ConsentPixel – Privacy · Verified

🇩🇪 EU Member State · Cookie Law

Germany Cookie Compliance in 2026

Germany is the only major EU market where a bad Cookie-Banner can be attacked from two directions at once: by one of 16 state data protection authorities, and — since the Federal Court of Justice ruled in March 2025 — by your own competitors. If your site reaches German visitors, § 25 TDDDG and the DSGVO both apply, and so does an entire private enforcement industry.

Updated July 2026 15 min read Covers the TTDSG → TDDDG rename
German enforcement — the structure
16
Independent state DPAs, plus the federal BfDI — enforcement varies by Bundesland
2
Separate enforcement fronts: regulators and private Abmahnungen
€300k
Maximum fine under § 28 TDDDG — before the DSGVO's own ceiling applies
~€100
Per person, the BGH's 2024 benchmark for loss of control over personal data
€35.3M
H&M — employee surveillance (Hamburg DPA, 2020); still Germany's largest DSGVO fine
€14.5M
Deutsche Wohnen — data retention (Berlin DPA, 2019; later reduced on appeal)
€300k
§ 28 TDDDG ceiling — for the act of placing or reading without valid consent
€20M / 4%
DSGVO ceiling — for unlawful processing of the data those cookies collect
Background

First, the name: TTDSG is now TDDDG

If you are searching for TTDSG, you are looking for the right law under its old name. On 14 May 2024, the Telekommunikation-Telemedien-Datenschutz-Gesetz (TTDSG) was renamed the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG). The change came via the Digitale-Dienste-Gesetz (DDG), Germany's transposition of the EU Digital Services Act, which replaced the term Telemedien with digitale Dienste and repealed the old Telemediengesetz (TMG) entirely.

📛

Nothing of substance changed — but your documents should

The decisive cookie provision is still § 25, now § 25 TDDDG. The rules are identical. Practitioners and most existing case law still say "TTDSG," and we use both names here because that is how people search. What should change is your paperwork: if your Datenschutzerklärung or Impressum still cites the TTDSG, update the reference. It is a small signal, and German regulators and Abmahn-lawyers read small signals as evidence of neglect.

Why German cookie compliance needs a legal basis twice

Germany runs two laws in parallel, and the division of labour is strict — with one detail that catches out almost every foreign operator.

§ 25 TDDDG governs Zugriff auf die Endeinrichtung — access to the end device. The moment you store information on a visitor's device or read information already there, this applies, regardless of whether personal data is involved. It is Germany's transposition of ePrivacy Article 5(3).

The DSGVO (Datenschutz-Grundverordnung — GDPR under its German name) then governs what you do with any personal data obtained. Setting an analytics cookie falls under the TDDDG. Analysing the resulting user profile falls under the DSGVO. You need both sides clean, and each has its own range of fines.

⚠️

§ 25 TDDDG has no legitimate interest — and this is the trap

Under Art. 6 DSGVO you can weigh interests and rely on berechtigtes Interesse. Under § 25 TDDDG you cannot. There is no balancing of interests for device access: either a narrow statutory exception applies, or you need consent. Full stop. That includes pure reach measurement — the statistics exemption that was floated in the ePrivacy draft never became law. Any consent strategy built on "legitimate interest covers our analytics" fails in Germany at the first hurdle.

 § 25 TDDDG (formerly TTDSG)DSGVO (GDPR)
What it governsStoring or reading information on the end deviceProcessing of personal data
Personal data required?No — applies regardlessYes, by definition
Legal bases availableConsent, or two narrow exceptions. No legitimate interest.Six bases under Art. 6, including legitimate interest
Maximum fineUp to €300,000 (§ 28 TDDDG)Up to €20M or 4% of global turnover
SupervisorState DPAs (16) + BfDIState DPAs (16) + BfDI

Does this apply if my business isn't German?

Yes. § 1(3) TDDDG applies the Marktortprinzip (market-location principle), modelled on the DSGVO: the law reaches anyone with a German branch, anyone participating in the provision of services in Germany, or anyone making goods available on the German market. In December 2025 the Oberlandesgericht Frankfurt pushed this further, holding that § 25 TDDDG is not limited to "providers" in the narrow statutory sense — it applies to everyone who causally initiates storage or access on a device. A third-party technology company was held directly liable for cookies it set through someone else's website, even though the website operator was the one who had failed to obtain consent.

Core requirement

The German word for consent is Einwilligung, and the standard comes from Art. 4(11) DSGVO via § 25(1) TDDDG: freely given, specific, informed, and unambiguous. Two supreme-court decisions settled the ground rules, and the DSK's Orientierungshilfe fills in the detail.

1

Active opt-in — Planet49 settled it

The CJEU ruled in Planet49 (C-673/17, 2019) that a pre-ticked box is not valid consent; the BGH adopted this for Germany on 28 May 2020 (Cookie-Einwilligung II, I ZR 7/16). Pre-set checkmarks and "continued browsing = consent" are both unlawful.

2

Nothing fires before the click

Non-essential cookies and similar technologies must be technically blocked until the visitor actively consents. A banner that informs while scripts already transmit is the most common German failure — and the easiest for an Abmahn-lawyer to document with a HAR file.

3

Equivalent options — including position

The DSK is specific: accept and reject must be gleichwertig. Equivalence isn't only colour — an identical-looking button is still insufficient if it sits at a different height or level of the banner. Rejecting must cost no more effort than accepting.

4

Withdrawal as easy as consent

Art. 7(3) DSGVO requires that revoking consent be as simple as giving it. In practice: a persistent "Cookie-Einstellungen" link in the footer, not a buried instruction in the Datenschutzerklärung.

The nuance most English-language guides get wrong. You will often read that German law requires a "Reject all" button on the first layer, full stop. The DSK's own position is narrower: a first-level reject function is not generally required — it is required when users must interact with the banner to continue visiting the site. Since almost every real-world banner does exactly that, the practical answer is usually yes, put reject on layer one. But the reasoning matters: if consent can only be given on a deeper level, the DSK accepts that rejection may live there too. What is never acceptable is asymmetry — offering acceptance on layer one while pushing refusal deeper. Without an objective justification, the DSK treats that as an attempt to influence users contrary to Treu und Glauben (Art. 5(1)(a) DSGVO), which invalidates the consent.

What a compliant German Cookie-Banner must and must not do

✕ NON-COMPLIANT

  • Cookies fire on page load, before consent
  • Pre-ticked boxes for analytics or marketing
  • "Weitersurfen gilt als Einwilligung" — continued browsing as consent
  • Accept on layer one, reject buried deeper, with no objective reason
  • Reject button present but at a different height or level
  • An "Okay"-only banner with no genuine choice
  • Google Fonts loaded dynamically from Google's servers
  • Banner text and Datenschutzerklärung listing different third parties
  • Relying on legitimate interest for device access

✓ COMPLIANT

  • All non-essential technologies blocked until active Einwilligung
  • Every non-essential category unchecked by default
  • An unambiguous affirmative action — a click
  • Accept and reject offered at the same level and effort
  • Buttons genuinely equivalent — position, size, contrast
  • Real choice presented, clearly labelled by purpose
  • Fonts self-hosted; embeds blocked until consent
  • Banner and Datenschutzerklärung congruent — same tools, same bases
  • Consent or a § 25(2) exception — nothing else
Full requirements

All German cookie requirements for website operators

Consent before device access

Storing or reading information on a visitor's device is only permitted with consent given on the basis of clear and comprehensive information — irrespective of whether the information is personal data.

§ 25(1) TDDDG

Two narrow exceptions only

Consent is unnecessary only where the sole purpose is carrying out the transmission of a message, or where access is unbedingt erforderlich — absolutely necessary — for a service the user has expressly requested. Nothing else qualifies.

§ 25(2) TDDDG

No legitimate interest for device access

§ 25 offers only two routes: a valid Einwilligung, or an exception under paragraph 2. Unlike Art. 6 DSGVO, there is no Interessenabwägung. Reach measurement is not exempt.

§ 25 TDDDG (systematic)

A lawful basis for the processing too

Consent under § 25 covers the cookie. The subsequent processing needs its own basis under Art. 6 DSGVO. If the § 25 consent is invalid, the DSK's position is that the downstream processing built on it is unlawful as well.

Art. 6(1) DSGVO

Congruent information

The DSK repeatedly flags banners whose stated third parties or legal bases differ from the Datenschutzerklärung. The two must match — mismatches are a documented supervisory finding, not a technicality.

Art. 13 DSGVO · DSK OH

Bundled consent must be visible as such

If one click grants several consents — TDDDG and DSGVO together — that must be unmistakably clear from the wording. A banner asking only about cookies, silent on downstream processing, is not valid bundled consent.

DSK Orientierungshilfe

Cookie lifetimes must be limited

The DSK ties cookie durations to the storage-limitation principle: cookies must carry defined lifetimes and automated deletion must be in place. Indefinite identifiers are a finding waiting to happen.

Art. 5(1)(e) DSGVO

Demonstrable consent (Nachweisbarkeit)

You must be able to show that consent was obtained, when, and to what. German authorities treat verifiability as a core expectation — consent logs are not optional.

Art. 5(2) + Art. 7(1) DSGVO

Pixels, fingerprinting and local storage count

The DSK's revised guidance incorporates EDPB Guidelines 2/2023 on the technical scope of Art. 5(3) ePrivacy. § 25 reaches localStorage, sessionStorage, fingerprinting scripts and tracking pixels — not just HTTP cookies.

EDPB Guidelines 2/2023

Third-country transfers still need care

The EU-US Data Privacy Framework (July 2023, upheld by the General Court in September 2025) legitimises transfers to participating US firms. It does not remove the need for consent before the transfer happens.

Chapter V DSGVO · DPF
🇪🇺

The EU AI Act applies to German sites from 2 August 2026

Article 50 requires disclosure of AI-powered features to EU visitors. We built the disclosure into the consent banner — enable the toggle, publish, done.

Learn more →
Enforcement

Two fronts: regulators and your competitors

This is what makes Germany different from every other EU market. In the Netherlands, one national authority scans and warns. In Germany, you face two independent enforcement mechanisms that can both hit the same violation — and the second one changed dramatically in 2025.

Front 1 — the regulators
16 DPAs
one per Bundesland, plus the federal BfDI

Independent, and uneven. Bayern's BayLDA runs systematic reviews and publishes explicit guidance on Google Analytics and cookies. Hamburg issued the H&M fine. Baden-Württemberg publishes detailed case reports. Your exposure depends partly on where you are established.

Front 2 — private Abmahnungen
Competitors
since BGH, 27 March 2025

A Abmahnung is a private cease-and-desist demand — no regulator involved. The BGH confirmed that DSGVO breaches are violations of market-conduct rules under § 3a UWG, so competitors and consumer associations can now pursue you civilly, without any affected individual complaining.

⚖️

The BGH ruling that opened the second front

On 27 March 2025, the Bundesgerichtshof decided a trio of cases (I ZR 186/17, I ZR 222/19, I ZR 223/19) holding that data protection violations count as breaches of market-conduct rules under § 3a UWG. The reasoning: personal data has economic value, so processing it unlawfully confers an unfair competitive advantage. The practical consequence is that your competitors can now abmahnen you for a non-compliant Cookie-Banner — and they don't need a single affected user to complain first. Data protection compliance in Germany is no longer only a matter between you and the authority. It is a competitive factor.

What the Abmahnung industry actually targets

The Google Fonts wave is the cautionary tale every German website operator knows. On 20 January 2022, the Landgericht München I (3 O 17493/20) held that embedding Google Fonts dynamically — loading them from fonts.googleapis.com rather than your own server — transmits the visitor's IP address to Google without consent, and awarded €100 in damages. Two law firms then sent tens of thousands of near-identical letters demanding €100–170 each, targeting everyone from bakers' online shops to law firms.

The wave broke: in March 2023 the LG München I ruled the mass-Abmahnung model rechtsmissbräuchlich — an abuse of rights — and Berlin prosecutors investigated at least 2,418 suspected cases of Abmahn-fraud. Mass letters have largely stopped.

But the underlying law didn't change. The LG München I judgment was never overturned. Dynamically embedded Google Fonts still transmit an IP address without a legal basis; the court rejected legitimate interest, holding that a particular typeface does not outweigh the visitor's data protection. What ended was the mass model — not the risk of a targeted Abmahnung from a competitor, or a fine from an authority. And the fix takes an hour: download the fonts, serve them yourself.

The same applies to every externally embedded resource: Google Maps, YouTube, reCAPTCHA — each sends the visitor's IP to Google on load. Self-host, use a privacy-preserving alternative, or block the embed behind consent.

TriggerFrontTypical exposure
Cookie-Banner without genuine opt-inBoth§ 28 TDDDG up to €300k · DSGVO up to €20M/4% · Abmahnung + Abmahnkosten
Cookies set despite rejectionBothTreated as especially serious — the technical failure is documented in seconds
Incomplete DatenschutzerklärungAbmahnungThe single most common trigger — must name every tool and processor
Google Fonts loaded remotelyAbmahnung€100–170 historically; targeted claims still possible
Loss of control over personal dataCivil claimBGH benchmark ~€100 per person (Nov 2024); some courts far higher; no de minimis threshold
Live compliance check — fresh German session, no cookies
Google Analytics (gtag / ga.js)BLOCKED
Meta Pixel (connect.facebook.net)BLOCKED
Google Fonts (fonts.googleapis.com)SELF-HOSTED
YouTube embed (youtube.com)BLOCKED
reCAPTCHA (google.com/recaptcha)BLOCKED
Cookie-Banner — Akzeptieren & Ablehnen, equal weight✓ DISPLAYED
Einwilligung log entry✓ PENDING CHOICE
This is the network view an Abmahn-lawyer captures as a HAR file. Every row that reads "LOADED" before the visitor clicks is documentary evidence. After Akzeptieren, scripts release and the choice is logged with a timestamp. After Ablehnen, everything above stays blocked.
📌

The EinwV: relief that hasn't arrived

The Einwilligungsverwaltungsverordnung (EinwV), in force since 1 April 2025 under § 26(2) TDDDG, was meant to reduce banner fatigue by letting recognised consent management services (PIMS) signal a user's stored preferences to websites. It is voluntary, and widely expected to fail: certification requirements are demanding, and because consent under the EinwV and consent under the DSGVO are separate, users could end up facing two dialogues instead of one. Do not plan around it. If your current stack satisfies § 25 TDDDG and the DSGVO, you need change nothing.

Where Germany sits among EU regulators

Germany is widely called the strictest EU market for cookies, and on the substantive law that is roughly right — the absence of any legitimate-interest route under § 25 is genuinely tighter than most member states. The more useful comparison is structural. The Dutch AP is centralised, funded to scan 10,000 sites a year, and predictable: it warns, then investigates. German regulatory enforcement is split across sixteen authorities and is correspondingly uneven — but sits on top of a private enforcement industry no other member state has at this scale. The upshot: the Dutch regulator finds you systematically; a German competitor finds you opportunistically. The same technical fix answers both.

Free tool

Scan your site for German cookie violations

Every German enforcement action — regulatory or private — starts identically: someone loads your site with a clean session and records what transmits before consent, saved as a HAR file. Our free scanner runs the same check in about ten seconds: it opens your homepage with no cookies, records every tracker and external resource firing before any Einwilligung, and shows you exactly what a German claimant would document. No account needed.

Action plan

How to make your website compliant for German visitors

1

Install a CMP that blocks, not just displays

The banner is not the compliance measure — the blocking is. A compliant platform prevents non-essential technologies from firing until Einwilligung is given, presents Akzeptieren and Ablehnen as genuinely equivalent options, and logs every decision. ConsentPixel — Privacy · Verified does all three from one script tag.

2

Self-host your fonts — today

Download your Google Fonts, serve the .woff2 files from your own server, and remove every fonts.googleapis.com reference. This takes under an hour, improves performance, and closes the single most-abgemahnt issue in German web history. There is no reason to keep the risk.

3

Block every external embed behind consent

Google Maps, YouTube, reCAPTCHA and similar all transmit the visitor's IP to a third party on load. Use privacy-preserving variants where they exist (youtube-nocookie, hCaptcha, Cloudflare Turnstile, OpenStreetMap), or hold the embed behind a consent placeholder.

4

Make Ablehnen genuinely equivalent

Same level, same height, same effort as Akzeptieren. The DSK is explicit that an identical-looking button is still insufficient if it sits elsewhere in the banner. If you cannot give an objective reason why refusal is harder than acceptance, the DSK treats the design as contrary to Treu und Glauben — and the consent as invalid.

5

Verify in DevTools — don't trust the banner

Open a private window, DevTools → Network, reload, and watch what transmits before you touch the banner. Then click Ablehnen and reload again. Cookies set despite rejection are the most damaging finding of all, because the evidence is unambiguous and takes seconds to capture.

6

Align the Datenschutzerklärung with reality

Name every tool, processor, purpose, legal basis and retention period — and make sure the banner says the same thing. An incomplete privacy statement is the most common Abmahnung trigger, and a mismatch between banner and Erklärung is a documented DSK finding. Replace any remaining "TTDSG" references with "TDDDG" while you are in there.

7

Keep an Einwilligung log you can produce

German authorities expect Nachweisbarkeit: proof of what was shown, what was chosen, and when. "We had a banner" is not an answer to a supervisory question — and in a civil claim, a timestamped log is the difference between a defence and a settlement.

Compliance checklist

German cookie compliance checklist 2026

Common questions

Germany cookie compliance — frequently asked questions

Is the TTDSG still called the TTDSG?
No. The Telekommunikation-Telemedien-Datenschutz-Gesetz (TTDSG) was renamed the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG) on 14 May 2024, when the Digitale-Dienste-Gesetz (DDG) transposed the EU Digital Services Act into German law and replaced the term "Telemedien" with "digitale Dienste". Nothing of substance changed — the cookie provision is still § 25, now § 25 TDDDG. Most practitioners and existing case law still say TTDSG. You should, however, update any reference in your Datenschutzerklärung or Impressum to the current name.
Which laws govern cookies in Germany?
Two apply together. § 25 TDDDG (formerly TTDSG) governs storing or reading information on a visitor's device — this applies regardless of whether personal data is involved — and carries fines up to €300,000 under § 28 TDDDG. The DSGVO then governs the processing of any personal data obtained, with fines up to €20 million or 4% of global annual turnover. Setting an analytics cookie falls under the TDDDG; analysing the resulting profile falls under the DSGVO. You need a valid legal basis under both.
Can I rely on legitimate interest for cookies in Germany?
Not for device access. This is the trap that catches most foreign operators. § 25 TDDDG offers only two routes: a valid Einwilligung, or one of two narrow exceptions in paragraph 2 — transmitting a message, or what is absolutely necessary for a service the user expressly requested. There is no balancing of interests, unlike Art. 6(1)(f) DSGVO. Pure reach measurement is not exempt; the statistics exemption discussed in the ePrivacy draft never became law.
Does a reject button have to be on the first layer of the banner?
In practice, almost always — but the DSK's reasoning is narrower than most guides suggest. The supervisory authorities state that a first-level reject function is not generally required, only where users must interact with the banner to continue visiting the site. Since nearly every real banner works that way, the practical answer is yes. What is never acceptable is asymmetry: offering acceptance on layer one while pushing refusal deeper, without an objective justification, is treated as contrary to Treu und Glauben under Art. 5(1)(a) DSGVO and invalidates the consent. Equivalence also covers position — an identical button at a different height is still insufficient.
Can competitors sue me over a bad cookie banner in Germany?
Yes, since 27 March 2025. The Bundesgerichtshof ruled in three cases (I ZR 186/17, I ZR 222/19, I ZR 223/19) that data protection violations constitute breaches of market-conduct rules under § 3a UWG, on the reasoning that unlawfully processing valuable personal data confers an unfair competitive advantage. Competitors and consumer protection associations can now pursue you civilly — no affected individual needs to complain, and no regulator need be involved. This is a second, entirely separate enforcement front alongside the 16 state data protection authorities.
Are Google Fonts still an Abmahnung risk in 2026?
The mass wave is over; the underlying risk is not. The Landgericht München I held on 20 January 2022 (3 O 17493/20) that dynamically embedding Google Fonts transmits the visitor's IP to Google without a legal basis, awarding €100. Two firms then sent tens of thousands of letters demanding €100–170. Courts subsequently ruled that model rechtsmissbräuchlich, and Berlin prosecutors investigated at least 2,418 suspected fraud cases. But the judgment was never overturned, targeted Abmahnungen from competitors remain possible, and authorities can still fine. Self-hosting the fonts takes under an hour and removes the issue entirely.
Does German cookie law apply if my business isn't in Germany?
Yes, if you serve the German market. § 1(3) TDDDG applies the Marktortprinzip — the market-location principle modelled on the DSGVO — reaching anyone with a German branch, anyone participating in providing services in Germany, or anyone making goods available on the German market. In December 2025 the Oberlandesgericht Frankfurt went further, holding that § 25 applies to everyone who causally initiates storage or access on a device, not only "providers" narrowly defined — a third-party technology company was held directly liable for cookies set through another operator's website.
Do I need to use a recognised consent management service under the EinwV?
No. The Einwilligungsverwaltungsverordnung (EinwV), in force since 1 April 2025 under § 26(2) TDDDG, is entirely voluntary — there are no penalties for not using a recognised service. It was intended to reduce banner fatigue by letting certified services signal stored preferences, but experts widely expect it to fail: certification requirements are demanding, and because EinwV consent and DSGVO consent are separate, users could face two dialogues rather than one. If your existing setup satisfies § 25 TDDDG and the DSGVO, you need change nothing.
Is Germany stricter than the Netherlands on cookies?
On the substantive law, marginally — § 25 TDDDG's complete absence of a legitimate-interest route is tighter than most member states. The bigger difference is structural. The Dutch AP is a single centralised regulator, specifically funded to scan around 10,000 websites a year and warn 500, so enforcement is systematic and predictable. German regulatory enforcement is split across 16 state authorities and is uneven — but it sits on top of a private Abmahnung industry that no other member state has at comparable scale. The Dutch regulator finds you systematically; a German competitor finds you opportunistically. The same technical fix answers both.

Compliant for German visitors in 10 minutes

ConsentPixel — Privacy · Verified blocks every non-essential technology until Einwilligung is given, presents Akzeptieren and Ablehnen as genuine equals, and logs every decision with a timestamp for Nachweisbarkeit. One script tag. § 25 TDDDG, DSGVO, and the rest of the EU.

No credit card required · Setup in 10 minutes · Cancel anytime

Not legal advice. This page is an educational summary of German and EU privacy law based on published statutes, court decisions, DSK guidance and reputable reporting. It is not legal advice, and German case law in this area is actively developing. Verify current requirements with your competent state authority and consult a qualified German IT-Recht lawyer about your specific situation — particularly if you have received an Abmahnung, where response deadlines are typically 7–14 days.
Scroll to Top