Cookie Consent Banners: What Obligations Apply to Your Website

Anyone who uses cookies, tracking pixels, or similar tools on their website that are not strictly necessary for the site to function needs the visitors' prior consent for this. A plain notice banner without a genuine choice is no longer sufficient.
In brief: this applies to every website that uses cookies, tracking pixels, or similar technologies that are not technically necessary. Section 25 of the German Telecommunications and Telemedia Data Protection Act (Telekommunikation-Telemedien-Datenschutz-Gesetz, TDDDG) requires prior, active consent from visitors, where rejecting must be just as easy as accepting. Ignoring this risks fines of up to 300,000 euros.
Who Is Affected by the Cookie Consent Obligation?
This applies to every website operator who uses cookies, tracking pixels, or comparable technologies that are not technically required for the site's function. This includes, for example, analytics tools, marketing pixels, embedded content with tracking, or social media plugins, but not purely functional elements such as the shopping cart or the login session. Section 25 TDDDG requires prior, active consent for all these non-essential technologies before they are stored on or read from the visitor's device. This obligation therefore applies to practically every website with analytics, marketing, or embedding tools, regardless of company size or legal form, from a sole proprietorship to an online shop to an association with its own homepage. Anyone who has commissioned an agency or an external service provider to build the website still remains responsible, as the operator, for obtaining consent correctly.
What Exactly Do You Need to Do?
Specifically, you need a consent management tool that obtains consent before any non-essential scripts are loaded at all. Before setting up such a tool, it is worth reviewing all systems embedded on the website, from analytics and marketing tools to video embeds to chat or review widgets. A legally compliant implementation includes the following steps:
- Inventory all cookies/tools in use and classify them as technically necessary vs. non-essential.
- Integrate a consent management tool (CMP) that obtains consent BEFORE non-essential scripts are loaded.
- Design the reject option to be equivalent to the accept option (no pre-checked boxes, no nudging).
- Document/log consent given and allow withdrawal at any time.
- Keep the cookie/tool list continuously up to date whenever new services (e.g., a new analytics tool) are added.
A properly configured consent management tool usually covers the documentation and logging of consent automatically, so this step no longer requires separate manual effort. A tool like Company Audit shows which of these and other obligations specifically apply to your business.
By When Do You Need to Act, and How Often?
There is no fixed deadline or recurring due date for this: the consent obligation applies continuously, from the moment a non-essential technology is used. Anyone already running a website with cookies or tracking tools should therefore review the current status promptly, rather than waiting for a specific date. It is also important to continuously update the cookie and tool list whenever a new service is added, for example a new analytics or marketing tool, and to adjust consent accordingly, instead of setting it up once and then forgetting about it. If a new tool is integrated without adjusting the cookie list and the consent management tool, the same violation occurs as if a banner were completely missing.
What Happens if You Violate the Rules?
Violating the consent obligation risks fines of up to 300,000 euros. This particularly affects anyone who sets non-essential cookies without prior consent, or who makes rejecting harder than accepting, for example through pre-checked boxes or visually emphasized accept buttons. Even a plain cookie notice banner without a genuine reject option no longer meets the requirements of Section 25 TDDDG and counts as a violation. For businesses, this means that the design of the banner itself can already be legally relevant, not just the question of whether one exists at all.
Frequently Asked Questions
Do I Need a Consent Banner for Simple Reach Measurement Too?
Yes, as soon as an analytics tool sets cookies or reads data on the visitor's device that is not technically required, prior consent is necessary, regardless of the tool's name, how small the website is, or what the data is used for.
Is a Banner With Only an "Accept" Button Enough?
No. Rejecting non-essential cookies must be just as easy as accepting them. A banner without an equally prominent, clearly visible reject option does not meet the requirements of Section 25 TDDDG, even if a notice text is present.
Do I Need to Document Consent Given?
Yes, consent given should be documented or logged, and visitors must be able to withdraw it at any time. A properly configured consent management tool usually covers this documentation and logging automatically.
What Counts as a Technically Necessary Cookie That Requires No Consent?
Technically necessary cookies are those without which a function explicitly requested by the visitor does not work, for example the shopping cart in an online shop or the session during login. Any cookies beyond that, for example for analytics, marketing, or embedded third-party content, count as non-essential and require consent.
What Happens if I Integrate a New Tool on the Website?
Every newly deployed tool must first be classified as "technically necessary" vs. "non-essential." Non-essential tools may only load after consent has been given via the consent management tool; the cookie list should therefore be kept continuously up to date so that no new tool starts unnoticed without consent.
Source: Section 25 TDDDG. This article is general information and does not replace legal advice for individual cases. As of July 2026.
Share this article
Stay up to date
Get the latest articles, insights and industry updates straight to your inbox.
Decide for yourself what Google shows you
Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.
Add provimedia.de to my preferred sourcesRelated articles
More articles you might find interesting.
Recapitulative Statement (ZM), OSS, and Intrastat in EU Trade
ZM due by the 25th of the following month, OSS filed quarterly, Intrastat from the threshold: EU reporting obligations explained compactly.
Ensuring Product Safety Under the GPSR
The GPSR and Germany's ProdSG require every seller of non-food products to carry out a risk analysis, appoint an EU responsible person, and provide warning notices, even for tiny quantities.
Product Liability: When Manufacturers Are Liable Without Fault
Manufacturers are liable without fault for defective products: product liability insurance protects against claims that could threaten a company's existence.
Ihre Unternehmerpflichten im Griff
Company Audit erstellt Ihnen in wenigen Minuten eine individuelle Pflichtenliste – mit Fristen-Kalender, Erinnerungen und KI-Assistent. Für Selbständige und KMU.