Cookies

Data protection glossary · 1 minute read

Cookies are small text files that a website stores on the user's terminal device in order to recognise the user or save settings.

Under Section 25 TDDDG, storing information on, and accessing information from, the terminal device generally requires consent. This applies to cookies as well as to comparable technologies such as local storage or fingerprinting.

Cookies that are strictly necessary for the service explicitly requested by the user are exempt, for example for a shopping basket, a login or storing the cookie choice itself.

Interplay with the GDPR

Where personal data is processed through cookies, the subsequent processing also requires a legal basis under the GDPR. For analytics and marketing cookies, this is regularly consent in practice.

The privacy notice must provide information about the cookies used, their purposes, providers and storage periods.

Section 25 TDDDG
Protection of privacy in terminal equipment, consent and exemptions.
Art. 6(1) GDPR
Legal basis for processing the data collected.
Art. 13 GDPR
Information obligations towards users.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.