regulations and Compliance

Kiosk Standards and Regulations

Kiosk Standards and Regulations

Here is our coverage of the regulatory compliance standards which affect and/or come into play for kiosks.  Some are by law, some by suggestion. Some apply to only federal but many are assumed across the board (based on legal activity).  States often have their own set of regulations (think California).  Biometrics in states like Illinois is another consideration.  On our Legal Actions page we track different court cases across self-service.

Good Kiosk Regulations References

  • Compliance Overview by KIOSK — UL Testing, Environmental and Attack testing.  At the KIOSK compliance lab, products undergo UL and other compliance testing to measure product safety and environmental testing to ensure kiosks can withstand the elements when placed in outdoor settings. Attack testing helps validate that the kiosk design provides a measure of security against vandalism.
  • Accessibility Compliance by Olea — the ADA regulations about kiosks aim to facilitate equal access and usage for individuals with physical disabilities, including those with mobility challenges, hearing, and vision impairments, parallel to those without such impairments. This inclusivity extends beyond the kiosk unit itself, encompassing the touchscreen, peripheral devices, and even the surrounding area.
  • Security Requirements —  here is good example from Broward County — circa 2025
    • Defines “County Data” and “County Confidential Information” including sensitive personal and financial info​

    • Contractor must follow County security policies, provide training, and notify the County when access changes​

    • All remote network access needs VPN, multi-factor authentication, and encryption; noncompliance may result in suspension​

    • Data privacy must comply with Florida law (Section 501.171, Chapter 119), stored in the U.S., and can’t be disclosed/sold without approval​

    • Storage devices holding County Data must be securely wiped with certificate when requested​

    • All security or cyber incidents must be reported within 24 hours and a full report within 5 days​

    • Contractor must fully cooperate in incident investigation and provide forensic access​

    • Staff with access to confidential info require background checks and must not pose a security risk​

    • County Data may only be transmitted securely (HTTPS, SFTP) and not released without written consent​

    • Current unqualified SOC 2 Type II report may be required, covering all Trust Service Principles​

    • Software must follow secure SDLC, support AD and least privilege access, and quickly fix CVEs; encryption must be AES-256 at rest, TLS 1.2 in transit​

    • Contractor-supplied equipment must include physical security, promptly patch vulnerabilities, and support signed firmware updates​

    • PCI DSS compliance required for any software/equipment touching payment data, with annual certifications and prompt notification of loss of compliance​

    • HIPAA/HITECH compliance required if relevant; subcontractors must also comply​

    • App dev projects must follow County security standards and provide testing attestations if requested​

Separate Content Pages

Standards Matrix

  • Framework
  • Standards to Kiosks Mapping
  • Devices

Standards Frameworks

Standard_or_FrameworkJurisdiction_or_DomainPrimary_Kiosk_Impact_AreaTypical_Deployments_AffectedKey_Kiosk_Requirements_or_CheckpointsCanonical_Reference_or_TIG_Anchor
ADA Standards for Accessible Design (Title II and III)United States; civil rights lawPhysical accessibility; reach ranges; operable parts; audio and tactile accessRetail self checkout; self order; hotel check in; DMV; smart city; ticketingClear floor space; approach and reach; tactilely discernible controls; audio output; accommodation for mobility, vision and hearing impairmentsKioskIndustry.org Standards section; ADA kiosk pages and checklist
ADA and ABA Guidelines for TerminalsUnited States; ADA and Architectural Barriers ActCounter heights; protruding objects; layout around terminalsHotel check in; restaurant kiosks; wall mount displays; transit ticketingMax protrusion from wall; knee and toe clearance; control heights; accessible routes around kiosksKioskIndustry.org ADA terminals commentary
Section 508 and Section 255 (U.S. ICT Accessibility)United States federal ICT and communicationsSoftware and UX accessibility; closed systems; procurement requirementsFederal agency kiosks; SSA; VA; USDA; federal building kiosksConformance to WCAG; audio or tactile access for blind users; procurement language; VPAT useKioskIndustry.org Section 508 kiosk page
EN 301 549 and European Accessibility ActEuropean Union ICT accessibilityAccessibility of ICT products and services including kiosks and POSPublic sector kiosks; ticket machines; payment terminals; smart city screens in EUPhysical access; operable parts; audio output; speech output; compatibility with assistive tech; accessible documentationKioskIndustry.org Standards listing for EN 301 549 and EU accessibility
Universal Design PrinciplesGlobal design frameworkInclusive hardware, software and environment designAll kiosk types as a design philosophyEquitable use; simple and intuitive operation; perceptible information; low physical effort; adequate space for approach and useUniversal Design links referenced in KioskIndustry.org Standards
WCAG 2.1 and 2.2 Web Content Accessibility GuidelinesGlobal W3C standardKiosk UI and web based UIs; PWA kiosksBrowser based kiosks; remote admin portals; web front ends driving kiosksText alternatives; contrast; keyboard access; focus visibility; timing and error handling; AT compatibilityWCAG references in KioskIndustry.org Standards
VPAT Voluntary Product Accessibility TemplateGlobal reporting template; widely used by public sector and enterprisesAccessibility conformance reporting for hardware, software and documentationAny kiosk solution sold into public sector or enterpriseDocumented conformance vs 508, WCAG and EN 301 549; four level rating; separate coverage for hardware and softwareVPAT resources linked from KioskIndustry.org Standards
Air Carrier Access Act ACAA Kiosk RulesUnited States; air travel accessibilityAirline check in and bag tag kiosksAirport self service check in; bag drop; boarding pass kiosksRequired percentage of accessible kiosks; placement rules; tactile controls; audio jacks; consistent accessible featuresACAA and DOT resources in KioskIndustry.org Standards
HIPAA and HITECH and Canadian privacy for healthUnited States health privacy and security; Canadian privacyElectronic protected health information privacy and security around kiosksPatient check in and payment; telehealth; pharmacy and health kiosksScreen privacy; short timeouts; limited PHI on screen and receipts; encrypted transport and storage; BAAs; audit loggingHIPAA kiosk pages and primers on KioskIndustry.org
FERPA and GLBAUnited States education and financial privacyPrivacy of student and financial records at kiosksCampus kiosks; tuition and bursar kiosks; financial institution kiosksAvoid exposing sensitive records on screen; strong authentication; secure sessions; compliance with institutional policiesFERPA and GLBA references under additional regulations on KioskIndustry.org Standards
PCI DSS Payment Card Industry Data Security StandardGlobal card brand data security standardCardholder data security; network and application controlsPayment kiosks; self checkout; restaurant self order; bill pay and ticketing kiosksNo storage of sensitive auth data; encryption; PTS approved devices; segmented networks; logging and monitoring; regular scansPCI and EMV payments entry in KioskIndustry.org Standards
EMV Specifications and Liability Shift RulesGlobal EMVCo and card brandsChip and contactless transaction security and liabilityKiosks taking chip and contactless paymentsCertified EMV kernels; correct cardholder verification; support for contactless; awareness of liability shift rulesSame PCI and EMV entry and processor and acquirer documentation
UL 2361 and UL 291 and UL 60950-22 and UL 62368-1North America and global safety and security standardsElectrical safety; fire; stability; burglary resistance for safesIndoor and outdoor kiosks; ATMs; safes; payment devicesStability and tip tests; enclosure strength; protection from shock and fire; burglary resistance where cash; documented certificationUL Kiosk Standards and outdoor kiosk guidance on KioskIndustry.org
Environmental Standards NEMA and IP ratingsNEMA United States enclosures; IEC IP ratingsWeather and ingress protection; dust; water and corrosion resistanceOutdoor ticketing; drive thru kiosks; EV charging; transit; smart city kiosksMatch enclosure rating to environment; consider rain, snow, dust, corrosion, vandalism; design for thermal and condensation controlEnvironmental and outdoor kiosk design articles on KioskIndustry.org
IEC 60601-1 Medical Electrical EquipmentInternational medical electrical safety standardSafety of medical electrical devices used with patientsVitals kiosks; diagnostic kiosks; point of care carts with kiosk UIsLimits for leakage current; isolation; creepage and clearance; essential performance and risk management integrationMedical kiosks and IEC 60601 references in KioskIndustry.org Standards
ISO 13485 Medical Devices Quality ManagementInternational QMS standard for medical devicesQuality system for design and manufacture of medical device kiosksKiosk products marketed as medical devices or accessoriesDocumented QMS; design controls; supplier and traceability controls; CAPA; post market surveillanceISO 13485 references in KioskIndustry.org Standards
FDA 510k Premarket NotificationUnited States FDA medical devicesRegulatory clearance for certain medical device kiosksDiagnostic kiosks; some telehealth and wellness devicesShow substantial equivalence to predicate devices; labeling and indications; safety and effectiveness data; human factors as neededFDA device and 510k links in KioskIndustry.org Standards
Gaming Labs International GLI StandardsGaming regulators with GLI as test labGaming kiosk compliance and integrityCasino ticket redemption; lottery; sports betting kiosksJurisdiction specific gaming rules; RNG and payout integrity; secure audit logs; age and ID verification; AML controlsGLI and gaming advisory content on KioskIndustry.org
Made in America and Buy America DOT TransitUnited States DOT and related procurement rulesDomestic content and final assembly for funded projectsTransit ticketing; fare collection; smart city kiosks under transit fundingDocument domestic content percentages; final assembly location; supplier certifications; alignment with grant languageBuy America and Made in America references in KioskIndustry.org Standards
SOC 2 and ISO 27001 and SSAE style auditsGlobal information security assurance frameworksBackend platform and cloud security for kiosk fleetsAny connected kiosk network with central CMS and back officeFormal security controls; encryption; access control; incident response; third party assessments and reportsSecurity framework mentions under additional regulations on KioskIndustry.org Standards
Dark Sky and Light Emission and FEMA and UL for LEVLocal and national environmental and safety codesLight pollution; structural resilience; battery and e mobility safetySmart city kiosks; transit shelters; LEV and EV adjacent deploymentsLimit light spill and glare; design for wind and hurricane loads; secure mounting; battery system safety where usedDark Sky and FEMA and LEV items under additional regulations on KioskIndustry.org Standards
Standards Frameworks

Standards to Kiosks

Kiosk_CategoryADA_USSection_508_WCAGEN_301549_EAAPCI_EMVHIPAA_Health_PrivacyUL_ElectricalNEMA_IP_OutdoorGLI_GamingISO13485_IEC60601ACAA_AirlineBuy_America_TransitSOC2_ISO27001Notes
Self Order RestaurantQSRYYMYNYMNNNNYDrive thru and outdoor variants need NEMA or IP and high brightness
Retail Self CheckoutYYMYNYMNNNNNYHigh ADA scrutiny in large chain deployments
Retail Information KiosksYYMNNYMNNNNNYOften browser or web based UIs using WCAG
Ticketing and EventsYYYYNYMNNNNNYTicketing plus payments; some outdoor deployments
Transit TicketingYYYYNYYNNNNYYOften subject to Buy America and outdoor environmental rules
DMV and Government ServicesYYYMNYMNNNNYYAlmost always Section 508 and strong security expectations
Hotel Check In and HospitalityYMMYNYMNNNNNYIndoor focus; ADA and PCI primary
Patient Check InYYMMYYMNYNNNYHIPAA and sometimes medical device rules apply
Telehealth and DiagnosticsYYMNYYMNYNNNYIf diagnostic, subject to IEC 60601 and possibly FDA
Pharmacy KiosksYYMYYYMNMNNNYHIPAA plus PCI for copays and cards
Financial Services KiosksYYMYNYMNNNNNYGLBA may apply; heavy PCI and EMV focus
Bill PayYYMYNYMNNNNNYUtility and bill payment with card or cash
Smart City InformationYYYNNYYNNNNYYOutdoor requirements and civic accessibility
EV Charging KiosksYYYYNYYNNNNYYAccessibility rulemaking active; NEMA and IP key
Smart VendingYMMYNYMNNNNNYInteractive screens trigger ADA; payments trigger PCI
Locker PickupYMMMNYMNNNNNYADA for screens and locker reach ranges
Photo KiosksYYMMNYNNNNNNYAccessibility and UL primary
Gaming KiosksYNNYNYMYNNNNYGLI and local gaming regulations dominate
Sports Betting KiosksYNNYNYMYNNNNYAge checks and AML rules in addition to gaming standards
Lottery KiosksYMMMNYMYNNNNYLottery commissions and GLI style testing
Campus KiosksYYMMNYMNNNNNYMay handle student records and FERPA
Visitor ManagementYYMNMYMNMNNNYPhoto capture and ID scanning raise privacy questions
Industrial KiosksMMMNNYMNNNNNYHeavy UL and environmental focus; accessibility varies
POS Mini KiosksYMMYNYMNNNNNYCountertop accessibility and PCI are key
Interactive DOOHYYYNNYYNNNNNYOutdoor advertising with touch or gesture interaction
Micro MarketsYMMYMYMNNNNNYHybrid of vending and retail self checkout
Autonomous KiosksYYYMMYMNMNNNYEmerging rules for AI transparency and biometrics
Standards to Kiosks
Regulation_or_StandardRegionCurrent_StatusKey_DatesNext_MilestoneNotes
ADA Standards for Accessible DesignUnited StatesIn force; periodically updated guidanceADA enacted 1990; 2010 Standards widely adopted in 2012Ongoing rulemaking and guidance updatesFuture rules likely to clarify self service and kiosks more explicitly
Air Carrier Access Act Kiosk RulesUnited StatesIn force for covered carriersDOT rules phased in over multiple years for accessible kiosksPotential refinements and enforcement guidanceAccessibility percentage and placement rules already in effect for airlines
Section 508 and Section 255United StatesRefreshed 508 standards in forceMajor refresh aligned with WCAG took effect in late 2010sFuture refreshes likely to align with newer WCAG versionsAffects federal procurement of kiosk hardware and software
EN 301 549 and European Accessibility ActEuropean UnionEN 301 549 in force; EAA phased inEN 301 549 adopted earlier; EAA compliance dates staggered by sectorFurther national transposition and enforcement actionsWill extend accessibility obligations to more private sector services including kiosks and POS
HIPAA and HITECHUnited StatesIn force; enforcement ongoingHIPAA privacy and security rules in place since early 2000s; HITECH strengthened enforcementFuture guidance on new tech such as telehealth and AICovers ePHI handled by patient and health kiosks
PCI DSSGlobalVersion 3 and 4 family in useMultiple revisions over the last decade to address EMV, tokenization and ecommerceFuture minor and major revisions as threats evolveCard brands set enforcement timelines for merchants and service providers
EMV SpecificationsGlobalWidely deployed for chip and contactlessLiability shifts for card present fraud rolled out over several years by regionOngoing updates for contactless, mobile and new form factorsKiosk operators must track acquirer and network deadlines
UL and IEC Kiosk Safety StandardsGlobal and North AmericaCurrent editions in forceVarious release dates by standard such as UL 62368-1 and IEC 60601-1Future edition updates and transition periodsManufacturers must track edition changes for new product approvals
NEMA and IP Environmental RatingsGlobalStable rating systems in useNEMA and IP frameworks have existed for many yearsNew guidance as new hazards and environments appearUsed at design stage to specify enclosure performance
GLI Gaming StandardsJurisdiction specificOngoing updates by gaming regulators and GLIStandards have evolved with digital gaming and kiosksNew versions and jurisdiction specific changesCasinos and lottery agencies track standards per jurisdiction
Buy America and Made in America RulesUnited StatesIn force; sometimes strengthened in new billsRequirements tied to specific infrastructure and transit funding programsFuture changes tied to new federal legislation and grant programsTransit and smart city kiosk projects must check current content thresholds
SOC 2 and ISO 27001GlobalWidely used assurance frameworksSeveral revisions and new controls over timeUpdates to reflect cloud, zero trust and supply chainApplies to backend systems supporting kiosk fleets
AI and Biometrics Related LawsVariousRapidly evolving landscapeKey state and regional rules passed in recent yearsNew AI and biometrics laws likely in multiple jurisdictionsRelevant for voice, vision and identity features on next generation kiosks

More Discrete Standards Listing

  • ADA Standards for Kiosks — Providing access for the disabled is the law, not an option. Disabled come in all forms from wheelchair, to hearing to sight to any number of “differences”. These standards apply to digital signage to ATMs to POS checkout to any public access system.
  • Section 508 — often overlooked but this standard ensures that government online cyber mechanisms communicate effectively with users.
  • Air Carrier Access Act from Department of Transportation
  • Universal Design by Section 508
  • Universal Design Principles by Berkeley
  • ADA for Europe is covered in EN 301-549. EN 301 549 is the European standard that sets out accessibility requirements for information and communication technology (ICT) procured by the public sector. It applies to products as well as services.
  • HIPAA Standards for Privacy & Self-Service — security in healthcare is originating basis but data security extends to all types of public data collection.  Violations can result in millions of dollars in fines.
  • FDA Standards – A 510(K) is a premarket submission made to FDA to demonstrate that the device to be marketed is as safe and effective, that is, substantially equivalent, to a legally marketed device (section 513(i)(1)(A) FD&C Act) that is not subject to premarket approval.
  • PCI & EMV Payment Standards — from out of scope to QSA to devices to much more, payment data must be protected.  October 2015 is the big Liability Shift  and organizations are putting in place their response now.
  • UL Standards — an exposition of UL standards which come into play for self-service (kiosks, ATMs, Checkouts) including UL 2361, UL 291
  • Made in America — see DOT for regulations. Many RFPs specify American Made and then you have the DOT doc explaining exactly what is meant by that. A bit like ADA compliant.
  • Environmental Standards for Outdoor — this includes the various standards that come into play for Outdoor or environmental circumstance. This ranges from NEMA rating to IP standards for ingression protection to vandal resistant touch screens.  What is the difference between NEMA 4 and NEMA 4X (besides about $200 in cost).
  • 60601-1 — Medical devices/equipment is held to a higher level of safety than almost all other types of equipment on the market.
  • Here is ISO page and here is ISO Medical Devices related page for ISO 13485.
  • Gaming Regulations – GLI Certification — GLI’s business is to test, review and report on gaming devices and systems against the standards established by relevant gaming jurisdictions worldwide. Each jurisdiction has the authority to set their own standards; however, many use our standards as a starting point in developing their regulations.
  • WCAG — Here is the working draft for 2.2. Web Content Accessibility Guidelines (WCAG) 2.2 covers a wide range of recommendations for making Web content more accessible.
  • For testing

Tools We Use Everyday

More Regulations and Certification That Come Into Play — Depending

Light Electric Vehicles (bikes, scooters, eg) — UL 2271, 2849 — ISO 13063

Typical Smart City –– from Cherry Creek Colorado 2023

  • Weatherproof, including ability to function in extreme heat and cold;
  • Graffiti resistant including procedures for preventing and rectifying damage from inclement weather, dirt and
    vandals, which shall be the responsibility of vendor;
  • ADA compliant including adjusting height of content and interactive features for users in wheelchairs and
    approach height/reach requirements and accessibility for the visually impaired;
  • Allow for the display of advertising as approved by the CCN BID, when passive, but upon engagement by a
    user, the advertising will be minimized or eliminated to take a secondary position to interactive content;
  • Employ interactive touchscreen technology, be location aware with customized mapping and wayfinding, in
    particular with supporting features for local retail locations;
  • Provide filtering to search by category of activity; include rational sorting protocol including proximity and type;
    include a procedure to ensure all content is up to date, accurate and relevant; and an ability to transfer
    information to user’s mobile devices.
  • Provide surveying capability including the ability to pose questions to users, collect responses and
    disseminate to the CCN BID;
  • Include potential integration of social media, gaming and other applications to encourage use engagement;
  • Have the ability to switch between Spanish and English with the capability of support for other languages at a
    later date

More