← All posts

February 2025

Accessibility and privacy are platform features

WCAG and GDPR are often treated as compliance checklists. On citizen-facing platforms, they are product requirements that shape architecture.

If your users are citizens, patrons, or public servants, accessibility and privacy are not polish. They decide whether the platform is usable, lawful, and trusted.

WCAG is interaction design with receipts

Accessibility work on institutional portals is not a late pass with a contrast plugin. It shows up in information architecture, admin tooling, multilingual layouts, and the components teams reuse under deadline pressure.

When we set engineering standards for citizen-facing surfaces, the goal was simple: the back office should make the accessible path the default path — not the heroic exception.

GDPR is data modeling with consequences

Privacy-conscious platforms force hard questions early: what is personal data, who can see it, how long it lives, and which services are allowed to touch it. Those answers belong in architecture and APIs, not in a policy PDF nobody reads after go-live.

What changes in practice

  • Treat personal and citizen spaces as first-class domains, not bolt-on accounts
  • Prefer clear consent and minimization over clever cross-linking
  • Keep auditability boring and reliable
  • Test with real assistive tech and multilingual content, not only happy-path screenshots

Compliance language can sound dry. The product outcome is not: people can use public services without being excluded or exploited by the system meant to help them.

© 2026 Toufic Hajj · Senior Full-Stack & Cloud Platform Engineer
Montreal, QC