// Blog
// Privacy, Optimization

Cookie banners: do I even need one?

The best cookie banner is the one you don't need – and that's possible more often than you'd think.

Home page of michael-becker-berlin.de – without a cookie banner

Hardly any website gets by without a cookie banner these days – and hardly anything annoys visitors so reliably. Many website owners add one because "that's just what you do", without really knowing whether they need it. In this article I explain when consent is actually required and how you can set up your website so that a banner often isn't necessary in the first place.

One thing up front: I'm a web developer, not a lawyer. This article puts the legal situation into context, but it doesn't replace legal advice. It's also written from a German perspective.

What the law says

In Germany, Section 25 TDDDG governs cookies and similar technologies. Until May 2024 the law was called TTDSG; when the Digital Services Act (Digitale-Dienste-Gesetz) came into force on 14 May 2024, it was renamed the "Telecommunications Digital Services Data Protection Act". The cookie rule itself didn't change.

The core idea is simple: anyone who stores information on a visitor's device or reads it from there generally needs consent. That covers not only cookies, but also the browser's local storage, tracking pixels and fingerprinting techniques.

The important exception: consent is not required if storing or reading the information is strictly necessary for a service the user has explicitly asked for.

On top of that, the GDPR applies as soon as personal data is processed – and in many cases even the IP address counts. So a cookie banner doesn't automatically solve every data protection question; it's just one building block.

A change is in the works at EU level: in November 2025 the European Commission proposed, as part of the so-called "Digital Omnibus", moving the cookie rules into the GDPR, making it easier to decline, and taking consent signals from the browser into account. None of this has been adopted yet (as of October 2026). For your website, Section 25 TDDDG still applies.

What doesn't need consent

Examples of technically necessary cookies:

  • the session cookie that keeps a shopping cart or a login together,
  • a protection cookie against forged form submissions (CSRF token),
  • a cookie that remembers a language setting someone chose themselves,
  • a cookie that stores the fact that a notice has already been closed.

You don't need consent for cookies like these. You should, however, mention them in your privacy policy.

What usually needs consent

It gets trickier with anything that isn't needed for the site's actual function:

  • analytics and tracking tools such as Google Analytics,
  • marketing pixels, for example from Meta or LinkedIn,
  • embedded videos from YouTube or Vimeo,
  • embedded maps from Google Maps,
  • fonts or scripts loaded from third-party servers, for example Google Fonts served by Google.

With the last three, it's often not just about cookies: simply loading the content sends the visitor's IP address to the third-party provider. For Google Fonts, the Munich Regional Court ruled back in 2022 that this can be unlawful without consent (judgment of 20 January 2022, ref. 3 O 17493/20) – which triggered a wave of cease-and-desist letters in Germany at the time. The matter still isn't fully settled: in 2025, in a Google Fonts case, the German Federal Court of Justice asked the Court of Justice of the European Union, among other things, whether IP addresses are always personal data (ref. VI ZR 258/24). An answer is still pending. If you host your fonts locally, though, you don't need to wait for it.

The best banner is no banner

Instead of hunting for the perfect consent solution, it's worth asking: do I need the thing I'd have to ask consent for? Quite often the honest answer is no. These measures help:

Drop tracking. Many small websites added Google Analytics at some point and never look at it. If you don't use the numbers, remove the script.

Host fonts locally. Fonts such as those from Google Fonts can usually be downloaded and served from your own server. Then no data flows to third parties, and the page usually even loads faster.

Two-click solution for videos and maps. Instead of embedding the YouTube video or Google map directly, first show a preview image with a notice. The third-party content only loads after a click. Alternatively, a simple link or a static map image with directions is often enough.

Privacy-friendly statistics. If you need visitor numbers, there are tools that work without cookies and without passing data to third parties, such as self-hosted solutions or server log analysis. In Laravel projects I like to use the package Pan. It only counts how often certain elements on the page are shown, hovered over or clicked, for example a button or a form. The numbers end up in your own database, and according to the project page Pan stores neither IP addresses nor any other personal data. For a question like "Is anyone actually using the new sign-up button?" that's all you need.

A word of caution, though: with tools like these, too, you should check (or have someone check) in each case whether consent really isn't required. "Cookieless" on a vendor's website is not a legal guarantee.

An example: ZerpenSafari

For the Kranich Lodge in Zerpenschleuse I developed the web app ZerpenSafari with interactive audio tours. The app only uses technically necessary cookies that are required for it to run, and no tracking. So instead of a consent banner with "Accept all" and "Settings", there's just a plain notice with a link to the privacy policy and a "Got it" button ("Verstanden").

ZerpenSafari home page on an iPhone with a notice that only technically necessary cookies are used and no tracking takes place, a link to the privacy policy and the button "Verstanden" (Got it)

Strictly speaking, even this notice isn't required – but it provides transparency without getting in the way.

This website gets by without tracking as well: it's served as static HTML built with my static site generator Nera, and the fonts live on my own server. That's why you don't see a cookie banner here.

Even so, there's no such thing as zero data processing: as with almost every website, the hosting provider keeps server log files, for example with the IP address and the time of the request. That doesn't require consent, but it belongs in the privacy policy. And the contact form doesn't send anything to a server either – it simply opens your own email program.

If you do need a banner

Sometimes tracking or an embedded video really is necessary. Then the banner should be designed fairly:

  • "Reject" has to be as easy as "Accept". In 2025 the Administrative Court of Hanover ruled that next to "Accept all", an equivalent "Reject all" button must appear on the first layer (report on heise online, German).
  • No pre-ticked boxes.
  • The services concerned must not load before consent has been given.
  • Consent must be revocable at any time.

A banner that's displayed but loads everything in the background anyway is worse than none at all.

Conclusion

You only need a cookie banner if you use things that require consent. Technically necessary cookies don't count. With locally hosted fonts, two-click solutions and no unnecessary tracking, many websites of associations, practices or freelancers can do without a banner entirely – to the delight of their visitors.

If you'd like to know what your website is currently loading and whether you can get rid of the banner, feel free to write to me. As part of my consulting, I'll take an independent and honest look.

Yours, Michael Becker