Ireland's EAA Enforcement: Director Liability and Criminal Sanctions
Ireland doesn't just fine companies for accessibility failures — it makes non-compliance a criminal offence, with up to 18 months' imprisonment and personal liability for directors. Here's exactly what the law says.
Quick answer
In Ireland, breaking the EAA is a criminal offence, not just an administrative one. On conviction on indictment, the penalty is a fine of up to €60,000, up to 18 months in prison, or both (S.I. 636/2023, Reg. 32). Directors, managers and officers can be personally prosecuted where the breach involved their consent, connivance or neglect. There's a written-in due-diligence defence for businesses that can prove a real compliance process — and no prosecutions have been confirmed yet.
Why Ireland is different
Most EU countries treat an accessibility breach as an administrative matter: a regulator investigates, orders a fix, and can levy a fine. Ireland goes further. Under S.I. No. 636/2023 — the regulations that brought the EAA into Irish law on 28 June 2025 — non-compliance is a criminal offence. That changes the nature of the risk in three ways that a euro figure alone doesn't capture:
- There's prison time on the table — up to 18 months.
- Individuals, not just the company, can be prosecuted — directors, managers, company secretaries.
- A conviction is a criminal record, with all the reputational and procurement consequences that carries.
The €60,000 headline fine is almost the least of it.
| Summary conviction (District Court) | Conviction on indictment (higher court) | |
|---|---|---|
| Maximum fine | Class A fine (up to €5,000) | €60,000 |
| Maximum prison term | 6 months | 18 months |
| Both? | Yes, fine and prison can be combined | Yes, fine and prison can be combined |
| Legal basis | S.I. 636/2023, Reg. 32(6)(a) | S.I. 636/2023, Reg. 32(6)(b) |
What the law actually says
The penalties are set out in Regulation 32(6):
"A person who commits an offence under these Regulations shall be liable — (a) on summary conviction to a class A fine or to imprisonment for a term not exceeding 6 months or to both, or (b) on conviction on indictment to a fine not exceeding €60,000 or to imprisonment for a term not exceeding 18 months or to both."
— S.I. No. 636/2023, Reg. 32(6) (Irish Statute Book)
("Class A fine" is the summary-court maximum — up to €5,000 under the Fines Act 2010.)
And the personal-liability provision, Regulation 33(1), is the one directors need to read:
"Where an offence under these Regulations is committed by a body corporate and is proven to have been so committed with the consent, connivance or approval of, or to be attributable to any wilful neglect on the part of, any person, being a director, manager, secretary or other officer of the body corporate… that person, as well as the body corporate, commits an offence…"
— S.I. No. 636/2023, Reg. 33(1)
In plain terms: if the company offends and a director let it happen, the director can be charged too — and punished as if personally guilty.
The penalty scales with the harm
Ireland doesn't apply a flat penalty. Regulation 32(7) tells the court to weigh three things when sentencing: the seriousness of the non-compliance, the number of units of products or services involved, and the number of people affected. The practical effect: the bigger your reach, the harsher the likely sentence within those bands. A large consumer platform faces a very different sentencing calculus from a small shop.
The due-diligence defence — your legal shield
Crucially, the regulations give businesses a real, statutory defence. It is a defence to prove you "exercised due diligence and took all reasonable precautions to avoid the commission of the offence." This is the single most important line in the Irish regime for a compliant business: a documented, dated accessibility process isn't just good practice — it's a written-in legal defence against criminal liability. It's the difference between "we tried" and "we can prove we tried."
Who enforces it
Ireland splits enforcement across six sector regulators, and — unusually — each can prosecute within its own remit:
| Regulator | Covers |
|---|---|
| CCPC (Competition & Consumer Protection Commission) | Products, e-books, software, e-commerce |
| ComReg | Electronic communications services |
| Coimisiún na Meán | Access to audiovisual media |
| Central Bank of Ireland | Consumer banking (incl. credit unions) |
| National Transport Authority | Bus, rail, waterborne transport |
| Irish Aviation Authority | Air passenger transport |
(The National Disability Authority advises them but does not enforce.) Authorised officers have real teeth under Regulation 31 — they can enter and search premises, obtain a warrant, and use reasonable force to execute it; obstructing one is itself an offence.
There's also a civil route running in parallel: regulators can issue compliance and prohibition notices, and — notably — consumers can apply directly to the Circuit Court for an order forcing compliance, with interest groups able to back those claims. Irish legal analysts compare this to the public-interest litigation pattern seen under GDPR.
Has it been enforced yet?
Not yet — as of now, no criminal prosecutions or Circuit Court cases under S.I. 636/2023 have been confirmed. But the framework is fully in force, the six regulators are operational, and the sentencing structure is detailed and ready to use. The absence of a first case is a matter of timing, not of a paper law.
What this means for your business
If you offer a consumer product or service in Ireland, treat this as a criminal-compliance issue, not a "we might get fined" issue — because the exposure reaches your directors personally. Two things follow. First, get to EN 301 549 / WCAG 2.1 AA with genuine, tested accessibility. Second — and this is Ireland-specific — build and keep the paper trail, because the due-diligence defence only works if you can produce dated evidence of the precautions you took. (One useful filter: purely B2B offerings are generally outside scope; the regime targets consumer-facing products and services.)
Frequently asked questions
Can you go to prison for an EAA breach in Ireland?
Yes. On conviction on indictment, the penalty can include up to 18 months' imprisonment, a fine up to €60,000, or both.
Can directors be held personally liable?
Yes. Under Regulation 33, a director, manager or officer can be prosecuted personally where the offence involved their consent, connivance or wilful neglect.
Is there any defence?
Yes — a statutory due-diligence defence. If you can prove you took all reasonable precautions and exercised due diligence, that's a defence. Documented compliance is what makes it work.
Who prosecutes?
Whichever of the six sector regulators covers the product or service — each prosecutes within its own remit.
Related
- ← Back to EAA Fines by Country — the full 27-state comparison
- Germany's EAA fines — administrative fines plus competitor warning letters
- How we verified all 27 national laws — our sourcing method



