Time
Click Count
On 23 May 2026, the European Commission formally submitted the draft Digital Services Infrastructure Compliance Amendment to EU Member States, mandating that all interactive kiosks (Kiosk Tech) and guestroom automation systems deployed in public venues—including hotels, airports, and exhibition centres—must comply with both the GDPR’s data localisation requirements and the updated accessibility standard EN 301 549 V3.2.1 starting 1 January 2027. Exporters from China—and other third countries—supplying such systems to the EU will lose eligibility for EU public procurement contracts and major hotel chain tenders if they fail to achieve dual certification ahead of the deadline.
The European Commission published the draft Digital Services Infrastructure Compliance Amendment on 23 May 2026. The draft requires Kiosk Tech and Guestroom Automation systems intended for deployment in publicly accessible locations across the EU to meet two concurrent compliance benchmarks by 1 January 2027: (i) GDPR-compliant data localisation (including storage and processing within the EEA), and (ii) conformance with EN 301 549 V3.2.1—the latest harmonised European standard for ICT accessibility. The draft is currently under review by Member States; no final adoption date or formal entry-into-force timeline has been announced.
Companies exporting Kiosk Tech or Guestroom Automation hardware, firmware, or integrated solutions to the EU are directly subject to the requirement. Non-compliance will result in exclusion from EU public procurement frameworks and pre-qualified vendor lists used by multinational hotel groups (e.g., Accor, Marriott, IHG). Certification must cover full system architecture—not just individual components—making retrofitting existing products technically and commercially challenging.
Suppliers of operating systems, access control modules, voice interface engines, or cloud-connected management platforms embedded in kiosks or room automation systems may face upstream compliance demands. If their software processes personal data or affects accessibility functionality (e.g., screen reader support, contrast settings, navigation logic), it falls within the scope of both GDPR data handling rules and EN 301 549 V3.2.1 conformance testing—even when supplied as a B2B component.
Distributors and value-added resellers placing these systems on the EU market bear legal responsibility under the EU’s Market Surveillance Regulation (Regulation (EU) 2019/1020). They must verify and retain technical documentation demonstrating dual certification before placing devices on the market. Absent valid conformity evidence, they risk enforcement actions—including product withdrawal and liability for non-compliant deployments.
The draft remains subject to intergovernmental consultation and possible revision. Enterprises should track updates via the Official Journal of the European Union and national market surveillance authorities (e.g., Germany’s BAFA, France’s DGCCRF). Final adoption is not guaranteed before end-2026, and transitional periods—if introduced—will only be confirmed upon publication of the adopted text.
Given resource constraints, companies should identify specific kiosk models or automation platform versions already qualified for EU hotel or airport tenders. These SKUs should be prioritised for dual certification. Avoid broad-spectrum testing; instead, align test scope with actual use cases (e.g., check-in kiosks with biometric capture require stricter GDPR data flow mapping than basic information displays).
As of now, the requirement exists only as a draft proposal. No penalties, audits, or mandatory certification schemes are yet active. However, leading EU procurement bodies and hotel chains are already referencing EN 301 549 V3.2.1 in RFPs. Treat the draft as a binding forward-looking signal—not current law—but one that shapes near-term tender criteria and vendor evaluations.
GDPR localisation and EN 301 549 V3.2.1 conformance are not post-manufacturing add-ons. Engineering, privacy, and UX teams must jointly review data flow diagrams, user interface code, assistive technology interfaces (e.g., WCAG-aligned ARIA labels), and default configuration settings. Early alignment reduces rework cycles and accelerates third-party assessment readiness.
Observably, this draft signals a structural shift in how the EU regulates digital infrastructure in shared physical spaces—not merely as IT equipment, but as regulated service delivery points with combined data protection and universal access obligations. Analysis shows the dual-certification mandate reflects growing policy convergence between digital rights (privacy, autonomy) and inclusive design (accessibility, usability). It is not yet an enforceable outcome, but rather a strong anticipatory signal: procurement gatekeepers and standards bodies are already aligning behind it. From an industry perspective, this is less about immediate compliance pressure and more about recalibrating product development roadmaps, supplier agreements, and tender response strategies over the next 12–18 months.

Conclusion
This draft regulation does not introduce new legal obligations overnight, but it crystallises an emerging compliance threshold for digital infrastructure serving EU public and hospitality environments. Its significance lies not in immediacy, but in directionality: it confirms that interoperability, data sovereignty, and accessibility are now co-equal pillars of market access. Enterprises are better advised to treat it as a forward-looking design and procurement benchmark—not a looming penalty trigger—and to calibrate investments accordingly.
Source: European Commission draft proposal, Digital Services Infrastructure Compliance Amendment, published 23 May 2026. Status remains draft; final adoption and entry into force pending Member State consultation and potential revision. Ongoing monitoring required.
Recommended News
Join 50,000+ industry leaders who receive our proprietary market analysis and policy outlooks before they hit the public library.