forumNew topic

Server-side tracking and DSGVO — how can we set this up in Germany without getting fined?

VVolkan Ö***Expert
Job title
Intern
Sector
E-commerce
Organization type
early-stage startup
Joined
Oct 2022
Message
51
#1

We run a multilingual e-commerce platform operating in the German market. Between browsers blocking third-party cookies and users running ad blockers, our marketing conversion tracking has taken a massive hit over the past year. Our marketing agency is suggesting we switch to a Server-Side Tracking setup.

According to the agency, because data is filtered through our own server instead of being sent directly from the visitor's browser to third-party ad platforms, we won't need a cookie consent banner anymore, and user IP addresses can be masked. We're looking at an estimated 450 EUR monthly server cost for this infrastructure.

But considering Germany's strict DSGVO and TDDDG (formerly TTDSG) regulations, this sounds a bit too good to be true. Can server-side tracking really be run in Germany legally without obtaining consent? What do we need to comply with regarding provider contracts and technical anonymization?

MMustafa M***Member
Job title
Quality control inspector
Sector
Food wholesale
Organization type
regional distributor
Joined
Feb 2024
Message
106
Most Helpful#2

Short answer: Your agency's claim that "server-side tracking eliminates the need for a consent banner" is completely false legally and could trigger severe penalties in Germany. Under TDDDG Section 25, storing information on or reading information from an end user's device (cookies, local storage, or device fingerprinting) for marketing purposes strictly requires explicit consent, regardless of where that data is forwarded afterward.

Server-side tracking breaks down into two parts: client side and server side. If a script running in the user's browser reads a device identifier, screen resolution, or cookie value and sends it to your server, the consent requirement still applies fully. Only technical session data strictly necessary for the core functionality of the site is exempt from consent; conversion tracking or retargeting does not qualify for this exemption.

If you want to run this fully compliant with German law: 1) Explicitly define server-side tracking in your consent banner, and do not trigger requests to your server if the user opts out. 2) Strip the user IP address entirely on your own server (IP masking/hashing) and drop unique identifiers before forwarding anything to external ad platforms. 3) Make sure you sign a DSGVO Article 28 compliant AVV with your cloud hosting provider. Ensure data isn't transferred outside the EU, or is properly safeguarded via standard contractual clauses.

RRecep K***MemberCommunity member
Joined
Mar 2023
Message
41
#3

Don't buy into this agency fairy tale of "we moved it to the server side ditch the cookies, no consent needed." German regulatory authorities (especially in Bavaria and Baden-Württemberg) know this playbook inside out. The moment you read a single byte off an end user's device for marketing, you fall under TDDDG. There's no loophole.

DDamla Ö***MemberCommunity member
Joined
Jan 2022
Message
70
#4

Here's the key technical detail to watch out for: If your server container passes the incoming request's IP address, User-Agent, and referrer header to the ad platform in their raw state, that is legally considered a direct transfer of personal data. You need to strip the last octet of the IP address and generalize timestamps on your own proxy server first.

ZZerrin M***MemberCommunity member
Joined
Feb 2024
Message
1
#5

You have to separate two different laws here: TDDDG Section 25 governs access to data stored on the device (cookies or fingerprinting) and mandates consent. DSGVO Article 6 governs the processing of the resulting personal data (like IP addresses). Even if server-side tracking gives you tighter control under DSGVO, it doesn't get you past the TDDDG hurdle on its own.

edit: I wrote something wrong above, sorry about that.

NNuri Y***ExpertCommunity member
Joined
Oct 2023
Message
246
#6

We set up a similar architecture on an independent server hosted in Frankfurt. We pay about 80 EUR a month for hosting. We only forward data via the server for users who opted in through the consent banner. Our tracking data loss from ad blockers dropped from 28% down to around 9%, but we don't route a single line of data without prior consent.

EErcan B***MemberCommunity member
Joined
Sep 2023
Message
140
#7

A consultant pitched us the exact same idea last year, so we disabled the consent banner. Two months later, we got a formal warning (Abmahnung) from a competitor's lawyer; we were hit with a 1.800 EUR legal fee and a cease-and-desist penalty. We reverted right back to the old consent system. In Germany, it's definitely not worth the risk.

CCem I***MemberCommunity member
Joined
Sep 2025
Message
4
#8

Will the server-side container be hosted in a data center within the EU? Do you also plan to match offline customer IDs (like hashed emails) when sending data to ad networks?

UUğur Y***MemberCommunity member
Joined
Jun 2023
Message
38
#9

id say dont listen to marketers all they care about is the conversion chart. if a fine comes its the legal entity taking the hit. hook the consent mechanism up to the server; if theres no consent the server shouldnt fire requests to third parties either.

SSinan E***Member
Job title
Store Manager
Sector
IT services
Organization type
20-person company
Joined
Nov 2024
Message
362

Doki · KVKK compliance consulting · 2023

#10

If your company employs or contracts an external Data Protection Officer (Datenschutzbeauftragter), it is a legal requirement to have this architectural change reviewed under a Data Protection Impact Assessment (DSFA). Your privacy policy (Datenschutzerklärung) must also be updated to reflect this new data flow.

ÜÜlkü B***New memberCommunity member
Joined
Sep 2026
Message
240
#11

Exactly, and not many people know this. Everything goes well for the first three months; problems arise in the fourth.

Of course, it varies if your situation is different.

AAhmet Ö***Member
Job title
Data entry clerk
Sector
Consulting
Organization type
40-person manufacturing company
Joined
May 2023
Message
228
#12

I'd appreciate it if you shared the outcome. Trying to do this alone is the most expensive way.

KKoray S***MemberCommunity member
Joined
Jul 2025
Message
286
#13

If I understood correctly, you're saying: Start with a small trial; don't commit to everything at once.

Forgotten test environments are more often the entry point than live systems.

EEmre G***MemberCommunity member
Joined
Dec 2022
Message
198
#14

You're right. The harder it is to reverse a decision, the slower you should make it.

Just because everyone does it doesn't mean it's right. If I were you, I'd go this route.

VVolkan U***Member
Job title
Production Manager
Sector
Cleaning services
Organization type
chain store
Joined
Dec 2025
Message
107

Doki · Interface design · 2023

#15

i disagree with you on this point. if permission and scope aren't in wrtiing don't start that test.

that's all, sorry if I went on too long.

YYağmur Y***Member
Job title
Administrative manager
Sector
Furniture manufacturing
Organization type
medium-sized business
Joined
Dec 2024
Message
2

Doki · Log management setup · 2025

#16

I agree with this. Don't rely on a single measure; go layer by layer.

Hope this helps.

RRamazan K***MemberCommunity member
Joined
Jan 2025
Message
33
#17

I was thinking the same thing. Most time waste accumulates in tasks waiting for approval.

If you have questions, write them; I'll answer as best I can.

RRabia G***VeteranCommunity member
Joined
Sep 2025
Message
75
#18

I agree with this. Hasty decisions become decisions you have to fix six months later.

Proven by experience.

JJülide A***Member
Job title
QA Tester
Sector
Electrical-electronics
Organization type
cooperative
Joined
Feb 2024
Message
1
#19

I agree, and I'd like to emphasize that. Hasty decisions become decisions you have to fix six months later.

Trying to do this alone is the most expensive way.

HHasan Ö***MemberCommunity member
Joined
Dec 2024
Message
39
#20

i didn't know that... payment information changes are never verified through the channel they came from.

correct me if I'm wrong.

Reply