German court rules cookie banners must offer "reject all" button

Skye Jacobs

Posts: 615   +13
Staff
What just happened? The Hanover Administrative Court has issued a ruling that sharpens digital privacy protections in Germany. The decision requires websites to offer users a clear, easy, and genuine choice on cookie consent. Manipulative consent banners that push users toward accepting cookies are not just unfair – they violate German and European data protection laws.

Lower Saxony Data Protection Officer Denis Lehmkemper has won a legal battle in his push for fairer digital privacy practices in Germany. The Hanover Administrative Court ruled that websites must display a clearly visible "reject all" button on cookie banners if they offer an "accept all" option.

The recently unsealed March 19 decision aims to curb manipulative designs that pressure users into consenting to cookies and reinforces the principle that users deserve a clear, genuine choice.

The case that led to this landmark decision centered on NOZ (Neue Osnabrücker Zeitung), a major media company in Lower Saxony. Lehmkemper's office ordered NOZ to redesign its cookie banner, arguing it failed to obtain valid, informed, and voluntary user consent before placing cookies and processing personal data.

NOZ challenged the order, insisting its consent process was effective, did not involve personal data processing, and that cookie compliance was outside the data protection authority's jurisdiction.

After reviewing the case, the court sided with the data protection authority. Judges ruled that NOZ's cookie banner made rejecting cookies significantly harder than accepting them. Users faced repeated consent prompts, and the banner's language – such as the headline "optimal user experience" and the "accept and close" button – misled users. It omitted any mention of the word "consent," and buried information about third-party partners and cross-border data transfers behind scrolling.

The court concluded that NOZ failed to obtain the informed, voluntary, and unambiguous consent required under the General Data Protection Regulation (GDPR). It ruled that consent secured through manipulative design is invalid, violating both the Telecommunications Digital Services Data Protection Act and the GDPR.

The judgment reinforces that websites must not nudge users into agreeing to cookies or make refusal unnecessarily difficult. Instead, the option to reject all must be as prominent and accessible as "accept all."

Lehmkemper welcomed the court's ruling, hoping it would set a precedent for other website operators. He acknowledged that many find cookie banners frustrating but emphasized their importance in safeguarding online privacy. The decision should prompt more providers to adopt consent solutions that comply with data protection standards.

Recent audits by data protection authorities, such as the Bavarian State Office for Data Protection Supervision, found many websites still use cookie banners that fall short of legal standards, often making it easier to accept cookies than to reject them. The Hanover court's ruling should push website operators to improve consent mechanisms and uphold online privacy rights.

Permalink to story:

 
That's a wrong step in the right direction.

Rejecting cookies should not be simple - it should be unnecessary.
Cookies should be strictly opt-in.
Each website should have an 'Accept cookies' button which, once clicked, presents a choice what cookies the user is willing to accept.

If I haven't explicitly stated my desire to accept cookies, the default assumption should be that I reject them. It's really simple.
 
Who knows what the websites are doing, whether you click accept or deny? Banners are just that - banners. To please the authorities.

The moment you land on a webpage, chances are, they already collected your information, or planted a cookie, before you even scroll a line or click on the banner.
 
I have disliked the cookie banner. While I get it, it makes surfing the net more frustrating. Particularly when your ad blocker hides the cookie banner and you have to disable it to see it.
 
You do realize that cookies also store your authentication details, so if you delete them like some user did, you always have to re-enter all your details. Imagine doing this for hundreds of websites.

I prefer to keep cookies and block only trackers.
 
Cookies are gone out of control, they're saved on you device even before you accept or deny them, most website allow you only to reject a part of cookie while always accept "legittimate interest" ones and/or third parties ones; some websites don't even allow you to refuse them, if you refuse they either get you back to main page or have a banner that say that without accepting cookies or a paid subscription you cannot access the website; smart tv and android are even worse situation.
I used to have opera set with block all cookies and manually make exception but they removed the option in the settings so now I manually had to block all cookies I don't want allowed.
 
Back