Legal framework
Obligation to notify the ACM about an inaccessible online shop
An online shop that does not meet the applicable accessibility requirements must inform the ACM without delay and specify the corrective measures being taken. First investigate the shortcomings, limit the impact on users, and document a credible remediation plan.

Figures, methodology and reuse terms: see the citable data →
The short answer
Yes. Since 28 June 2025, a service provider subject to the Dutch rules arising from the European Accessibility Act must inform the competent authority without delay upon finding that its service is non-compliant. For a webshop supervised by the Autoriteit Consument & Markt, the notification must describe the non-compliance and the corrective measures. Before submitting the notification, gather verifiable facts and formalise a remediation plan.
This obligation requires concrete action. It is not enough to report that an audit identified errors or that part of the website appears difficult to use. The company must be able to identify the affected user journeys, explain the nature of the barriers found, and present the actions already undertaken or planned. The objective is to provide the authority with sufficiently precise information to understand the situation and monitor how it is being addressed.
The existence of non-compliance does not necessarily mean that the entire webshop is unusable. A defect may affect a specific stage, such as navigation, product selection, account creation, payment, or access to information after placing an order. The first priority is to assess the actual impact of the problem, particularly when it prevents certain users from purchasing a product or accessing a service.
What the notification obligation means
The notification obligation is the requirement to inform the supervisory authority of a known instance of non-compliance. The statutory timeframe is worded as “without undue delay”, rather than as a fixed number of days.
The notification is not a general declaration that the online store is entirely inaccessible. It must enable the ACM to understand the identified deficiencies and have them corrected.
The concept of undue delay requires prompt action while gathering the information needed for a meaningful notification. Waiting until every issue has been fully resolved before informing the authority could be difficult to justify. Conversely, immediately submitting an imprecise statement without specifying its scope or corrective measures may not properly fulfil the purpose of the obligation.
A prudent organisation therefore records the date on which the non-compliance was identified, how it was confirmed and the decisions made from that point onward. This timeline demonstrates that the company did not remain inactive and that it used the necessary time to assess the issue, limit its consequences and prepare its remediation.
The notification obligation must also be distinguished from a simple internal technical report. A ticket submitted to the development team provides useful evidence that remediation has begun, but it does not replace the information that must be provided to the authority when the conditions for regulatory notification are met.
When the obligation applies to an online store
The rules have applied since 28 June 2025 to e-commerce services that fall within their scope. Classification depends on the service provided, the operator and any exemptions established by the legislation.
The scope must therefore be verified before concluding that notification is mandatory or, conversely, that it is not. This analysis must focus on the activity actually offered to consumers, not merely on how the company describes its website. The presence of a catalogue, checkout process or online payment functionality may be among the factors to consider when classifying the service.
The identity of the responsible service provider must also be established precisely. Several parties may be involved in operating an online store: the commercial operator, platform provider, agency, payment service provider or module publisher. Regulatory responsibility cannot automatically be inferred from the identity of the party that technically created the defective page. Contracts and the operational allocation of roles may help clarify the situation, without replacing an analysis of the applicable legislation.
- Identify the entity providing the service
- Verify that the service qualifies as an e-commerce service
- Examine whether a microenterprise exemption may apply
- Document the reasoning and its sources
A potential exemption must not be presumed. It must be verified against the relevant criteria and the company’s actual circumstances. It is advisable to retain the evidence supporting this conclusion, together with the date of the analysis, so that the reasons why the obligation was considered applicable or inapplicable can be explained at a later stage.
What to do before notification
A vague statement risks revealing a problem without demonstrating that it is under control. You must first establish the facts, secure any blocked user journeys, and assign responsibility for each correction.
The initial assessment should focus first on the webshop’s essential functions. The team can start by reproducing the reported difficulties, identifying the technologies or components involved, and determining whether the problem occurs on several pages. This step helps avoid treating as an isolated defect what is actually caused by a shared component, such as a menu, modal window, form, or payment module.
When the defect blocks an essential action, a temporary measure may be considered while the permanent correction is being implemented. It must be genuinely accessible to the people concerned, clearly indicated, and sufficiently operational. However, a workaround must not become a permanent substitute for bringing the digital service into compliance.
Compile an actionable case file
- List the pages and user journeys concerned
- Distinguish automated findings from manual checks
- Describe the concrete impact on users
- Assign an owner and define a validation method
For each defect, the case file may specify the date it was identified, the reproduction context, the users potentially affected, the internal priority level, and the proposed correction. Screenshots, report excerpts, or test scenarios may supplement this description, provided that they are dated and easy to understand.
The remediation plan must remain realistic. An arbitrary or overly ambitious deadline undermines the credibility of the case file if it is not met. It is better to distinguish between immediate corrections, changes requiring more substantial development, and final validations. Each action must be assigned to an identified person or team.
Finally, the webshop must verify that the correction does not merely shift the problem elsewhere. A visual change may, for example, improve contrast while creating a keyboard navigation issue. Validation must therefore cover the complete user journey and not be limited to checking the modified code.
What the notification must explain
The notification must set out the non-compliance and the corrective measures taken or planned. It must remain precise, consistent with the available evidence, and updated if the situation changes.
A structured presentation makes it easier to understand: service concerned, date of discovery, scope of the defect, observed consequences, any temporary measures, planned correction, estimated timeline, and validation method. If some information is not yet known, it is preferable to state this clearly rather than present an assumption as an established fact.
The description must be understandable without requiring the authority to reconstruct the incident from a lengthy technical report. Detailed references may be retained in an appendix or in the internal file. The body of the notification must explain specifically what a user cannot do, or can only do with particular difficulty.
Corrective measures are not necessarily limited to a code change. They may also include replacing a component, adapting content, changing an editorial process, introducing a new acceptance testing procedure, or training the people who publish content on the online store. The key is to establish a clear link between each identified defect and the proposed response.
Retain audits, tickets, decisions, and test results. Inclaria can contribute to the initial automated inventory, but a comprehensive assessment also requires manual testing.
After submission, any significant development must be monitored. If the actual scope differs from the initial findings, if a deadline changes, or if validation reveals a new issue, the file must be updated. This discipline prevents the initial notification and the actual situation from eventually contradicting each other.
Do not confuse notification with an accessibility statement
An accessibility statement publicly describes the accessibility of the service. It does not replace notification to the ACM when non-compliance triggers the notification obligation.
The two procedures have different recipients and purposes. The accessibility statement primarily informs users about the status of the service, its known limitations, and the available ways to request assistance or report a difficulty. The regulatory notification informs the competent authority of non-compliance and the measures taken to remedy it.
A company may therefore need to update its public communications while separately submitting the required notification. The information provided in these two contexts must remain consistent. A public statement claiming full compliance would be problematic if the company had concurrently identified significant defects that had not yet been corrected.
Public content must neither conceal known limitations nor promise unproven compliance. Use understandable language and provide an accessible way to report a difficulty.
The proposed contact channel must itself be usable by the people for whom it is intended. It is useful to establish an internal process for handling feedback, with a designated person, a response timeframe, and a method for linking reports to remediation work. This feedback can supplement audits, as it sometimes reveals barriers that are difficult to detect through standardized testing.
A proportionate and verifiable approach
Automation identifies some testable defects, but not every barrier encountered during a real user journey. The Inclaria 2026 study found at least one critical or serious non-compliance issue on 94.5% of the 55 websites analysed in its French e-commerce sample, illustrating the value of structured verification without drawing conclusions about the Dutch market.
An automated tool can help identify certain recurring problems quickly and monitor their reappearance. However, its results must be interpreted. An automated alert may require human confirmation, while a check that reports no errors does not prove that the entire user journey is accessible.
Manual checks make it possible, in particular, to examine the navigation order, use without a mouse, the clarity of labels, the behaviour of error messages and the continuity of a purchasing journey. The aim is not to accumulate abstract evidence, but to determine whether a person can search for a product, understand the essential information, place an order and access the intended tracking information.
Proportionality concerns how remediation is organised, not whether a known barrier may be ignored. Problems that prevent access to an essential function must be addressed as a priority. Less obstructive defects may be incorporated into a documented schedule, provided that the schedule is followed and the decisions made can be justified.
Ultimately, a verifiable approach rests on four elements: a clearly defined scope, reproducible findings, assigned responsibilities and validation after remediation. This method helps the company prepare a consistent notification, while also reducing the risk that the same defects will be reintroduced during a subsequent update to the online store.
This content is for informational purposes only and does not constitute legal advice. To determine the obligations applicable to a particular case, consult a lawyer familiar with Dutch digital accessibility law.
Frequently asked questions
Do I have to notify the ACM myself that my online store is not accessible?
Yes, if your service falls within the scope of the rules and you identify non-compliance. The notification must be made without unjustified delay and specify the corrective measures. First check the scope of application, identify the relevant defects, and keep a chronological record of the findings and actions taken.
Is there a fixed deadline in days?
The text uses “without delay” rather than a fixed number of days. The meaning of this deadline must be assessed according to the circumstances and the procedure published by the ACM. It is prudent to act quickly, without waiting for the correction to be completed, while gathering enough information to submit an accurate notification.
Is an accessibility statement sufficient?
No. A public accessibility statement and a regulatory notification do not serve the same purpose. The former informs users about the status of the service, while the latter informs the authority of non-compliance and the corrective measures.
Can an automated scan prove compliance?
No. A scan can detect certain testable instances of non-compliance, but full compliance also requires manual checks. Essential user journeys must be tested in their entirety to assess the actual impact of the detected defects.
What should I retain after submitting the notification?
Retain the findings, decisions, remediation plan, and validation results. These materials help demonstrate a consistent and verifiable approach. Also retain the dates, assigned responsibilities, changes to deadlines, and any updates communicated to the authority.
Start with a free scan
Get your accessibility score, your priority issues and the missing statement in seconds.
Scan my site