What is a cookie banner?
A cookie banner is an upstream element of a website with which visitors can make personal settings as to which services they would like to allow on this website and which not.
Above all, however, the cookie banner must absolutely ensure, due to the requirements of DSGVO and TTDSG, that data processing operations only take place if the visitors to the website have actively consented. Cookie banners therefore take technical measures to ensure that all scripts on the website that collect personal data are blocked.
As a website operator, you must provide a cookie banner to comply with the DSGVO (General Data Protection Regulation), as cookies and other data are counted as personal data.
In addition, the TTDSG (Telecommunications Telemedia Data Protection Act) will apply in Germany from 01.12.2021. This is another reason why you absolutely need a cookie banner on your website - otherwise it can quickly become very expensive.
On this information page we list everything you as a website operator should know about cookie banners.
- What is a cookie banner?
- Do I need a cookie banner for my website?
- What are the requirements for cookie banners?
- Cookie Banner integrated in 5 minutes!
- What must be included in the cookie banner?
- Cookie Banner Categories
- Data per integration / script
- How does a cookie banner work?
- 1. Cookie Banner Blocking
- 2. Cookie Banner as Tag Manager
- How to create a DSGVO-compliant cookie banner
- Cookie Banner and TTDSG
- The relevant passage in the TTDSG from the new Section 25 reads:
- High fines threaten in the new TTDSG
- Is your website also affected? Test it now free of charge!
- From when does the TTDSG apply?
- What are the benefits of a cookie banner?
- Cookie Banner Generator
- Cookie Banner Design / Cookie Banner Layout
- Standard positions:
- What is a Cookie Consent Manager?
- What does Consent / Consent Management mean?
- Which cookies are allowed?
- What are technically necessary cookies?
- What is stored in a cookie?
- Does my cookie banner have to contain a link to my imprint?
- Can I use a Cookie Banner in combination with the Google Tag Manager (GTM)?
- What choices / confirmation types should my cookie banner offer?
- How can my website visitor revoke his cookie decision?
- Optimize Cookie Banner OptIn Rate
- How many users reject or accept cookies?
- Are cookie banners mandatory?
- noyb wants to put an end to cookie banners
- New browser signal aims to make cookie banners obsolete
- Are cookie banners DSGVO compliant?
What are the requirements for cookie banners?
The DSGVO / General Data Protection Regulation and the new TTDSG require the prior, informed consent of the users of your website. In addition, the DSGVO requires - and this is important! - that you must document any consent in the cookie banner
In order to implement the site in a DSGVO-compliant and TTDSG-compliant manner, the Cookie Banner must be part of a cookie consent management solution for your website, so that the following 4 points are covered!
- To make an informed decision, you need to provide visitors with detailed, specific and accurate information about all scripts and cookies used on the website in the Cookie Banner.
- Visitors must be able to consent or withhold consent to each script and cookie , and you must be able to easily revoke that consent at any time!
- Cookies may only be set after consent (Consent) and this consent must be documented.
- Regular renewal of the consent of your visitors, preferably every 6 to max. 12 months is necessary. Check the respective regulations in your country.
Cookie Banner integrated in 5 minutes!
Here you can see how to integrate a CCM19 Cookie Banner into a website in 5 minutes. You don't believe? Then go ahead!
What must be included in the cookie banner?
The cookie banner, the first banner that opens when you enter a website for the first time, must contain text, buttons and links
Under this text there are usually 3 different buttons:
- Accept - this is where you accept all cookies and scripts.
- Reject - if you click here, only technically necessary cookies will be set.
- More information or settings - this opens another window where additional detailed information about all cookies and scripts can be found.
Below the buttons there should be links to privacy information and the imprint of the site. Both pages must be accessible without blocking the content and without setting cookies!
After clicking on"Information" the following window should open.
Here, the available categories are listed, which are currently assessed by leading lawyers as legally usable and thus also appear in various guidelines or judgments
Cookie Banner Categories
- Technically necessary
- Advertisements / Ads
- Analysis / Statistics
- Social Media
You can define a hint text for each category here and visitors can check/uncheck each category. Of course, the category "Technically necessary" must remain, otherwise the website would no longer function correctly. So cookies from this category may always be set.
This banner should contain both the "Save" and "Cancel" buttons. Additionally, buttons like "accept / reject all" can be included.
Next to the categories there is a button/link with a question mark, which, when clicked, opens another window with detailed information about the individual scripts and cookies.
In the detail view all data about all scripts are listed in detail. Among other things:
Data per integration / script
- From whom does the script originate?
- Description of what it does
- What data is collected in detail?
- For what purpose is the data collected?
- What cookies, local storage elements or other data are stored in the visitor's browser, how long are they stored and how are they stored?
- Legal basis
- Place of data processing
You can explicitly check and uncheck each inclusion here. To (de)activate cookies individually is technically not possible in most cases, so we have switched to listing and displaying them in a package with the respective script / tool.
With the close/save button, the data is transferred and stored in the browser of the browser. This so-called Consent is also stored anonymously in the Consent Management System.
It is of course possible to store the IP with, however, should be refrained from, because it is here again a personal data element, which could again require consent.
How to create a DSGVO-compliant cookie banner
To create a cookie banner that is DSGVO compliant and TTDSG compliant, YOU need a specialized provider.
Most simple cookie banner scripts you find unfortunately don't include essential points like detailed information, documentation of consent or detailed listing of providers at all!
If you use a non-compliant banner here that does not meet the above requirements, it can get very expensive very quickly in the event of warning letters.
To create a DSGVO compliant / TTDSG compliant cookie banner, simply sign up for free here and go through the automatic scan in onboarding. This process usually takes 2-3 minutes.
After that, everything is set up and you can integrate the Cookie Banner script into your site
Cookie Banner and TTDSG
On 20.05.2021, the German Bundestag passed the new TTDSG, which newly regulates the use and consent of cookies and any other information in the visitor's browser. Particular attention should be paid to the fines that come into play here.
The relevant passage in the TTDSG from the new Section 25 reads:
'The storage of information in the end-user's terminal equipment or access to information already stored in the terminal equipment is only permitted if the end-user has consented on the basis of clear and comprehensive information. The information to the end user and the consent must be provided in accordance with Regulation (EU) 2016/679.
In addition to cookies, this of course also concerns
- Local Storage,
- Session storage
- as well as database data
In other words, all data that is stored in the browser.
High fines threaten in the new TTDSG
If website operators do not take this into account, they will face high fines - up to 300,000 EUR can be imposed as fines. Presumably, this amount will only be imposed in individual cases, which is then at the discretion of the fine authority
§ 26 Rules on fines
(1) It is an administrative offence to wilfully or negligently ... stores or accesses information in contravention of section 25, paragraph 1, sentence 1.
(2) The administrative offence can be punished in the cases of paragraph 1 number 2, 3, 9, 11, 12 and 13 with a fine up to three hundred thousand euros, .....
Is your website also affected? Test it now free of charge!
You can test whether it affects you directly here with our Cookie Scanner. If cookies or other elements appear in the result that are not exclusively listed under the category "technically necessary", you need a Cookie Banner from CCM19
From when does the TTDSG apply?
The law comes into force on 01.12.2021 - so there are still a few months left until then to get the problem under control.
Cookie Banner Generator
A cookie banner generator automatically creates a cookie banner suitable for your website or online shop.
Usually you go through a multi-step process in which:
- Your website is scanned
- Cookies and other data are detected and categorized
- Data protection and imprint are read out
- Cookie banner designs pre-populated
- And an HTML snippet to be integrated is generated.
You then only have to integrate this snippet into your page, which can then look like this, for example:
CCM19, for example, is such a cookie banner generator - and even a so-called cookie content management system.
Cookie Banner Design / Cookie Banner Layout
Cookie banners can of course be designed and laid out in any way, and always in accordance with the CI of the respective page. Initially, however, the main question is where to place the banner on the page.
- Centered, blocking
- Top, blocking
- Bottom, blocking and non-blocking
- Bottom left, blocking and non-blocking
- Bottom right, blocking and non-blocking
Blocking means that visitors cannot use the site until they have interacted with the cookie banner. So you have to agree or disagree with the cookies.
What does Consent / Consent Management mean?
Consent management simply means consent management, in this context the management of consents via the cookie banner of your own website.
Visitors must also be able to independently change this consent again via the website, for which you also need a suitable tool such as CCM19.
Which cookies are allowed?
In principle, all cookies are allowed, but you must obtain consent via a cookie banner before setting the cookies in the browser.
Only technically necessary cookies, such as for the shopping cart, language settings or login status, may be set without consent.
Generally, cookies or their scripts are assigned to these categories:
- Technically necessary
- Display / Ads
- Analysis / Statistics
- Social Media
For all cookies except those assigned to the "Technically Necessary" category, you need visitor consent before they can be set.
What is stored in a cookie?
Almost any data can be stored in cookies, but in principle the storage space per cookie is limited to 4kB.
What data is actually stored depends entirely on the provider of a cookie. Some only store a simple ID - for example a UserID like 14839457, others store detailed GEO information in the cookie to check the location of visitors to the website.
To find out what the cookies store, you can go into the developer console in the browser and look at the contents of the cookies, however this is very technical.
Additionally, the information in the cookies is often encrypted as well, so the data is not easily decipherable.
For this reason, cookie banners are important because almost any personal information can be stored and transported in the cookies and with the help of the scripts that set these cookies.
Above all, it is important that
- the cookie banner does not obscure it
With cookie banners, make sure that the link is included, because according to the GDPR, you must be able to explain the data protection provisions before cookies from third-party providers are set.
Does my cookie banner have to contain a link to my imprint?
A link to the imprint should also be included in the cookie banner.
It is especially important that
- the imprint is accessible without the cookie banner,
- the cookie banner does not cover the imprint
- and that no cookies are set on the imprint page for which a consent would be necessary.
Make sure that the link is included in cookie banners, because according to the DSGVO / Data Protection Ordinance you must be able to present the imprint legibly before cookies are set by third-party providers and also before visitors enter your actual site.
What choices / confirmation types should my cookie banner offer?
Cookie banners should generally offer a choice of all scripts used that process personal data and are not technically necessary.
The choices are usually tiered by category, these are usually:
- Technically Necessary
- Advertisements / Ads
- Analysis / Statistics
- Social Media
In addition, it is necessary that in each category each individual tool that you include or use is sorted into the respective categories and can be (de)activated.
These settings are confirmed normally with the help of buttons and checkboxes in forms.
How can my website visitor revoke his cookie decision?
Visitors to your website should be able to revoke their cookie decision just as quickly and easily as you did - this is a result of the GDPR.
With CCM19 we give you 2 possibilities.
- Via a link to be inserted - which you enter manually in your page, e.g. in the footer of the page. A click on this link opens the settings mask where the visitor can revoke the decision completely or in parts.
- Via an automatically displayed icon in the page - which you can also see here in the lower left corner. A click on it also opens the consent mask with the corresponding setting options.
Try it out!
The revocation is of course also documented and can be compared in case of request.
How many users reject or accept cookies?
What percentage of your visitors fully accept your cookie banners or only the technical minimum depends on very many factors, such as:
- and much more.
Basically it can be said that only about 1/3 of the visitors accept all cookies without further optimization measures.
Another third accepts the technically necessary ones, the rest rejects everything but accepts the technically necessary cookies.
Are cookie banners mandatory?
But it is different as soon as you use tools or scripts that transfer data abroad, set cookies, local storage elements or other data in the browser of your visitors.
As soon as you use this, cookie banners are indispensable for you because you cannot set this data without the consent of your visitors - each of them individually.
New browser signal aims to make cookie banners obsolete
noyb and CSL of WU Vienna publish the specification and a prototype.
In the meantime, Noyb has also made a proposal on how to make a large number of banner queries obsolete. With the help of a technical specification and a browser extension they want to show that cookie banners are not needed.
The problem is unfortunately divided, it will be difficult to understand these settings not as a super tracking cookie and it remains the duty of the operators cookies and scripts only after consent to set.
I.e. even in the event that this eventually prevails, the banners will be invisible at most more often, but still be present. Simply because they take care of the playout of cookies and scripts and comply with the mandatory documentation obligation and there may be visitors who do not send the signal.
Are cookie banners DSGVO compliant?
In order to make your website DSGVO compliant, we think you need a cookie banner in any case.
The DSGVO / Basic Data Protection Regulation and, more recently, the current TTDSG clearly stipulate that cookies may only be set with the consent of the visitor.
DSGVO compliant - this is how a cookie banner must be structured:
A DSGVO compliant cookie banner allows visitors to your website to decide which cookies and scripts may be set, CCM19 is such a cookie banner and offers you the technical security that this function is also guaranteed.
In addition to the existential cookies, which serve to display the website properly, there are also functional and analytical cookies, which are intended to help the website operator to better tailor its offer to the user and generate more customers or interested parties. The operator of the site is naturally responsible for the DSGVO-compliant design of the cookie consent banner.