By Daniel de Almeida Afonso · Last updated: October 7, 2026
Germany's cookie law is the TDDDG, the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz. It started life as the TTDSG on December 1, 2021, and was renamed in May 2024 without a change to its core consent rule. Section 25 still says you need prior, informed consent before you store or read anything on a user's device, unless a narrow exception applies.
This guide covers what the law requires, which cookies need consent, who enforces it, what the fines are, and where the consent management ordinance (EinwV) stands today.
What is the TDDDG, and why was the TTDSG renamed?
The TDDDG is the German law that implements Article 5(3) of the EU ePrivacy Directive. It sits next to the GDPR and covers privacy on end devices such as browsers, phones, and smart TVs.
The renaming followed a change in a neighboring law. On May 14, 2024, the Digitale-Dienste-Gesetz (DDG) replaced the Telemediengesetz (TMG) and adapted German law to the EU Digital Services Act. The TTDSG used the word "Telemedien" throughout, so the legislature swapped it for "digitale Dienste" and renamed the law the TDDDG.
The official long title is now "Gesetz über den Datenschutz und den Schutz der Privatsphäre in der Telekommunikation und bei digitalen Diensten." The text is on gesetze-im-internet.de.
Some points to keep straight:
- The TTDSG and TDDDG are the same law under two names. Older guidance that says TTDSG still describes the rules you follow today.
- The 2021 law was not an amendment. It pulled the privacy provisions that had been spread across the TMG and the Telecommunications Act (TKG) into one statute.
- It covers only the privacy side of telecoms and digital services. It does not regulate how those services are delivered.
What does Section 25 require?
Section 25(1) says storing information on a user's terminal equipment, or reading information already stored there, requires the user's consent. The consent must be informed and based on clear and comprehensive information. The standard for consent is the one in the GDPR.
The rule is not limited to cookies. It covers any technology that writes to or reads from the device, including:
- Local storage and session storage
- Device identifiers and SDKs in apps
- Pixels and scripts that read data from the browser
- Fingerprinting techniques
In practice, consent under the TDDDG has to meet the same tests as GDPR consent. For a deeper look at those tests, see our guide to GDPR cookie consent. In short, consent must be:
- Freely given, so access to content cannot depend on agreeing to non-essential tracking.
- Specific, so each purpose is approved on its own.
- Informed, so the user knows who is processing what and why.
- Unambiguous, so the user acts actively. Pre-ticked boxes do not count.
- Easy to withdraw, so revoking consent is as simple as giving it.
The pre-ticked box point comes from the Planet49 case. The Court of Justice of the EU held in 2019 (case C-673/17) that a pre-ticked checkbox is not valid consent. Germany's Federal Court of Justice (BGH) followed in May 2020 (case I ZR 7/16). The Hunton privacy blog summarizes the BGH ruling.
Note that Planet49 was a consumer-group lawsuit, not a regulatory fine. The ruling shaped the law, but it did not come with a penalty.
Which cookies do not need consent?
Section 25(2) lists two exceptions. Consent is not needed when storage or access:
- Has the sole purpose of carrying out the transmission of a message over a public telecommunications network, or
- Is strictly necessary ("unbedingt erforderlich") for the provider to deliver a digital service the user has explicitly requested.
Authorities read the second exception narrowly. The question is whether the service the user asked for would fail without the storage, not whether the storage helps your business.
| Technology | Consent needed? | Why |
|---|---|---|
| Login or session cookie | No | Needed to deliver the requested service |
| Shopping cart cookie | No | Needed to complete the purchase the user started |
| Cookie that stores the user's own consent choice | No | Needed to honor the choice |
| Analytics for advertising measurement | Yes | Not needed to deliver the service |
| Advertising and retargeting pixels | Yes | Serve the provider's commercial interest |
| Social media embeds that set trackers | Yes | The tracker is not needed to show the page |
The Data Protection Conference (DSK), the joint body of Germany's data protection authorities, published its Telemedia guidance in December 2021 and a revised version 1.1 in December 2022. As summarized by Noerr, it accepts narrow technical uses, such as measurement needed to deliver the page without errors. It treats advertising measurement and profiling as needing consent.
Also remember that Section 25 and the GDPR work in two steps. Section 25 governs the access to the device. The GDPR then governs what you do with any personal data you collect. You can need a legal basis under both.
Who enforces the TDDDG, and what are the fines?
Section 28 TDDDG makes a breach of Section 25(1) an administrative offense. Intentional or negligent violations can lead to a fine of up to EUR 300,000.
Enforcement is split between authorities:
- The Federal Data Protection Commissioner (BfDI) is the competent authority under Section 28 for Section 25 breaches by telecommunications providers and federal bodies.
- The data protection authorities of the German states oversee most private website operators. We confirmed this from secondary sources but not from a primary text, so check with counsel for your case.
- The Federal Network Agency (Bundesnetzagentur) handles telecoms rules that do not concern personal data.
Do not mix this up with the GDPR's EUR 20 million or 4% of turnover ceiling. That figure applies to GDPR violations, such as processing personal data without a legal basis. A single tracking setup can trigger both regimes, so plan for both.
Courts also look closely at banner design. In March 2025 the Administrative Court of Hanover ruled on a publisher's cookie banner brought by the Lower Saxony authority. Analysts disagree about whether the court required a "reject all" button. The safer reading is that banners cannot be designed to push users toward consent while making refusal harder. Our guide to dark patterns in cookie banners shows what to avoid.
What is the consent management ordinance (EinwV)?
Section 26 TDDDG allows "recognized services for consent management," often called PIMS (personal information management systems). The idea is that users set their consent choices once, in a trusted service, and websites read those choices instead of showing a banner each time.
The details are in the Einwilligungsverwaltungsverordnung (EinwV), which the federal government adopted in September 2024. It entered into force on April 1, 2025, and the BfDI is the authority that recognizes services. The full text is on gesetze-im-internet.de.
What we can say with confidence:
- Recognition requires user-friendly design, easy switching between services, equal treatment of all digital service providers, and independence from any financial interest in the user saying yes.
- Using a recognized service is voluntary for website operators. The ordinance does not oblige you to adopt one.
- On October 17, 2025, the BfDI recognized its first service, the browser plugin Consenter from Law & Innovation Technology GmbH.
The BfDI's page listed Consenter as the only recognized service when we checked. Check the BfDI register before you rely on that, since new services can be added.
A user who has not set up a recognized service still sees your banner as usual. Until PIMS signals are common, you still need your own consent flow.
Own consent banner or a recognized PIMS: which should you rely on?
| Your own consent banner | Recognized PIMS signal | |
|---|---|---|
| Who collects consent | Your site, via a CMP | The user's chosen service |
| Works for visitors with no PIMS | Yes | No |
| Setup effort | Moderate, one-time | Needs support for the signal |
| Status | Required baseline | Voluntary |
Choose your own banner if you need reliable consent from every visitor today, which is the case for nearly all sites. Choose to also honor PIMS signals if recognized services reach your audience and your tools can read their signals. Most operators will run both over time.
How does the TDDDG relate to EU law?
The TDDDG is a national implementation of the ePrivacy Directive of 2002. It is not the long-planned EU ePrivacy Regulation, which has not been adopted. For background on that file, see our article on the ePrivacy Regulation.
The Directive sets the EU-wide baseline, and each member state writes its own national version. The TDDDG is Germany's.
What should you do now?
A practical checklist for website and app operators serving users in Germany:
- Run a cookie and SDK audit so you know every script that reads or writes on the device.
- Classify each item as strictly necessary or consent-based, using the narrow reading above.
- Block every consent-based item until the user opts in.
- Offer a refusal that is as easy as acceptance.
- Keep a record of each consent choice and its timestamp.
- Review the setup when guidance or case law changes.
A consent management platform (CMP) can handle the banner, the script blocking, and the consent log in one place. If you are comparing vendors, our CMP comparison is a good starting point. Whatever you pick, check that it blocks scripts before consent rather than only displaying a banner.
If you are unsure whether a specific technology needs consent, ask your data protection officer or a German privacy lawyer. This article is general information, not legal advice.
FAQ
Is the TTDSG still in force?
The TTDSG is now called the TDDDG. The law has been in force since December 1, 2021, and was renamed in May 2024. The consent rule in Section 25 is unchanged, so TTDSG guidance still applies in substance.
Do I need consent for all cookies in Germany?
No. Strictly necessary cookies do not need consent, such as login, session, and shopping cart cookies. Analytics for advertising, retargeting, and tracking pixels do.
What is the fine for breaching Section 25 TDDDG?
Up to EUR 300,000 under Section 28 TDDDG. Separate GDPR fines of up to EUR 20 million or 4% of annual worldwide turnover can apply to the related processing of personal data.
Does the TDDDG apply to my company if I am not based in Germany?
It can. The law applies to digital services offered to users in Germany. If you set trackers on devices of German users, plan to comply.
Is a cookie banner still required after the EinwV?
Yes for most sites. The ordinance allows recognized consent management services but does not replace your own consent flow, and using them is voluntary.
Does the TDDDG cover apps and not just websites?
Yes. Section 25 covers any storage on or access to information on a user's terminal equipment, including app SDKs and device identifiers.
Who supervises compliance?
The BfDI is competent for Section 25 breaches by telecommunications providers and federal bodies. The state data protection authorities oversee most private website operators.
What did the DSK guidance say?
The DSK published its Telemedia guidance in December 2021 and updated it to version 1.1 in December 2022. It sets out how German authorities read the consent and strictly-necessary rules.


