Skip to content
Call, 0511 – 47 55 58 11

Tracking and German device access rules

The German Telecommunications Digital Services Data Protection Act governs access to the terminal device. It applies regardless of whether personal data is involved, and it knows only one narrow exception.

The provision is short and its effect is wide. It requires consent for storing information on the terminal device and for accessing information stored there, and it does so regardless of whether personal data is involved.

How we review a site

  1. Step 1: Record what happens

    We look at the site in operation to see which services load on access and what they store on or read from the device.

  2. Step 2: Assess necessity

    Which of them does the service genuinely need? That assessment goes service by service, not across a category.

  3. Step 3: Design the consent

    Everything else needs consent obtained beforehand, and consent that actually controls what loads.

  4. Step 4: Settle the second level

    For the subsequent processing, determine the legal basis under the GDPR, including recipients and retention.

How we support you

We record the actual state of the site, classify every service and tell you what may run without consent and what may not. The configuration of the banner follows from that, not the other way round.

Unclear what may run without consent?

We go through the services one by one rather than trusting categories.

Get in touch

Frequently asked questions

Does this apply without cookies?

Yes. The provision does not attach to cookies but to storing information on the terminal device and accessing information already stored there. Fingerprinting, reading out device properties and comparable techniques are therefore equally covered.

What counts as strictly necessary?

What the service needs in order to work, such as the shopping basket, the session identifier or a language setting. Not what improves the offering or makes it commercially more attractive. Reach measurement is the contested case, and the supervisory authorities have so far not taken a generous line on it.

How does this relate to the GDPR?

The provision takes precedence over the GDPR for access to the terminal device. The subsequent processing of the data obtained continues to follow the GDPR and needs its own legal basis there. Two assessments, not one.

Related