Few website elements annoy visitors as reliably as the cookie banner — and few are used incorrectly as often. Many small businesses show a banner they don’t actually need. Others skip it while their site happily loads tracking services. This guide explains when a cookie banner is genuinely required in Germany, what it must look like — and why the most elegant solution is often to build a site that doesn’t need one at all.

The legal basis for cookie banners in Germany is § 25 of the TDDDG (known as TTDSG until May 2024), Germany’s implementation of the ePrivacy rules. The principle is simpler than the name suggests: anyone who stores or reads information on a visitor’s device — cookies, but also local storage or tracking pixels — needs prior, active consent.
There is one important exception: under § 25(2) TDDDG, cookies that are strictly necessary for the service the visitor requested are exempt from consent. Everything beyond that — analytics, marketing, personalised advertising — requires opt-in. On top of this, the GDPR applies as soon as personal data is processed through those cookies, which is practically always the case with tracking services.
The answer that surprises many: a cookie banner is not mandatory for every website. If you only use strictly necessary cookies and embed no consent-requiring third-party services, you don’t need a banner — a section in your privacy policy is enough.
A typical business-card website for a trade business or practice — services, references, contact form, directions as a link instead of an embedded Google Map — can operate entirely without a banner, provided no tracking tools run. That is not just legally clean but also a conversion advantage: visitors reach your content without a click hurdle.
“Strictly necessary” means: without this cookie, a feature the visitor actively wants does not work. Classic examples are the shopping-cart cookie in an online shop, the login cookie in a customer area, session cookies for forms, security cookies against abuse — and, somewhat ironically, the cookie that stores the visitor’s consent decision.
What does not qualify — even if some vendors like to suggest otherwise — are statistics and reach-measurement cookies. Wanting to know how many visitors your site has does not make an analytics cookie “necessary”. Supervisory authorities interpret the exception narrowly: the benchmark is the benefit for the visitor, not for the site owner.
Consent is required for anything that measures visitors beyond pure functionality or transfers data to third parties. On typical SME websites, that is mainly:
If a banner is needed, it must meet real requirements — this is where most mistakes happen. Consent must be freely given, informed and active, before the first consent-requiring cookie is set. In practice: no tracking on page load, no pre-ticked boxes, and “Reject” must be as easy as “Accept” — ideally an equivalent button on the first layer.
So-called dark patterns are prohibited: a huge colourful “Accept all” button next to a hidden grey “Settings” link, banners that cannot be closed without consenting, or wording that frames rejection as a disadvantage. Courts and data protection authorities have repeatedly objected to such designs — the consent is then invalid, and the tracking runs without a legal basis.
Consent must also be revocable at any time, usually via a permanent link or a small icon in the footer. And the banner does not document itself: which cookies run and why also belongs in the privacy policy.
If tracking runs without valid consent, there are two risks. First, cease-and-desist letters (Abmahnungen) from competitors or specialised law firms — typically in the range of 500 to 2,000 euros plus a declaration to cease and desist. Second, data protection authorities can impose fines; for small businesses these usually stay moderate, but the hassle, the time and the risk of a contractual penalty on repetition are not worth it.
The most common mistake is not the missing banner but the ineffective one: a consent tool is installed, yet the tracking scripts load before any click. This can be proven with the browser’s developer tools in two minutes — and that is exactly how warning-letter law firms work. A banner that is mere decoration does not protect you.
For most small businesses, the best cookie strategy is simple: build the site so that no banner is needed. Cookie-free analytics tools like Plausible, or Matomo in a cookie-free configuration, deliver the visitor numbers that matter without a consent requirement. Fonts are hosted locally; maps and videos load via two-click solutions only after the visitor actively clicks.
That is how we build the websites in our subscription plans: cookie-free by default with privacy-friendly statistics — a banner is only added when a client deliberately uses marketing tools such as Google Ads conversion tracking. The result: less legal risk, faster pages, and visitors who don’t have to dismiss a dialog first. If your current website shows a banner, it is worth asking your provider: what is it actually for?
Custom web design, German hosting, maintenance and personal support in one monthly package.
Book a free consultation