Operations and security
What happens before someone clicks “Accept”
The interesting moment on a website is the one between opening the page and clicking the cookie notice.
9 min read
By Timo Wessels Published
The interesting moment on a website is the one between opening the page and clicking the cookie notice. Whatever happens in that time happens without consent — and that is exactly what the relevant rules are written about.
The questions here:
- Which third-party servers are contacted?
- Which cookies are set?
- What else is stored on the device?
- Are fonts loaded from third-party servers?
- Are videos or maps embedded that already phone home while loading?
First, one clarification that carries through the whole article: This is not legal advice. It describes what happens technically and which duties it touches. Whether it amounts to a breach in an individual case is a legal assessment, and that belongs with a lawyer or a data protection officer.
The rule
The relevant provision is § 25 TDDDG — the law formerly called TTDSG, renamed in May 2024. It requires explicit consent before anything is stored on a user's device or accessed there.
In practice that means: scripts have to stay blocked until consent is given. A notice banner that merely informs while everything loads in the background does not meet that.
The point where most implementations fail
It is not about cookies. It is about storage on the device.
That is the most important sentence on this topic, and it is rarely said this clearly.
The term “cookie banner” has become established and is misleading. Cookies are only one of several forms of storage. Equally covered are:
- localStorage — persistent storage in the browser
- sessionStorage — storage for the duration of the session
- other browser storage
The European Data Protection Board explicitly named HTML5 storage as covered in its Guidelines 2/2023.
Two subtleties that make it stricter:
Writing alone triggers the provision. Reading it later is not necessary. It is enough that something is stored.
It does not matter whether the value is personal. The wording speaks of “information”, not of personal data. An anonymous counter is covered.
From that it follows: a check that looks only at cookies is systematically incomplete. Many tools and many reports do exactly that.
(Atlas, legal/eprivacy-localstorage.md)
The second common misconception: analytics
There is an exemption for strictly necessary storage. It is often claimed for audience measurement.
It does not apply there. The exemption requires two conditions at the same time:
- strictly necessary, and
- for a service explicitly requested by the user.
And necessity is judged from the user's point of view, not the provider's. Audience measurement serves the operator. The user did not request it.
The German supervisory authorities agree that audience measurement requires consent.
What actually falls under the exemption are things like the shopping basket, the login session, a language setting the user made themselves, or security functions. So everything the user would notice if it were missing.
(Atlas, legal/eprivacy-localstorage.md)
The third problem area: third-party servers
As soon as your page loads a file from a third-party server, your visitor's IP address goes there. Automatically, without anyone clicking anything.
IP addresses are personal data. The European Court of Justice decided that in 2016 in the Breyer case (C-582/14). It is enough that the operator could obtain the identification through third parties — they do not have to be able to do it themselves.
The classics, in the order in which I find them:
Fonts from a third-party server. The most common finding of all, and the easiest to fix — more on that in a moment.
Videos in the standard embed mode. As soon as the page loads, the connection is made.
Maps. The same.
Checks against automated input. On Google reCAPTCHA there are two relevant decisions: the Austrian Federal Administrative Court on 13 September 2024 and the French data protection authority CNIL in 2023. Both with the same result: prior consent required.
And the less obvious ones: chat windows, review widgets, social network buttons, embedded booking systems, tracking pixels from ad campaigns.
(Atlas, legal/ip-as-personal-data-breyer-ecj.md; legal/recaptcha-gdpr-rulings-bvwg-cnil.md)
How to check it yourself
The test takes two minutes and is surprisingly revealing.
1. Open a private browser window. Important, so that you see the state a new visitor sees.
2. Open your home page.
3. Do not click the cookie notice. Neither accept nor reject. Exactly this state is being checked.
4. Open the developer tools (F12), “Network” tab. There you see which addresses have already been contacted. Everything that is not your own domain is contact with a third party before consent.
Tip: there is a column for the domain. If it is not shown, it can be switched on by right-clicking the column headers. Then sort by domain — the foreign addresses will then stand together.
5. “Application” tab (in Firefox: “Storage”). Under “Cookies” you find all cookies set, and below that “Local Storage” and “Session Storage”. Whatever is already there before your click was written without consent.
A practical note that avoids false alarms: antivirus programs and browser extensions create entries of their own that look like yours. If you are unsure, check in a freshly set-up browser without extensions.
6. The quick source test. Ctrl+U, then Ctrl+F. Search for fonts.googleapis.com, youtube.com/embed, google.com/maps and google.com/recaptcha.
7. And the test that says most about the implementation: click “Reject” and look at the Network tab again. With a surprising number of consent solutions, things still load after rejecting.
What to do
The approach that solves all cases at once is: load nothing until consent is given.
The basis is a consent tool that actually blocks scripts instead of just showing a notice. That is the difference between a solution and a decoration — and many of the common banners are decoration.
For the individual cases:
Serve fonts from your own server. That removes the third-party contact completely, and you no longer need consent for it at all. That is the best case: not managing, but eliminating. There is an article of its own on this.
Put videos behind a preview image that only loads the video on click. Whoever clicks has decided. The alternative is the provider's enhanced privacy mode — better than nothing, but the preview image is cleaner.
Replace maps with a static image, with a link to the map application. For directions that is usually enough — and it loads faster.
Swap the checking mechanisms. Cloudflare Turnstile and Friendly Captcha are both defensible without consent; Friendly Captcha is based in Germany. And for a small business's normal contact form, a simpler method against automated input without any third-party service is often enough.
Put audience measurement either behind consent — then the data of those who reject is missing — or use a solution without storage on the device. Server-side analysis without storage in the browser does not fall under § 25 TDDDG in the first place. That is the cleanest route when the numbers are needed.
And remove everything nobody needs any more. On almost every grown website I find tracking pixels from campaigns that ran years ago and widgets from services long cancelled. They keep loading.
The self-check nobody does
Finally, the exercise with the best ratio of effort to insight:
Compare your privacy policy with the list from the Network tab.
Every service your page loads has to be named there. And the other way round: services that are in the policy and have long stopped being embedded should come out.
The nice thing about it is that no provision has to be interpreted. You only put two of your own statements side by side and see whether they fit together. On almost every website I look at for the first time, they do not.
The most common case: the privacy policy comes from a generator and names services that were never used — and does not name the one service that is actually running.
What that means for a conversation with a lawyer
If you get a legal assessment, the list from the Network tab is the most useful thing you can bring. It answers the question that otherwise costs the most time: what actually happens on this website?
A lawyer who gets this list can assess at once. A lawyer who does not get it first has to obtain it — or assesses on the basis of what you told them.
And the honest assessment at the end: the technical part of this topic can be done in an afternoon. Fonts local, videos behind a click, map as an image, superfluous services out — after that the list is short enough for the rest to become manageable. The effort only rises when you try to manage many services instead of having few.
Sources
- Atlas,
legal/dach-website-compliance-stack.md— that § 25 TDDDG (until May 2024 TTDSG) requires explicit consent before any non-necessary storage on or access to devices and that scripts have to stay blocked until consent, the information duties from Art. 13 and 14 GDPR at the point of collection, and that server-side audience measurement without storage in the browser can be exempt from § 25. - Atlas,
legal/eprivacy-localstorage.md— that Art. 5(3) of the ePrivacy Directive covers “information” rather than personal data, that the EDPB Guidelines 2/2023 explicitly name HTML5 storage, that writing alone triggers the provision and reading is not necessary, that the exemption cumulatively requires “strictly necessary” and “explicitly requested by the user” and that necessity is judged from the user's point of view, that audience measurement is not among the exempt categories, and that the German supervisory authorities agree it requires consent. - Atlas,
legal/ip-as-personal-data-breyer-ecj.md— that dynamic IP addresses are personal data (ECJ C-582/14 Breyer, judgment of 19.10.2016) and that identifiability does not require the operator to be able to identify alone. - Atlas,
legal/recaptcha-gdpr-rulings-bvwg-cnil.md— the decisions BVwG W298 2274626-1/8E of 13.09.2024 and CNIL Cityscoot SAN-2023-003 of 16.03.2023, both requiring prior consent for Google reCAPTCHA, and Cloudflare Turnstile and Friendly Captcha as defensible alternatives, with the note on Friendly Captcha's German base and the recommendation to get a written assessment in risky cases. - Atlas,
wordpress/core/patterns/local-google-fonts.md— that serving locally removes the data flow completely and that German supervisory authorities have issued warnings for loading from the third-party network without consent. - Own audit practice — the seven-step check in a private window, the note on entries created by antivirus software and browser extensions, sorting by domain in the Network tab, the reject test as a check of the actual blocking, the list of less obvious third-party services, the recommendation to put videos behind a preview image and maps behind a static image, comparing the privacy policy with the Network tab as a self-check, the observation on generator policies, and the advice to bring the service list to legal advice.