Compliance for municipalities and public websites

The obligations that shape a public sector website: accessibility, transparency, archiving, procurement, open standards and algorithm registers.

4 minread 824words last updated

The short answer

A public sector website carries obligations a business website does not. Accessibility is a legal requirement under the Web Accessibility Directive as implemented nationally, with a published accessibility statement in a prescribed model, a feedback mechanism, an escalation route and monitoring by supervisory bodies. Published content may constitute a public record, bringing archiving and retention obligations that affect how the site is versioned and how you demonstrate what it said on a given date. Procurement rules govern how the site is bought and typically require consideration of open standards and avoidance of supplier lock-in. Transparency obligations extend beyond documents to how decisions are made, which is why algorithm registers describing automated systems have become established practice and are increasingly expected. And the audience is everyone, which raises the bar for plain language, for multilingual provision where relevant, and for channels beyond the web. On top of all that sit the ordinary requirements: privacy, cookies, security and identification.

The obligations in outline

AreaRequirementPractical implication
AccessibilityConform to the standard; publish a statement; provide feedback and escalation; monitoredAudit, fix, publish, maintain; build checks into the process
ArchivingPublished content may be a public record with retention and preservation dutiesVersioning; ability to show past states; disposal per schedule
ProcurementRules on tendering; open standards; avoiding lock-inSpecify ownership, exit and standards in the tender
TransparencyInformation about decisions and automated processingAlgorithm register; plain explanations
PrivacyUsual obligations plus a higher bar for a public authorityData protection officer; impact assessments; published statements
SecurityBaseline requirements and, for some bodies, sector obligationsMonitoring, patching, incident procedures
Plain languageExpected and often mandatedEditorial standards and testing with residents
Channel equityServices must remain reachable by non-digital meansThe website is one channel, not the only one

Running a compliant public website

  1. Audit accessibility properly, with automated checks and manual testing, and publish an honest statement.
  2. Build accessibility checks into publishing, so new content cannot regress the site.
  3. Agree with your records manager what constitutes a record, how it is versioned and how long it is kept.
  4. Keep content in version control, which makes archiving and demonstration far easier.
  5. Specify ownership, exit and open standards in procurement, not after award.
  6. Publish an algorithm register and keep it current.
  7. Do impact assessments for new processing and publish summaries where appropriate.
  8. Write in plain language and test with residents, including those with low digital skills.
  9. Maintain non-digital channels for the services the site provides.
  10. Review annually against the statement, the register and the retention schedule.

Where the effort actually goes

Not in the legal reading but in the publishing process. Accessibility holds only if every new page and document meets it, which means editors need training, templates need to be accessible by construction, and documents, especially PDFs, need attention or replacement with web pages. Archiving holds only if versioning is built in. Transparency holds only if the register is updated when systems change. Each is a process change rather than a project, and each fails quietly when it depends on someone remembering.

What this means for you

A public website must meet accessibility with an honest published statement and a feedback route, handle published content as records with versioning and retention, procure with open standards and exit in mind, publish transparency information including an algorithm register, write in plain language and keep non-digital channels open. Build the obligations into the publishing process rather than treating them as periodic projects. This is general information rather than legal advice; national implementation governs your specific duties.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

What is different about a municipal website?

Accessibility is a legal requirement with a published statement, monitored by supervisory bodies. Content may constitute public records subject to archiving law, which means versions and changes matter. Procurement rules govern how the site is bought and often require open standards and avoidance of lock-in. Transparency obligations extend to how decisions are made, including by algorithms. And the audience includes everyone, which raises the bar for plain language and for channels beyond the web.

Do we have to publish an algorithm register?

National practice varies and expectations are rising. Several Dutch public bodies publish registers of the algorithms and automated systems they use, describing what each does and what safeguards apply, and national guidance encourages it. Whether formally required for your organisation or not, publishing a register is the cheapest transparency measure available and answers questions from councillors, journalists and residents before they become stories.

How does archiving affect the website?

If published content constitutes a public record, archiving law governs how long it must be kept and how it is preserved and disposed of. That affects publication workflows, versioning and the ability to show what the site said on a given date. Keeping the site's content in version control makes this considerably easier, and it should be discussed with your records manager rather than after a request arrives.

Sources

  1. EUR-Lex: Directive (EU) 2016/2102 on the accessibility of websites and mobile applications of public sector bodies (accessed 2026-09-12)
  2. Digitale Overheid: Digitale toegankelijkheid (accessed 2026-09-12)