Legal & Compliance
Accessibility, privacy, consent, and website disclosure requirements explained.
- ADA Title II: Web Accessibility Requirements for State and Local Government
The DOJ's 2024 rule under ADA Title II sets explicit WCAG 2.1 AA requirements for US state and local government websites and apps. An April 2026 DOJ interim final rule pushed the compliance dates to 2027 and 2028.
- ADA Title III: Web Accessibility for Private Businesses
ADA Title III covers private businesses open to the public, but has no explicit web accessibility regulation — courts have filled that gap by treating WCAG AA as the practical benchmark.
- Section 508: Accessibility Requirements for US Federal Agencies
Section 508 of the Rehabilitation Act requires US federal agencies and their vendors to meet accessibility standards aligned with WCAG — covering procurement, not just agencies' own sites.
- The European Accessibility Act and EN 301 549
The EU Accessibility Act has applied since June 2025. EN 301 549 v3.2.1 is harmonised for the Web Accessibility Directive and is useful guidance while EAA-specific harmonised standards are developed.
- What Is a VPAT? Voluntary Product Accessibility Templates Explained
A VPAT is a standardized document where a vendor reports how their product conforms to accessibility standards, criterion by criterion. Here's what's actually in one, and why it always says DRAFT.
- Web Accessibility Lawsuit Trends: Reading the Evidence
Understand the scope of digital accessibility lawsuit reports and why scan results cannot predict legal exposure.
- EU Cookie Consent: Prior Consent, Equal Choices, and Withdrawal
Understand when EU websites need consent before cookies or tracking, what equal accept and reject choices mean, and why withdrawal must stay easy.
- Third-Party Fonts, Embeds, and Website Privacy
Learn why remotely loaded fonts, videos, maps, and widgets can disclose visitor data before consent and how AllyProof observes those requests.
- German Website Legal Notice (Impressum) Requirements
Understand when German websites need an accessible Impressum, which provider details it may need, and when an editorial responsible person must be named.
- GDPR Privacy Notice Requirements for Websites
A practical guide to accessible website privacy notices, Article 13 disclosures, observed trackers, readable language, and what an automated check can verify.
- Website TLS, HTTPS, Mixed Content, and Privacy Security
Learn how HTTPS and mixed-content observations relate to GDPR security duties and what AllyProof can and cannot conclude from a browser scan.
- EU ODR Platform Closed: Should Websites Remove the Old Link?
The EU Online Dispute Resolution platform closed in 2025 and its founding regulation was repealed. Learn what AllyProof's stale ODR link check means.
- BFSG Accessibility Information for Services
Understand Germany's BFSG requirement to provide public accessibility information for covered services and what a website scan can verify.
- EU Online-Shop Withdrawal Information and Model Form
Learn what EU and German distance sellers generally disclose about withdrawal rights, deadlines, procedures, return costs, and the model form.
- California Privacy Policy and Notice at Collection
A practical guide to CCPA/CPRA privacy-policy disclosures, Notice at Collection, request methods, annual updates, language, and accessibility.
- California Privacy Choice Links: Do Not Sell or Share and Limit Use
Understand when CCPA/CPRA websites need Do Not Sell or Share, Limit Sensitive Information, or alternative Your Privacy Choices controls.
- Global Privacy Control (GPC) and the Sec-GPC Header
Learn how Global Privacy Control works through Sec-GPC and navigator.globalPrivacyControl, when California businesses must honor it, and what AllyProof tests.