Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
July 2, 2025
No Result
View All Result
Concur News

Home » German Court Rules Google Tag Manager (GTM) Illegal Without Consent

German Court Rules Google Tag Manager (GTM) Illegal Without Consent

June 30, 2025
in Germany, Global, News
Reading Time: 3 mins read
Google Tag Manager - news.concur.live
Share on LinkedinShare on Whatsapp

The Administrative Court of Hanover has ruled that the use of Google Tag Manager (GTM) without obtaining prior, informed user consent violates the General Data Protection Regulation (GDPR) and the German Telecommunications-Telemedia Data Protection Act (TTDSG).

The case, registered under VG Hannover 10 A 5385/22, involved a website operator who had implemented GTM on its site. The court examined the behavior of GTM during initial page load and determined that the tool:

  • Reached out to Google servers immediately upon the user arriving at the website.
  • Disclosed personal data information, including IP address, device data, browser information, and referrer data.
  • Stored a JavaScript file (‘gtm.js’) in the user’s browser/device.
  • Started to run third party scripts, which could further process more data.

Court addressed that these activities included accessing (and storing) information in the user’s device, as well as processing personal data – all of which required valid user consent under §25(1) TTDSG and Article 6(1)(a) GDPR.

Consent Foundation

The court clarified that GTM operates in a recognizable way. GTM is not a neutral tool, in that integrated in its operation is a kind of data flow and the storage of data in the browser/device, even if the website operator did not trigger an actual tag. As a result, the court found that consent is paramount before the downloading of GTM.

The ruling also discussed the CMP of the website. While there was a banner in place, the Court found that the banner did not stop GTM from loading/transferring data before consent was provided. The CMP was implemented using the IAB TCF (Version 2.0). The Court held that this implementation did not satisfy the requirements for informed and voluntary consent of users under the GDPR and TTDSG.

The Court also addressed the layout of the cookie banner. The Judge held that the design of the banner made it easier to accept tracking than to reject tracking, therefore the cookie banner did not provide users with a true and fair choice and did not meet the standards for valid consent under the law.

The ruling noted that even in the case where GTM did not store cookies through GTM, the loading of third-party scripts and contacting other servers, especially servers not located within the European Economic Area, triggers obligations under GDPR Article 49(1)(a) on international transfers of data.

This ruling is a reinforcement of the requirement that all tools and scripts that access devices, process data, and/or transfer data internationally must only be activated after a user has explicitly consented.

The court relied on the following statutes to support its decision:

  • §25(1) TTDSG (Telecommunications-Telemedia Data Protection Act)
  • Article 6(1)(a) GDPR (Lawfulness of processing – consent
  • Article 4(11) GDPR (Definition of consent)
  • Article 49(1)(a) GDPR (Derogations for data transfers to third countries)
  • Article 5(3) of the ePrivacy Directive (2002/58/EC)

Also Read: Apple, Google, Facebook Among Victims in 16 Billion Password Leak

Tags: AI PrivacyData privacyData ProtectionTech giants

Related Posts

AT&T
Regulation

AT&T’s $177 Million Data Breach Settlement Gets Court Approval

June 23, 2025
Data breach
Global

Apple, Google, Facebook Among Victims in 16 Billion Password Leak

June 23, 2025
Indian Banks Urged to Adopt AI, Privacy Under DPDP Act
India

Indian Banks Urged to Adopt AI, Privacy Under DPDP Act

June 21, 2025
TRAI Pilot
India

TRAI Teams Up with RBI and Banks to Launch Digital Consent Pilot Against Spam

June 17, 2025

RECOMMENDED NEWS

Japan’s New AID Bill Sparks Controversy Over Privacy

AID Bill of Japan Sparks Controversy Over Privacy

3 months ago
Are Gurugram's Gate Apps Compromising Your Privacy?

Are Gurugram’s Gate Apps Compromising Your Privacy?

2 months ago
Zerodha CEO Nithin Kamath Warns Users About Apps Misusing Personal Data Without Consent

Zerodha CEO Nithin Kamath Warns Users About Apps Misusing Personal Data Without Consent

2 months ago
Shopify Data Privacy

Shopify Faces Revived Data Privacy Lawsuit in U.S. Appeals Court

2 months ago

BROWSE BY TOPICS

AI AI Governance AI Privacy Apps Children privacy Compliance Consent Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy Data Protection Data security Data Violation Digital DPDP DPDPA DPDP Act EU FBI Fines GDPR google Hack Hacked Industry Interview Investigation Investment Law Meity penalty Personal data Press Release Privacy RBI RTI Act Startek Tech giants Technology Training Trending

701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager