Skip to content

Blog

What market surveillance under the BFSG really checks, and why the fine comes at the end

This article describes the situation in Germany. The rules are European, the enforcement is national, so both the deadlines and the amounts differ per country.

This article was translated from German. Where the two differ, the original is the one to go by. Read the authoritative version

The Market Surveillance Authority of the Federal States for the Accessibility of Products and Services (MLBF) conducts risk-based inspections, both proactively and reactively. Who is inspected depends primarily on user reach, company size, relevance to independent living and the results of automated preliminary checks. A fine is not the first step, but the last: first comes a request to make corrections within a reasonable period, followed by a restriction or prohibition, and only then a fine of up to 10,000 euros, or up to 100,000 euros for certain breaches of obligations. There is expressly no quantitative minimum inspection level for the current strategy period.

The BFSG is usually discussed in terms of a single figure: 100,000 euros. The figure is correct, it appears in § 37 of the law, and it says almost nothing about what actually happens to a provider. The more interesting question is who is inspected in the first place and in what order things happen. Since the beginning of 2026, there has been a first-hand answer to this question, as the competent authority has published its own strategy.

Who is responsible

The federal states have established a joint body to carry out the tasks under the BFSG: the Marktüberwachungsstelle der Länder für die Barrierefreiheit von Produkten und Dienstleistungen, abbreviated to MLBF, based in Magdeburg. There is a separate strategy document for services, including online shops and apps, dated 08.01.2026. It was created as an internal operational document and is publicly available.

Active and reactive, and what makes the difference

The authority distinguishes between two approaches. Active market surveillance is not triggered by a specific event: it consists of systematic inspections that are carried out continuously and evaluated regularly. Reactive market surveillance is triggered by a specific event and takes place on the basis of external information and through the processing of applications.

For active surveillance, the strategy lists the risk factors individually. They are worth reading verbatim because, taken together, they form the profile used for selection:

  • Market shares or user reach of a service or service category
  • Company size
  • Relevance to independent living
  • Complexity and interactivity of the service
  • Results of automated preliminary checks
  • Public user feedback and ratings
  • Market trends

The fifth point is the one you rarely find in summaries. The authority states that it relies on automated preliminary checks, particularly for web-based services, because technical testing software can cover a significantly larger number of services across the market than purely manual inspections. Selection therefore does not begin with a complaint, but with a machine-based preliminary scan of the market.

Being large does not help, being small does not protect you

A particular focus is placed on market-dominating services with a high user reach, because a lack of accessibility there affects a particularly large number of people. That is to be expected. The opposite is less expected, and it is stated there explicitly: even where absolute user numbers are lower, high market penetration is assumed if the provider holds a monopoly position in local or sectoral provision. If you are the only local provider, you are therefore of interest not because of your size, but because you are indispensable.

For niche offerings with a low market share, market penetration plays a subordinate role. The other risk factors are then weighted more heavily, such as complexity, interactivity and the results of the automated preliminary check.

Past performance matters, and so does cooperation

Service providers that have previously attracted attention because of formal or substantive deficiencies will be prioritised in future monitoring activities. And a second factor carries equal weight: willingness to cooperate. Those that have shown little willingness to participate are assessed as presenting a higher risk. The way a company responds to the first request therefore affects the second.

The staged model: the fine comes last

Enforcement follows the principle of proportionality and a staged model. Three stages, in this order:

  • Request for correction. If formal or substantive non-conformance is identified, the authority will first request that the deficiency be remedied within a reasonable period.
  • Restriction and prohibition. If conformance is not achieved within the specified period, an order may follow requiring the offering or provision of the service to cease.
  • Fine. Breaches of individual obligations also constitute administrative offences and may be punished with a fine of up to 10,000 euros, or up to 100,000 euros for certain breaches of obligations.

This changes the question that a provider should ask. The question is not how high the fine could be in the worst case, but whether the provider can remedy the alleged deficiency within a reasonable period. If you do not know what is broken on your site, you cannot assess or make use of that period.

The detail that contradicts the usual narrative

The strategy contains a paragraph that does not appear in any provider summary we found. Since the provisions of the BFSG apply only from 28 June 2025, there are no historical data on case numbers or deficiency rates for the current strategy period from which a quantitative minimum inspection level could be derived. The strategic focus is therefore on responsiveness and the qualitative development of a data basis.

In plain language: there is no target number of inspections for this period. That is the opposite of what a countdown on a provider’s website suggests, and it is not a free pass either. A significant share of resources goes towards substantiated triggers arising from reactive monitoring, and these take priority because of the statutory framework.

What triggers action

The strategy lists the sources of information from which proceedings may arise:

  • Applications under § 32 BFSG, submitted by consumers or recognised associations.
  • Declarations of exemptions under §§ 16 and 17 BFSG, meaning reliance on a fundamental alteration or a disproportionate burden.
  • Notifications by providers themselves under § 14 BFSG, when they determine that a service does not conform.
  • General reports under § 22 BFSG: information from third parties, media reports and complaints that do not meet the formal requirements for an application but provide grounds for action.

The third source deserves a second look, because it is an obligation, not an option. If a service provider finds that its service does not conform to the requirements, it must immediately take the necessary corrective measures and immediately inform the authority of the nature of the non-conformity and the measures taken.

A note to put the figures currently circulating into context: The wave of cease-and-desist letters in August 2025 did not come from market surveillance. They were largely identical letters from lawyers claiming costs of around 600 euros, sent on behalf of a marketing and SEO provider, without identifying a specific infringement and with the sender's status as a competitor being disputed. A letter from a lawyer and an official measure are two different things that require different responses.

What this means in practice

  • Assess where you stand in relation to the risk factors. Reach, company size, relevance to independent living, complexity and interactivity are not matters of opinion, but can be described objectively.
  • Expect the initial review to be automated. The authority itself states that it carries out preliminary checks of web-based services using technical testing software.
  • The decisive factor is the deadline, not the maximum amount. If you know what is broken and how serious it is, you can make use of a reasonable deadline. If you do not know, you lose that opportunity.
  • Take the initial request seriously. Willingness to cooperate is expressly listed as a risk factor for the further assessment.
  • If you identify a non-conformity yourself, you have a reporting obligation under § 14 Abs. 4 BFSG. This is mandatory, not optional.

Frequently asked questions

How high is the fine under the BFSG?
Up to 10,000 euros, and up to 100,000 euros for certain breaches of obligations. These are statutory maximum amounts under Section 37 BFSG, not standard rates. There are two stages before a fine: a request to make corrections within a reasonable period and the possible restriction or prohibition of the service.
Has a fine already been imposed under the BFSG?
We are not aware of any. As at 17 August 2026, the MLBF publishes neither penalty notices nor a list of cases, and we have not found any other reliably documented individual case. This is a statement about what can be found, not about what exists: there is no public register.
How likely is it that my shop will be inspected?
There is no figure for this. The strategy expressly states that no quantitative minimum inspection level has been set for the current period because the necessary historical data is lacking. Anyone who gives you a probability has not obtained it from this source.
Does the small size of my business protect me?
Not reliably. The size of the business is one of several risk factors. Even where there are few users, high market penetration is still assumed if the provider holds a monopoly in local or sector-specific provision. Irrespective of this, Section 3(3) BFSG exempts microenterprises in the case of services, and you should check whether you fall within this exemption by reference to the definition, not based on intuition.
Do I need a certificate or an audit?
The strategy does not establish any such obligation. It states that the service provider must ensure accessibility, provide the information required under Section 14(2) BFSG, fulfil its correction and notification obligations, and provide information in response to a reasoned request. It does not provide for a certification mark.
Does the authority exchange information with other EU Member States?
Yes, as needed, for the general exchange of experience. The BFSG does not provide for a formalised reporting system for services through central EU database systems such as ICSMS, and none is currently planned.

Sources

For web-based services, the authority begins with an automated preliminary check. You can take the same step yourself first: a free scan shows you the findings on your site and their severity, so that you can assess what can be implemented within a reasonable period.

Start a free scan

This article is for information purposes and does not constitute legal advice. We have read the cited texts from the authority and in the legislation itself, but rules change and your case may differ. If you are unsure about your own obligations, contact the competent body or a lawyer. Wexlo scans websites for accessibility and explains what automated testing covers and what it does not.

Test one page of your own site.

Free and without an account. Rather ask a question first? Use the contact form.