Cookie Banners 2026: What the New Liability Means for Website Operators — Plainly Explained
Legal & Compliance

Cookie Banners 2026: What the New Liability Means for Website Operators — Plainly Explained

The Frankfurt Higher Regional Court has expanded liability for cookie violations: third-party cookie tool providers are now directly liable. What this means for website operators, why the rules have shifted, and how to realistically assess your risk — explained in plain English.

10 min read Lindwurm Digital

Cookie Banners 2026: What the New Liability for Website Operators Means — Plainly Explained

If you run a website, you know the drill: a cookie banner pops up, you click “Accept” or “Settings,” and life goes on. For most people, it’s annoying but trivial. For you as an operator, it is a legal minefield — and the landscape has just shifted. In late 2025, the Frankfurt Higher Regional Court (OLG Frankfurt) issued a decision that changes the existing rules: it is no longer only you, the website operator, who may be liable for improperly deployed cookies. The provider of the cookie tool can now also be held directly accountable. What sounds like legal jargon has concrete consequences for anyone responsible for a website. In this post, we explain plainly what happened, what has actually changed, and what it means for you — without scaremongering.

Important note: This post does not constitute legal advice. The information is based on publicly available sources and reflects the current state of affairs as of August 2026. For legally binding advice about your specific situation, please consult a specialist lawyer in IT and data protection law.

A quick primer: what are cookies and cookie banners actually about?

Let’s take a step back before diving into the details. You may never have looked closely at what happens behind a cookie banner. Here is the short version.

Cookies are small text files that a website stores in the visitor’s browser. They can do useful things: remember what’s in the shopping cart, or recognise that someone is logged in. But they can also track visitors across multiple websites — for example, to later show them ads for the exact product they just browsed.

For cookie consent in Germany, the key distinction comes from Section 25 TDDDG:

  1. Strictly necessary cookies — you need these for the website to function at all. A shopping-cart cookie, for instance. These generally do not require consent.
  2. Non-essential access to stored information — for example, through analytics and marketing services or embedded third-party content. This generally requires the visitor’s informed, freely given consent — and that is exactly what the cookie banner is for.

So far, so familiar. The banner asks: “May we?” The visitor says yes or no — and the website sets cookies accordingly. In theory. In practice, as a ruling from Frankfurt now shows, it’s more complicated than that.

What the Frankfurt court decided — and why it’s new

In December 2025, the Frankfurt Higher Regional Court issued a ruling (case no. 6 U 81/23) that closes a gap in the liability system. The case: a website was setting cookies through a third-party tool — without valid user consent. Until now, in such a situation, only the website operator could be sued. The tool provider was off the hook, even if their product was technically flawed.

The Frankfurt court said: the third-party provider is also directly liable. This applies even if “they were not actually aware of the missing consent,” according to IFH Köln.

To make it more concrete: imagine you rent a car. The rental company hasn’t serviced the brakes. You drive off, there’s an accident. Up to now, only the driver could be held liable. Now the rental company is directly liable too — because they provided the defective tool.

What this means for you as a website operator

The short answer: more protection — but also more responsibility.

The good news first. The cookie tool provider can no longer pass the buck. If their tool doesn’t document consent properly, loads tracking scripts before consent is given, or makes “Reject” artificially difficult, they are now directly liable. This creates a strong incentive for tool providers to finally make their products watertight. As an operator, you benefit because the tools you use are under greater pressure to work correctly.

Now the nuanced part — because this is not a free pass. The ruling does not relieve you of liability. It adds a second liable party. You, the website operator, remain fully responsible for everything that happens on your site. The tool provider is now additionally liable — but you remain liable yourself. The question is not: “Is the provider liable instead of me?” but: “Is the provider liable alongside me?” The answer: alongside you.

The ECC legal team at IFH Köln therefore recommends that website operators take action: “Check whether your consent tool logs collected consent without gaps — and contractually ensure that an indemnity from liability is agreed upon for data protection violations caused by the provider.” Even if the provider is jointly liable, the formal warning, the disruption, and the dispute may still land on your desk first.

The shift that really matters

Here is the point that often gets lost in legal reporting: the most important change is not legal — it’s practical.

Until now, cookie tool providers could say: “We only provide the technology — how the customer uses it is their problem.” That no longer works. If a provider knows (or should know) that their tool does not operate in a legally compliant way with its default settings, they can be sued — not just by the website operator, but also by competitors or consumer protection associations.

The consequence: cookie tool providers will have to audit their products more strictly, configure them more restrictively, and document them more transparently. That, in turn, affects you as an operator. Your provider may soon change default settings, disable certain features, or require explicit configuration that was previously optional. This is not an annoyance — it’s the logical consequence of both sides now being in the same liability boat.

The three rules that have changed

Let’s summarise what has concretely changed — in plain language.

Rule 1: The liability chain is longer. Previously, the website operator was liable. Now, operators and tool providers are jointly liable. That doesn’t mean less responsibility for you — but more pressure on the provider to do things properly.

Rule 2: Knew or didn’t know — both can be costly. The GDPR provides for fines of up to €20 million or 4% of worldwide annual turnover (Art. 83 GDPR). In practice, most SME cases are not million-euro fines but warning letters from competitors — with legal fees, cease-and-desist declarations, and the effort of rectification. That is the more realistic cost framework, and it now applies to both sides.

Rule 3: Preventive pressure is increasing. Because tool providers are now directly liable, they will enforce compliance more rigorously. For you, that means checking, documenting, and asking questions. Confirming today whether your consent tool works properly reduces the risk of an unexpected formal warning tomorrow.

What you can do concretely — in three steps

Step 1: Check whether your cookie banner does what it’s supposed to. It sounds trivial, but: visit your own website in private browsing mode. Reject all cookies. Reload the page. Are marketing cookies still being set? Is the page loading external scripts from analytics, advertising, or social media services before you’ve consented? If so, you have a problem — regardless of the Frankfurt ruling.

Step 2: Ask your consent tool provider specific questions. Request written confirmation that the tool documents and logs consent in a GDPR-compliant manner. Ask about a contractual indemnity for data protection violations caused by the tool itself. A reputable provider will be able — and willing — to answer these questions, because they now carry the same risk you do.

Step 3: Document your decisions. Write down briefly: which tool are you using? Which cookies are being set for which purpose? What is the legal basis for each? Who checked the configuration, and when? This documentation is gold in the event of a warning letter — it shows that you didn’t blindly assume “everything is fine.”

The three most common misconceptions

“This only affects large websites.” Wrong. The underlying consent requirement does not depend on company size. The Frankfurt court ruled on a specific case, but the logic of the ruling applies to every cookie tool — whether the customer is an SME or a corporation.

“My cookie tool provider now takes over the liability.” That’s not how it works. You remain liable yourself. The difference is that you now have someone you can hold jointly responsible in a worst-case scenario — but for that to work, you need to have laid the contractual groundwork beforehand (see Step 2).

“As long as there is a cookie banner, everything is fine.” This is the most dangerous assumption. What matters is not whether a banner exists, but whether it obtains valid consent, documents it correctly, and ensures that the cookies set reflect the user’s actual choice. A banner that loads tracking scripts before the user consents is worse than none at all: it creates the appearance of compliance while simultaneously producing evidence of the violation.

What it costs not to do this

The question is not: “What does it cost me to review my cookie management?” but: “What does it cost me if I don’t review — and then a warning letter arrives?”

A competition-law warning does not just create legal fees and potential claims for costs. It ties up time, attention, and energy — resources that are already scarce in a small company. On top of that, there is the risk of a second warning if the first violation has not been fully remedied.

The opportunity costs can’t be precisely quantified, but they are rarely zero. Those who do the review today avoid tomorrow’s crisis-response effort. That’s a simple calculation — even without a euro amount.

Conclusion

The Frankfurt court has shifted the rules, not invented the game. Cookies without consent were unlawful before the ruling too. What has changed is the dynamic of enforcement: competitors, consumer associations, and supervisory authorities can now pursue two potentially liable parties instead of one. That increases the pressure on tool providers to operate correctly — and, indirectly, on you as a website operator.

The good news: those who check, document, and ask the right questions of their consent tool provider today are in a strong position. The bad news: those who assume “everything will be fine” are playing a game whose rules have just become stricter.

In an initial consultation with no obligation, we assess your website’s current cookie compliance setup and identify concrete next steps.

Related posts: GDPR Checklist 2026 for Websites | Cookie Banner Alternatives: What Privacy-Compliant Tracking Without Banners Really Looks Like | Digital Obligations 2026: BFSG, NIS2, and E-Invoicing for SMEs

Lindwurm Digital GmbH — Web development and digital solutions.