assessing the legal risk under the BFSG realistically
Few terms cause as much anxiety around accessibility as the cease and desist letter. Understanding the actual risk for a Magento store requires cleanly separating unfair competition law from the BFSG's own, quite different enforcement mechanism.
Table of Contents
- 1. Why the cease-and-desist framing misleads in the BFSG context
- 2. Who can actually take action: associations, not competitors
- 3. The actual process: from complaint to association lawsuit
- 4. The fine range in detail
- 5. Comparison to enforcement in unfair competition and data protection law
- 6. Documentation duties and the burden of proof in a dispute
- 7. The accessibility statement as a practical protective factor
- 8. Realistic risk for small and mid sized stores
- 9. In practice: responding to authorities and the recommended approach
- 10. Summary
- 11. FAQ
1. Why the cease-and-desist framing misleads in the BFSG context
Under German unfair competition law, a cease and desist letter is an out of court instrument that lets competitors or qualified trade associations flag a violation of the Act Against Unfair Competition and demand a penalty backed declaration to stop, combined with reimbursement of their own legal fees. This model caused years of anxiety around issues like flawed withdrawal notices or missing legal disclosures, because practically any competitor was entitled to send one, which turned into its own business model for specialized law firms.
The Barrierefreiheitsstärkungsgesetz works structurally differently and does not grant competitors this kind of right at all. Instead, the BFSG is enforced through two separate channels: administrative market surveillance run by the federal states, and civil association lawsuits under the Injunctions Act, reserved exclusively for specific, officially recognized associations. Anyone warning of an impending wave of BFSG cease and desist letters from individual competitors is transposing a model from unfair competition law that simply does not exist for accessibility in this form.
2. Who can actually take action: associations, not competitors
Standing to sue under the BFSG combined with the Injunctions Act is reserved exclusively for qualified consumer protection associations and associations representing the interests of people with disabilities that are listed in an official register maintained by the Federal Office of Justice. An individual competitor running an accessible shop themselves cannot directly sue or send a cease and desist letter to a rival over missing accessibility, the way they could over an incorrect price display.
Likewise, an individual person with a disability cannot file their own injunction claim under the BFSG, but must instead file a complaint with the responsible market surveillance authority in the relevant federal state or rely on the support of an association with standing to sue. This structure significantly limits the pool of potential claimants compared to unfair competition law, where practically any market participant can act as a claimant, and explains why the widely feared wave of cease and desist letters has not materialized in practice so far.
3. The actual process: from complaint to association lawsuit
In practice, a case usually starts with a complaint filed with the market surveillance authority, organized independently in each federal state. This authority reviews the matter, can demand information from the company, and, if deficiencies are found, typically sets a deadline for remediation before escalating to further measures such as a prohibition order or a fine proceeding. This staged process differs markedly from the immediate, fee triggering cease and desist letter common in unfair competition law.
In parallel, associations with standing to sue can file an association lawsuit under the Injunctions Act without first going through the administrative route. In practice, established associations tend to use this route cautiously and focus on especially serious, structural violations rather than minor technical details, because an association lawsuit carries its own litigation risk and effort and is typically filed only after informal contact with the affected company has failed to resolve the issue.
4. The fine range in detail
Violations of the BFSG can be sanctioned as an administrative offense with a fine of up to one hundred thousand euros, with the specific amount set case by case by the responsible market surveillance authority in the relevant federal state, based among other things on the severity of the violation, the size of the company, and the company's conduct during the proceeding. A first violation that is promptly remediated after being asked to fix it does not, in established administrative practice so far, regularly result in the maximum amount.
For risk assessment purposes, it matters that market surveillance authorities are primarily oriented toward proportionality and cooperation: their statutory mandate is to achieve accessibility, not to maximize punishment of individual companies. A company that responds to an official inquiry, presents a realistic remediation roadmap, and actually implements it operates in a fundamentally different risk scenario than a company that ignores inquiries or files an obviously false conformance declaration.
5. Comparison to enforcement in unfair competition and data protection law
Comparing this to other legal areas helps put the real scale into perspective. Unfair competition law caused years of anxiety through mass cease and desist campaigns over formal errors in withdrawal notices or privacy statements, because a financial incentive existed: sending firms or associations could recover their own costs, which created a self sustaining business model. The GDPR, in turn, gives supervisory authorities a fine range of up to twenty million euros or four percent of global annual turnover, combined with an active, often complaint driven enforcement practice.
The BFSG sits structurally between these two models, but closer to the data protection pattern: there is no financial incentive for private claimants, because no competitor cease and desist right exists, but there is administrative oversight with its own fine range. The key difference from the GDPR lies in the currently far lower enforcement intensity of BFSG market surveillance, which is still being built out compared to the data protection authorities that have been established for years, noticeably reducing the near term detection risk for individual violations.
6. Documentation duties and the burden of proof in a dispute
In principle, the company bears the burden of demonstrating that its product or service meets the BFSG's requirements, especially once a market surveillance authority requests specific information. In practice, this duty is fulfilled through technical documentation, such as audit reports, a documented mapping to EN 301 549, and the company's own accessibility statement, which sets out the current conformance status, known limitations, and a timeline for remediation.
If such documentation is entirely missing, that significantly worsens the company's position in the proceeding, because the authority then has to rely on its own findings and, in case of doubt, may assume a broader violation than actually exists. Honest, even incomplete documentation is nearly always more favorable from an evidentiary standpoint than no documentation at all, because it shows the company has actively engaged with the topic rather than ignoring it.
7. The accessibility statement as a practical protective factor
A carefully maintained accessibility statement functions in practice like a protective factor, without legally exempting a company from the actual conformance obligation. It documents that a company has actively engaged with its barriers, names concrete limitations instead of hiding them, and presents a realistic remediation roadmap. Exactly these three elements, honest stocktaking, concrete naming of gaps, and a timeline, distinguish a company showing recognizable good faith from one ignoring the topic entirely.
Especially relevant here is the disproportionate burden exemption the BFSG provides for certain cases, for example when full accessibility would require a fundamental change to the product or would be disproportionate relative to the company's economic benefit. Anyone wanting to invoke this exemption must justify and document it comprehensibly, for example through a cost benefit analysis, rather than simply asserting it in general terms.
8. Realistic risk for small and mid sized stores
For small and mid sized Magento stores, a realistic risk assessment needs some nuance. To begin with, the BFSG does not apply to micro enterprises under the EU definition at all, meaning companies with fewer than ten employees and annual turnover or balance sheet total of at most two million euros, provided they render services. For all other affected companies, a transitional rule applies on top: certain service contracts concluded before the cutoff date may, under specific conditions, continue in their existing form until 2030 at the latest.
That does not mean ignoring the topic, but prioritizing it realistically: the near term risk of a sudden, existence threatening sanction is currently low for most small and mid sized stores, while the medium term risk of standing without any documentation or implementation progress at a future review is real and growing, particularly because market surveillance tends to become more active as it gains experience.
9. In practice: responding to authorities and the recommended approach
If a company receives an inquiry from a market surveillance authority or a complaint, the most important first step is to respond promptly and factually rather than ignoring the communication, since exactly that kind of silence regularly escalates a proceeding in established administrative practice. In parallel, it pays off to run a fast, focused review of the specific points raised, to distinguish between a genuine structural deficiency and a misunderstanding. The next step should be presenting a realistic, documented remediation roadmap and actually implementing it, rather than issuing mere statements of intent. This combination of response speed, honest stocktaking, and traceable implementation has, in experience, proven to be the decisive factor in whether a proceeding ends with a deadline or escalates into a more burdensome fine procedure.
The most realistic overall strategy sits between two extremes: neither the widespread panic over a cease and desist wave modeled on unfair competition law is justified, because that model simply does not exist under the BFSG, nor is completely ignoring the topic a smart choice, because the medium term risk is real and grows over time, while the cost of belated, time pressured remediation usually exceeds that of a planned, prioritized implementation. A sensible prioritization starts with the areas that matter most for users with disabilities and are simultaneously reviewed most often: the checkout process, the accessibility statement itself, and basic keyboard operability of central purchase paths. Anyone documenting and communicating substantial progress here reduces the real legal risk far more effectively than any measure oriented solely around a supposed cease and desist threat.
| Legal Framework | Who Can Take Action | Sanction Range | Character of Enforcement |
|---|---|---|---|
| BFSG (Accessibility) | State market surveillance authorities, qualified associations | Fine up to 100,000 euros | Staged, cooperation oriented, no competitor right to sue |
| UWG (Unfair competition) | Competitors, associations with standing to sue | Injunction, cost reimbursement, possibly damages | Immediate, fee triggering cease and desist by competitors common |
| GDPR (Data protection) | Data protection supervisory authorities, some associations | Fine up to 20 million euros or 4% annual turnover | Active enforcement practice, high review intensity |
| Injunctions Act (association lawsuits generally) | Only registered associations with standing to sue | Injunction, no direct fines | Selective, mainly for serious structural violations |
| EAA implementation in other EU states | National market surveillance authorities per member state | Country specific, sometimes stricter than BFSG | Relevant for cross border sales within the EU |
| Press visibility | Market surveillance rarely public, low reputational risk | Competitor and association lawsuits often draw press coverage | Reputational damage usually exceeds the fine itself |
| Typical limitation period for claims | Administrative oversight without classic limitation | Civil claims generally within three years | Fixing issues early shrinks the window for claims |
Mironsoft
WCAG audits, accessible Magento shops, and training
Not sure whether the shop is actually accessible?
We audit existing Magento shops against WCAG 2.2, fix concrete barriers in the Hyvä frontend, and train teams so accessibility stays anchored in the development process for good.
WCAG Audit
Systematically review the shop against WCAG 2.2 AA, with a prioritized issue list.
Fixing Barriers
Concrete implementation: keyboard operability, screen reader support, contrast, forms.
Team Training
Raise developer and editor awareness for accessible implementation day to day.
10. Summary
Accessibility and Legal Risk: Key Facts at a Glance
No competitor right to sue
Unlike unfair competition law, individual competitors cannot directly sue or send cease and desist letters under the BFSG.
Two enforcement channels
Administrative market surveillance by the states and civil association lawsuits by registered associations with standing to sue.
Fine range
Up to 100,000 euros, staged in practice based on proportionality, cooperation, and severity of the violation.
Documentation as protection
An honest accessibility statement with a roadmap significantly improves a company's position in a proceeding.