentation. Depending on the offering, full compliance also requires manual checks, expert assessment, and testing of key user journeys.
Does fixing the technical issues bring the warning letter matter to an end?
Not automatically. A correction can reduce the practical risk, but it does not in itself eliminate costs already claimed or an alleged risk of recurrence. The legal response and technical remediation must therefore be managed in parallel.
Is a BFSG warning letter the same as administrative fine proceedings?
No. A warning letter is typically a private-law instrument, whereas an administrative fine is imposed by a competent authority in public-law proceedings. The two procedures have different requirements and cannot simply be treated as equivalent.
Related definitions
Read next
Start with a free scan
Get your accessibility score, your priority issues and the missing statement in seconds.
Scan my site