If your users are citizens, patrons, or public servants, accessibility and privacy are not polish. They decide whether the platform is usable, lawful, and trusted.
WCAG is interaction design with receipts
Accessibility work on institutional portals is not a late pass with a contrast plugin. It shows up in information architecture, admin tooling, multilingual layouts, and the components teams reuse under deadline pressure.
When we set engineering standards for citizen-facing surfaces, the goal was simple: the back office should make the accessible path the default path — not the heroic exception.
GDPR is data modeling with consequences
Privacy-conscious platforms force hard questions early: what is personal data, who can see it, how long it lives, and which services are allowed to touch it. Those answers belong in architecture and APIs, not in a policy PDF nobody reads after go-live.
What changes in practice
- Treat personal and citizen spaces as first-class domains, not bolt-on accounts
- Prefer clear consent and minimization over clever cross-linking
- Keep auditability boring and reliable
- Test with real assistive tech and multilingual content, not only happy-path screenshots
Compliance language can sound dry. The product outcome is not: people can use public services without being excluded or exploited by the system meant to help them.