Website compliance check 2027: what changes, what to verify
Most of what applies to an SMB website in 2027 is already law. This is the calendar of dates that matter, the rules that do not change, and a checklist that says which items a scan can verify and which need a person.
For most SMB websites, no single new compliance law switches on in 2027. Almost everything that applies to an SMB website next year already applies today: the European Accessibility Act, EU cookie consent under GDPR and ePrivacy, the UK’s amended PECR, and the EU AI Act’s chatbot disclosure duty. What 2027 adds is a short list of dated obligations, mostly for Australian privacy policies and US public-sector websites, on top of rules that have been in force for a while. This post is the calendar of those dates, the rules that do not change, and a checklist that says which items a scan can verify and which need a person. For what an audit covers in general, start with what a website compliance audit is.
Most dates below are ones we cite elsewhere on this site with their sources; the linked posts carry the detail. Where something is a proposal rather than law, it says so, with the date we last checked.
Dates in and around 2027
Accessibility: EU, UK, US, Canada, Australia
- European Accessibility Act: in force since 28 June 2025 for websites and apps used by consumers. The transitional rule in Article 32 (service continuity until 28 June 2030) only covers services that were already using pre-2025 products or contracts; it is not a general deadline extension. Details in EAA compliance for SMBs and the microenterprise exemption.
- Technical standard: EN 301 549 v3.2.1 still references WCAG 2.1 AA. A revision tracking WCAG 2.2 is expected; until it is published and cited, 2.1 AA is the floor and 2.2 the recommendation. See WCAG 2.1 vs 2.2: which applies.
- United States, ADA Title II: state and local government websites must meet WCAG 2.1 AA by 26 April 2027 for larger public entities and 26 April 2028 for smaller ones, after a Department of Justice interim final rule on 20 April 2026 pushed the dates back. Title III (private businesses) has no technical rule; the bar is set by litigation. The dates are in WCAG 2.1 vs 2.2; the private-sector picture is in the ADA audit guide.
- United Kingdom: the Equality Act’s anticipatory duty names no standard; public-sector bodies are assessed against WCAG 2.2 AA under current GOV.UK guidance.
- Canada, Ontario: the AODA’s IASR still names WCAG 2.0 AA. It has not been amended to 2.1 or 2.2.
- Australia: the Disability Discrimination Act names no version; the AHRC’s April 2025 guidelines point to WCAG 2.2 AA. See website compliance in Australia.
Privacy and cookies
- EU: the ePrivacy Directive’s Article 5(3) consent rule and the GDPR apply as before. The European Commission’s Digital Omnibus proposals include changes to how cookie consent works. As at September 2026 that part is still being negotiated by Parliament and Council and is not law. Do not change a banner on the strength of it until it is adopted and its start date is known. Today’s rule is in what “reject all” has to do.
- UK: since 5 February 2026 the Data (Use and Access) Act 2025 exempts certain low-risk cookies, first-party aggregate analytics among them, from PECR consent, and raised the PECR penalty ceiling to the UK GDPR level. The ICO’s cookie guidance is the reference; the change is summarised in multi-jurisdiction website compliance.
- Australia: from 10 December 2026 the new APP 1.7 to 1.9 require a privacy policy to describe automated decision-making that significantly affects individuals. The small business exemption (turnover of AUD 3 million or less) is still in place; its repeal was deferred to a later tranche and, as at 20 August 2026, no Bill has been introduced. See the Privacy Act small business exemption.
AI on your website
EU AI Act, Article 50: transparency duties for AI that interacts with people have applied since 2 August 2026: a chatbot must say it is one, and some AI-generated content, deepfakes and AI-written text published on matters of public interest, has labelling duties. The Act’s other tiers concern high-risk systems, not a marketing site with a chat widget; their dates have been the subject of amendment proposals and are outside this post. See AI chatbots on your website.
What does not change in 2027
- Consent before non-essential cookies, pixels and browser storage in the EU, with a reject option as easy as accept. Tracking pixels firing before consent are among the most common failures we see. See tracking pixel audit.
- WCAG 2.1 AA as the practical accessibility bar everywhere, with 2.2 as the target if you are building or rebuilding now.
- A privacy policy that names what you collect and who receives it, an accessibility statement where the EAA applies, and an Impressum in Germany and Austria. See Impressum requirements.
- No overlay shortcut. A script tag does not make a site accessible, and the FTC’s January 2025 settlement with accessiBe is the reference point for why claims to the contrary are risky.
The 2027 checklist
Each item ends with who can verify it. A clean scan covers only what a scan can see.
- No cookie, pixel or storage write before consent on every page a scan crawls. Scan: it verifies what the browser does; it cannot see server-side tracking, and it sees one moment in time.
- Reject as easy as accept, no pre-ticked boxes. Scan, then person: the scan finds the controls it recognises, a person confirms that rejecting stops the tags.
- Every vendor that loads is named or categorised in the privacy policy. Scan, then person: the scan flags vendors it cannot find in the policy text, a person judges whether a category description is specific enough.
- Automated WCAG checks pass on every page: alternative text, form labels, contrast, language, ARIA, link and button names. Scan.
- The criteria an automated check cannot judge: keyboard operation end to end, focus order and visibility, meaningful alt text, error messages, consistent navigation. Person.
- Accessibility statement present and current where the EAA applies. Scan, then person: the scan verifies presence, a person verifies the claims inside it.
- Chatbot disclosure and AI-use notice if you run a chat widget for EU visitors, or publish deepfakes or AI-written text on matters of public interest. Scan, then person: the scan detects known chat widgets and whether a disclosure phrase is present; it does not detect AI-generated content. A person confirms the wording.
- Australian privacy policy describes automated decisions by 10 December 2026, if you are an APP entity. Person.
- Public-sector work in the US meets WCAG 2.1 AA by the Title II date that applies to the client. Scan, then person, as in items 4 and 5.
- Re-check after every deploy. A new tag or a redesign can undo a fix on a page that was clean. Scan, on a schedule. See re-scanning after a fix.
How Veracly runs the check
Veracly scans the pages it crawls for the automated items above, grades them per jurisdiction that applies to your markets, and issues a signed PDF you can verify without trusting us. Every report also carries a version-labelled inventory of all 55 WCAG 2.2 Level A and AA criteria (4.1.1 Parsing is obsolete and noted separately), marking each as partly automated, an automated review signal, or not automated, and stating what a person still has to check. It does not say you are compliant, because no automated tool can. It lists what it checked and what it could not see. The full map of what is checked per country is in coverage by country.
If you want the 2027 check done now rather than in January, the free scan covers one page and takes about five minutes. The paid plans re-run it on a schedule so the checklist stays true after the next deploy.
Common questions
Is there a new website compliance law in 2027?
For most SMB websites, no single new law switches on in 2027. The rules that matter are already in force: the European Accessibility Act since 28 June 2025, GDPR and the ePrivacy cookie rule, the UK PECR changes since 5 February 2026, and the EU AI Act Article 50 transparency duties since 2 August 2026. The dated items that land around 2027 are narrower: Australian privacy policies from 10 December 2026, and US state and local government websites from 26 April 2027 or 2028.
Does WCAG 2.2 become mandatory in 2027?
Not by any law we know of. WCAG 2.2 is the current W3C version and the sensible build target, but the EU harmonised standard EN 301 549 v3.2.1 still references WCAG 2.1 AA, the US Title II rule locks in 2.1 AA, Ontario's AODA still names 2.0 AA, and the UK Equality Act names no version at all. A revision of EN 301 549 tracking 2.2 is expected; until it is published and cited, 2.1 AA is the legal floor in the EU and 2.2 is the recommendation.
Do I need to change my cookie banner in 2027?
In the EU the rule has not changed: consent before any non-essential cookie or tracker, a reject option as easy as accept, and no pre-ticked boxes. The European Commission has proposed changes to the cookie rule in its Digital Omnibus proposals; as at September 2026 that part has not been adopted, so check its status before relying on it. In the UK, since 5 February 2026 certain low-risk cookies such as first-party aggregate analytics no longer need consent, and the PECR penalty ceiling now matches UK GDPR. If you serve both markets, the EU rule is the stricter one and the safe default.
What changes for ADA website compliance in 2027?
For private businesses (Title III) nothing changes: there is still no federal technical rule, only case law that treats WCAG 2.0 or 2.1 AA as the bar. The 2027 date belongs to Title II: state and local government websites must meet WCAG 2.1 AA by 26 April 2027 for larger public entities and 26 April 2028 for smaller ones, after a Department of Justice interim final rule on 20 April 2026 pushed the dates back. If you build sites for public bodies, that is your deadline.
See where your site stands.
Run a free Veracly scan and get a multi-jurisdiction report, EAA, GDPR, ADA, UK Equality Act, AODA, with copy-paste developer fixes.
Run a free scan