Skip to main contentOpen accessibility widget
Compliance

Ireland EAA Fines: €60,000 and Criminal Liability

Ireland's EAA fine: €60,000, 18 months in prison, and directors can be charged.

Alen Velkov

Alen Velkov

Author

Ireland - EAA Fines

Ireland's EAA Enforcement: Director Liability and Criminal Sanctions

Ireland doesn't just fine companies for accessibility failures — it makes non-compliance a criminal offence, with up to 18 months' imprisonment and personal liability for directors. Here's exactly what the law says.

Quick answer

In Ireland, breaking the EAA is a criminal offence, not just an administrative one. On conviction on indictment, the penalty is a fine of up to €60,000, up to 18 months in prison, or both (S.I. 636/2023, Reg. 32). Directors, managers and officers can be personally prosecuted where the breach involved their consent, connivance or neglect. There's a written-in due-diligence defence for businesses that can prove a real compliance process — and no prosecutions have been confirmed yet.


Why Ireland is different

Most EU countries treat an accessibility breach as an administrative matter: a regulator investigates, orders a fix, and can levy a fine. Ireland goes further. Under S.I. No. 636/2023 — the regulations that brought the EAA into Irish law on 28 June 2025 — non-compliance is a criminal offence. That changes the nature of the risk in three ways that a euro figure alone doesn't capture:

  • There's prison time on the table — up to 18 months.
  • Individuals, not just the company, can be prosecuted — directors, managers, company secretaries.
  • A conviction is a criminal record, with all the reputational and procurement consequences that carries.

The €60,000 headline fine is almost the least of it.

Summary conviction (District Court)Conviction on indictment (higher court)
Maximum fineClass A fine (up to €5,000)€60,000
Maximum prison term6 months18 months
Both?Yes, fine and prison can be combinedYes, fine and prison can be combined
Legal basisS.I. 636/2023, Reg. 32(6)(a)S.I. 636/2023, Reg. 32(6)(b)

What the law actually says

The penalties are set out in Regulation 32(6):

"A person who commits an offence under these Regulations shall be liable — (a) on summary conviction to a class A fine or to imprisonment for a term not exceeding 6 months or to both, or (b) on conviction on indictment to a fine not exceeding €60,000 or to imprisonment for a term not exceeding 18 months or to both."

— S.I. No. 636/2023, Reg. 32(6) (Irish Statute Book)

("Class A fine" is the summary-court maximum — up to €5,000 under the Fines Act 2010.)

And the personal-liability provision, Regulation 33(1), is the one directors need to read:

"Where an offence under these Regulations is committed by a body corporate and is proven to have been so committed with the consent, connivance or approval of, or to be attributable to any wilful neglect on the part of, any person, being a director, manager, secretary or other officer of the body corporate… that person, as well as the body corporate, commits an offence…"

— S.I. No. 636/2023, Reg. 33(1)

In plain terms: if the company offends and a director let it happen, the director can be charged too — and punished as if personally guilty.

The penalty scales with the harm

Ireland doesn't apply a flat penalty. Regulation 32(7) tells the court to weigh three things when sentencing: the seriousness of the non-compliance, the number of units of products or services involved, and the number of people affected. The practical effect: the bigger your reach, the harsher the likely sentence within those bands. A large consumer platform faces a very different sentencing calculus from a small shop.

Crucially, the regulations give businesses a real, statutory defence. It is a defence to prove you "exercised due diligence and took all reasonable precautions to avoid the commission of the offence." This is the single most important line in the Irish regime for a compliant business: a documented, dated accessibility process isn't just good practice — it's a written-in legal defence against criminal liability. It's the difference between "we tried" and "we can prove we tried."

Who enforces it

Ireland splits enforcement across six sector regulators, and — unusually — each can prosecute within its own remit:

RegulatorCovers
CCPC (Competition & Consumer Protection Commission)Products, e-books, software, e-commerce
ComRegElectronic communications services
Coimisiún na MeánAccess to audiovisual media
Central Bank of IrelandConsumer banking (incl. credit unions)
National Transport AuthorityBus, rail, waterborne transport
Irish Aviation AuthorityAir passenger transport

(The National Disability Authority advises them but does not enforce.) Authorised officers have real teeth under Regulation 31 — they can enter and search premises, obtain a warrant, and use reasonable force to execute it; obstructing one is itself an offence.

There's also a civil route running in parallel: regulators can issue compliance and prohibition notices, and — notably — consumers can apply directly to the Circuit Court for an order forcing compliance, with interest groups able to back those claims. Irish legal analysts compare this to the public-interest litigation pattern seen under GDPR.

Has it been enforced yet?

Not yet — as of now, no criminal prosecutions or Circuit Court cases under S.I. 636/2023 have been confirmed. But the framework is fully in force, the six regulators are operational, and the sentencing structure is detailed and ready to use. The absence of a first case is a matter of timing, not of a paper law.

What this means for your business

If you offer a consumer product or service in Ireland, treat this as a criminal-compliance issue, not a "we might get fined" issue — because the exposure reaches your directors personally. Two things follow. First, get to EN 301 549 / WCAG 2.1 AA with genuine, tested accessibility. Second — and this is Ireland-specific — build and keep the paper trail, because the due-diligence defence only works if you can produce dated evidence of the precautions you took. (One useful filter: purely B2B offerings are generally outside scope; the regime targets consumer-facing products and services.)

Frequently asked questions

Can you go to prison for an EAA breach in Ireland?

Yes. On conviction on indictment, the penalty can include up to 18 months' imprisonment, a fine up to €60,000, or both.

Can directors be held personally liable?

Yes. Under Regulation 33, a director, manager or officer can be prosecuted personally where the offence involved their consent, connivance or wilful neglect.

Is there any defence?

Yes — a statutory due-diligence defence. If you can prove you took all reasonable precautions and exercised due diligence, that's a defence. Documented compliance is what makes it work.

Who prosecutes?

Whichever of the six sector regulators covers the product or service — each prosecutes within its own remit.


Share this post

You might also like

Two more articles worth reading while this topic is still fresh.

Lithuania - EAA Fines

Lithuania EAA Fines: €500–€15,000, and Fintechs Now Covered

Lithuania fines EAA breaches €500–€15,000 and amended its law twice in 2026.

Latvia - EAA Fines

Latvia EAA Fines: €20,000 for Products, Orders for Services

Latvia EAA Fines: €20,000 for Products, Orders for Services