German Telecommunications and Telemedia Data Protection Act
The TTDSG is a German law that governs data protection and privacy in the telecommunications and telemedia sectors, including how websites and apps may store information on or access information from a user's device. It is the German framework under which cookie consent rules are applied, and it took effect on 1 December 2021. The TTDSG works alongside broader EU data protection rules rather than replacing them.
The TTDSG (Telekommunikation-Telemedien-Datenschutz-Gesetz) is Germany's national statute regulating privacy in telecommunications and telemedia services, in force since 1 December 2021. It consolidated numerous German and EU-derived data protection provisions and provides the domestic legal basis for cookie consent requirements, specifically governing the storing of, and access to, information on a user's terminal equipment. Per § 2(2)6 TTDSG, 'terminal equipment' is defined as any device connected directly or indirectly to the interface of a public telecommunications network, which brings not only cookies but functionally similar technologies (such as local storage, SDKs, and device-based identifiers) potentially within its scope where they involve storing or accessing information on the device. The TTDSG operationalizes the consent standard associated with the ePrivacy Directive's device-access rules within German law, while the separate question of whether any resulting personal data may be processed is governed by the GDPR and Germany's Federal Data Protection Act (BDSG); the two regimes should not be conflated. Note that the TTDSG has since been affected by German legislative reform (associated with the abbreviation TDDDG in later sources), so practitioners should verify the current statutory designation and text; the precise interplay with GDPR bases and the treatment of specific technologies remain matters of evolving national interpretation and are beyond the scope of this definition.
Why it matters
The TTDSG matters because it provides the specific national legal basis under which cookie consent rules are enforced in Germany. While the ePrivacy Directive sets the EU-level standard for storing and accessing information on a user's device, that directive must be transposed into national law to take effect. Since 1 December 2021, the TTDSG has served as that domestic framework in Germany, meaning organizations operating websites or apps directed at German users must look to the TTDSG (and its subsequent legislative evolution) rather than the directive alone when assessing their consent obligations.
The statute's broad definition of 'terminal equipment' under § 2(2)6 is significant for practitioners because it extends the analysis beyond traditional cookies. Any device connected directly or indirectly to the interface of a public telecommunications network falls within scope, which means functionally similar technologies such as local storage, SDKs, and device-based identifiers may also be caught where they involve storing or accessing information on a user's device. This makes the TTDSG relevant to a wide range of tracking and measurement practices, not just those that literally deploy cookies.
Equally important is what the TTDSG does not do. It governs the placing of and access to information on a device, but the separate question of whether any resulting personal data may lawfully be processed remains governed by the GDPR and Germany's Federal Data Protection Act (BDSG). These regimes should not be conflated, and satisfying the device-access consent standard does not by itself resolve every processing question. Practitioners should also note that the TTDSG has since been affected by German legislative reform associated with the abbreviation TDDDG in later sources, so the current statutory designation and text should be verified before relying on the framework.
Who it's relevant to
Inside TTDSG
Common questions
Answers to the questions practitioners most commonly ask about TTDSG.

