Implementation guide · sources checked 29 July 2026
Cookie banner Germany: test every state
The pop-up is only the interface. The real test is what the site stores, reads, sends, and changes before a choice, after reject, after one purpose is accepted, and after withdrawal.

Direct answer
- A German website does not need a banner merely because it exists. It needs a consent mechanism when the scoped storage or access to terminal equipment, and any following processing, requires consent.
- Section 25 TDDDG addresses storing information on or accessing information from terminal equipment. It is broader than cookies and can include local storage, pixels, SDK behavior, identifiers, and fingerprinting techniques.
- The GDPR separately governs processing of personal data that may follow. Record the two questions separately.
- Do not decide from a product label such as analytics, chat, or necessary. Record purpose, operation, data, state, and claimed exception for accountable review.
- Test five states: before choice, reject, purpose-specific accept, change, and withdraw. A banner screenshot cannot prove the technical effect.
Two rules, one implementation
First ask what touches the device. Then ask what happens to personal data.
Section 25 TDDDG starts with consent for storing information on or accessing information from terminal equipment and states two exceptions. One concerns transmitting a communication. The other concerns what is strictly necessary to provide a digital service expressly requested by the user.
The DSK guidance for digital services explains that the TDDDG and GDPR questions are distinct. The terminal-equipment rule can apply without personal data. Further processing of personal data requires a separate GDPR assessment.
Your browser test records operations and effects. The DPO or counsel decides whether an exception applies, whether personal data is involved, which legal basis is used, and whether the consent interface meets the legal standard.
Five-state test matrix
Capture the same evidence at every transition.
| State | Action | Capture | Question |
|---|---|---|---|
| Before choice | Load a representative route with a fresh profile and do nothing | Requests, response headers, cookies, local/session storage, IndexedDB, service workers, interface state | What happens without an affirmative action? |
| Reject | Reject optional purposes on the first available path | New, removed, and unchanged requests, storage, IDs, and banner state | Did rejection change the scoped behavior? |
| Purpose-specific accept | Accept one purpose only | The exact requests, tags, storage, IDs, and configuration transition caused by that choice | Did unrelated purposes remain in their prior state? |
| Change | Reopen preferences and change one purpose | Interface state, consent signal, tag transition, storage changes, and log entry | Does the system honor a later choice? |
| Withdraw | Withdraw the accepted purpose | Future requests, new storage, retained IDs, log behavior, and the next page load | What stops, what remains, and which legal or deletion decision is still open? |
Implementation checks
Eight checks behind the banner interface.
01
Inventory every storage operation
For each technology, record who initiates it, what it stores or reads, endpoint, purpose, data, recipient, trigger, and claimed TDDDG treatment. Include local storage, link decoration, pixels, fingerprinting inputs, SDKs, and service workers.
02
Separate capture from enforcement
The interface can save a choice while a hard-coded script, plugin, tag-manager trigger, or embed ignores it. Trace each optional technology to the rule that prevents or permits execution. Then confirm the effect in network and storage evidence.
03
Review first-layer choice
Record whether reject, accept, settings, and close actions are visible, understandable, and comparable in effort and presentation. The DSK guidance and EDPB taskforce report discuss first-layer reject options and potentially deceptive emphasis. The final assessment remains case-specific.
04
Require an active choice where consent is used
Optional purposes should not start selected. Closing or ignoring the interface should not be recorded as affirmative consent. The CJEU Planet49 judgment addressed preselected checkboxes and active consent. Record the actual control defaults and event sent.
05
Test purpose boundaries
Accept one purpose at a time. Check whether analytics acceptance also enables advertising, personalization, embeds, or unrelated vendors. Record bundled behavior and route the purpose and granularity decision to the privacy owner.
06
Trace change and withdrawal
Make the preference control reachable after the first visit. Record whether changing or withdrawing a choice stops future optional operations. Do not assume that withdrawal deletes prior data or identifiers; record what remains and assign the retention or deletion decision.
07
Treat Consent Mode as a signal
Google Consent Mode communicates consent state to Google tags. Its presence does not prove that every tag, request, identifier, or processing operation is blocked. Inspect the default state, update event, firing rules, advanced or basic behavior, and observed requests.
08
Retest every injection path
On WordPress and GTM sites, inventory theme code, plugins, Site Kit, analytics plugins, embeds, tag templates, custom HTML, and server-side containers. Repeat affected states when a plugin, tag, template, CMP configuration, vendor, or purpose changes.
Interface evidence
Do not turn one layout recipe into a legal verdict.
The EDPB consent guidance covers freely given, specific, informed, and unambiguous consent and withdrawal. The Cookie Banner Taskforce report discusses missing reject options, preselected boxes, deceptive colors and contrast, legitimate-interest claims, and withdrawal icons.
Use those sources to review the actual interface in context. Save desktop and mobile screenshots, keyboard order, labels, purpose text, button treatment, close behavior, settings depth, and the event created by each action. Do not claim legal validity from color or click count alone.
The Planet49 case is the primary reference for active consent and preselected cookie controls.
Beyond cookies
The rule is technology-neutral.
The final EDPB Guidelines 2/2023 examine the technical scope of storing or gaining access under Article 5(3) of the ePrivacy Directive. The German DSK guidance applies the same broader frame under TDDDG.
A check limited to cookies listed by name can miss local storage, tracking pixels, URL and link identifiers, JavaScript access to device characteristics, and other techniques. Record the operation and information flow before applying a label.
Compliance next step
Get a compliance check on: Cookie banner GDPR Germany
Send us where your site stands today. We reply with the risks that carry real exposure, not a generic checklist.
Release smoke test
Run this on representative desktop and mobile routes.
✓
Start with a fresh profile. Save network and browser-storage evidence before any choice.
✓
Test reject, each purpose separately, change, and withdrawal without reusing prior test state.
✓
Confirm every optional technology has an enforcement rule. A banner category alone cannot enforce the choice.
✓
Compare CMP state, GTM or plugin configuration, network requests, and browser storage.
✓
Check keyboard access, mobile layout, labels, settings depth, close action, and preference reopening.
✓
Record inaccessible server-side behavior, legal questions, and any claimed TDDDG exception as explicit decisions or limits.
Next step
Keep the banner test inside the wider data-flow review.
Use the GDPR website checklist for the evidence-register method across forms, vendors, notices, rights workflows, security, and retention. Use the Google Analytics guide for GA4-specific implementation questions.
For independent state testing, configuration evidence, finding ownership, and a post-fix retest, use the technical GDPR audit. The cost guide compares audit categories and published prices.
Common questions
Questions about cookie banners in Germany.
Is a cookie banner mandatory for every German website?
No. The decision depends on what the implementation stores on or accesses from terminal equipment, whether a section 25 TDDDG exception applies, and what personal-data processing follows. A site with no consent-requiring operation may not need a consent banner. Record the facts and have the accountable reviewer decide.
What replaced TTDSG?
The law was renamed TDDDG when German digital-services terminology changed in May 2024. Section 25 remains the central German rule for storing information on or accessing information from terminal equipment.
Must reject be available on the first banner layer?
The current DSK guidance says that if accept is offered on the first layer, a reject option should also be available there and be clearly visible. The EDPB taskforce also discusses missing or visually weak reject paths. Review the whole interface and facts with the accountable privacy or legal owner.
Can optional categories be preselected?
Where consent is the basis, an affirmative action is required. Planet49 addressed preselected cookie controls and found them insufficient. Capture default controls, the user action, and the event the system records.
Does Google Consent Mode make the banner compliant?
No single configuration proves legal compliance. Consent Mode carries state to Google tags. You still need to review the legal treatment, configure defaults and updates, control every injection path, and observe requests and storage in each state.
Do we need a CMP?
The sources do not require a particular CMP brand. Use a maintained CMP or a custom implementation that your team can test and operate. In both cases, document capture, enforcement, evidence, withdrawal, change ownership, and verification limits.
Written by
Vineet Talwar
Co-founder, Tech & Operations at Some Tech Work. WordCamp speaker across Europe and Asia, and host of the WP Shoutout podcast.
Start here
Ready to talk.Book a short diagnostic.
Tell us what needs fixing
We read every brief and reply within one business day.
Prefer to talk first?or request a tech stack audit →or email us directly →
Not sure where to start? Send the stuck decision, workflow, or page. We will say whether you need a diagnostic call, a tech stack audit, or a different first step.