Implementation guide · sources checked 29 July 2026

Cookie banner Germany: test every state

The pop-up is only the interface. The real test is what the site stores, reads, sends, and changes before a choice, after reject, after one purpose is accepted, and after withdrawal.

Growth and marketing work
On this page
  1. Direct answer
  2. Two rules, one implementation
  3. Five-state test matrix
  4. Implementation checks
  5. Interface evidence
  6. Beyond cookies
  7. Release smoke test
  8. Next step
  9. Common questions
Five-state German cookie banner test from first visit through withdrawal
Direct answer
  • A German website does not need a banner merely because it exists. It needs a consent mechanism when the scoped storage or access to terminal equipment, and any following processing, requires consent.
  • Section 25 TDDDG addresses storing information on or accessing information from terminal equipment. It is broader than cookies and can include local storage, pixels, SDK behavior, identifiers, and fingerprinting techniques.
  • The GDPR separately governs processing of personal data that may follow. Record the two questions separately.
  • Do not decide from a product label such as analytics, chat, or necessary. Record purpose, operation, data, state, and claimed exception for accountable review.
  • Test five states: before choice, reject, purpose-specific accept, change, and withdraw. A banner screenshot cannot prove the technical effect.
Two rules, one implementation

First ask what touches the device. Then ask what happens to personal data.

Section 25 TDDDG starts with consent for storing information on or accessing information from terminal equipment and states two exceptions. One concerns transmitting a communication. The other concerns what is strictly necessary to provide a digital service expressly requested by the user.

The DSK guidance for digital services explains that the TDDDG and GDPR questions are distinct. The terminal-equipment rule can apply without personal data. Further processing of personal data requires a separate GDPR assessment.

Your browser test records operations and effects. The DPO or counsel decides whether an exception applies, whether personal data is involved, which legal basis is used, and whether the consent interface meets the legal standard.

Five-state test matrix

Capture the same evidence at every transition.

Save route, market, language, browser state, time, and artifacts. Mark server-side or inaccessible behavior as a verification limit.
StateActionCaptureQuestion
Before choiceLoad a representative route with a fresh profile and do nothingRequests, response headers, cookies, local/session storage, IndexedDB, service workers, interface stateWhat happens without an affirmative action?
RejectReject optional purposes on the first available pathNew, removed, and unchanged requests, storage, IDs, and banner stateDid rejection change the scoped behavior?
Purpose-specific acceptAccept one purpose onlyThe exact requests, tags, storage, IDs, and configuration transition caused by that choiceDid unrelated purposes remain in their prior state?
ChangeReopen preferences and change one purposeInterface state, consent signal, tag transition, storage changes, and log entryDoes the system honor a later choice?
WithdrawWithdraw the accepted purposeFuture requests, new storage, retained IDs, log behavior, and the next page loadWhat stops, what remains, and which legal or deletion decision is still open?
Implementation checks

Eight checks behind the banner interface.

Terminal-equipment operation inventory
01

Inventory every storage operation

For each technology, record who initiates it, what it stores or reads, endpoint, purpose, data, recipient, trigger, and claimed TDDDG treatment. Include local storage, link decoration, pixels, fingerprinting inputs, SDKs, and service workers.

Consent choice linked to tag enforcement
02

Separate capture from enforcement

The interface can save a choice while a hard-coded script, plugin, tag-manager trigger, or embed ignores it. Trace each optional technology to the rule that prevents or permits execution. Then confirm the effect in network and storage evidence.

Cookie banner first-layer choice review
03

Review first-layer choice

Record whether reject, accept, settings, and close actions are visible, understandable, and comparable in effort and presentation. The DSK guidance and EDPB taskforce report discuss first-layer reject options and potentially deceptive emphasis. The final assessment remains case-specific.

Unselected optional consent controls
04

Require an active choice where consent is used

Optional purposes should not start selected. Closing or ignoring the interface should not be recorded as affirmative consent. The CJEU Planet49 judgment addressed preselected checkboxes and active consent. Record the actual control defaults and event sent.

Purpose-specific consent boundary test
05

Test purpose boundaries

Accept one purpose at a time. Check whether analytics acceptance also enables advertising, personalization, embeds, or unrelated vendors. Record bundled behavior and route the purpose and granularity decision to the privacy owner.

Consent change and withdrawal evidence
06

Trace change and withdrawal

Make the preference control reachable after the first visit. Record whether changing or withdrawing a choice stops future optional operations. Do not assume that withdrawal deletes prior data or identifiers; record what remains and assign the retention or deletion decision.

Google Consent Mode signal and network verification
07

Treat Consent Mode as a signal

Google Consent Mode communicates consent state to Google tags. Its presence does not prove that every tag, request, identifier, or processing operation is blocked. Inspect the default state, update event, firing rules, advanced or basic behavior, and observed requests.

WordPress and GTM consent injection paths
08

Retest every injection path

On WordPress and GTM sites, inventory theme code, plugins, Site Kit, analytics plugins, embeds, tag templates, custom HTML, and server-side containers. Repeat affected states when a plugin, tag, template, CMP configuration, vendor, or purpose changes.

Interface evidence

Do not turn one layout recipe into a legal verdict.

The EDPB consent guidance covers freely given, specific, informed, and unambiguous consent and withdrawal. The Cookie Banner Taskforce report discusses missing reject options, preselected boxes, deceptive colors and contrast, legitimate-interest claims, and withdrawal icons.

Use those sources to review the actual interface in context. Save desktop and mobile screenshots, keyboard order, labels, purpose text, button treatment, close behavior, settings depth, and the event created by each action. Do not claim legal validity from color or click count alone.

The Planet49 case is the primary reference for active consent and preselected cookie controls.

Beyond cookies

The rule is technology-neutral.

The final EDPB Guidelines 2/2023 examine the technical scope of storing or gaining access under Article 5(3) of the ePrivacy Directive. The German DSK guidance applies the same broader frame under TDDDG.

A check limited to cookies listed by name can miss local storage, tracking pixels, URL and link identifiers, JavaScript access to device characteristics, and other techniques. Record the operation and information flow before applying a label.

Compliance next step

Get a compliance check on: Cookie banner GDPR Germany

Send us where your site stands today. We reply with the risks that carry real exposure, not a generic checklist.

Name the regulation, the page, or the deadline you are working against.

By submitting you agree to our privacy policy.

Release smoke test

Run this on representative desktop and mobile routes.

Start with a fresh profile. Save network and browser-storage evidence before any choice.
Test reject, each purpose separately, change, and withdrawal without reusing prior test state.
Confirm every optional technology has an enforcement rule. A banner category alone cannot enforce the choice.
Compare CMP state, GTM or plugin configuration, network requests, and browser storage.
Check keyboard access, mobile layout, labels, settings depth, close action, and preference reopening.
Record inaccessible server-side behavior, legal questions, and any claimed TDDDG exception as explicit decisions or limits.
Next step

Keep the banner test inside the wider data-flow review.

Use the GDPR website checklist for the evidence-register method across forms, vendors, notices, rights workflows, security, and retention. Use the Google Analytics guide for GA4-specific implementation questions.

For independent state testing, configuration evidence, finding ownership, and a post-fix retest, use the technical GDPR audit. The cost guide compares audit categories and published prices.

Common questions

Questions about cookie banners in Germany.

Is a cookie banner mandatory for every German website?

No. The decision depends on what the implementation stores on or accesses from terminal equipment, whether a section 25 TDDDG exception applies, and what personal-data processing follows. A site with no consent-requiring operation may not need a consent banner. Record the facts and have the accountable reviewer decide.

What replaced TTDSG?

The law was renamed TDDDG when German digital-services terminology changed in May 2024. Section 25 remains the central German rule for storing information on or accessing information from terminal equipment.

Must reject be available on the first banner layer?

The current DSK guidance says that if accept is offered on the first layer, a reject option should also be available there and be clearly visible. The EDPB taskforce also discusses missing or visually weak reject paths. Review the whole interface and facts with the accountable privacy or legal owner.

Can optional categories be preselected?

Where consent is the basis, an affirmative action is required. Planet49 addressed preselected cookie controls and found them insufficient. Capture default controls, the user action, and the event the system records.

Does Google Consent Mode make the banner compliant?

No single configuration proves legal compliance. Consent Mode carries state to Google tags. You still need to review the legal treatment, configure defaults and updates, control every injection path, and observe requests and storage in each state.

Do we need a CMP?

The sources do not require a particular CMP brand. Use a maintained CMP or a custom implementation that your team can test and operate. In both cases, document capture, enforcement, evidence, withdrawal, change ownership, and verification limits.

Start here

Ready to talk.Book a short diagnostic.

Tell us what needs fixing

A process, a tool, a decision that's stuck. One sentence is fine.

By submitting you agree to our privacy policy.

We read every brief and reply within one business day.

Prefer to talk first?or request a tech stack audit or email us directly

Not sure where to start? Send the stuck decision, workflow, or page. We will say whether you need a diagnostic call, a tech stack audit, or a different first step.