Compliance guide

The ADA Title II exceptions for documents: archived content, preexisting PDFs, password-protected files, and third-party content, read closely

What 28 CFR 35.201 actually excepts from the WCAG 2.1 AA requirement, with the DOJ's own examples: archived web content, preexisting conventional electronic documents, third-party content, individualized password-protected documents, and social media posts.

Updated September 2, 2026. Reviewed by the DocAccessible team under our editorial policy.

The Title II web rule's exceptions are where most document triage decisions get made, and where most mistakes happen: an archive that is not an archive, an "old form" that is still the only way to apply, a portal of bills that someone decided was exempt as a whole. This guide reads the five exceptions in 28 CFR 35.201 closely, with the definitions from 35.104 and the Department of Justice's own examples, and ends with the provisions that apply even when an exception does.

The requirement the exceptions modify

Under 28 CFR 35.200, as amended on April 20, 2026, a public entity with a total population of 50,000 or more must ensure from April 26, 2027 that the web content and mobile apps it provides or makes available, "directly or through contractual, licensing, or other arrangements", comply with WCAG 2.1 Level A and AA; entities under 50,000 and special district governments have until April 26, 2028. Documents are web content: the rule defines "conventional electronic documents" as web content or content in mobile apps in portable document, word processor, presentation, or spreadsheet file formats, which is the complete list. The Title II deadline guide covers the 2026 extension.

Exception (a): archived web content

The rule excepts archived web content as defined in 35.104. The DOJ fact sheet restates the definition as four conditions that must all be met: the content was created before the entity's compliance date, or reproduces paper documents or physical media created before it; it is kept only for reference, research, or recordkeeping; it is kept in a special area for archived content; and it has not been changed since it was archived. The fact sheet's examples are instructive. A 1998 water quality report stored in an archive section and never updated qualifies. City council minutes created after the compliance date do not qualify even if posted in the archive, because they were created too late. A 2021 spreadsheet edited and reposted in the archive loses the exception because it changed. A PDF with a current county park map does not qualify however it is filed, because it provides current information rather than being kept for reference. The DOJ guidance is explicit that entities may not circumvent their obligations merely by labelling content archived.

Exception (b): preexisting conventional electronic documents

The rule text: conventional electronic documents "that are available as part of a public entity's web content or mobile apps before the date the public entity is required to comply with this subpart, unless such documents are currently used to apply for, gain access to, or participate in the public entity's services, programs, or activities." Two tests, then. First, was the document there before your compliance date? Second, is it currently used to apply for, access, or take part in anything? A permit application form, a benefits instruction sheet, a school enrolment packet, a meeting agenda for a meeting people can still attend, and a fee schedule people still pay against all fail the second test and are in scope. A superseded policy from 2019 that nobody uses passes it. The website PDF scanner is a quick way to inventory what is actually linked, which is where this triage has to start.

Exception (c): content posted by a third party

Content posted by a third party is excepted "unless the third party is posting due to contractual, licensing, or other arrangements with the public entity". The fact sheet draws the line clearly: a member of the public's message on a town's online message board would probably fall under the exception; content developed by an outside technology company that the government itself posts (calendars, scheduling tools, maps), and the message board platform itself, do not. A consultant's report that the entity publishes is the entity's content.

Exception (d): individualized, password-protected documents

Conventional electronic documents that are both "about a specific individual, their property, or their account" and "password-protected or otherwise secured" are excepted. The fact sheet's example is a water or tax bill behind a login. The exception is narrow in two directions. It covers the individual documents, not the portal, login, or delivery system, which must meet WCAG. And it does not cover general forms or documents that many users access, even behind a password. For organisations that generate these documents at volume, the statements at scale guide explains why fixing the template is still the right move.

Exception (e): preexisting social media posts

A public entity's social media posts made before its compliance date are excepted; the fact sheet's example is a 2017 post about delayed trash collection. Posts after the date are in scope. This exception rarely affects documents, but PDFs linked from old posts are governed by the document exceptions above, not by this one.

What the exceptions do not change

The fact sheet has a section titled "What the exception does not change" for a reason. The ADA still requires public entities to provide effective communication, reasonable modifications, and an equal opportunity to participate. If a person who is blind asks for an archived report or an old bill, the entity must provide it in a form that person can use, for instance by providing an accessible version of that document on request. The exceptions remove the obligation to remediate proactively; they do not remove the obligation to serve the individual.

Three provisions that apply when no exception does

  • Conforming alternate versions (35.202) may be used "only where it is not possible to make web content directly accessible due to technical or legal limitations". An accessible HTML version of a PDF that cannot be changed for legal reasons is the textbook case; a separate accessible site as a general strategy is not.
  • Fundamental alteration or undue burdens (35.204) limit the requirement to the extent compliance would fundamentally alter a service or impose undue financial and administrative burdens, and the entity bears the burden of proving it.
  • Minimal impact (35.205) treats an entity as compliant despite nonconformance only where it can show the nonconformance would not affect a person's ability to access the same information, engage in the same interactions, and so on, with substantially equivalent timeliness, privacy, independence, and ease of use.

A triage that follows the rule

  1. Inventory every linked document; the free website PDF scanner lists what a site links to and where.
  2. Mark anything used to apply for, access, or participate in a service as in scope regardless of age, and remediate it first.
  3. Move genuinely historical material into a clearly labelled archive area and stop editing it; record the archive date.
  4. Treat individualized secured documents as excepted but keep their portal accessible and fix the generating template.
  5. For everything in scope, choose a path: accessible HTML, a remediated PDF, or both; the remediation paths guide compares them.
  6. Publish the accessible-format request route and answer requests, because the effective communication duty applies to excepted content too.

Frequently asked questions

What counts as a "conventional electronic document" under the ADA Title II rule?

Web content or content in mobile apps that is in portable document formats, word processor file formats, presentation file formats, or spreadsheet file formats. That is the complete list in 28 CFR 35.104. PDFs, Word, PowerPoint, and Excel files published by a public entity are conventional electronic documents; HTML pages are not.

Are old PDFs exempt from the ADA Title II web rule?

Only if they were available before the entity's compliance date and are not currently used to apply for, gain access to, or participate in the entity's services, programs, or activities. A form, application, instruction sheet, or fee schedule still in use is in scope however old it is. Separately, content kept purely for reference in a clearly identified archive area and never changed since archiving is excepted as archived content.

Does the archived content exception apply if I put old documents in an "Archive" folder?

Not on its own. All four conditions must be met: the content predates the compliance date or reproduces pre-existing physical records, it is kept only for reference, research, or recordkeeping, it is stored in a clearly identified archive area, and it has not been changed since archiving. The DOJ states that entities may not circumvent their obligations merely by labelling content archived, and a document that provides current information, such as a current park map, does not qualify wherever it is stored.

Sources

The statements above rest on the primary sources below. Where a source is a law or standard, the version and date named in the text are the ones checked on the review date. This guide is general information, not legal advice.

  1. eCFR: 28 CFR Part 35, Subpart H, sections 35.200 to 35.205 . The requirement, compliance dates as amended April 20, 2026, the five exceptions, conforming alternate versions, undue burden, and minimal impact.
  2. ADA.gov: Fact Sheet, New Rule on the Accessibility of Web Content and Mobile Apps Provided by State and Local Governments . The four archived-content conditions, the examples quoted, and the section on what the exceptions do not change.
  3. eCFR: Appendix D to Part 35, Guidance to Revisions to ADA Title II Regulation on Accessibility of Web Information and Services
  4. Federal Register, April 20, 2026: Extension of Compliance Dates (DOJ interim final rule)

Keep reading