Cookies play an important role in the General Data Protection Regulation (GDPR). This is especially true when it comes to providing a website. Until now, the use of cookies was regulated by the GDPR as well as the ePrivacy Directive, also known as the Cookie Directive. After many years, the Cookie Directive was finally implemented into national law through the Telecommunications Telemedia Data Protection Act (TTDSG), which came into force on December 1, 2021. This act contains specific rules for the use of cookies on websites. In the following article, you can read about the new rules for cookie tracking consent and the mandatory contents of a cookie banner.
The most important points in brief
- The TTDSG is intended to supplement and clarify the data protection regulations for telecommunications and telemedia services from the GDPR.
- When personal data is processed, which is usually the case with cookie installation, both the TTDSG and the GDPR, as well as the cookie policy, must be observed.
- If data with a personal reference is processed in the specific application area of the TTDSG, the TTDSG takes precedence over the GDPR.
Relationship of the TTDSG to the GDPR
The relationship between the TTDSG and the GDPR has not yet been definitively clarified. However, it can be stated that the TTDSG is intended to supplement and clarify the data protection regulations for telecommunications and telemédia services from the GDPR.
If no personal data is processed when using digital services, only the provisions of the TTDSG must be observed. The scope of the GDPR only applies if data relating to a person is processed. If cookies are set for tracking user behavior, this usually involves the processing of personal data, so that both the TTDSG and the GDPR, as well as the Cookie Directive, apply. This is particularly evident from the reference to the GDPR contained in Section 25 (1) Sentence 2 of the TTDSG.
In the event of a conflict between the two regulatory frameworks, Art. 95 GDPR stipulates that the TTDSG, as a national implementation of the ePrivacy Directive, shall take precedence over the GDPR, provided that the TTDSG already contains corresponding provisions for the specific case that pursue the same objective as the GDPR.
Consent rules in the TTDSG
The TTDSG contains significantly stricter rules for consent. In the event of violations of the consent obligation, companies are threatened with warnings and substantial fines of up to 300,000 Euros. This applies particularly when cookies are set for marketing or profiling purposes, or if the information obligations regarding cookies and the privacy policy are not sufficiently fulfilled. According to § 25 para. 1 TTDSG, information on end devices may only be stored or access to already existing information may only be granted if consent has been obtained that meets the requirements of the GDPR or if a legal exception applies. Whether consent under § 25 para. 1 sentence 1 TTDSG is valid is assessed according to the same standards that apply to consent under Art. 6 para. 1 sentence 1 lit. a) GDPR.
Exceptions to the consent requirement
According to § 25 (2) TTDSG, there is no obligation to obtain consent if, on the one hand, the cookies are solely for the transmission of a message over a public communication network and, on the other hand, if they are technically absolutely necessary. Cookies are only to be classified as technically necessary if they are required for the operation of the website and enable its basic functions, or if the provider can only make the service requested by the user available using cookies. This applies, for example, to login, authentication, and shopping cart cookies.
Cookie Consent Requirements
It should be noted that cookie consent must always be given in an informed, voluntary manner, through an unambiguous declaration of intent, and as a clearly affirmative active action. Therefore, effective cookie consent can only be achieved through a proactive action by the consenting website user. To date, this can only be practically realized through an opt-in procedure, where the user gives their consent by ticking a box. Furthermore, it is impermissible from a data protection perspective for the website operator to present pre-ticked boxes for cookie consent, requiring the user to actively opt out. The user's consent must be given on their own initiative.
Cookie banner consent acquisition
In principle, not every website needs a cookie banner. If no data processing requiring consent takes place, no consent is required under the GDPR and TTDSG. If cookies are used that do not require user consent, the privacy policy must still point out the use of cookies. It should also be noted that consent must always be requested immediately before the cookies requiring consent are used.
Cookie banner content
First, the banner content should be understandable and legally sound. In particular, users should be informed about the possibility of revoking their consent at any time. Furthermore, as detailed information as possible must be provided about the purposes of cookie use. Additionally, the banner should contain links to the imprint and the privacy policy. All information should be presented in a transparent and understandable way for users.
User-friendly design of cookie banners
Data protection authorities and consumer advocates repeatedly criticize the design of cookie banners. While brightly colored buttons to encourage users to consent to data processing via cookies are not yet prohibited by current law, the so-called nudging or the use of dark patterns constitutes a form of user guidance – albeit only optical. Therefore, cookie banners should always be designed in a way that does not favor consent.
No subliminal influence on website visitors
Nudging refers to the use of techniques that serve to subliminally influence website visitors to give their consent. Nudging occurs, for example, when the consent option in cookie consent windows is made more conspicuous than the refusal option through font size, color, or other highlights.
Furthermore, when using dark patterns, the user is induced to give consent against their interests and will through manipulative, deceptive, or coercive behavior. In the context of consent management design, it is referred to as a dark pattern when the option to decline is not immediately apparent to the user, but can only be reached after several clicks.
In principle, it is not permissible to make cookie rejection more difficult than acceptance. It is therefore advisable to place rejection, consent, and settings options for the website operator's data processing on the first level of the cookie banner.
Consistent user-friendliness across all devices
Since users typically access websites via various devices, it is recommended to design cookie banners flexibly to ensure consistent user-friendliness across all devices (desktop computers, tablets, and smartphones). This can be achieved with so-called responsive web design. While such a website design is not mandatory, it can promote user satisfaction to the company's advantage.
In contrast, it is imperative to place cookie consent tools in such a way that the user gives consent before they can navigate the site.
Furthermore, the request for technical access permissions (e.g., to the camera or contacts) should be omitted, as it is not permitted under the GDPR.
Since a repeated consent request with each new website visit is usually annoying for the user, the consent already given should be stored for a certain period of time to offer the user the most pleasant browsing experience possible. A storage period of six months is standard practice, provided the user does not reset their cookies and browser settings.
Central Cookie Consent Management according to the TTDSG
With the introduction of Section 26 in the new TTDSG, the possibility of a central consent management system is being created. So-called Personal Information Management Systems (PIMS for short) are intended to enable users to centrally manage cookie consent and to permit the use of their data through a design that is technically sound and, above all, privacy-friendly. Users can subsequently share their pre-selected settings with the websites they wish to access, so that new consent does not have to be given repeatedly for each website. If users make use of a PIMS provider, website operators must take into account the cookie consent settings made there. It should be noted that PIMS providers must be recognized by an independent body according to a procedure established by the Federal Republic of Germany.
New fine regulation in § 28 TDSG
The TTDSG also includes a new penalty provision in Section 28, which serves to sanction violations of the TTDSG. However, it is unclear which authority is to be responsible for sanctioning violations of the new law according to the new penalty provision. This is because the Cookie Directive itself does not clearly specify that the imposition of fines should necessarily be the responsibility of the national data protection authorities. In this context, it remains to be seen whether the question of jurisdiction will be clarified uniformly by the European legislator or whether the German legislator will have to take action.
Outlook
It remains to be seen how the courts will rule under the TTDSG and to what extent existing case law on the use of cookies will be adapted. To avoid warnings and fines – but above all to protect the privacy of website users – the requirements of the TTDSG and the GDPR for cookie consent must be taken into account, and the previous cookie notices should be reviewed and, if necessary, adapted to the new legal situation.