Web analytics under Germany’s TTDSG data protection law

😎 Price promotion
10% discount on all Trackboxx annual subscriptions with the code: tb10action
Table of contents

Important

Germany’s TTDSG took effect on 1 December 2021, introducing several data protection rules. For websites, section 25 TTDSG is particularly relevant. It implements the EU’s ePrivacy Directive, often known as the Cookie Directive.

Section 25 TTDSG concerns access to users’ devices. Cookies are only one way of accessing them; other technologies are covered too. Reading system variables in a browser using JavaScript, for example, could also count as device access.

The TTDSG requires consent for access that is not necessary, whether through a cookie or by reading a system variable. Section 25(2) sets this out more precisely, although in longer and less accessible legal language.

Previously, the Telemedia Act’s consent rules covered cookies used for marketing and user profiling. The TTDSG made it more demanding to count visitors without asking for consent.

Tracking and counting visitors

“Tracking” has no single precise definition. It usually means following users across sessions and websites. Google Analytics is a well-known example of this invasive approach. It requires consent not just for that reason, but because of the cookies it uses. That means presenting visitors with a cookie pop-up. These pop-ups are not only irritating; they often leave websites in breach of the rules, as my Cookiegeddon investigation explains.

For simplicity, this article also uses “tracking” to mean basic visitor counting. To count visitors, you need to tell one user from another. Otherwise, you count too many or too few visits. Counting the same person as two unique visitors because they open two pages in succession skews the statistics. Counting two different people as one when they visit the same page is no more accurate.

So how do you tell users apart? HTTP, the protocol used to retrieve web pages, is stateless: it does not remember earlier requests. On its own, it cannot recognise a returning visitor. It is rather like having no memory and mistaking the same passer-by for a different person every time.

Cookies used to provide that memory. Under the interpretation of the TTDSG discussed here, they require consent even for simple visitor counting. The law refers to what is “strictly necessary”. Cookies for counting visitors fail that test for two reasons. First, an exact visitor count is not strictly necessary—a debatable point, although I think the stricter interpretation is more likely to prevail. Second, you can count visitors without cookies. That second point is what matters here.

How can you tell users apart?

If you want to avoid asking for consent, cookies are not an option.

You can distinguish visitors reliably without cookies by using the metadata a browser sends to the website with every HTTP connection.

Technical specialists often call this connection data or traffic data. Lawyers may use those terms differently, so this article uses the broader term “metadata”.

The metadata sent with a website request includes:

  • Browser type and browser version. Example: Mozilla Firefox Version 95.3, subversion 47.11
  • Operating system type and version. Example: Microsoft Windows 10, 64-bit
  • Preferred language. Example: German
  • Network address (IP address)
  • Cache settings
  • Requested page. Example: https://dr-dsgvo.de/
  • The time of the request. It is not sent directly, but the server knows when the request arrives.

Using this metadata to distinguish users without cookies is known as browser fingerprinting.

Fingerprinting can be made more precise by collecting additional information through JavaScript, for example:

  • Screen resolution. Example: 1920×1080
  • Size of the browser window. Example: 1788×910
  • Color depth. Example: 24-bit
  • Time zone. Example: GMT+1

These fingerprinting details have to be actively requested. The metadata listed earlier arrives with the connection, so no extra request is needed. In my view, screen resolution is not stored on the user’s device, although the TTDSG could be interpreted differently. One argument is that a smartphone’s portrait or landscape orientation does not need to be stored: it can change continually. When you switch the phone back on, the display orientation depends on how you are holding it, not on its orientation before shutdown.

Techniques such as canvas fingerprinting gather further information that makes users easier to distinguish. However, there is little dispute that canvas fingerprinting is a form of device access that requires consent.

The safest legal approach is not to actively read any additional metadata from the user’s device.

The challenge is to retain enough data quality to count visitors accurately.

Counting visitors without consent

Trackboxx shows that a minimal form of tracking can work without cookies or device access—and therefore without consent.

Trackboxx uses only the metadata that already accompanies every page request. It does not make additional requests to access the user’s browser. Under a strict interpretation of the TTDSG, those additional requests would require consent.

Trackboxx does not use cookies, not even session cookies, unless the customer configures it differently. A cookie that lasts for one session is less intrusive than one that remains for a month—its lifespan. Legally, though, the TTDSG does not distinguish between session and persistent cookies. It distinguishes only between necessary and unnecessary cookies or access.

Because Trackboxx does not access the device within the meaning of the TTDSG, it does not require consent under that law.

GDPR and TTDSG

The GDPR also applies. Its requirements must be considered after addressing the TTDSG rules on cookies and other device access. GDPR stands for General Data Protection Regulation. In German, the regulation is abbreviated as DS-GVO, although texts for a general audience often omit the hyphen and write DSGVO.

The GDPR covers personal data, including data that can be linked to a person. Being able to distinguish one user from another can be enough. The Court of Justice of the EU ruled in 2016 that IP addresses can constitute personal data; Germany’s Federal Court of Justice confirmed the ruling in 2017.

You cannot therefore simply store a user’s IP address to improve visitor counting. Storing it unencrypted would, on this interpretation of Article 6 GDPR, likely require consent.

To avoid that requirement, Trackboxx does not store IP addresses themselves. Instead, it pseudonymises each address in combination with other values.

A time-limited key is applied to a combination of the IP address, browser version, operating system version and current calendar day. The Trackboxx database therefore contains no IP address. In theory, an address could only be recovered from the encrypted data if the user returned on the same day. That recovery is unnecessary, however, because the next request supplies the IP address again anyway. This approach meets the GDPR requirements described here, with pseudonymised storage based on legitimate interests—one of the GDPR’s legal bases alongside consent.

Unlike consent, legitimate interests do not require an irritating cookie pop-up. Avoiding consent requests also offers greater legal certainty, because pop-ups are subject to numerous requirements, including those in Articles 7 and 13 GDPR. For example, a consent request must explain where and how consent can be withdrawn. Many cookie pop-ups omit this legally required information.

IP addresses usually change over time, apparently less often on cable connections than on DSL. They do not, however, change precisely when someone opens a website, so the same visitor can very likely be recognised within a day. Users on corporate networks are harder to tell apart if centrally managed updates give employees identical browser and operating system versions. In practice, though, the resulting imprecision has little impact.

Conclusion

You can measure visits and improve content without cookies or intrusive, error-prone cookie pop-ups. Tools such as Trackboxx offer a privacy-friendly solution that meets the TTDSG and GDPR requirements described here.

Data quality need not suffer compared with cookie-based visitor counting. Cookie-based tools have another weakness besides legal uncertainty: anyone can delete browser cookies, manually or with utilities such as CCleaner and antivirus software. Deleting a cookie wipes the tracker’s memory. It then performs no better than Trackboxx, yet still needs consent. Corporate networks offer no advantage to cookie-based trackers either, since larger organisations routinely delete cookies from employees’ computers under their security policies.

Good to know…

You can respect data protection rules, avoid irritating pop-ups and still find out which content visitors read most. The TTDSG and GDPR do not rule out a workable solution.

Try Trackboxx free for 30 days now

No payment information required! No automatic renewal! Your Trackboxx ready to go in 1 minute.

Start for free now

Expert in web development & online marketing with over 15 years of experience.
Developer & CEO of Trackboxx – the Google Analytics alternative.

This might also interest you.

😎 Price promotion

10% off all annual subscriptions of Trackboxx with the code: