Compliance

Why Your Web Developer Cannot Be Held Responsible for Your Compliance

May 30, 2026  •  4 min read

The most dangerous misconception in digital compliance — and the one that leaves business owners most exposed. Understanding who is legally responsible for your website’s compliance.

One of the most common responses we hear when speaking with business owners about website compliance is a variation of: “That is my web developer’s responsibility.” Or: “The agency that built our site handles that.” Or even: “We pay for a maintenance contract — surely they take care of compliance.”

This belief is understandable, widespread and completely incorrect. More importantly, it is the single belief most likely to result in a business owner being personally caught off guard by a regulatory investigation or a lawsuit.

What the Law Actually Says

Under GDPR, the legally responsible party for data processing activities on a website is the data controller — the entity that determines the purposes and means of processing personal data. In almost all cases, this is the business that owns and operates the website. Not the agency that built it. Not the developer who maintains it. The business owner.

Under the European Accessibility Act, the responsible party is the economic operator — the business providing the service to consumers. Again, this is the business, not its contractors.

In the United States, ADA website lawsuits name the business as the defendant. A plaintiff who sues over an inaccessible restaurant booking website is suing the restaurant — not the web design studio.

Why the Developer Is Not Responsible

Web developers and agencies are service providers. They build what they are asked to build, within the brief they are given and to the standards their clients require. Compliance with legal frameworks is generally not part of a standard web development brief unless it is explicitly requested and specified.

Most web developers are not compliance experts. They are designers and engineers. Many are not aware of the specific requirements of GDPR cookie consent, WCAG 2.1 accessibility standards or the European Accessibility Act. They are not expected to be — that is not their area of expertise.

Even if a developer builds a non-compliant site, any legal consequences flow to the business that operates it, not the contractor who built it. The developer may have contractual liability to the business owner in some cases, but that is a separate civil matter between the parties — it does not affect the business’s obligations to regulators or plaintiffs.

The Practical Implication

This means that responsibility for compliance rests with you as a business owner, and that you need to actively ensure your website meets its legal obligations — either by acquiring the knowledge to assess it yourself, or by engaging specialists who can do so on your behalf.

It also means that when you engage a web developer for a new project or a redesign, compliance requirements need to be explicitly specified in the brief. If you do not ask for WCAG 2.1 Level AA compliance, you should not expect to receive it. If you do not specify that cookie consent must be GDPR-compliant, a developer may implement whatever looks convenient.

What This Means for Existing Sites

If your website was built by an agency and you have been assuming they handled compliance, the right action is to have it audited — ideally before a regulatory investigation or a lawsuit prompts you to do so.

A compliance audit will tell you exactly what your site’s current status is, which issues carry the most significant legal risk and what needs to be fixed in what order. You can then take those findings back to your web developer with a clear, specific brief — which is exactly the kind of instruction they need to address the issues correctly.

The cost of an audit is a fraction of the cost of discovering these issues through enforcement. The time invested in compliance now is the time you do not spend dealing with a regulatory investigation later.

Is your website compliant?

A Veritron compliance audit covers GDPR, the European Accessibility Act, WCAG 2.1 and ADA — delivered as a comprehensive written report with developer-ready recommendations. Starting at $599.

View Audit Packages →

← Back to Insights