The pre-launch checklist everyone shares is missing two things
There is a checklist going around: twenty things to run through before a website goes live. Most of it maps cleanly onto what Google itself asks for. It is also written from a United States point of view, and two of the things it treats as single checkboxes are, in the EU, separate legal obligations. If you are launching into a European market, those two are the ones that can come back to you.
Here is the list, as it circulates: privacy policy, terms, a clear call to action, an FAQ, robots.txt, sitemap.xml, a custom 404, alt text, analytics, meta titles and descriptions, social share images, a favicon, canonical URLs, cookie consent, a mobile version, accessibility, working forms, no broken links, decent performance.
It is a good list. Most of it maps cleanly onto what Google itself asks for in Search Essentials, and if you tick all twenty you are ahead of most sites that launched last week.
The two worth a second look are accessibility and cookie consent. Each sits in the list as a single line. In the EU, neither of them is a single thing.
1. “Accessibility” is not one checkbox. It is a standard and a public statement.
The list has one line for accessibility. In the EU that line covers two different obligations.
The first is the content itself. The European Accessibility Act applies to products and services placed on the market from 28 June 2025 onward. The directive names no technical standard, and no reference has been published in the Official Journal under it so far. What people work with is EN 301 549, a European standard for accessible ICT: version 3.2.1 carries WCAG 2.1 level AA, and version 4.1.1, published in September 2026, carries WCAG 2.2 level AA. That is the part most people think of: contrast, keyboard access, labels, focus order.
The second obligation is a document. You publish a statement that says how your site meets those requirements, where it does not, and how someone can reach you if they run into a barrier. It is a separate, public page, and it is not produced by fixing your contrast ratios. A site can pass every automated check and still be missing it.
This is the one that surprises people, because “accessibility” reads like a technical task and the statement is a written one.
2. “Cookie consent” is not the same as a cookie banner.
The list says cookie consent, and most teams read that as “add a banner.” A banner is the easy part.
Under the ePrivacy rules combined with the GDPR, consent has to be a real choice. Three things follow from that, and they are not the same thing.
The first is about timing, not design, and it is the one that catches most sites. Non essential cookies and trackers may not be placed on a visitor's device, or read from it, before that visitor says yes. On 7 December 2020 the French regulator fined Google 100 million euro and Amazon 35 million for that alone, with a further 100,000 euro per day if it was not fixed within three months. The Google decision records exactly what the inspectors saw on arrival at the page: seven cookies “déposés sur leur équipement terminal, avant toute action de leur part”, placed on the device before the user did anything. A consent banner that appears while your analytics has already loaded is that same finding. Two limits worth knowing: strictly necessary cookies are exempt, and the rule is about reading from or writing to the device, whether or not what you read is personal data. Continuing to scroll is not a choice either.
The second is settled and enforced too. On 31 December 2021 the same regulator fined Google 150 million euro and Facebook Ireland 60 million euro for exactly one design detail: accepting cookies took one click, refusing took several. The decision puts it plainly (Facebook, SAN-2021-024): “il doit être aussi facile de refuser les cookies que de les accepter”, it must be as easy to refuse cookies as to accept them. Both decisions came with a further 100,000 euro per day if the banners were not fixed within three months.
The third is narrower than people often claim. The European Data Protection Board, writing with eighteen national regulators in January 2023, does say a banner with no refuse option on the first layer is an infringement, and that a refuse option hidden behind a vague link or rendered in text that is effectively unreadable is misleading. It stops short of prescribing that the refuse button must be the same size or colour as the accept button. So: a refuse option on the first screen, at the same level and not visually buried, is the line you can rely on. Matching pixel for pixel is good practice, not a published EU rule.
There is a simpler version of the same problem worth checking first: whether you need the banner at all. If your analytics do not set cookies and do not track people across sites, you may not need consent for them. Fewer things to get right is usually the better fix.
What we would add to the list
Four items, numbered 21 to 24 in the same style as the original twenty. The first three apply to any launch into the EU. The fourth applies only if your site uses AI, which is why it sits apart from the two obligations above.
- A published accessibility statement, not just accessible content.
- Nothing fires before the choice, not just a banner on top of scripts that already ran.
- Reject as easy as accept, not just a cookie banner.
- Say when it is AI, if your site uses any. Since 2 August 2026 the AI Act asks for that, and it is a subject of its own.
One honest note about checking this
Automated tools, including ours, find the machine testable layer. Our scanner tests 31 of the 55 WCAG AA criteria by machine, in full or in part. That is a real and useful layer, and it is not the whole picture: judgement calls, screen reader flows and real user paths need a person. Nobody can promise you a compliant website from a scan, and anybody who does is telling you something about their sales process rather than about their product.
What a scan is good at is telling you where to start, and giving you something concrete to hand to whoever does the work.
Two of the twenty-three are things you can check in a minute.
Start the free scanSources
- Google Search Essentials, the guidelines most of the original list maps onto
- Directive (EU) 2019/882 (European Accessibility Act), applicable to products and services placed on the market from 28 June 2025, with the public information duty in article 13(2) and annex V
- EN 301 549, a European standard for accessible ICT, used in practice for websites
- CNIL, délibération SAN-2020-012 of 7 December 2020 (Google, 100 million euro for cookies placed before any user action, with 100,000 euro per day); Amazon was fined 35 million the same day in SAN-2020-013
- CNIL, délibération SAN-2021-024 of 31 December 2021 (Facebook Ireland, 60 million euro); Google was fined 150 million the same day in SAN-2021-023
- EDPB, Report of the work undertaken by the Cookie Banner Taskforce, 17 January 2023
Correct as of 8 September 2026. The legal basis for the cookie rules is on the move: the ePrivacy Regulation proposal was withdrawn in February 2025 and a later proposal would move the cookie rules into the GDPR framework, so this is worth rechecking rather than filing away. Wexlo scans websites for accessibility and is open about what automated testing does and does not see. This article is information, not legal advice.