How 100 Irish charity websites handle cookie consent
We checked what 100 of Ireland’s largest charity websites do with cookies before a visitor chooses anything. 47 set analytics or advertising cookies first.

Most Irish public bodies and charities receiving public funding are operating websites that breach a legally enforceable statutory obligation right now. That is the predictable consequence of a regulatory framework that has been in force since 2020 and remains largely unimplemented across the public and third sectors.
The European Union (Accessibility of Websites and Mobile Applications of Public Sector Bodies) Regulations 2020, transposed into Irish law as SI 358/2020, impose binding website accessibility requirements on a wide range of organisations, from government agencies and semi-state bodies to publicly funded charities and educational institutions. The technical standard at the centre of those requirements is WCAG 2.1 AA, and compliance must be documented through a formal accessibility statement monitored by the National Disability Authority.
This analysis covers the full scope of what SI 358/2020 actually demands. It examines which organisations are caught, what the technical and governance obligations involve, what evidenced conformance means in practice, and why the current vendor-led model of web management leaves most organisations directly exposed. If your organisation has not yet mapped this obligation formally, this is where to start.
A public body’s website answers to more than its visitors. It answers to a statutory framework that has been in force since 2020.
The European Union (Accessibility of Websites and Mobile Applications of Public Sector Bodies) Regulations 2020, enacted as SI 358/2020, transpose Directive 2016/2102 into Irish domestic law. The effect is unambiguous: for covered bodies, website accessibility compliance is a legal obligation rather than a statement of best-practice intent.
The regulations impose WCAG 2.1 AA as the mandatory technical baseline. Every website and mobile application operated by an in-scope body must meet this standard as a matter of law. There is no discretionary opt-out and no general provision allowing a body to defer on grounds of cost or complexity.
The National Disability Authority (NDA) is designated as Ireland’s official monitoring body under the directive. Its remit is active rather than passive: it assesses compliance across the public sector and reports its findings to the European Commission under a formal EU accountability mechanism. An organisation that assumes the NDA operates only as a guidance provider is misreading its statutory function.
Non-conformance under SI 358/2020 constitutes a breach of a statutory obligation. That classification matters because it shifts the risk profile entirely for governed bodies. This is not a reputational shortcoming that can be managed through communications; it is a compliance failure that creates accountability to funders, regulators, and the public.
Ireland’s implementation followed a phased schedule. Public sector websites published before 23 September 2018 were required to conform by 23 September 2020. Websites published on or after 23 September 2018 faced a conformance deadline of 23 September 2019. Mobile applications were required to conform by 23 June 2021.
Every one of those deadlines has passed. Any organisation within scope that has not achieved conformance is already in breach.
The deadlines established by SI 358/2020 have all passed, which means the immediate practical question is whether they apply to your organisation specifically.
Covered bodies under the regulations are “public sector bodies” as defined in Irish and EU administrative law. That category encompasses central government departments, state agencies, semi-state bodies, local authorities, publicly funded educational institutions from primary through third level, and HSE bodies and affiliates. If your organisation receives its funding from the Exchequer or operates under a statutory mandate, the starting assumption is that you are in scope.
The reach extends further than many organisations assume. Certain charities and NGOs that receive public funding may also be in scope. Whether the regulations apply to a particular third-sector organisation depends on its legal classification and funding relationship; legal counsel should be sought where scope is genuinely unclear. This is not a peripheral edge case. A significant portion of the Irish charity sector, including organisations that would not describe themselves as public bodies in any conventional sense, may carry the same statutory obligation as a government department.
For any organisation outside the obvious public-sector categories, scope should be assessed against the statutory definition of “public sector body” under the regulations rather than assumed.
Exemptions exist but are narrow. The regulations provide a set of defined exemptions; the full list is set out in the statutory text of SI 358/2020. The burden of demonstrating that an exemption applies rests with the organisation. An organisation that claims an exemption without documented justification is assuming a risk, not eliminating one.
Knowing which organisations are in scope is only half the picture. The next question is what, precisely, those organisations must actually do.
WCAG 2.1 AA is a technical specification published by the World Wide Web Consortium (W3C) and incorporated by reference into SI 358/2020 as the binding conformance standard. The guidelines are organised around four principles, abbreviated as POUR: content must be Perceivable (users can access it through at least one sense), Operable (users can navigate and interact with it), Understandable (content and interfaces behave predictably), and Robust (content works reliably across assistive technologies).
At Level AA, the practical requirements include:
WCAG 2.1 extended its predecessor, WCAG 2.0, by adding 17 new success criteria. Several address mobile and responsive behaviour directly: content must reflow on small screens without horizontal scrolling, non-text interface components must meet contrast thresholds, form labels must remain visible when a field is active, and users must receive warnings before session timeouts. These criteria are not aspirational additions; they are fully enforceable under SI 358/2020.
WCAG 2.2 AA was published in 2023 and introduces further requirements, including enhanced focus visibility rules. SI 358/2020 mandates WCAG 2.1 AA, so WCAG 2.2 is not yet a statutory obligation. Organisations that audit against 2.2 now are positioned ahead of any future regulatory update.
One important framing point: conformance is not binary. The standard defines three levels, A, AA, and AAA. The law sets AA as a floor, not a ceiling. A compliant accessibility statement must name any known gaps honestly rather than assert full conformance that cannot be evidenced.
Knowing what WCAG 2.1 AA requires is one thing; producing the formal documentation that regulators expect is another. SI 358/2020 requires every in-scope organisation to publish an accessibility statement on each covered digital property. This is a prescribed compliance deliverable with mandatory content, not a generic disclaimer page.
What a compliant statement must contain
The Centre for Excellence in Universal Design sets out the required elements clearly. A valid accessibility statement must declare one of three conformance statuses: fully conformant, partially conformant, or non-conformant. It must identify each specific WCAG 2.1 AA success criterion that is not yet met, with a documented reason for each gap. Any content covered by a permitted exemption must be identified as such. The statement must carry the date it was last reviewed.
Beyond conformance status, the statement must include a feedback mechanism through which users can report accessibility barriers, a named or designated contact point for accessibility queries, and a reference to the enforcement procedure available if a complaint is not resolved. In Ireland, that escalation route runs through the Irish Human Rights and Equality Commission (IHREC).
The risk of asserting conformance you cannot evidence
An organisation that publishes a statement claiming full WCAG 2.1 AA conformance without a formal audit is creating a false compliance record. If the NDA investigates a complaint and the stated conformance cannot be substantiated, the organisation faces double exposure: the underlying non-conformance, and the inaccuracy of the statement itself.
Automated tools have well-documented limitations and cannot identify the full range of WCAG failures. An accessibility statement produced solely on the basis of automated scanning will not withstand scrutiny, because the methodology behind the claim is the part a reviewer examines.
A compliant accessibility statement is the regulatory surface of conformance; the evidence beneath it is what determines whether that statement holds up. The distinction that matters to a regulator, funder, or auditor is between assertion and evidence.
Evidenced conformance means an organisation can demonstrate, through documented proof, that its website meets WCAG 2.1 AA requirements. The documentation must be sufficient to withstand external scrutiny, whether from the NDA, the Charities Regulator reviewing governance standards, a government department assessing funding compliance, or a board conducting internal audit.
The evidence base that satisfies that scrutiny comprises four elements:
That last element is where many organisations underestimate the obligation. A one-time audit conducted at website launch does not constitute ongoing evidenced conformance. Every content update, plugin change, theme modification, or structural change to a WordPress or other CMS-based site can introduce new accessibility failures without any deliberate technical decision. Compliance is therefore a governance framework that runs for as long as the site does.
The practical test, when external scrutiny arrives, is whether the organisation can produce a current and accurate compliance record. For most bodies subject to SI 358/2020, that record does not exist because no internal function owns it and no vendor has been contracted to maintain it.
A managed care arrangement that includes periodic WCAG 2.1 AA auditing, structured remediation and regular reporting against the standard is the operational model that sustains evidenced conformance over time. The output that matters is a continuous, documented compliance record the organisation can produce on demand.
The dominant reason most organisations are currently exposed is ungoverned compliance: the obligation is known in general terms, but no named person within the organisation owns it operationally, no budget line funds it, and no vendor has been contracted to produce ongoing evidence of conformance. The regulation exists; the governance structure to meet it does not.
Traditional web agency engagements are designed around project delivery. A site is scoped, built, launched, and handed over. Ongoing maintenance contracts typically cover security patching, plugin updates, and uptime monitoring. Website accessibility conformance is not a standard deliverable in that model, and the agency carries no contractual accountability for it once the project closes. The compliance posture of the site at launch, whatever it was, begins to degrade the moment content is added.
That liability does not transfer with the handover. The regulatory obligation under SI 358/2020 rests with the organisation itself, and the NDA’s investigation, if a complaint is made, will be directed at the organisation rather than its supplier.
The exposure compounds in practice because most sites are live publishing environments. On WordPress and comparable CMS platforms, communications staff, programme officers, and content editors are routinely uploading PDFs without tagged structure, publishing images without alt text, and embedding video without captions. Each action can introduce a WCAG 2.1 AA failure without any change to the underlying code. The site can be technically sound and still accumulate content-level failures week by week.
The structural root of the problem is diffuse ownership. Accessibility sits across IT, communications, legal and HR, and without a designated responsible officer or a vendor whose contract explicitly covers it, the obligation falls between functions. Where nobody claims it, nothing gets addressed.
That governance gap has a direct enforcement consequence. The NDA conducts periodic compliance monitoring cycles and reports its findings to the European Commission as part of the EU-level accountability structure. The NDA’s active monitoring function means unaudited organisations are exposed to regulatory scrutiny, not just user complaints.
Under the regulations, organisations are required to provide a mechanism for users to report accessibility barriers, and to identify a complaints or escalation route in their accessibility statement. The NDA and IHREC each play a role in the broader enforcement and complaints landscape. A single motivated user, including a user with a disability who relies on assistive technology, can trigger a formal regulatory process. The mechanism requires no legal representation and no threshold of harm beyond the barrier itself.
For charities and NGOs, the consequences extend beyond regulatory correspondence. Organisations whose public credibility rests on demonstrated commitment to inclusion face a particular reputational problem when a disability rights complaint produces a finding of WCAG 2.1 AA non-conformance. The finding becomes part of the public record at precisely the point where funder confidence matters most. Most sites drift out of compliance quietly, without any single event triggering attention, until a complaint makes the gap visible.
Funding risk is a related and practical concern. Funding bodies may raise accessibility compliance during grant review cycles; organisations that cannot evidence conformance face a harder conversation at those moments than those who can produce a current audit record.
The cumulative cost of that reactive position, covering legal exposure, reputational damage, potential funding conditions, and emergency remediation under regulatory pressure, consistently exceeds the cost of structured, proactive compliance. The governance investment is most easily justified when quantified against that downside.
Knowing the exposure exists is only half the problem. The other half is structured remediation.
As noted in the accessibility statement section, automated scanning alone is insufficient; the same principle governs every audit in the roadmap below.
The starting point is a formal WCAG 2.1 AA audit covering the entire site, not a sample of representative pages. The audit should combine automated scanning with qualified manual review. The output should be a structured report mapping each failure to its specific success criterion, not a generic list of issues.
Prioritise by severity. Level A failures represent the baseline floor of accessibility and create the most significant barriers; address these first. Level AA failures must also be remediated to achieve statutory conformance under SI 358/2020. Where failures affect users across multiple disability types, including motor, visual, cognitive, and auditory, weight those issues accordingly in the remediation schedule.
Remediation is not purely a technical exercise. A substantial proportion of failures on public sector and charity websites are content failures rather than code failures: PDFs without tagged structure, images missing alt text, video without captions, data tables without header markup, and forms without properly associated labels. Fixing these requires both developer input and structured training for content editors. Without the training component, the same failures recur with every content update.
Once initial remediation is complete, update the accessibility statement to reflect the current audited position accurately. For most organisations beginning this process, the honest status will be partially conformant with documented known issues. That is a legally compliant position under the regulations, provided the statement is specific about outstanding gaps and includes a realistic remediation timeline. A partial-conformance statement supported by evidence is materially stronger than an unsupported assertion of full conformance.
Ongoing governance requires three things: periodic re-audit at minimum annually and after any significant redesign or CMS update; a content governance policy setting accessibility requirements for editors; and a named responsible officer or contracted managed service provider with documented accountability for maintaining and evidencing conformance on a continuous basis.
The governance gap diagnosed above has a vendor dimension: who, specifically, has accepted contractual responsibility for closing it?
A traditional web agency relationship terminates at handover. Ongoing accessibility conformance is not a standard deliverable in that model, and ordinary site activity, content additions, plugin updates, structural changes, introduces new failures silently. The compliance gap opens not through neglect but through the ordinary operation of a live website under a vendor model that was never designed to govern it.
Managed care changes the accountability structure. A hosting and care arrangement that includes website accessibility as a contracted deliverable assigns the provider ongoing responsibility: periodic WCAG 2.1 AA audits, structured remediation of identified failures, maintenance of a current and accurate accessibility statement, and documented evidence of conformance suitable for governance reporting. The obligation that previously sat with no one now sits with a named party under a service agreement.
For compliance officers, finance directors, and board secretaries, the operative question is whether the vendor can produce a compliance record that holds up in front of the NDA, a funder or an auditor twelve months from now. That requires a continuous service model rather than a project relationship.
HostLogic is an Automattic for Agencies Pro Partner. We audit and remediate to WCAG 2.2 AA, which meets and exceeds the 2.1 AA the Regulations require, and offer continuous accessibility monitoring alongside managed WordPress hosting and care. Audit, remediation and monitoring are priced separately from the care plan. The deliverable is the evidence trail: periodic audits, remediation with documented resolution, and a statement kept current.
When evaluating any managed care arrangement, confirm the following in writing:
The vendor accountability question above applies equally to a dimension many organisations have not considered at all: their mobile applications.
SI 358/2020’s full title is the European Union (Accessibility of Websites and Mobile Applications of Public Sector Bodies) Regulations 2020. The mobile scope is written into the instrument from the outset. Any public body or funded charity operating a native iOS or Android application as a service delivery channel carries the same WCAG 2.1 AA obligation for that application as it does for its website.
The compliance deadline for mobile applications was 23 June 2021. That date has passed, so any gap in mobile app accessibility is a live breach. An organisation that has addressed its website but not its mobile application has a partial compliance posture only, and a partial posture does not satisfy the regulations.
The perception that mobile obligations are somehow lower priority is a risk assumption with nothing in the Regulations behind it. The NDA’s remit explicitly extends to mobile applications. Monitoring activity to date has emphasised web properties, which reflects audit prioritisation and resource sequencing rather than a lower legal standard for apps.
The technical requirements add a further complication. WCAG 2.1 AA applies to both channels, but mobile accessibility requires specific attention to areas that do not map directly from web practice: gesture-based interaction design, screen reader compatibility (VoiceOver on iOS and TalkBack on Android), touch target sizing, and content reflow on small screens. These requirements overlap with but are not identical to web accessibility criteria. A website audit does not cover a mobile application. A separate, platform-specific audit is required.
Finally, the accessibility statement obligation under SI 358/2020 applies to each digital property individually. A single website-level statement cannot satisfy the requirement for a native mobile application. Organisations operating both must produce and maintain separate statements, each accurately reflecting the conformance status of its respective channel.
The scope question, for websites and mobile applications alike, is now settled. What remains is whether your organisation has acted on it.
Start with an inventory. List every website and mobile application your organisation operates or controls, then confirm whether a compliant accessibility statement exists for each. If a statement exists, verify that it reflects a formal audit rather than an assumption of conformance. Many published statements assert full WCAG 2.1 AA conformance without any documented basis for that claim, which creates a false compliance record rather than evidence of one.
If no formal WCAG 2.1 AA audit has been conducted, commission one. Automated tools have well-documented limitations and cannot identify the full range of WCAG failures; a conformance assertion built on automated scanning alone will not withstand scrutiny from the NDA, a funder, or an internal auditor.
Ownership must be assigned explicitly. Accessibility compliance sits at the intersection of IT, communications, and legal, and that intersection is where accountability disappears in most organisations. Either designate an internal responsible officer with a clear remit or contract an external managed service provider whose accountability for ongoing conformance and evidence production is documented in the engagement terms.
The steps, inventory, audit, remediation, statement update, and ongoing governance, are set out earlier in this piece. The question is whether they have been assigned to a named party.
The organisations that face the most difficult regulatory conversations are usually the ones that assumed compliance was in hand and never confirmed it in evidence.
This article sets out how we read the Regulations and it is not legal advice. Where the position matters, take your own.
Get a free HostLogic site audit covering Core Web Vitals, security posture, infrastructure and a maintenance gap analysis. Written report within 3 working days. No obligation, no sales pitch.