Skip to content
AI Nova Apps
Mobile Apps

Selling Apps in the EU: Accessibility Act, AI Act & GDPR Checklist for 2026

What app teams must build for EU users in 2026–2027: European Accessibility Act, AI Act chatbot transparency, GDPR, the Data Act, EUDI wallets, payments and iOS distribution.

AI Nova Apps Team 4 min read
Selling Apps in the EU: Accessibility Act, AI Act & GDPR Checklist for 2026
Table of Contents

If you sell an app or online service to people in the European Union, 2025–2027 brings more new obligations than any period since GDPR. The European Accessibility Act now applies, the AI Act's transparency rules started in August 2026, and the Data Act and digital identity wallets are arriving. This checklist is for product owners and CTOs who need to know what to build — not a legal treatise.

1. European Accessibility Act (in force since 28 June 2025)

Who it covers: consumer-facing e-commerce, consumer banking services, e-books and e-reading software, passenger-transport services such as ticketing and journey information, electronic communications and access to audiovisual media. Microenterprises providing services are exempt.

What to build:

  • Meet EN 301 549, which currently means WCAG 2.1 level AA. A new version based on WCAG 2.2 was published in September 2026 and is expected to become the reference standard, so building to WCAG 2.2 AA now saves a second round of work.
  • Label every control for screen readers, support dynamic text sizes, keep colour contrast above the minimum and make every flow usable with a keyboard or switch access.
  • Test with VoiceOver on iOS and TalkBack on Android before each release, not only with automated scanners.
  • Publish the accessibility information the Act requires — usually in your terms or a dedicated page — explaining how the service meets the requirements.

2. EU AI Act — transparency for chatbots (since 2 August 2026)

Most apps that use AI are not "high-risk" systems. But if users interact with an AI system, you now have transparency duties under Article 50:

  • Tell people they are talking to an AI, unless it is obvious from the context.
  • Mark AI-generated audio, images, video and text in a machine-readable way. Systems already on the market before August 2026 have until 2 December 2026.
  • Label deepfakes and AI-generated text published to inform the public.

High-risk uses — such as recruitment, credit scoring, education and access to essential services — carry much heavier obligations. After the 2026 "digital omnibus" amendment, they apply from 2 December 2027 for standalone systems and 2 August 2028 for AI built into regulated products. If your feature might fall into one of these categories, start documenting training data, testing and human oversight now.

3. GDPR — still the foundation

  • Consent screens that record what each user agreed to and let them change it later.
  • Self-service data export and account deletion.
  • Logging and alerting that let you assess a breach and notify your regulator within 72 hours.
  • A list of every sub-processor — analytics, crash reporting, email, AI APIs — with where data goes.
  • If any part of your team or a supplier is outside the EU in a country without an adequacy decision, use Standard Contractual Clauses and a transfer impact assessment. The EU–US Data Privacy Framework survived its first court challenge in September 2025, but an appeal is pending.

4. Data Act — if your app talks to a device

The Data Act has applied since 12 September 2025. For connected products and their companion apps placed on the market from 12 September 2026, users must be able to access the data their device generates by design. Plan export and sharing APIs into the architecture.

5. EU Digital Identity Wallet — plan for 2027

Member states must offer EUDI Wallets by the end of 2026. By the end of 2027, organisations that are legally or contractually required to authenticate users strongly — banks, payment providers, telecoms, energy, health and transport among them — must accept the wallet if a user chooses it. Design onboarding so a wallet sits alongside your existing KYC or login provider.

6. Payments and invoicing

  • SEPA Instant is now universal among euro-area banks, making pay-by-bank more practical.
  • Local methods matter: iDEAL | Wero in the Netherlands, Bancontact in Belgium, BLIK in Poland, Vipps MobilePay and Swish in the Nordics. giropay closed in 2024 and Sofort became part of Klarna — remove them if they are still in your checkout.
  • B2B e-invoicing is spreading: Belgium (Peppol, since January 2026), France (from September 2026) and Germany (issuing from 2027–2028), with EU-wide intra-community e-invoicing from July 2030.

7. iPhone distribution under the DMA

In the EU, iPhone apps can be distributed through alternative app marketplaces or directly from the web, and apps can offer payment options other than Apple's. Apple revised its EU terms again from 1 October 2026, so compare fees and requirements for your business model before choosing a route.

Turning the checklist into a plan

The cheapest way to comply is to treat each item as an acceptance criterion from the first sprint. Retrofitting accessibility or consent into a finished app typically costs several times more than building it in. We build apps for European companies with these requirements planned from day one — see how we work with EU businesses and UK businesses, or read about our mobile app development service.

This checklist is general technical guidance, not legal advice. Confirm your obligations with your legal adviser.

Share this article:

Get Insights in Your Inbox

Practical guides on app development, AI and software — straight from our engineers. No fluff, just useful reads.

No spam. Unsubscribe anytime.

Back to all articles

Ready to Start Your Project?

Partner with AI Nova Apps and bring your vision to life with cutting-edge technology solutions.