See how Syrenis helps simplify compliance, build trust, and gain greater control over customer data. Book a Demo

Blog Article

Germany’s Consent Management Model: Could it Reduce Cookie Banner Fatigue?

Posted: September 8, 2026

An internet user might open ten websites in a morning and dismiss ten cookie banners without reading any of them.

According to a survey commissioned by Germany’s federal data protection authority, only 43 percent of users know what cookies actually are, while 83 percent want more control over how their data is used.

Germany’s answer to “cookie fatigue” is the Consent Management Ordinance, a legal framework for centralized consent management that took effect on April 1, 2025. It offers an early look at how cookie consent might work when users state their choices once instead of on every website they visit.

The Einwilligungsverwaltungsverordnung (EinwV) is an ordinance made under Section 26(2) of Germany’s Telecommunications Digital Services Data Protection Act (TDDDG), the law that governs cookies and similar technologies in Germany.

The ordinance creates a framework for recognized consent management services: Independent services that store an end user’s consent decisions centrally and automatically communicate them to participating websites.

Where the system operates, a participating website can read the user’s stored choices instead of displaying its own banner.

The ordinance regulates consent at two levels: 

  1. Between the end user and the service, where choices are collected and stored
  2. Between the service and the digital service provider, where those choices are transmitted in bundled, automated form

It also places obligations on providers of digital services and on makers of browsers and display software, whose products must be able to recognize that a user is relying on a recognized service.

Adoption is voluntary on both sides. No website is required to work with a recognized service, and no user is required to adopt one, so conventional cookie consent management remains the default for now.

What it Takes to Become a Recognized Service

Recognition is granted by the Federal Commissioner for Data Protection and Freedom of Information (BfDI) on application, and the bar is high.

Applicants must: 

  • Demonstrate user-friendly and competition-compliant procedures for managing consent
  • Submit a detailed security concept
  • Confirm that personal data collected through the service will not be used for any purpose beyond managing consent

If successful, recognized services must also review their own compliance annually and report any deficiencies, and the BfDI can withdraw recognition where the requirements are no longer met. 

The design points toward a small set of vetted and independent intermediaries rather than an open market.

The First Recognized Service has Arrived

On October 17, 2025, the BfDI recognized the first service: a browser-based tool called Consenter, developed by the Berlin legal technology firm Law & Innovation Technology.

Announcing the recognition, the BfDI published survey findings that explain the policy’s appeal. Two thirds of German internet users could imagine using such a service, provided their settings applied across platforms.

But one recognized service does not end the cookie banner. Websites must choose to participate, users must install the tool, and its signals must interoperate with the consent management platforms that websites already run. 

The register may also grow slowly, given recognition costs and the absence of any commercial upside in the consent data itself.

Germany’s ordinance is a national experiment with international implications. 

The European Commission’s Digital Omnibus proposals have revived debate about machine-readable consent signals at EU level, and regulators elsewhere are watching whether Germany’s model reduces consent fatigue without degrading genuine choice.

And note that the ordinance sits alongside the GDPR rather than replacing it. 

As such, a choice transmitted by a recognized service must still meet the GDPR standard of being informed, specific, and freely given, and the website remains responsible for what happens after the signal arrives.

For enterprises, a practical point remains: If external services can transmit consent decisions, an organization’s consent management platform must be able to receive, record, and act on choices made elsewhere, alongside those captured through its own banner.

That is the same synchronization challenge that already exists between websites, apps, and marketing systems, extended to a new external source of truth.

Organizations whose consent records live in one authoritative place will be in a position to respond to such signals easily, while those with consent scattered across disconnected tools may struggle to do so.

A signal Worth Preparing For

German cookie banners will not disappear this year, and the EinwV may never achieve the scale its drafters hoped for. 

The direction of travel is nonetheless clear: Regulators want consent decisions that persist, travel across services, and get enforced, rather than choices extracted one banner at a time.

Enterprises operating in Germany should watch the BfDI register, assess whether their consent tooling could technically recognize and honor signals from a recognized service, and treat the exercise as a stress test of their wider consent architecture.

Wherever the German experiment lands, the underlying expectation is already the standard regulators apply: A consent decision made once should be respected wherever it is relevant.