As described in the second post of this series, the ePrivacy Directive is a directive, not directly applicable EU law — every member state had to translate it into its own national law. Germany struggled with this for a long time, and that history is worth its own look, because it explains why German cookie banners today cite a law that has only existed since the end of 2021.
After the 2009 tightening of the ePrivacy Directive (transposition deadline: 25 May 2011), Germany initially stuck with the existing Telemedia Act (TMG). Section 15(3) provided a right to object to cookies, but its wording still leaned on the old pre-2009 opt-out logic rather than the new consent requirement. For years, the federal government maintained that the TMG already implemented the directive adequately — a position increasingly challenged by data protection authorities, courts, and the European Commission. In practice, this left prolonged legal uncertainty: some websites followed the stricter European reading, others relied on the weaker domestic legal position.
That uncertainty only ended with the Telecommunications-Telemedia Data Protection Act (TTDSG), which came into force on 1 December 2021. Section 25 TTDSG explicitly and unambiguously transposed the requirements of Article 5(3) of the ePrivacy Directive into German law: storing information on end devices, or accessing information already stored there, is only permitted with the user's consent — with a narrow exception for purposes that are technically strictly necessary to provide a function the user explicitly requested. The TTDSG also brought telecommunications and telemedia law together in a single, standalone statute for the first time, rather than spreading it across several separate frameworks as before.
In May 2024, the TTDSG was renamed the Telecommunications-Digital-Services Data Protection Act (TDDDG), as part of adapting German law to the EU's Digital Services Act (DSA), which introduced EU-wide rules for digital services and platforms. The actual cookie rule itself didn't change: the provision previously cited as Section 25 TTDSG is now found under the same number as Section 25 TDDDG — only the name of the statute it sits within changed.
In practice, this means a cookie banner in Germany today typically cites two legal bases at once: Section 25 TDDDG for whether consent is needed in the first place, and Article 6 GDPR (together with the requirements in Articles 4(11) and 7 GDPR) for the quality that consent has to meet. Understood in context, that's not an unnecessary double citation but two laws answering two different questions that build on each other — the domestic transposition of a European directive on one side, a directly applicable European regulation on the other.
The next post in this series turns to a specific case that decisively sharpened the requirements for valid consent: the Court of Justice of the EU's Planet49 ruling.
For a website operator, this dual citation is more than a legal formality: it shows which authority is responsible for which question in a dispute. Questions about whether the cookie use itself was permissible — whether consent was needed in the first place — fall under Section 25 TDDDG and therefore under the relevant state data protection authority. Questions about the quality of the consent actually given, such as whether it was sufficiently informed, fall under the GDPR. In practice, the same authorities usually examine both together, but the legal basis remains distinct — a detail that becomes important the moment a decision needs to be challenged.
