Tracking and German device access rules
The German Telecommunications Digital Services Data Protection Act governs access to the terminal device. It applies regardless of whether personal data is involved, and it knows only one narrow exception.
The provision is short and its effect is wide. It requires consent for storing information on the terminal device and for accessing information stored there, and it does so regardless of whether personal data is involved.
How we review a site
Step 1: Record what happens
We look at the site in operation to see which services load on access and what they store on or read from the device.
Step 2: Assess necessity
Which of them does the service genuinely need? That assessment goes service by service, not across a category.
Step 3: Design the consent
Everything else needs consent obtained beforehand, and consent that actually controls what loads.
Step 4: Settle the second level
For the subsequent processing, determine the legal basis under the GDPR, including recipients and retention.
How we support you
We record the actual state of the site, classify every service and tell you what may run without consent and what may not. The configuration of the banner follows from that, not the other way round.
Unclear what may run without consent?
We go through the services one by one rather than trusting categories.
Get in touchFrequently asked questions
What counts as strictly necessary?
What the service needs in order to work, such as the shopping basket, the session identifier or a language setting. Not what improves the offering or makes it commercially more attractive. Reach measurement is the contested case, and the supervisory authorities have so far not taken a generous line on it.
How does this relate to the GDPR?
The provision takes precedence over the GDPR for access to the terminal device. The subsequent processing of the data obtained continues to follow the GDPR and needs its own legal basis there. Two assessments, not one.