Germany Cookie Compliance in 2026
Germany is the only major EU market where a bad Cookie-Banner can be attacked from two directions at once: by one of 16 state data protection authorities, and — since the Federal Court of Justice ruled in March 2025 — by your own competitors. If your site reaches German visitors, § 25 TDDDG and the DSGVO both apply, and so does an entire private enforcement industry.
First, the name: TTDSG is now TDDDG
If you are searching for TTDSG, you are looking for the right law under its old name. On 14 May 2024, the Telekommunikation-Telemedien-Datenschutz-Gesetz (TTDSG) was renamed the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG). The change came via the Digitale-Dienste-Gesetz (DDG), Germany's transposition of the EU Digital Services Act, which replaced the term Telemedien with digitale Dienste and repealed the old Telemediengesetz (TMG) entirely.
Nothing of substance changed — but your documents should
The decisive cookie provision is still § 25, now § 25 TDDDG. The rules are identical. Practitioners and most existing case law still say "TTDSG," and we use both names here because that is how people search. What should change is your paperwork: if your Datenschutzerklärung or Impressum still cites the TTDSG, update the reference. It is a small signal, and German regulators and Abmahn-lawyers read small signals as evidence of neglect.
Why German cookie compliance needs a legal basis twice
Germany runs two laws in parallel, and the division of labour is strict — with one detail that catches out almost every foreign operator.
§ 25 TDDDG governs Zugriff auf die Endeinrichtung — access to the end device. The moment you store information on a visitor's device or read information already there, this applies, regardless of whether personal data is involved. It is Germany's transposition of ePrivacy Article 5(3).
The DSGVO (Datenschutz-Grundverordnung — GDPR under its German name) then governs what you do with any personal data obtained. Setting an analytics cookie falls under the TDDDG. Analysing the resulting user profile falls under the DSGVO. You need both sides clean, and each has its own range of fines.
§ 25 TDDDG has no legitimate interest — and this is the trap
Under Art. 6 DSGVO you can weigh interests and rely on berechtigtes Interesse. Under § 25 TDDDG you cannot. There is no balancing of interests for device access: either a narrow statutory exception applies, or you need consent. Full stop. That includes pure reach measurement — the statistics exemption that was floated in the ePrivacy draft never became law. Any consent strategy built on "legitimate interest covers our analytics" fails in Germany at the first hurdle.
| § 25 TDDDG (formerly TTDSG) | DSGVO (GDPR) | |
|---|---|---|
| What it governs | Storing or reading information on the end device | Processing of personal data |
| Personal data required? | No — applies regardless | Yes, by definition |
| Legal bases available | Consent, or two narrow exceptions. No legitimate interest. | Six bases under Art. 6, including legitimate interest |
| Maximum fine | Up to €300,000 (§ 28 TDDDG) | Up to €20M or 4% of global turnover |
| Supervisor | State DPAs (16) + BfDI | State DPAs (16) + BfDI |
Does this apply if my business isn't German?
Yes. § 1(3) TDDDG applies the Marktortprinzip (market-location principle), modelled on the DSGVO: the law reaches anyone with a German branch, anyone participating in the provision of services in Germany, or anyone making goods available on the German market. In December 2025 the Oberlandesgericht Frankfurt pushed this further, holding that § 25 TDDDG is not limited to "providers" in the narrow statutory sense — it applies to everyone who causally initiates storage or access on a device. A third-party technology company was held directly liable for cookies it set through someone else's website, even though the website operator was the one who had failed to obtain consent.
What valid Einwilligung requires in Germany
The German word for consent is Einwilligung, and the standard comes from Art. 4(11) DSGVO via § 25(1) TDDDG: freely given, specific, informed, and unambiguous. Two supreme-court decisions settled the ground rules, and the DSK's Orientierungshilfe fills in the detail.
Active opt-in — Planet49 settled it
The CJEU ruled in Planet49 (C-673/17, 2019) that a pre-ticked box is not valid consent; the BGH adopted this for Germany on 28 May 2020 (Cookie-Einwilligung II, I ZR 7/16). Pre-set checkmarks and "continued browsing = consent" are both unlawful.
Nothing fires before the click
Non-essential cookies and similar technologies must be technically blocked until the visitor actively consents. A banner that informs while scripts already transmit is the most common German failure — and the easiest for an Abmahn-lawyer to document with a HAR file.
Equivalent options — including position
The DSK is specific: accept and reject must be gleichwertig. Equivalence isn't only colour — an identical-looking button is still insufficient if it sits at a different height or level of the banner. Rejecting must cost no more effort than accepting.
Withdrawal as easy as consent
Art. 7(3) DSGVO requires that revoking consent be as simple as giving it. In practice: a persistent "Cookie-Einstellungen" link in the footer, not a buried instruction in the Datenschutzerklärung.
What a compliant German Cookie-Banner must and must not do
✕ NON-COMPLIANT
- Cookies fire on page load, before consent
- Pre-ticked boxes for analytics or marketing
- "Weitersurfen gilt als Einwilligung" — continued browsing as consent
- Accept on layer one, reject buried deeper, with no objective reason
- Reject button present but at a different height or level
- An "Okay"-only banner with no genuine choice
- Google Fonts loaded dynamically from Google's servers
- Banner text and Datenschutzerklärung listing different third parties
- Relying on legitimate interest for device access
✓ COMPLIANT
- All non-essential technologies blocked until active Einwilligung
- Every non-essential category unchecked by default
- An unambiguous affirmative action — a click
- Accept and reject offered at the same level and effort
- Buttons genuinely equivalent — position, size, contrast
- Real choice presented, clearly labelled by purpose
- Fonts self-hosted; embeds blocked until consent
- Banner and Datenschutzerklärung congruent — same tools, same bases
- Consent or a § 25(2) exception — nothing else
All German cookie requirements for website operators
Consent before device access
Storing or reading information on a visitor's device is only permitted with consent given on the basis of clear and comprehensive information — irrespective of whether the information is personal data.
§ 25(1) TDDDGTwo narrow exceptions only
Consent is unnecessary only where the sole purpose is carrying out the transmission of a message, or where access is unbedingt erforderlich — absolutely necessary — for a service the user has expressly requested. Nothing else qualifies.
§ 25(2) TDDDGNo legitimate interest for device access
§ 25 offers only two routes: a valid Einwilligung, or an exception under paragraph 2. Unlike Art. 6 DSGVO, there is no Interessenabwägung. Reach measurement is not exempt.
§ 25 TDDDG (systematic)A lawful basis for the processing too
Consent under § 25 covers the cookie. The subsequent processing needs its own basis under Art. 6 DSGVO. If the § 25 consent is invalid, the DSK's position is that the downstream processing built on it is unlawful as well.
Art. 6(1) DSGVOCongruent information
The DSK repeatedly flags banners whose stated third parties or legal bases differ from the Datenschutzerklärung. The two must match — mismatches are a documented supervisory finding, not a technicality.
Art. 13 DSGVO · DSK OHBundled consent must be visible as such
If one click grants several consents — TDDDG and DSGVO together — that must be unmistakably clear from the wording. A banner asking only about cookies, silent on downstream processing, is not valid bundled consent.
DSK OrientierungshilfeCookie lifetimes must be limited
The DSK ties cookie durations to the storage-limitation principle: cookies must carry defined lifetimes and automated deletion must be in place. Indefinite identifiers are a finding waiting to happen.
Art. 5(1)(e) DSGVODemonstrable consent (Nachweisbarkeit)
You must be able to show that consent was obtained, when, and to what. German authorities treat verifiability as a core expectation — consent logs are not optional.
Art. 5(2) + Art. 7(1) DSGVOPixels, fingerprinting and local storage count
The DSK's revised guidance incorporates EDPB Guidelines 2/2023 on the technical scope of Art. 5(3) ePrivacy. § 25 reaches localStorage, sessionStorage, fingerprinting scripts and tracking pixels — not just HTTP cookies.
EDPB Guidelines 2/2023Third-country transfers still need care
The EU-US Data Privacy Framework (July 2023, upheld by the General Court in September 2025) legitimises transfers to participating US firms. It does not remove the need for consent before the transfer happens.
Chapter V DSGVO · DPFThe EU AI Act applies to German sites from 2 August 2026
Article 50 requires disclosure of AI-powered features to EU visitors. We built the disclosure into the consent banner — enable the toggle, publish, done.
Two fronts: regulators and your competitors
This is what makes Germany different from every other EU market. In the Netherlands, one national authority scans and warns. In Germany, you face two independent enforcement mechanisms that can both hit the same violation — and the second one changed dramatically in 2025.
Independent, and uneven. Bayern's BayLDA runs systematic reviews and publishes explicit guidance on Google Analytics and cookies. Hamburg issued the H&M fine. Baden-Württemberg publishes detailed case reports. Your exposure depends partly on where you are established.
A Abmahnung is a private cease-and-desist demand — no regulator involved. The BGH confirmed that DSGVO breaches are violations of market-conduct rules under § 3a UWG, so competitors and consumer associations can now pursue you civilly, without any affected individual complaining.
The BGH ruling that opened the second front
On 27 March 2025, the Bundesgerichtshof decided a trio of cases (I ZR 186/17, I ZR 222/19, I ZR 223/19) holding that data protection violations count as breaches of market-conduct rules under § 3a UWG. The reasoning: personal data has economic value, so processing it unlawfully confers an unfair competitive advantage. The practical consequence is that your competitors can now abmahnen you for a non-compliant Cookie-Banner — and they don't need a single affected user to complain first. Data protection compliance in Germany is no longer only a matter between you and the authority. It is a competitive factor.
What the Abmahnung industry actually targets
The Google Fonts wave is the cautionary tale every German website operator knows. On 20 January 2022, the Landgericht München I (3 O 17493/20) held that embedding Google Fonts dynamically — loading them from fonts.googleapis.com rather than your own server — transmits the visitor's IP address to Google without consent, and awarded €100 in damages. Two law firms then sent tens of thousands of near-identical letters demanding €100–170 each, targeting everyone from bakers' online shops to law firms.
The wave broke: in March 2023 the LG München I ruled the mass-Abmahnung model rechtsmissbräuchlich — an abuse of rights — and Berlin prosecutors investigated at least 2,418 suspected cases of Abmahn-fraud. Mass letters have largely stopped.
The same applies to every externally embedded resource: Google Maps, YouTube, reCAPTCHA — each sends the visitor's IP to Google on load. Self-host, use a privacy-preserving alternative, or block the embed behind consent.
| Trigger | Front | Typical exposure |
|---|---|---|
| Cookie-Banner without genuine opt-in | Both | § 28 TDDDG up to €300k · DSGVO up to €20M/4% · Abmahnung + Abmahnkosten |
| Cookies set despite rejection | Both | Treated as especially serious — the technical failure is documented in seconds |
| Incomplete Datenschutzerklärung | Abmahnung | The single most common trigger — must name every tool and processor |
| Google Fonts loaded remotely | Abmahnung | €100–170 historically; targeted claims still possible |
| Loss of control over personal data | Civil claim | BGH benchmark ~€100 per person (Nov 2024); some courts far higher; no de minimis threshold |
The EinwV: relief that hasn't arrived
The Einwilligungsverwaltungsverordnung (EinwV), in force since 1 April 2025 under § 26(2) TDDDG, was meant to reduce banner fatigue by letting recognised consent management services (PIMS) signal a user's stored preferences to websites. It is voluntary, and widely expected to fail: certification requirements are demanding, and because consent under the EinwV and consent under the DSGVO are separate, users could end up facing two dialogues instead of one. Do not plan around it. If your current stack satisfies § 25 TDDDG and the DSGVO, you need change nothing.
Where Germany sits among EU regulators
Germany is widely called the strictest EU market for cookies, and on the substantive law that is roughly right — the absence of any legitimate-interest route under § 25 is genuinely tighter than most member states. The more useful comparison is structural. The Dutch AP is centralised, funded to scan 10,000 sites a year, and predictable: it warns, then investigates. German regulatory enforcement is split across sixteen authorities and is correspondingly uneven — but sits on top of a private enforcement industry no other member state has at this scale. The upshot: the Dutch regulator finds you systematically; a German competitor finds you opportunistically. The same technical fix answers both.
Scan your site for German cookie violations
Every German enforcement action — regulatory or private — starts identically: someone loads your site with a clean session and records what transmits before consent, saved as a HAR file. Our free scanner runs the same check in about ten seconds: it opens your homepage with no cookies, records every tracker and external resource firing before any Einwilligung, and shows you exactly what a German claimant would document. No account needed.
How to make your website compliant for German visitors
Install a CMP that blocks, not just displays
The banner is not the compliance measure — the blocking is. A compliant platform prevents non-essential technologies from firing until Einwilligung is given, presents Akzeptieren and Ablehnen as genuinely equivalent options, and logs every decision. ConsentPixel — Privacy · Verified does all three from one script tag.
Self-host your fonts — today
Download your Google Fonts, serve the .woff2 files from your own server, and remove every fonts.googleapis.com reference. This takes under an hour, improves performance, and closes the single most-abgemahnt issue in German web history. There is no reason to keep the risk.
Block every external embed behind consent
Google Maps, YouTube, reCAPTCHA and similar all transmit the visitor's IP to a third party on load. Use privacy-preserving variants where they exist (youtube-nocookie, hCaptcha, Cloudflare Turnstile, OpenStreetMap), or hold the embed behind a consent placeholder.
Make Ablehnen genuinely equivalent
Same level, same height, same effort as Akzeptieren. The DSK is explicit that an identical-looking button is still insufficient if it sits elsewhere in the banner. If you cannot give an objective reason why refusal is harder than acceptance, the DSK treats the design as contrary to Treu und Glauben — and the consent as invalid.
Verify in DevTools — don't trust the banner
Open a private window, DevTools → Network, reload, and watch what transmits before you touch the banner. Then click Ablehnen and reload again. Cookies set despite rejection are the most damaging finding of all, because the evidence is unambiguous and takes seconds to capture.
Align the Datenschutzerklärung with reality
Name every tool, processor, purpose, legal basis and retention period — and make sure the banner says the same thing. An incomplete privacy statement is the most common Abmahnung trigger, and a mismatch between banner and Erklärung is a documented DSK finding. Replace any remaining "TTDSG" references with "TDDDG" while you are in there.
Keep an Einwilligung log you can produce
German authorities expect Nachweisbarkeit: proof of what was shown, what was chosen, and when. "We had a banner" is not an answer to a supervisory question — and in a civil claim, a timestamped log is the difference between a defence and a settlement.
German cookie compliance checklist 2026
Germany cookie compliance — frequently asked questions
Is the TTDSG still called the TTDSG?
Which laws govern cookies in Germany?
Can I rely on legitimate interest for cookies in Germany?
Does a reject button have to be on the first layer of the banner?
Can competitors sue me over a bad cookie banner in Germany?
Are Google Fonts still an Abmahnung risk in 2026?
Does German cookie law apply if my business isn't in Germany?
Do I need to use a recognised consent management service under the EinwV?
Is Germany stricter than the Netherlands on cookies?
Compliant for German visitors in 10 minutes
ConsentPixel — Privacy · Verified blocks every non-essential technology until Einwilligung is given, presents Akzeptieren and Ablehnen as genuine equals, and logs every decision with a timestamp for Nachweisbarkeit. One script tag. § 25 TDDDG, DSGVO, and the rest of the EU.
No credit card required · Setup in 10 minutes · Cancel anytime