Accessibility and Cease-and-Desist Letters: Assessing the Legal Risk Realistically
AI generated
A11Y
WCAG
Accessibility · Law & Risk
Cease-and-Desist Letters and Accessibility
assessing the legal risk under the BFSG realistically

Few terms cause as much anxiety around accessibility as the cease and desist letter. Understanding the actual risk for a Magento store requires cleanly separating unfair competition law from the BFSG's own, quite different enforcement mechanism.

12 min read BFSG & Law Risk Assessment

1. Why the cease-and-desist framing misleads in the BFSG context

Under German unfair competition law, a cease and desist letter is an out of court instrument that lets competitors or qualified trade associations flag a violation of the Act Against Unfair Competition and demand a penalty backed declaration to stop, combined with reimbursement of their own legal fees. This model caused years of anxiety around issues like flawed withdrawal notices or missing legal disclosures, because practically any competitor was entitled to send one, which turned into its own business model for specialized law firms.

The Barrierefreiheitsstärkungsgesetz works structurally differently and does not grant competitors this kind of right at all. Instead, the BFSG is enforced through two separate channels: administrative market surveillance run by the federal states, and civil association lawsuits under the Injunctions Act, reserved exclusively for specific, officially recognized associations. Anyone warning of an impending wave of BFSG cease and desist letters from individual competitors is transposing a model from unfair competition law that simply does not exist for accessibility in this form.

2. Who can actually take action: associations, not competitors

Standing to sue under the BFSG combined with the Injunctions Act is reserved exclusively for qualified consumer protection associations and associations representing the interests of people with disabilities that are listed in an official register maintained by the Federal Office of Justice. An individual competitor running an accessible shop themselves cannot directly sue or send a cease and desist letter to a rival over missing accessibility, the way they could over an incorrect price display.

Likewise, an individual person with a disability cannot file their own injunction claim under the BFSG, but must instead file a complaint with the responsible market surveillance authority in the relevant federal state or rely on the support of an association with standing to sue. This structure significantly limits the pool of potential claimants compared to unfair competition law, where practically any market participant can act as a claimant, and explains why the widely feared wave of cease and desist letters has not materialized in practice so far.

3. The actual process: from complaint to association lawsuit

In practice, a case usually starts with a complaint filed with the market surveillance authority, organized independently in each federal state. This authority reviews the matter, can demand information from the company, and, if deficiencies are found, typically sets a deadline for remediation before escalating to further measures such as a prohibition order or a fine proceeding. This staged process differs markedly from the immediate, fee triggering cease and desist letter common in unfair competition law.

In parallel, associations with standing to sue can file an association lawsuit under the Injunctions Act without first going through the administrative route. In practice, established associations tend to use this route cautiously and focus on especially serious, structural violations rather than minor technical details, because an association lawsuit carries its own litigation risk and effort and is typically filed only after informal contact with the affected company has failed to resolve the issue.

4. The fine range in detail

Violations of the BFSG can be sanctioned as an administrative offense with a fine of up to one hundred thousand euros, with the specific amount set case by case by the responsible market surveillance authority in the relevant federal state, based among other things on the severity of the violation, the size of the company, and the company's conduct during the proceeding. A first violation that is promptly remediated after being asked to fix it does not, in established administrative practice so far, regularly result in the maximum amount.

For risk assessment purposes, it matters that market surveillance authorities are primarily oriented toward proportionality and cooperation: their statutory mandate is to achieve accessibility, not to maximize punishment of individual companies. A company that responds to an official inquiry, presents a realistic remediation roadmap, and actually implements it operates in a fundamentally different risk scenario than a company that ignores inquiries or files an obviously false conformance declaration.

Comparing this to other legal areas helps put the real scale into perspective. Unfair competition law caused years of anxiety through mass cease and desist campaigns over formal errors in withdrawal notices or privacy statements, because a financial incentive existed: sending firms or associations could recover their own costs, which created a self sustaining business model. The GDPR, in turn, gives supervisory authorities a fine range of up to twenty million euros or four percent of global annual turnover, combined with an active, often complaint driven enforcement practice.

The BFSG sits structurally between these two models, but closer to the data protection pattern: there is no financial incentive for private claimants, because no competitor cease and desist right exists, but there is administrative oversight with its own fine range. The key difference from the GDPR lies in the currently far lower enforcement intensity of BFSG market surveillance, which is still being built out compared to the data protection authorities that have been established for years, noticeably reducing the near term detection risk for individual violations.

6. Documentation duties and the burden of proof in a dispute

In principle, the company bears the burden of demonstrating that its product or service meets the BFSG's requirements, especially once a market surveillance authority requests specific information. In practice, this duty is fulfilled through technical documentation, such as audit reports, a documented mapping to EN 301 549, and the company's own accessibility statement, which sets out the current conformance status, known limitations, and a timeline for remediation.

If such documentation is entirely missing, that significantly worsens the company's position in the proceeding, because the authority then has to rely on its own findings and, in case of doubt, may assume a broader violation than actually exists. Honest, even incomplete documentation is nearly always more favorable from an evidentiary standpoint than no documentation at all, because it shows the company has actively engaged with the topic rather than ignoring it.

7. The accessibility statement as a practical protective factor

A carefully maintained accessibility statement functions in practice like a protective factor, without legally exempting a company from the actual conformance obligation. It documents that a company has actively engaged with its barriers, names concrete limitations instead of hiding them, and presents a realistic remediation roadmap. Exactly these three elements, honest stocktaking, concrete naming of gaps, and a timeline, distinguish a company showing recognizable good faith from one ignoring the topic entirely.

Especially relevant here is the disproportionate burden exemption the BFSG provides for certain cases, for example when full accessibility would require a fundamental change to the product or would be disproportionate relative to the company's economic benefit. Anyone wanting to invoke this exemption must justify and document it comprehensibly, for example through a cost benefit analysis, rather than simply asserting it in general terms.

8. Realistic risk for small and mid sized stores

For small and mid sized Magento stores, a realistic risk assessment needs some nuance. To begin with, the BFSG does not apply to micro enterprises under the EU definition at all, meaning companies with fewer than ten employees and annual turnover or balance sheet total of at most two million euros, provided they render services. For all other affected companies, a transitional rule applies on top: certain service contracts concluded before the cutoff date may, under specific conditions, continue in their existing form until 2030 at the latest.

That does not mean ignoring the topic, but prioritizing it realistically: the near term risk of a sudden, existence threatening sanction is currently low for most small and mid sized stores, while the medium term risk of standing without any documentation or implementation progress at a future review is real and growing, particularly because market surveillance tends to become more active as it gains experience.

9. In practice: responding to authorities and the recommended approach

If a company receives an inquiry from a market surveillance authority or a complaint, the most important first step is to respond promptly and factually rather than ignoring the communication, since exactly that kind of silence regularly escalates a proceeding in established administrative practice. In parallel, it pays off to run a fast, focused review of the specific points raised, to distinguish between a genuine structural deficiency and a misunderstanding. The next step should be presenting a realistic, documented remediation roadmap and actually implementing it, rather than issuing mere statements of intent. This combination of response speed, honest stocktaking, and traceable implementation has, in experience, proven to be the decisive factor in whether a proceeding ends with a deadline or escalates into a more burdensome fine procedure.

The most realistic overall strategy sits between two extremes: neither the widespread panic over a cease and desist wave modeled on unfair competition law is justified, because that model simply does not exist under the BFSG, nor is completely ignoring the topic a smart choice, because the medium term risk is real and grows over time, while the cost of belated, time pressured remediation usually exceeds that of a planned, prioritized implementation. A sensible prioritization starts with the areas that matter most for users with disabilities and are simultaneously reviewed most often: the checkout process, the accessibility statement itself, and basic keyboard operability of central purchase paths. Anyone documenting and communicating substantial progress here reduces the real legal risk far more effectively than any measure oriented solely around a supposed cease and desist threat.

Legal Framework Who Can Take Action Sanction Range Character of Enforcement
BFSG (Accessibility) State market surveillance authorities, qualified associations Fine up to 100,000 euros Staged, cooperation oriented, no competitor right to sue
UWG (Unfair competition) Competitors, associations with standing to sue Injunction, cost reimbursement, possibly damages Immediate, fee triggering cease and desist by competitors common
GDPR (Data protection) Data protection supervisory authorities, some associations Fine up to 20 million euros or 4% annual turnover Active enforcement practice, high review intensity
Injunctions Act (association lawsuits generally) Only registered associations with standing to sue Injunction, no direct fines Selective, mainly for serious structural violations
EAA implementation in other EU states National market surveillance authorities per member state Country specific, sometimes stricter than BFSG Relevant for cross border sales within the EU
Press visibility Market surveillance rarely public, low reputational risk Competitor and association lawsuits often draw press coverage Reputational damage usually exceeds the fine itself
Typical limitation period for claims Administrative oversight without classic limitation Civil claims generally within three years Fixing issues early shrinks the window for claims

Mironsoft

WCAG audits, accessible Magento shops, and training

Not sure whether the shop is actually accessible?

We audit existing Magento shops against WCAG 2.2, fix concrete barriers in the Hyvä frontend, and train teams so accessibility stays anchored in the development process for good.

WCAG Audit

Systematically review the shop against WCAG 2.2 AA, with a prioritized issue list.

Fixing Barriers

Concrete implementation: keyboard operability, screen reader support, contrast, forms.

Team Training

Raise developer and editor awareness for accessible implementation day to day.

10. Summary

Accessibility and Legal Risk: Key Facts at a Glance

No competitor right to sue

Unlike unfair competition law, individual competitors cannot directly sue or send cease and desist letters under the BFSG.

Two enforcement channels

Administrative market surveillance by the states and civil association lawsuits by registered associations with standing to sue.

Fine range

Up to 100,000 euros, staged in practice based on proportionality, cooperation, and severity of the violation.

Documentation as protection

An honest accessibility statement with a roadmap significantly improves a company's position in a proceeding.

11. FAQ: Accessibility and Legal Risk: Key Facts at a Glance

1Can a competitor send me a cease and desist letter over missing accessibility?
Under the BFSG combined with the Injunctions Act, individual competitors cannot directly sue or send cease and desist letters over insufficient accessibility. Standing to sue is reserved exclusively for qualified, registered consumer protection and disability associations, plus state market surveillance.
2How high can a fine under the BFSG be?
The statutory range allows fines of up to one hundred thousand euros. The specific amount in an individual case is set by the responsible market surveillance authority in the relevant federal state and depends among other things on the severity of the violation and the company's willingness to cooperate.
3What is the difference between a cease and desist letter and an association lawsuit?
A cease and desist letter in the classic unfair competition sense can be issued by any competitor. An association lawsuit under the Injunctions Act can only be filed by specially authorized associations listed in an official register, not by individual companies or private persons.
4Does the BFSG apply to small Magento stores too?
Micro enterprises with fewer than ten employees and at most two million euros in annual turnover or balance sheet total are exempt, provided they render services. Larger stores generally fall under the law, in some cases with transitional rules for existing contracts.
5Does an accessibility statement legally shield a company completely from sanctions?
No, it does not exempt a company from the actual conformance obligation. It does, however, act as a practical protective factor, because it documents active effort and, in a dispute, shows the company has engaged with the topic consciously and traceably.
6What happens when a market surveillance authority makes contact?
Typically, an inquiry follows first, requesting information or remediation within a deadline. If the response is adequate and deficiencies are fixed, matters usually stay at this stage without a fine proceeding being opened.
7What does the disproportionate burden exemption mean?
It allows companies, in certain cases, to deviate from individual accessibility requirements when fully implementing them would require a fundamental change to the product or would cause disproportionately high costs relative to the benefit. This exemption must be documented and justified.
8Is the legal risk comparable to that under the GDPR?
Both legal areas have no competitor cease and desist right, only administrative enforcement. GDPR supervision, however, has been established for years and reviews far more actively, while BFSG market surveillance is still being built out, which makes the current detection risk noticeably different.
9Should a store owner wait until 2030 to act because transitional periods apply?
That would be risky, since transitional rules only cover specific service contracts concluded before the cutoff date and do not apply blanket to an entire store. In addition, the medium term risk grows as authorities' enforcement practice matures.
10Which area of a store should be reviewed first on a limited budget?
The checkout process deserves top priority, since it matters most for users with disabilities and is regularly the focus of reviews. In parallel, an honest, current accessibility statement is a quickly achievable protective factor.