Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Laws and Regulations

German Telecommunications and Telemedia Data Protection Act

Also known as: TTDSG, Telekommunikation-Telemedien-Datenschutz-Gesetz, Act to Regulate Data Protection and Privacy in Telecommunications and Telemedia, German Federal Act on Privacy in Telecommunications and Telemedia
Simply put

The TTDSG is a German law that governs data protection and privacy in the telecommunications and telemedia sectors, including how websites and apps may store information on or access information from a user's device. It is the German framework under which cookie consent rules are applied, and it took effect on 1 December 2021. The TTDSG works alongside broader EU data protection rules rather than replacing them.

Formal definition

The TTDSG (Telekommunikation-Telemedien-Datenschutz-Gesetz) is Germany's national statute regulating privacy in telecommunications and telemedia services, in force since 1 December 2021. It consolidated numerous German and EU-derived data protection provisions and provides the domestic legal basis for cookie consent requirements, specifically governing the storing of, and access to, information on a user's terminal equipment. Per § 2(2)6 TTDSG, 'terminal equipment' is defined as any device connected directly or indirectly to the interface of a public telecommunications network, which brings not only cookies but functionally similar technologies (such as local storage, SDKs, and device-based identifiers) potentially within its scope where they involve storing or accessing information on the device. The TTDSG operationalizes the consent standard associated with the ePrivacy Directive's device-access rules within German law, while the separate question of whether any resulting personal data may be processed is governed by the GDPR and Germany's Federal Data Protection Act (BDSG); the two regimes should not be conflated. Note that the TTDSG has since been affected by German legislative reform (associated with the abbreviation TDDDG in later sources), so practitioners should verify the current statutory designation and text; the precise interplay with GDPR bases and the treatment of specific technologies remain matters of evolving national interpretation and are beyond the scope of this definition.

Why it matters

The TTDSG matters because it provides the specific national legal basis under which cookie consent rules are enforced in Germany. While the ePrivacy Directive sets the EU-level standard for storing and accessing information on a user's device, that directive must be transposed into national law to take effect. Since 1 December 2021, the TTDSG has served as that domestic framework in Germany, meaning organizations operating websites or apps directed at German users must look to the TTDSG (and its subsequent legislative evolution) rather than the directive alone when assessing their consent obligations.

The statute's broad definition of 'terminal equipment' under § 2(2)6 is significant for practitioners because it extends the analysis beyond traditional cookies. Any device connected directly or indirectly to the interface of a public telecommunications network falls within scope, which means functionally similar technologies such as local storage, SDKs, and device-based identifiers may also be caught where they involve storing or accessing information on a user's device. This makes the TTDSG relevant to a wide range of tracking and measurement practices, not just those that literally deploy cookies.

Equally important is what the TTDSG does not do. It governs the placing of and access to information on a device, but the separate question of whether any resulting personal data may lawfully be processed remains governed by the GDPR and Germany's Federal Data Protection Act (BDSG). These regimes should not be conflated, and satisfying the device-access consent standard does not by itself resolve every processing question. Practitioners should also note that the TTDSG has since been affected by German legislative reform associated with the abbreviation TDDDG in later sources, so the current statutory designation and text should be verified before relying on the framework.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for compliance at organizations serving German users need to understand the TTDSG as the domestic framework under which cookie consent rules are applied, and to distinguish its device-access requirements from the separate processing obligations under the GDPR and BDSG. They should also track the statute's evolution, including the reform associated with the TDDDG designation, to ensure they are working from the current text.
Legal counsel advising on German operations
Lawyers advising clients with a German presence or German-facing digital services should treat the TTDSG as the relevant national statute for assessing when consent is required to store or access information on a user's device. Because the framework's broad definition of terminal equipment and its interplay with GDPR bases involve evolving national interpretation, counsel should flag areas of unresolved uncertainty rather than treat the position as settled.
Web developers and app teams
Developers implementing tracking, analytics, or measurement technologies for German audiences should be aware that the TTDSG's scope can extend beyond cookies to functionally similar technologies such as local storage, SDKs, and device-based identifiers, given the broad § 2(2)6 definition of terminal equipment. This affects how consent gating and technical controls are designed for German-facing properties.
Marketing and advertising compliance teams
Teams deploying advertising pixels, measurement tags, and similar technologies to German users should coordinate with legal and privacy functions to confirm which activities require prior consent under the TTDSG. Because tools such as consent management platforms support but do not guarantee compliance, these teams should not assume that technical implementation alone satisfies the statute's requirements.

Inside TTDSG

TTDSG (Telecommunications-Telemedia Data Protection Act)
The German Telekommunikation-Telemedien-Datenschutz-Gesetz, which entered into force to consolidate data protection rules for telecommunications and telemedia services in Germany. Among other things, it contains the German national implementation of the ePrivacy Directive's rules on storing and accessing information on a user's terminal equipment.
Section on terminal equipment (device storage and access)
The provision (commonly referenced as the consent rule for end devices) that governs the placing of, and access to, information on a user's terminal equipment. This generally requires prior consent unless an exemption applies, transposing the core requirement of the ePrivacy Directive into German law.
Consent exemption for strictly necessary access
An exemption from the consent requirement where storing or accessing information is strictly necessary to provide a telemedia service explicitly requested by the user, or is solely for carrying out the transmission of a communication. This typically covers essential cookies and similar technologies but not analytics or advertising by default.
Consent standard by reference to the GDPR
The TTDSG generally ties the required consent to the GDPR's consent standard, meaning consent must be freely given, specific, informed, and unambiguous through a clear affirmative action. The TTDSG governs the device access step, while any subsequent processing of personal data remains governed by the GDPR.
Scope beyond literal cookies
The device-access rule is technology-neutral and can apply to techniques such as pixels, local storage, SDKs, and fingerprinting where they involve storing or accessing information on terminal equipment, not only to cookies in the strict sense.
Provision for recognized consent management services
The TTDSG includes a basis for recognized consent management services or arrangements intended to allow users to express and manage their consent choices. The detailed operation of such arrangements has depended on further implementing rules, and their practical availability and adoption may vary.

Common questions

Answers to the questions practitioners most commonly ask about TTDSG.

Did the TTDSG replace the GDPR for cookies in Germany?
No. The TTDSG (Telecommunications-Telemedia Data Protection Act) implements the ePrivacy Directive's rules on storing and accessing information on a user's device in German law. It works alongside, not in place of, the GDPR. In practice, Section 25 TTDSG typically governs whether you may place or read a cookie or similar technology on a device, while the GDPR continues to govern any subsequent processing of personal data that results. Consent obtained for one does not automatically satisfy the other, and you generally need to consider both.
Does the TTDSG only apply to browser cookies?
No. Although often discussed in terms of cookies, Section 25 TTDSG concerns the storing of information in, and access to information already stored in, a user's terminal equipment. This is generally understood to extend to similar technologies such as pixels, local storage, SDKs, and device fingerprinting, regardless of whether personal data is involved. The consent and exemption rules apply to these techniques in a comparable way, so scoping your analysis only to literal cookies may leave other tracking technologies unaddressed.
When can we place a cookie under the TTDSG without asking for consent?
The TTDSG provides a limited exemption for cases where storing or accessing information is strictly necessary to provide a telemedia service that the user has expressly requested. This is generally read narrowly, similar to the essential-cookie exemption under the ePrivacy Directive. Analytics, advertising, and many functional cookies typically fall outside this exemption and require prior consent. Whether a given cookie qualifies depends on the specific facts of your service, and borderline cases can be contested, so a documented necessity assessment is advisable.
What standard of consent does the TTDSG require?
The TTDSG references the GDPR's consent standard, so consent is generally expected to be freely given, specific, informed, and unambiguous, based on a clear affirmative action. Pre-ticked boxes and implied consent from continued browsing are widely regarded as non-compliant. Practical implementation usually involves a consent banner or CMP that does not set non-exempt cookies before consent and that presents accept and reject options in a clear manner. The precise design expectations may be shaped by guidance from German data protection authorities, which can evolve.
How does the TTDSG affect our consent management platform (CMP) setup?
A CMP can help operationalize TTDSG requirements by blocking non-exempt technologies until consent is given, presenting consent choices, and logging consent records. However, a CMP supports compliance rather than guaranteeing it. Configuration matters: technologies must be correctly categorized as exempt or consent-requiring, and the interface should reflect valid consent standards. You should also confirm that the CMP's own operation and any frameworks it uses, such as the IAB TCF, are configured consistently with your legal analysis under both the TTDSG and the GDPR.
Do we need to keep records of consent obtained under the TTDSG?
Because the TTDSG relies on the GDPR's consent standard, being able to demonstrate that valid consent was obtained is generally important, which in practice points toward maintaining consent logs or records. What specific information to retain, and for how long, is not something to state as a fixed universal rule here; it depends on your setup and applicable guidance. Coordinating record-keeping with your broader GDPR accountability obligations is a common approach, but the exact requirements are outside the scope of this definition.

Common misconceptions

The TTDSG replaced the GDPR for cookies in Germany, so complying with it is enough.
The TTDSG primarily governs the placing of and access to information on a user's device, transposing the ePrivacy Directive's rules into German law. Any processing of personal data that follows remains subject to the GDPR. Both regimes can apply, and satisfying one does not automatically satisfy the other.
Under the TTDSG, all cookies require consent.
The Act generally exempts storage or access that is strictly necessary to provide a service the user has explicitly requested, or that is solely for transmitting a communication. Analytics, advertising, and many functional technologies typically require prior consent, but genuinely essential ones generally do not.
The TTDSG sets a Europe-wide standard for cookie consent.
The TTDSG is Germany's national implementation. Other EU member states have their own transpositions of the ePrivacy Directive, and rules differ further in the UK and in US state frameworks such as the CCPA/CPRA, which often rely on opt-out rather than opt-in. Claims about the TTDSG should be scoped to Germany.

Best practices

Treat device access and personal data processing as two distinct compliance steps: assess the TTDSG requirement for storing or accessing information on the user's device, and separately assess the GDPR basis for any personal data processing that follows.
Classify each cookie and similar technology (including pixels, local storage, SDKs, and fingerprinting) and document why any technology relied upon as strictly necessary genuinely qualifies for the exemption rather than assuming it does.
Obtain prior consent for non-essential technologies using a clear affirmative action, and avoid pre-ticked boxes, implied consent from continued browsing, and other patterns widely regarded as non-compliant with the applicable consent standard.
Maintain records of consent and of your cookie classification decisions so you can demonstrate the basis for each technology used and the choices users made.
Where you rely on a consent management platform or any recognized consent management arrangement, remember that such tools support compliance but do not replace legal judgment; validate their configuration against the current requirements.
Scope your compliance approach to the jurisdictions you serve, consult current guidance from the relevant German data protection authorities where facts are contested or unresolved, and obtain legal advice for fact-specific questions the definition does not resolve.
Promotional banner for the Pentest Readiness checklist download