Cookie consent in Deutschland
Consent and privacy law in Deutschland
GDPR applies since 25 May 2018, with the federal BDSG and 16 state laws
Deutsch
Who must comply
Any organization that offers goods or services to people in the EU or monitors their behavior, wherever the organization is based.
Penalties
Up to 20 million euros or 4 percent of global annual turnover, whichever is higher
Key obligations
- Obtain prior, opt-in consent before non-essential cookies
- Make refusing as easy as accepting
- Keep records that prove consent
- Honor withdrawal at any time
- Respect data subject rights (access, erasure, portability)
Local guidance
- Map your establishment to the correct state DPA, as Germany has 16 state authorities plus the federal BfDI
- Follow the TDDDG (formerly TTDSG) for cookies, which requires prior opt-in for all non-essential storage and access
- Give Reject the same prominence as Accept on the first banner layer
- Keep auditable consent logs, as German authorities frequently request proof of consent
How ConsentX helps
- Prior-script blocking for true opt-in
- Equal-weight Allow and Reject controls
- Tamper-evident consent receipts and evidence
- One-click withdrawal trigger
- Built-in DSAR workflow with 30-day SLA
We value your privacy
We ask for your consent before any non-essential cookie, with the rules that apply in your region.
Get Deutschland ready with ConsentX
Geo-aware banners, prior-script blocking, DSAR and tamper-evident evidence.
This page is a plain-English summary for general information and is not legal advice. Confirm your obligations with qualified local counsel.
How to comply with Deutschland using ConsentX
- 1
Scan your website
Run a free scan to find every cookie and tracker on your site, so you know exactly what needs consent under Deutschland.
- 2
Show a geo-aware consent banner
Add the ConsentX banner. It detects each visitor region and shows the consent experience that Deutschland requires, automatically.
- 3
Block trackers until consent
Keep non-essential cookies and trackers blocked until the visitor agrees, so nothing fires before consent.
- 4
Record tamper-evident proof
Every choice is stored as a tamper-evident consent receipt you can produce in a Deutschland audit.
- 5
Handle data requests on time
Use the built-in DSAR workflow with SLA timers to answer access, deletion and opt-out requests within the legal deadline.