legally compliant banners for your shop in 2026
Almost every online shop sets cookies, whether for the shopping cart, statistics or advertising. But a simple banner with only an "OK" button has long stopped being legally sufficient. The German Telecommunications-Telemedia Data Protection Act, known as the TTDSG, sets out exactly when you need prior consent from your visitors, and in 2026 this obligation is becoming newly relevant through stricter enforcement. We explain in plain language what this is about and what you can calmly take care of.
Table of Contents
- 1. What is the cookie consent requirement under TTDSG?
- 2. Since when does it apply, why does 2026 make it newly relevant?
- 3. Who is affected, even small shops?
- 4. What you specifically need to do
- 5. Checklist for a legally compliant banner
- 6. Fines and risks of non-compliance
- 7. Common misconceptions
- 8. What Mironsoft can take care of for you
- 9. Summary
- 10. FAQ
1. What is the cookie consent requirement under TTDSG?
The TTDSG, spelled out as Telekommunikation-Telemedien-Datenschutz-Gesetz, has been in force since 1 December 2021. Its Section 25 governs when information may be stored on the device of a user, or when information already stored on that device may be read out. This covers not only classic cookies, but also related techniques such as local storage in the browser, tracking pixels, or so-called fingerprinting, where a device is recognised again based on technical characteristics. With this rule, Germany implements a requirement from the EU ePrivacy Directive, specifically Article 5(3).
It is important to understand that the TTDSG applies alongside the General Data Protection Regulation, known as the GDPR, and does not replace it. The TTDSG governs the purely technical act: whether anything may be stored on or read from the device at all. The GDPR, on the other hand, governs what may subsequently happen with any personal data obtained this way, for example when an analytics tool builds user profiles from it. Both laws therefore work together, and a legally compliant cookie banner has to satisfy both.
The core rule can be summarised simply: to store or read non-essential information on an end device, you need prior, freely given, purpose-specific, informed and unambiguous consent, meaning active agreement measured against the standard set by Article 4(11) and Article 7 of the GDPR. An exception to this consent requirement applies to "technically necessary" cookies, for example session cookies for the shopping cart, login state, or security features of your shop. This exception is interpreted narrowly, however, and explicitly does not cover analytics, marketing, retargeting or social-media-embed cookies, even if you consider them helpful for your business.
2. Since when does it apply, why does 2026 make it newly relevant?
The underlying obligation from Section 25 TTDSG is therefore nothing new, it has applied since December 2021. If you have not addressed it so far, you have not missed a "new" rule, but may simply not yet have fully implemented an obligation that has existed for years. What makes the topic newly relevant in 2026 is mainly enforcement practice: the German state data protection authorities and courts now scrutinise the specific design of cookie banners considerably more closely than a few years ago.
Three points in particular keep coming up in recent decisions and guidance. First, a "reject all" button on the first layer of the banner must be just as visible and just as easy to click as an "accept all" button, not hidden behind an extra click or a separate settings screen. Second, users must not be forced through so-called consent walls, meaning banners that fully block access to the site until consent is given, when the content of the site provides no compelling reason for this. Third, misleading or unclear category labels in the banner are increasingly viewed critically, for example when marketing cookies are euphemistically described as "comfort features".
On top of this, the technical side keeps evolving as well. At EU level, there has been ongoing discussion about a future ePrivacy Regulation intended to eventually replace the current directive, as well as about standardised consent signals and so-called personal information management systems, sometimes discussed in connection with a possible future regulation pursuant to Section 26 TTDSG. These developments should currently be regarded as under discussion and planned, not as settled law. For you as a shop owner, this mainly means one thing: a cookie banner is not a one-time task you tick off and forget, but something that should be reviewed periodically, much like a legal notice page or a withdrawal policy.
3. Who is affected, does this apply to small shops too?
Yes, explicitly also to small and side-business shops. The consent requirement does not distinguish by company size or turnover. Any website or online shop that uses non-essential cookies or similar techniques is affected, for example Google Analytics or a comparable statistics tool, the Facebook pixel or other advertising trackers, embedded YouTube videos, common marketing plugins, or the tracking features that many shop systems ship with by default.
Many shop owners are surprised how many scripts in their own shop actually set cookies or send data to third parties, often without them ever being aware of it. Some of these scripts come from themes, extensions or marketing tools installed a while ago that have simply kept running ever since. There is no exemption for small businesses or shops with low turnover. What matters is exclusively which techniques are actually used on the website, not the size of the business behind it.
4. What you specifically need to do
The first and most important step is an honest inventory: which cookies and scripts does your shop actually set before any consent has been given? This check tends to reveal things that shop owners themselves did not expect, for example tracking code from plugins that were only supposed to serve a completely different function.
Based on this, a bare "OK" notice should be replaced with a genuine consent management setup where accepting and rejecting are actually offered on equal terms. What matters here is not just the visual design, but above all the technical implementation: non-essential scripts must not merely be hidden, they must be technically blocked until consent has actually been given. A banner that looks correct but still loads marketing cookies in the background does not meet the legal requirements.
In addition, given consent should be documented in a traceable way, so that you can demonstrate, if needed, who consented to which category and when. This is why most shops rely on a specialised consent management tool rather than a homemade solution. Equally important is an always-accessible way for visitors to change their cookie preferences later, usually via a permanently visible link in the footer of the page. Finally, the entire setup should be reviewed periodically, because new plugins, new marketing tools, or a change of shop system can quietly introduce new cookies.
5. Checklist: making your cookie banner legally compliant
- ✓Take an inventory of all cookies, scripts and embedded third-party content in your shop.
- ✓Replace a bare "OK" notice with a consent tool that has an equally prominent "reject all" button.
- ✓Make sure non-essential scripts technically load only after consent has been given, not merely hidden visually.
- ✓Label categories in the banner clearly and honestly, without downplaying marketing cookies as a mere "comfort feature".
- ✓Document consent in a traceable way so it can be demonstrated if needed.
- ✓Set up a permanently accessible link to cookie settings in the footer.
- ✓Review the setup regularly, especially after new plugins, new marketing tools, or a shop system change.
6. Fines and risks of non-compliance
Because faulty consent affects not only the TTDSG but, as a consequence, the GDPR as well, violations generally fall within the GDPR's fine framework. This framework can be tied to a company's worldwide annual turnover and can therefore turn out to be considerable. A specific figure cannot seriously be stated in general terms, since the amount is set by the supervisory authority in the individual case, taking many circumstances into account. What matters most for you as a smaller shop owner is that such proceedings are entirely avoidable if the banner is set up cleanly from the start.
Just as relevant in practice, and often underestimated by shop owners, is a different risk: warning letters, known in Germany as Abmahnungen, sent by competitors. A faulty cookie banner, for example one with a hidden reject button or pre-ticked boxes, is a classic target for such warning letters under German competition law. These warning letters arise independently of whether a data protection authority ever gets involved, and already bring real costs and considerable effort on their own, for example for legal review and issuing a cease-and-desist declaration. For small shops in particular, this warning-letter risk is often the more immediate and faster-felt hassle compared with a regulatory procedure.
Important to know
Two kinds of risk run in parallel with a faulty cookie banner. On one hand, official fines under the GDPR framework threaten, which can be tied to worldwide annual turnover, if a supervisory authority takes action. On the other hand, sloppy banners, for example with hidden reject options or pre-ticked boxes, are a well-known target for competition-law warning letters from competitors, independently of any regulatory procedure. Whoever sets up the banner cleanly and on equal terms from the start reduces both risks at once.
A real-world example from a small shop
A shop owner has used a simple, free cookie notice showing only an "OK" button since opening his online shop several years ago. In the background, Google Analytics and an advertising pixel load on the very first page view, regardless of whether anyone actually consents. For years nobody notices, until a customer complains and shortly afterwards a warning letter from a competitor lands in his inbox, criticising exactly this banner. The subsequent legal review and the switch to a proper consent tool would have caused far less effort and cost had they been planned from the start, instead of being handled only under outside pressure.
7. Common misconceptions
A widespread misconception goes: "A simple cookie notice with an OK button is surely enough." This exact pattern is now considered outdated and non-compliant, because it offers no genuine, equal option to reject and often already loads cookies before anyone has even clicked. A second misconception concerns Google Analytics: many shop owners assume their analytics data is anonymous anyway and therefore does not need consent. In practice, standard configurations of common analytics tools are not anonymous enough to be exempt from the consent requirement.
A third misconception is the assumption that consent given once is valid forever. If the purposes or the vendors involved change, for example because a new marketing tool is added, consent should be renewed. In addition, withdrawal must always be just as easy as the original consent. A fourth misconception is the idea that this obligation is only ever about classic cookies in the narrow sense. In fact, the rule also covers similar storage techniques such as local storage in the browser or fingerprinting methods, which can recognise a device again even without a classic cookie.
8. What Mironsoft can take care of for you
We know that many shop owners feel uncertain about this topic, because technical detail, data protection law and competition law all intertwine. Mironsoft takes care of the practical and technical side for you: we check which cookies and scripts your shop actually sets, often a surprising first step, and set up a cookie banner or fix an existing one, so that accepting and rejecting are genuinely offered on equal terms and non-essential scripts stay properly blocked until consent has been given.
We also make sure consent is documented in a traceable way and that an always-accessible way to change cookie settings is in place. Because tracking tools and requirements change over time, we keep an eye on your setup on an ongoing basis, rather than setting it up once and leaving it to itself.
For specific legal questions about your individual case, we work closely with your legal counsel or your data protection officer, or put you in touch with a suitable contact if needed. This way you do not have to fight your way alone through technical detail and legal nuance, but have a single point of contact keeping an overview and making sure an unassuming banner never turns into a real problem.
| Cookie/script type | Consent needed? | Example | Typical mistake |
|---|---|---|---|
| Technically necessary cookies | No | Shopping cart session, login state, security features | Wrongly blocked in the banner too, breaking shop functionality |
| Analytics cookies | Yes | Google Analytics, other statistics tools | Assumed to be "anonymous anyway" and loaded without consent |
| Marketing and retargeting cookies | Yes | Facebook pixel, Google Ads remarketing | Loads on page view already, before any click on the banner |
| Embedded third-party content | Yes | YouTube video, embedded map, social media widget | Classified as a mere comfort feature although it sets cookies |
9. Summary
The cookie consent requirement under Section 25 TTDSG is not a new invention of 2026, it has applied since December 2021. It becomes newly relevant mainly because German state data protection authorities and courts now scrutinise the specific design of banners more closely, in particular whether "reject" is really just as easy as "accept". Every shop that uses non-essential cookies or similar techniques is affected, regardless of size or turnover.
The two biggest practical risks are fines under the GDPR framework and competition-law warning letters from competitors, which are particularly likely with a faulty banner. Whoever sets up the banner cleanly, both technically and visually, documents consent, and reviews the setup regularly, reduces both risks considerably. This article offers a general overview and does not replace individual legal advice for your specific case.
Cookie Consent Under TTDSG — The Essentials at a Glance
What it is about
Section 25 TTDSG requires prior consent before non-essential cookies or similar techniques are set or read.
Who is affected
Every shop using analytics, marketing cookies or embedded third-party content, regardless of size or turnover.
Biggest risk
GDPR fines and, often more immediate in practice, competition-law warning letters over a faulty banner.
What to do
Audit your cookies, set up a banner with an equally prominent reject option, technically block scripts, and review the setup regularly.
10. FAQ: Cookie Consent Under TTDSG
1What does cookie consent under TTDSG mean in simple terms?
2Is a banner with just an OK button enough?
3Does this affect small shops too?
4Does Google Analytics need consent?
5Since when has this applied?
6Do I need to document consent?
7What happens if the banner is faulty?
8Is consent valid forever?
9Is it only about classic cookies?
10Can Mironsoft help me with this?
This article offers a general overview of the cookie consent requirement under TTDSG and does not replace individual legal advice for your specific case.