German accessibility compliance is being sold with the same fear that sold cookie banners in 2018. The law is real — the BFSG has applied since June 2025 and the fines reach €100,000 — but the details matter: that ceiling only applies to a specific subset of violations, the actual regulator is a new authority in Magdeburg called the MLBF, and a large share of the cease-and-desist letters currently circulating have questionable legal standing. Fix your sites. Just don’t buy anything out of panic.
If you sell compliance services in Germany, your inbox looks like mine: a steady stream of blog posts announcing an Abmahnwelle, warning that market surveillance authorities will begin mass-scanning shops any quarter now, and offering a widget that solves it. We have seen this exact playbook before — it ran from 2018 to about 2021, and the product was a cookie banner.
The underlying law is genuine and the obligation is real. What follows is the part the panic posts leave out.
Who actually enforces the BFSG
The Barrierefreiheitsstärkungsgesetz — Germany’s transposition of the European Accessibility Act — has applied since 28 June 2025. Enforcement sits with the Marktüberwachungsstelle der Länder für die Barrierefreiheit von Produkten und Dienstleistungen (MLBF), a joint authority of all sixteen federal states, seated in Magdeburg.
Two things about how the MLBF works are worth knowing. First, it acts both on reports — consumers and businesses can file a complaint about a specific barrier — and on its own risk-based surveillance strategy. Second, its escalation path starts with a request to correct the problem. Restrictions, bans and fines come after non-compliance persists, not on first contact. An authority that opens with “please fix this” is a very different threat model from a lawyer who opens with an invoice.
The €100,000 figure is real, and narrower than advertised
Nearly every vendor page cites the €100,000 maximum. Almost none of them cite § 37 BFSG, which is where that number comes from and which splits the penalties in two:
- Up to €100,000 for the violations listed in § 37(1) nos. 1, 7, 8, 9 and 10 — broadly, placing a non-conforming product on the market, offering a non-conforming service, and the CE-marking offences.
- Up to €10,000 for the remaining numbers, which cover information, labelling and documentation duties.
Both are ceilings, not tariffs. German administrative fines are assessed on the nature, severity and duration of the violation and the risk of repetition — the same logic every GDPR practitioner already knows from Art. 83. A first-time contrast failure on a mid-sized shop is not a €100,000 event, and anyone implying otherwise is selling something.
The Abmahnung question
Here is where the German market gets genuinely interesting, because the fastest-moving risk is not the regulator at all. Under German unfair competition law, private parties can send a cease-and-desist letter — an Abmahnung — demanding you stop a violation and reimburse their legal costs. That mechanism is what made cookie banner compliance urgent in Germany years before any DPA acted, and letters citing accessibility failures did start circulating shortly after the BFSG took effect.
But standing is not automatic. § 8 UWG restricts who may send one: actual competitors, qualified trade and consumer associations, and chambers of commerce. And a competitive relationship requires that both parties offer similar or interchangeable goods or services. German practitioners analysing the letters now in circulation — notably an assessment by attorney Axel Dreyer LL.M. that has been widely discussed in the German accessibility community — point to recurring defects: senders with no plausible competitive relationship to the recipient, allegations that never name a specific provision or a specific broken function, and inflated dispute values that exist to inflate the fee.
The practical advice from German counsel is consistent and it is not “ignore it”: never let the deadline pass, never sign the attached declaration unexamined, and have a lawyer check standing and specificity before paying anything. An Abmahnung with defects is still a legal deadline. It is just not automatically a bill.
What actually reduces risk
Strip out the fear and the work is unglamorous and finite. The technical benchmark runs through EN 301 549 to WCAG level AA, and the failures that get cited first are the ones a machine can find: contrast below 4.5:1, missing alternative text, unlabelled form fields, empty links, keyboard traps.
- Scan every German-market site you are responsible for and fix the machine-detectable failures. This is the cheap half and it removes the easiest allegations.
- Publish an accessibility statement. It is a distinct obligation from the site being accessible, and its absence is trivially provable by anyone looking for something to cite.
- Document what you did and when. Demonstrated, ongoing effort is what turns a hostile letter into a negotiation.
- Monitor for regressions. A site that passed in March and shipped a redesign in June is not a site that passes in June.
We wrote up the statutory detail — scope, the microenterprise exemption, transition arrangements and how the Abmahnung risk actually compares to the regulator — in our BFSG guide for websites on WCAG Inspector, the accessibility audit tool we are building alongside CookieInspector.
The pattern repeats because it works: a real European obligation arrives, the panic content arrives first, and the actual remediation turns out to be a scan and a checklist. CookieInspector’s agency tools do that job for consent and trackers; WCAG Inspector is the accessibility half — join the waitlist for early access.