Skip to content
Call, 0511 – 47 55 58 11

Cookie banners: what actually matters

A banner is not evidence. Nothing may load before consent, rejecting must be as easy as accepting, and both have to be documented.

Most banners fail not on the legal position but on the implementation. They ask correctly and load anyway, or they make accepting comfortable and rejecting tedious.

The most common design mistakes

Holds up

  • Nothing loads before consent, including external fonts
  • Rejecting sits on the same layer and is as easy as accepting
  • Purposes are named, not merely categories such as comfort
  • Withdrawal is available at any time and actually takes effect

Does not hold up

  • Pre-ticked boxes or continued use treated as agreement
  • Rejecting available only behind a settings layer
  • A banner with no way to close it that blocks the page
  • Consents recorded without timestamp and version of the notices

Section 25(2) of the German Telecommunications Digital Services Data Protection Act knows two exceptions, and both are narrow. Access is permitted where its sole purpose is carrying out the transmission of a message, and where it is strictly necessary in order to provide a service the user has expressly requested.

That covers the shopping basket, the login session, the choice of language within the session, load balancing and security functions. It does not cover audience measurement, tests of different page versions or anything serving advertising, even where it is self-hosted. The yardstick is the service the visitor asked for, not the interest of the provider.

Two points are often confused. First, the exception does not turn on the cookie: it applies to any access to the terminal device, including fingerprinting and reading from local storage. Second, it permits only the access. What happens to the data afterwards still needs its own basis under the GDPR.

What we review

How we support you

We look at the site in operation, not only at the configuration of the consent platform. You then receive a list of what needs changing, ordered by risk and effort.

Banner in place, all quiet?

We check whether it does what it displays.

Have your banner reviewed

Frequently asked questions

Can we base tracking on legitimate interests?

Not for access to the terminal device. The German Telecommunications Digital Services Data Protection Act requires consent and knows only narrow exceptions for what is strictly necessary for the service. Reach measurement and advertising networks are not among them. Only the subsequent processing can rest on other bases.

Does the reject button have to be on the first layer?

The supervisory authorities require that rejecting must not be harder than accepting. A reject option reachable only after two clicks in a settings layer, while accepting costs one click, regularly falls short. Design, colour and labelling count towards this.

How long does a consent given remain valid?

There is no statutory period. Supervisory authorities consider a renewed request appropriate after some time, and six to twelve months are common. Independently of that, you have to ask again as soon as the services used, the purposes or the recipients change, because the old consent does not cover the new scope. Withdrawal must at all times be as easy as giving consent.

May we offer a paid option instead of consent?

Whether such a model preserves the freely given nature of consent is not settled. The European Data Protection Board took a critical view in 2024, particularly for large platforms. Anyone taking that route should watch the proportion between price and service, offer a genuinely equivalent alternative and document the decision. As a safe route the model does not currently qualify.

How do we evidence consent?

You need to show who consented, when, to what, and under which version of the notices. A simple count does not suffice. In practice that means logging consents with a timestamp and version, and doing the same for withdrawals.

Related