Point of law
Cookies, tracking and the consent banner
Sec. 25(1) TDDDG covers access to terminal equipment and applies regardless of whether personal data arise in the course of it. It supplies no legal basis for what happens to the data afterwards. That assessment follows from Art. 6(1) GDPR. Both assessments are worth little as long as nobody measures whether the site keeps to what the banner says.
Sixty services behind one banner
The banner has been on the site for two years, set up by the agency that also built the site. The administration screen lists sixty services, not all of which anyone in the organisation can still place. What the site actually loads when it is called up has not been looked at since.
Two consents, and the first does not replace the second
What exactly consent is needed for is the question most banner designs founder on before design even begins. Access to terminal equipment and the processing of the data obtained through it are two operations with two assessments.
The order of the assessment
Access to the device
Sec. 25(1) TDDDG. It applies to any storing and any reading out, and under the case law of the Court of Justice regardless of whether personal data are affected.
Exemption or consent
Sec. 25(2) TDDDG covers the transmission of a message and whatever is strictly necessary for a service the user expressly requested. Everything else needs consent.
The processing afterwards
Art. 6(1) GDPR. Consent under sec. 25 TDDDG covers the setting of the identifier, not its evaluation, its combination and its disclosure to third parties.
3 von 3
The separation has a practical consequence. Consent resting on sec. 25 TDDDG alone names no legal basis for the profiling and the disclosure to advertising partners that follow. Under Art. 5(2) GDPR that basis has to be settled beforehand.
The exemption in sec. 25(2) no. 2 TDDDG, on the other hand, is narrower than it is commonly read. The yardstick is the service the user expressly wants, not the one the business needs. The Administrative Court of Hanover declined to bring Google Tag Manager under the exemption on three grounds. It makes it easier for the operator to embed other services, it offers the user no function, and the loading sequence can be controlled without it.
The limit is not symmetry but steering
How a banner has to look is widely answered with a sentence the case law does not supply.
What is settled is the limit in the other direction. A banner may not steer users towards consent and away from refusal. The authorities also describe how such steering arises in their inspection practice, namely rarely through a single feature and mostly through several acting together. What is assessed is therefore the banner as a whole and not the individual button.
Five features that amounted to steering when taken together
The cross that consents
Top right the banner read “Accept and close x”. A cross in that position closes a window on any ordinary expectation, and that it gives a declaration of intent is surprising.
The banner that returns only to those who refused
After consent the banner stayed away. After a saved selection it appeared again on every visit. That difference is not technically necessary.
The colour that makes a recommendation
“Accept all” was set off in colour, “Save selection” was not. The authorities require the refusal option to be comparable in size, colour, contrast and typeface.
The statement below the fold
The note on transfers to third countries and the number of embedded services appeared only after scrolling down inside the banner. Anyone reading only the visible area decides without them.
Two items of substance are expressly required by the Court of Justice. They are the lifespan of the cookies and information on whether third parties can access them.
No banner is better than the site it sits on
Whether the site does what the banner announces is something hardly anyone checks, in our experience. That is precisely where lawfulness hangs, because storing and reading out are permitted only after the active step has been taken.
The data protection authority of Lower Saxony called up a publisher’s site in its own IT laboratory. Before any interaction with the banner, the IP address, device configuration, country and referrer went to a server in the United States, and a script was placed on the device. What was objected to was therefore not the banner but what ran behind it.
Answerable in half an hour
Four questions to put to your own site
von 3
Consent management is itself a processing operation. The standard of the industry association IAB Europe places a string on the device, the TC String, which embedded service providers are able to read. Together with the IP address it is a personal datum under the case law of the Court of Justice.
How we support you with the consent banner
At the outset there is no legal assessment but a record. The site is called up three times in a fresh browser profile, without any interaction, after a refusal and after consent. What is loaded in the process yields the list against which the consent interface, the record of processing activities and the privacy notice can be compared. Only then is work on wording and arrangement worthwhile.
Frequently asked questions
Does sec. 25 TDDDG apply only to cookies?
No. The provision covers any storing of information in terminal equipment and any access to information already stored there. Tracking pixels, local storage, device characteristics and the reading out of installed fonts fall under it, and under the case law of the Court of Justice it does not matter whether personal data arise in the course of it.
Does a reject button have to appear on the first layer?
Under the supervisory authorities' guidance wherever users have to deal with the banner in order to carry on reading the page, and otherwise not. The authorities add that common banner designs very frequently meet that condition. A button reading “Settings or reject” that leads to a further layer does not suffice there.
Is audience measurement possible without consent?
Only where it works without access to terminal equipment, for instance through a server-side evaluation without an identifier. As soon as an identifier is set or read, sec. 25(1) TDDDG applies, and the exemption in paragraph 2 requires the access to be strictly necessary for a service the user expressly requested. In the authorities' view an operator's own analytics is not such a service.
Does a recognised consent management service help?
So far hardly. Sec. 26 TDDDG and the consent management regulation in force since 01.04.2025 provide for the Federal Commissioner for Data Protection to recognise such services. To date the public register lists a single recognised service, recognised on 17.10.2025. As long as the common browsers do not act on the settings, the banner remains the form in which the question is put in practice.
More questions from this area
Microsoft 365
Whether Microsoft 365 may be used has long been settled in most organisations.
HR management systems
In data protection terms an HR management system is only as good as its access model.
Video surveillance
The yardstick for private video surveillance is Art. 6(1)(f) GDPR and not section 4 BDSG.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.