forumNew topic

Using Google Tag Manager — what should we watch out for regarding data privacy and DSGVO in Germany?

CCeren B***Member
Job title
Sales Manager
Sector
Law
Organization type
early-stage startup
Joined
Jan 2025
Message
282
#1

We run a small-scale wholesale e-commerce site based in Cologne. Our marketing and ad budget is around 1,800 EUR a month. Up until now, we’ve been manually hardcoding conversion pixels and analytics scripts directly into our website’s codebase. But this approach slows down the site and makes us rely on a developer for every new campaign.

Our agency suggested setting up Google Tag Manager to speed things up. However, the strict DSGVO rules in Germany and the strict stance of the data protection authorities have me genuinely worried. A lawyer we consulted mentioned that the tag manager itself processes user IP addresses and must be tied directly into the consent mechanism.

We already use a cookie consent management tool on our site. What steps do we need to take to deploy a Google Tag Manager infrastructure in the German market without risking fines? How should we set up consent management and our tag inventory in full compliance with the law?

BBurhanMember
Job title
Retired Engineer
Joined
Aug 2024
Message
132
Most Helpful#2

Short answer: Even though Google Tag Manager doesn't drop cookies on its own, it processes the user's IP address, so under DSGVO it must be fully integrated with your consent management system. No marketing or analytics tags should fire before the user grants explicit consent, and the container should be configured strictly to provide basic technical functionality until then.

In practice, your first step should be building a comprehensive tag inventory detailing every tracking script running on your site. You need to document what data each tag collects, where that data is sent, and the legal basis for it. Then, integrate your consent management platform (CMP) with your tag manager's triggers. That means Google Analytics, Meta Pixel, or remarketing tags only fire once the visitor gives consent.

The second step covers contracts and disclosures. You must enter into an up-to-date Data Processing Agreement (AVV) with Google. Your site's privacy policy (Datenschutzerklärung) must clearly state the purpose of using the tag manager, the server locations of the collected data, and the risks of transferring data to third countries. You also need to keep IP anonymization enabled by default.

CCansu K***Member
Job title
Accounting clerk
Sector
Paper
Organization type
medium-sized business
Joined
Sep 2024
Message
4
#3

On the technical side, don't skip setting up Consent Mode v2. When configuring triggers, listen for custom events pushed by the CMP instead of using "All Pages". Check outgoing requests in your browser's network tab yourself to make sure scripts definitely don't fire when consent isn't granted.

MMelis Ç***Expert
Job title
System support specialist
Sector
Energy
Organization type
two-branch business
Joined
Apr 2025
Message
4
#4

Open a spreadsheet right now and log every active tag: 1) Tag name 2) Provider and server location, 3) Purpose, 4) Required consent category (statistics, marketing, etc.). If you switch to a tag manager without this inventory, nobody will know what code is firing or when three months from now.

JJülide V***Member
Job title
Digital marketing specialist
Sector
Chemistry
Organization type
sole proprietorship
Joined
Jul 2023
Message
320
#5

Some agencies brush it off saying "GTM is just a container, it doesn't set cookies itself so you don't need consent." That mindset is super risky in Germany. When the container script downloads, the visitor's IP address hits a third-party server. That's why it absolutely has to sit right behind your consent mechanism.

YYusuf Y***Member
Job title
Social media manager
Sector
Real estate
Organization type
a company within a holding
Joined
Sep 2024
Message
79
#6

we went through the exact same thing with our hamburg agency last year. like lawyer had us rewrite the datenschutzerklärung from scratch and billed us 600 eur for the consult. but it gave us total peace of mind, we have our audit-ready binder if an inspection letter ever shows up.

HHasan Y***MemberCommunity member
Joined
Aug 2025
Message
3
#7

We tracked our consent rates when we made the switch. Around 68 percent of visitors opted into analytics cookies, while marketing pixels only hit about 42 percent. If you don't configure your consent setup properly, you risk losing all that data completely.

KKeremMember
Job title
Agency sales
Joined
Jul 2024
Message
94
#8

Does your current consent banner support server-side tagging (Server-Side GTM)? If you want to stop data from routing directly to Google's servers, have you thought about proxying it through an EU-hosted server?

HHakan U***Member
Job title
Regional Manager
Sector
Sports and fitness
Organization type
40-person manufacturing company
Joined
Aug 2022
Message
13

Doki · Server maintenance contract · 2025

#9

I’d recommend reviewing the guidance issued by your state's data protection supervisory authority (Landesbeauftragte für Datenschutz). When audits happen, the presence of standard contractual clauses (SCC) for third-country data transfers and the transparency of your cookie disclosure are the very first things they check.

SSelin P***Member
Job title
Customer service representative
Sector
Freight
Organization type
early-stage startup
Joined
Nov 2024
Message
130
#10

I felt relieved reading this answer, so it's not just me. Start with a small trial; don't commit to everything at once.

Everyone rushing into google tag manager data privacy gets stuck at the same point. That's all, sorry if I went on too long.

ZZeynep Ş***VeteranCommunity member
Joined
Aug 2024
Message
26
#11

Following.

ZZerrin C***Member
Job title
Supply chain manager
Sector
Healthcare services
Organization type
workshop
Joined
Jan 2024
Message
10
#12

I felt relieved reading this answer, so it's not just me. When we decide without measuring, we always end up in the same place.

That's all, sorry if I went on too long.

HHakan K***New member
Job title
Content Editor
Sector
Healthcare services
Organization type
120-person company
Joined
Jun 2026
Message
375
#13

Just a heads-up. Don't rely on a single measure; go layer by layer.

If I were you, I'd go this route.

MMetin C***MemberCommunity member
Joined
Feb 2024
Message
170
#14

The opposite happened to me, thats why Im writing. Taking notes for two weeks yields better results than a six-month estimate.

This is my opinion Im not claiming its absolute truth.

MMustafa G***Member
Job title
Co-founder
Sector
Machinery manufacturing
Organization type
boutique agency
Joined
May 2022
Message
155
#15

I'd appreciate it if you shared the outcome.

MMert U***ExpertCommunity member
Joined
Jan 2024
Message
112
#16

I feel the same way. Having backups accessible on the same network and with the same identity makes them part of the target.

An untested backup is not a backup. If you post the result here, it will help others too.

FFerhat O***Member
Job title
Software team lead
Sector
Packaging
Organization type
20-person company
Joined
Sep 2023
Message
52

Doki · Infrastructure migration · 2024

#17

Exactly like that. An untested backup is not a backup.

This is my opinion, I'm not claiming it's absolute truth.

İİlker K***Member
Job title
Technical service technician
Sector
IT services
Organization type
medium-sized business
Joined
Nov 2025
Message
273
#18

We've heard this a lot, but it never happened like that for us. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Proven by experience.

BBora Y***New member
Job title
Intern
Sector
Insurance
Organization type
workshop
Joined
May 2026
Message
1
#19

Let me share my experience. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

An automated scan report is not the same as a penetration test. Hope this helps.

FFiliz B***VeteranCommunity member
Joined
Sep 2024
Message
3
#20

I agree.

Reply