What market surveillance actually does — read in the authority’s own strategy
There is a great deal of speculation about accessibility enforcement and very little evidence. Yet the competent authority has published how it works. We read the document. It contains some remarkable things — and one thing that is claimed everywhere is explicitly absent.
Who is actually responsible
One body, nationwide, since 2025 — and expressly not your legal adviser.
The European Accessibility Act (Directive (EU) 2019/882) leaves enforcement to the member states. Germany transposed it as the Barrierefreiheitsstärkungsgesetz (BFSG), and the federal states set up a joint body for it: the Marktüberwachungsstelle der Länder für die Barrierefreiheit von Produkten und Dienstleistungen, a public-law institution known as the MLBF, based at Carl-Miller-Straße 6 in 39112 Magdeburg. It supervises nationwide — there is no per-state jurisdiction, and therefore no difference between North Rhine-Westphalia, Bavaria and Saxony.
The BFSG has applied since 28 June 2025. The statute knows no grandfathering for existing websites: § 1(3) turns on whether a service is provided to consumers after that date, not on when the website was built.
What the MLBF states it does not provide: legal advice. Its statutory mandate, it writes, does not include “legal advice by the market surveillance authority”; it does publish information for the public and about its own work and decisions. Advising micro-enterprises is instead expressly the task of the Federal Agency for Accessibility (§ 15 BFSG).
The MLBF also has an advisory board in which disability organisations and business umbrella associations sit together — among them the German Disability Council, the German Confederation of Skilled Crafts, the Association of German Chambers of Commerce, Bitkom and the German Publishers and Booksellers Association. That is not a footnote: the authority’s priorities are professionally accompanied in this body.
Two documents almost nobody has read
On its website, under “Marktüberwachungsstrategien”, the MLBF publishes two PDF files: a market surveillance strategy for the products covered by the BFSG and a market surveillance strategy for the services covered by the BFSG. Both are dated 8 January 2026. For online shops the second one applies, because a shop is a “service provided by electronic commerce” within the meaning of § 1(3) no. 5 BFSG.
The products strategy fulfils, by its own account, the statutory mandate in § 20(2) BFSG. The services strategy was “drawn up in addition to the products strategy as an internal working document” — so it need not exist at all, and yet it is publicly available. Both are embedded as a sectoral component in Germany’s national market surveillance strategy and follow its structure.
The structure is the same in both. Central to it is a division maintained throughout: the authority distinguishes between active (unprompted) and reactive (prompted) market surveillance. Reactive means there is a request, a complaint or a self-report. Active means there is nothing — and the authority looks anyway.
So anyone who wants to know how the authority works need not speculate. They need to open two PDF files of under 80 kilobytes each.
The sentence that matters
The services strategy contains one sentence of immediate practical relevance to anyone running a website.
In the chapter on market penetration it reads, in the original German: „Zur effizienten Durchdringung des Markts setzt die MÜB insbesondere bei webbasierten Dienstleistungen auf automatisierte Vorprüfungen. Durch den Einsatz technischer Prüfsoftware ist es möglich, eine deutlich größere Anzahl an Dienstleistungen in der Breite zu erfassen, als dies durch rein manuelle Prüfungen möglich wäre.“ In English: to penetrate the market efficiently, the authority relies on automated preliminary checks, particularly for web-based services; using technical testing software makes it possible to cover a far larger number of services than purely manual testing would allow.
Consistently with that, the same document lists the “results of automated preliminary checks” among the risk factors for active market surveillance — alongside user reach, company size, relevance for independent living, complexity and interactivity of the service, public user feedback and market trends. The corresponding strategy for products does not contain this item; it is specific to the services part, and web-based services are named explicitly.
That substantiates what has so far only been asserted: the competent authority does not check websites only when someone complains, and it does not check them only by hand. It uses testing software to achieve breadth — and the results of those preliminary checks feed into the selection of what it then examines more closely.
And now what the document does not say. It gives no date. It gives no scope, no number of sites checked, no tool name, no threshold at which a finding is pursued. Anyone writing “automated scanning starts in the third quarter of 2026” did not take that from a source but invented it. We know this precisely because that claim stood twice in our own texts and had to be removed twice after we failed to find it at the source.
And a preliminary check remains a preliminary check. It is the filter in front, not the examination itself. What the actual examination has to look like is laid down in the statute — see the next section.
What is examined: Annex 1 BFSG
The sample is not a matter of discretion. The statute prescribes which pages belong in it.
§ 28(1) BFSG covers the prompted case: if the authority has reason to believe that a service does not meet the requirements, it examines it. The under-appreciated sentence is in subsection 2: the market surveillance authority examines a service “even without a specific occasion, on the basis of appropriate samples, in a suitable manner and to an appropriate extent”. And further: for websites or mobile applications it applies the specifications of Annex 1 no. 1 and selects the sample in accordance with Annex 1 no. 2.
Annex 1 no. 1 describes the monitoring method. It is expressly technology-neutral and independent of any particular testing tool, operating system or browser. What is examined is perceivability, operability, understandability and robustness — the four principles that also structure WCAG. Letter (a) requires that all steps of a procedure be examined, at least in the standard order followed by a typical user. For a shop that means the ordering process, from product to confirmation. Letter (b) expressly names forms, controls, dialogue boxes, input confirmations, error messages and behaviour with different assistive technologies.
Annex 1 no. 2 sets the sample. It comprises, where present:
- home page, login, sitemap, contact, help pages and help functions, and pages carrying legal information
- at least one relevant page for each type of service and each further main purpose, including the search function
- the page with the accessibility information under § 14(1) no. 2 in conjunction with Annex 3
- sample pages with a distinctly different appearance or different types of content
- at least one relevant downloadable document per type of service and per main purpose
- any further pages the market surveillance authority considers relevant
- and on top of that, at random, at least 10 per cent additional pages and documents
This list is the best available indication of where to look first — it is statutory text, not a recommendation. What stands out is that it consists almost entirely of pages many operators treat as sideshows: contact, help, legal texts, login. The 10 per cent random share additionally ensures that a façade optimised only on the home page will not hold.
To be straight about it: our own tool largely mirrors the page-selection part of that list — home, category, product, basket, login, contact, legal notice, privacy. It does not mirror the procedural part of no. 1 letter (a): the basket is opened but not filled, and no order is placed. What an automated test fundamentally cannot do is set out in the article on the most common barriers.
What happens when something is found
The procedure is staged, and the first stage is a deadline, not a fine.
§ 29 BFSG sets out three stages for services. If the authority concludes that the requirements are not met, it requires the service provider without delay to take suitable measures within an appropriate deadline it sets (subsection 1). If that produces nothing, it issues a second demand, this time threatening prohibition, again with an appropriate deadline (subsection 2). Only then does it take the necessary measures and may in particular order that the offering or provision of the service be discontinued (subsection 3). If the provider demonstrates that conformity has been established, the authority lifts the order.
The market surveillance strategy describes exactly this staged model again in its own words and expressly places it under the “principle of proportionality”: first a demand to correct, then restriction and prohibition, then a fine.
On the size of fines: § 37(2) BFSG names up to 100,000 euros — but only for the cases listed in subsection 1 nos. 1, 7, 8, 9 and 10. For a shop operator, no. 8 is the relevant one: offering or providing a service that does not meet the requirements of the implementing regulation (§ 14(1) BFSG). In all other cases — including the information and disclosure duties — the ceiling is up to 10,000 euros. Both figures are the upper limits of a range, not standard amounts.
One point of perspective: an administrative offence requires intent or negligence (§ 37(1)). And the staged procedure means that at least two set deadlines lie between first contact and a prohibition. That is the difference between supervision and a trap — and the reason why alarmism on this subject is not merely unattractive but simply inaccurate.
The right to request proceedings: the route almost nobody knows
A consumer can request that proceedings be opened — and the authority has to open them.
§ 32(1) sentence 1 BFSG is short and unambiguous: upon a consumer’s request, the market surveillance authority has to open proceedings for measures against an economic operator — provided the consumer asserts that there is an infringement and that, as a result, they cannot use the service or can use it only in a limited way. The economic operator concerned must then be given an opportunity to comment, and the request is decided by formal notice (subsection 3).
The consumer may also have the request made by an association recognised under § 15(3) of the German Disability Equality Act or by a body under § 3(1) sentence 1 no. 1 of the Injunctions Act. And under subsection 2 such associations and bodies may apply in their own right, provided the alleged infringement touches their statutory remit — “no infringement of the applicant’s own rights is required to assert the right”.
There is also a little-noticed right to information: under § 28(4) BFSG the authority provides a consumer, on request, with the information available to it on whether a particular economic operator complies with the accessibility requirements — and with the assessment by which that operator may be invoking an exemption under § 16 or § 17.
The market surveillance strategy itself classifies these requests as a central source of information and writes that a “substantial part of the resources” goes to substantiated cases from reactive market surveillance; because of the statutory design, those measures take precedence. Put differently: a single consumer’s request weighs more heavily in the authority’s resource allocation than any speculation about automated bulk testing.
What the authority leaves open too
Completeness includes saying where the source is silent.
There is no minimum level of control. The strategy says so itself: because the BFSG has only applied since 28 June 2025, there are “no historical data on case numbers or defect rates for the current strategy period” from which a quantitative minimum could be derived. The focus therefore lies on securing responsiveness and on building a qualitative data base. Anyone claiming the authority checks “X shops per month” is inventing a figure that, by the authority’s own account, does not yet exist.
There is no European reporting system for services. For products, authorities report non-conformities to the Commission and the other member states via the Federal Institute for Occupational Safety and Health. For services the strategy expressly states that a formalised reporting system via central EU databases such as ICSMS does not follow from the BFSG and is not currently envisaged; cooperation takes place case by case.
The testing methodology in detail is not published. Which software is used, with which rule sets, at what point a preliminary check turns into a proper examination — none of that appears in either document. We do not guess.
What is known is how priorities are set. For active market surveillance the strategy names above all relevance for independent living and market penetration — where a service has high user reach, a lack of accessibility affects many. For a local or sectoral monopoly, high market penetration is assumed even if absolute user numbers are small. And anyone who has already come to notice, or has shown little willingness to cooperate, is “monitored as a priority” and rated higher in risk.
The picture that emerges is sober. The authority works on a risk basis, in stages and with limited means — and for websites it uses testing software simply to achieve breadth. No looming threat. But also not the calm that many read into the fact that they have heard nothing so far.
Sources
All provisions were checked at the primary source on 27 August 2026. Quotations follow the wording of the respective version; German statutes are cited in the original and paraphrased in English.
- Barrierefreiheitsstärkungsgesetz (BFSG) of 16 July 2021 (Federal Law Gazette I p. 2970), last amended by Article 32 of the Act of 6 May 2024 (BGBl. 2024 I no. 149)§ 1(3) no. 5 — scope, services provided by electronic commercehttps://www.gesetze-im-internet.de/bfsg/__1.html (opens in a new window)Retrieved on 27.08.2026
- BFSG§ 28 — market surveillance of services, in particular subsection 2 (samples without a specific occasion) and subsection 4 (information to consumers)https://www.gesetze-im-internet.de/bfsg/__28.html (opens in a new window)Retrieved on 27.08.2026
- BFSGAnnex 1 (to § 28) — monitoring of services: no. 1 monitoring method, no. 2 sampleshttps://www.gesetze-im-internet.de/bfsg/anlage_1.html (opens in a new window)Retrieved on 27.08.2026
- BFSG§ 29 — measures where services do not meet the accessibility requirements (staged procedure)https://www.gesetze-im-internet.de/bfsg/__29.html (opens in a new window)Retrieved on 27.08.2026
- BFSG§ 32 — rights of consumers, recognised associations and qualified entities in administrative proceedingshttps://www.gesetze-im-internet.de/bfsg/__32.html (opens in a new window)Retrieved on 27.08.2026
- BFSG§ 37 — administrative fines, in particular subsection 1 no. 8 and subsection 2 (up to 100,000 euros / up to 10,000 euros)https://www.gesetze-im-internet.de/bfsg/__37.html (opens in a new window)Retrieved on 27.08.2026
- BFSG§ 15 — advisory service of the Federal Agency for Accessibilityhttps://www.gesetze-im-internet.de/bfsg/__15.html (opens in a new window)Retrieved on 27.08.2026
- Marktüberwachungsstelle der Länder für die Barrierefreiheit von Produkten und Dienstleistungen (MLBF AöR), “Marktüberwachungsstrategie für die Dienstleistungen des BFSG”, as of 08.01.2026Chapters 3.X.2 (active and reactive surveillance, risk factors), 3.X.2.1 (automated preliminary checks), 3.X.3 (priority areas), 3.X.4 (minimum level of control, enforcement), 3.X.5 (cooperation). PDF, linked from the page “Marktüberwachungsstrategien”https://www.mlbf-barrierefrei.de/Marktüberwachungsstrategien/ (opens in a new window)Retrieved on 27.08.2026
- MLBF AöR, “Marktüberwachungsstrategie für die Produkte des BFSG”, as of 08.01.2026Chapters 3.X.1 (competent authority and contact details), 3.X.2 (risk-based approach). PDF, linked from the same pagehttps://www.mlbf-barrierefrei.de/Marktüberwachungsstrategien/ (opens in a new window)Retrieved on 27.08.2026
- MLBF AöR, page “Über Uns”Tasks, jurisdiction, absence of an advisory mandate, advisory board and its membershttps://www.mlbf-barrierefrei.de/Über-Uns/ (opens in a new window)Retrieved on 27.08.2026
- Directive (EU) 2019/882 of the European Parliament and of the Council of 17 April 2019 on the accessibility requirements for products and servicesThe act transposed by the BFSG (European Accessibility Act)https://eur-lex.europa.eu/eli/dir/2019/882/oj (opens in a new window)Retrieved on 27.08.2026
Read on
Who is exempt — and who only appears to be
The micro-enterprise exemption in its exact wording, business-to-business sales, and three exemptions that are rarely mentioned.
The most common barriers in German online shops
792 findings across 20 sites — and what an automated test fundamentally cannot see.
Enforcement and warning letters
Three routes that are constantly confused: market surveillance, association requests and competitors.
Testing, remediation and ongoing monitoring
What we do, what it costs, and what the test mark is tied to.
What would a preliminary check find on your site?
The same kind of tool, the same standard: EN 301 549 V3.2.1 pointing to WCAG 2.1 AA. Enter your address, get the number straight away.