Latest posts Visit blog
In plain words: what is this page about?

This article is about running a shop without a cookie banner. Many visitors click it away, and then you lose their data. You can count visits in a way that needs no consent. We explain how this works. Read on, or ask us.

Cookie banners annoy your customers and cost you data: Anyone who rejects the banner or clicks it away without making a choice never shows up in your web analytics. The result is a blind spot that covers the majority of visits whenever the banner offers an equally prominent reject button. Yet there is a way to operate your online shop completely without a consent banner – legally compliant, in line with Section 25 TDDDG, and with near-complete visit tracking. In this guide, we show you step by step how to eliminate the need for consent.

Cookie banners are more than just an annoyance for visitors – they have measurable impacts on your business. As soon as the banner offers consent and rejection with equal prominence, the ratio tips: in 60% of visits (etracker), consent-dependent cookies and data processing are rejected. How high that share turns out in your own shop depends on sector, audience and banner design – and can only be measured in your own data.

The consequence: If you use Google Analytics or other consent-dependent tools, you are missing the data from every visit in which consent was refused. On top of that comes consent bias – your remaining data is not just incomplete but systematically skewed. Marketing decisions based on this data amount to flying blind. Proper conversion optimization becomes impossible when most of your data foundation is missing.

MetricWith Cookie BannerWithout Cookie Banner
Consent Refused60% of visits (etracker)No consent required
Entering the ShopExtra click before the first contentNo Distraction
Data QualityConsent BiasComplete Sample
User ExperienceInterruption on EntrySeamless Page Load

The legal foundation is Section 25 TDDDG (formerly TTDSG), which transposes Article 5(3) of the ePrivacy Directive into German law. The principle: Any access to information on the user's device – such as setting cookies or using local storage – requires prior consent. But there is a crucial exception.

Section 25(2) TDDDG – The Exception

No consent is required if the storage of or access to information is “strictly necessary in order for the provider of a digital service to deliver a service explicitly requested by the user.” German supervisory authorities (DSK) even recommend NOT displaying a consent banner for technically necessary cookies, as this would be misleading.

This means: If your online shop exclusively uses technically necessary cookies and does not employ any tracking cookies or third-party services that access the user's device, the consent requirement does not apply. The North Rhine-Westphalia supervisory authority explicitly confirms that “strictly functional cookies such as shopping cart cookies or fraud prevention systems” are exempt from the consent requirement.

Technically Necessary Cookies: What's Allowed

German data protection authorities interpret “technically necessary” strictly – Hamburg's supervisory authority emphasizes it refers to technical, not economic necessity. Nevertheless, there is a clear list of cookies that may be set without consent:

  • Session cookies for shopping cart and checkout process
  • Authentication cookies for login areas and customer accounts
  • Language preference cookies for multilingual shops
  • Payment cookies for payment processing (e.g., PayPal, Stripe)
  • CSRF token cookies for form security
  • Load balancing cookies for server distribution
What still requires consent

Google Analytics (including GA4), Facebook Pixel, advertising cookies, A/B testing tools, heatmap services, and social media plugins typically require consent. Even cookieless tracking via Google Analytics remains consent-dependent as it still accesses the user's device (Section 25 (1) TDDDG). The difference to Server-Side Tracking is important: That approach handles consent differently – here, the goal is to eliminate the consent requirement entirely.

Step 1: Cookieless Analytics with Matomo or Plausible

The most important step toward a banner-free shop is switching to a privacy-friendly analytics solution. Two options have established themselves: Matomo (self-hosted) and Plausible (EU cloud or self-hosted). Both can be configured to operate without cookies, and under certain conditions, may not require consent.

Configuring Matomo Cookieless

In cookieless mode, Matomo uses a so-called config_id – a time-limited, pseudonymized hash derived from browser settings and an anonymized IP address. This hash resets daily, preventing long-term tracking of individual users. At XICTRON, we use Matomo cookieless ourselves – based on our experience, we capture nearly all page views without a consent banner.

matomo-cookieless.js
var _paq = window._paq = window._paq || [];
// Disable cookies entirely
_paq.push(['disableCookies']);
// IP anonymization (at least 2 bytes)
_paq.push(['setCustomVariable', ...]);
_paq.push(['trackPageView']);
_paq.push(['enableLinkTracking']);

In addition to disabling cookies, you need to ensure the following for consent-free operation:

  1. IP anonymization – Anonymize at least 2 bytes (under Privacy > Anonymize Data)
  2. Disable User ID – No cross-session identification
  3. Exclude e-commerce order IDs – Order numbers can be linked to personal data
  4. Self-hosting on EU servers – No data transfers to third countries (e.g., via XICTRON Hosting)
  5. Provide opt-out option – Link it in your privacy policy

Plausible as an Alternative

Plausible Analytics is built from the ground up without cookies. Unique visitor identification uses a daily-reset cryptographic hash. Plausible stores no personal data and does not access the user's device – a key advantage over cookie-based tracking. Servers are located in Falkenstein, Germany (Hetzner), ensuring all data remains within EU jurisdiction.

Important Note on German Legal Interpretation

German supervisory authorities interpret the TDDDG strictly: Typically, consent is required for any form of analytics. However, using cookieless tools like Matomo or Plausible provides a significantly stronger legal position. France's CNIL has explicitly classified Matomo as consent-exempt. For a reliable legal assessment, we recommend individual consultation with a data protection lawyer.

Step 2: Self-Hosted Fonts Instead of Google Fonts

A frequently overlooked consent trigger: Google Fonts. When your shop loads fonts directly from Google servers, your visitor's IP address is transmitted to Google – which violates the GDPR according to a ruling by the Munich Regional Court (Case 3 O 17493/20). The court awarded the plaintiff €100 in damages. The court also set a penalty payment of up to €250,000 for each case of non-compliance with the injunction.

The solution is simple: Host fonts locally. At XICTRON, we use the variable font technique with Inter – a single WOFF2 file served from our own server. No access to Google servers, no data transfer, no consent required. Your Shopware or WordPress shop can be configured the same way.

font-embedding.html
<!-- WRONG: Load Google Fonts externally -->
<link href="https://fonts.googleapis.com/css2?family=Inter" rel="stylesheet">

<!-- RIGHT: Host font locally -->
<link rel="preload" href="/fonts/Inter.var.woff2" as="font" type="font/woff2" crossorigin>
<style>
  @font-face {
    font-family: 'Inter';
    src: url('/fonts/Inter.var.woff2') format('woff2');
    font-display: swap;
  }
</style>

Beyond the privacy benefit, self-hosted fonts typically improve your load times as well, since the additional DNS lookup and connection to Google servers is eliminated – a plus for your Core Web Vitals and SEO.

Step 3: Eliminate Third-Party Services

Every external service loaded in your visitor's browser is a potential consent trigger. A systematic review of all embedded third-party services is therefore essential. Typical problem areas in e-commerce shops:

Problematic ServiceConsent-Free Alternative
Google Analytics / GA4Matomo cookieless (self-hosted)
Google Fonts (CDN)Host fonts locally (WOFF2)
Google Maps EmbedStatic map image + link
YouTube EmbedThumbnail + click-to-play
Facebook PixelRemove or use server-side
External Chat WidgetsSelf-hosted solution or contact form
Social Media ButtonsSimple links (no tracking)

Check your shop's network requests in the browser (DevTools > Network tab). Every request to an external domain is a potential privacy issue. The goal is for your shop to only make requests to your own domain and possibly your self-hosted analytics. Our hosting team can assist you with this analysis.

Step 4: Update Your Privacy Policy

Even without a cookie banner, you must inform visitors transparently. Your privacy policy should clearly state which technically necessary cookies your shop sets and why, which analytics tool you use (including its cookieless configuration), where data is stored (EU hosting), and how visitors can opt out of tracking.

The DSK guidelines (Version 1.2, November 2024) clarify: When you exclusively use technically necessary cookies, you should not display a consent banner – because the user has no real choice in this case, and a banner would be misleading. Instead, information is provided through the privacy policy.

Use this checklist to make your online shop consent-free step by step:

  • Analytics switched to Matomo cookieless or Plausible
  • IP anonymization enabled in web analytics (at least 2 bytes)
  • Fonts hosted locally (no Google Fonts CDN embedding)
  • Google Maps replaced with static image + link
  • YouTube embeds replaced with thumbnail + click-to-play
  • Social media buttons replaced with simple links
  • Chat widget removed or replaced with self-hosted solution
  • Facebook Pixel and advertising trackers removed
  • Privacy policy updated (opt-out, listing of technical cookies)
  • Network analysis completed: No unexpected third-party requests
  • IT security verified: HTTPS, security headers configured

This is what your shop without a cookie banner could look like:

FoodDemo

Farm Shop with Subscription Box

This design example shows how a privacy-friendly online shop with cookieless analytics, local fonts and exclusively technically necessary cookies can look. No consent banner required, complete visitor tracking, clean privacy policy. This is exactly how we set up your shop too.
Shopware 6GDPRCookielessMatomo
Discuss Your Project

Performance Comparison: Banner vs. No Banner

The impact of a consent-free setup on your business metrics is typically substantial. A complete data foundation enables informed decisions in marketing and shop optimization.

Full Data Capture

Instead of only the visits that carry consent, you track nearly all visits – without consent bias.

Better Load Times

No banner JavaScript, no Google Fonts requests – typically fewer requests and faster LCP.

Reduced Fine Risk

48% (Privado AI) of the most-visited websites have Consent Mode misconfigured, sending data to Google even when users opt out. Without a banner, this risk disappears.

Limitations: When You Still Need a Banner

The consent-free approach has clear limitations. It is important to be transparent about these, as violations of the TDDDG carry fines of up to €300,000, and under the GDPR up to €20 million or 4% of annual revenue:

  • Google Ads / Meta Ads tracking – If you need conversion tracking for advertising campaigns, consent-dependent tools are unavoidable. In this case, Server-Side Tracking is the better solution.
  • Personalization – Cross-session profiles and personalized product recommendations typically require consent.
  • Affiliate tracking – Affiliate cookies are not technically necessary and require consent.
  • Third-party payment providers – Some payment providers set their own tracking cookies beyond what is technically necessary.
  • Cloud-based chat tools – Live chat widgets like Intercom or Zendesk set their own cookies.

In these cases, we recommend a hybrid approach: cookieless analytics for baseline tracking of all visitors, combined with a lean consent banner for marketing tools only. This minimizes data loss while maintaining compliance. Contact us for individual advice.

How We Set Up Your Consent-Free Shop

As an e-commerce agency with years of experience in privacy compliance, we implement the consent-free approach for your shop:

  1. Audit – We analyze all cookies and third-party requests in your shop
  2. Concept – Individual plan to eliminate all consent-dependent services
  3. Analytics setup – Matomo cookieless on EU infrastructure (or Plausible)
  4. Font migration – Self-hosting of all fonts, removal of external font services
  5. Third-party cleanup – Replacement or removal of all consent-dependent services
  6. Privacy policy – Update and implementation of opt-out functionality
  7. Testing – Final verification: No unexpected cookies or third-party requests
Sources and Studies

This article is based on data from: etracker (cookie consent benchmarks), Munich Regional Court (judgment of 20 January 2022, case 3 O 17493/20, Google Fonts), Privado AI (The State of Google Consent Mode, 2026), DSK Guidelines Version 1.2 (November 2024), Matomo (Cookieless Tracking FAQ), Plausible Analytics (Data Policy and Legal Assessment) and the German DPAs of Hamburg, NRW and Lower Saxony on the interpretation of Section 25 TDDDG. The fine ranges are set out in Section 28 TDDDG and Article 83(5) GDPR. The figures mentioned may vary depending on the time and industry.

Frequently Asked Questions

Yes, provided you exclusively use technically necessary cookies and do not embed any third-party services that access the user's device. The DSK even recommends not displaying a consent banner in this case. For a compliant implementation, we additionally recommend consultation with a data protection lawyer.

Compared to a fully configured Matomo with cookies, you typically lose returning visitor data across day boundaries, since the hash resets daily. Page views, traffic sources, device types, and conversions are reliably tracked in our experience – and for nearly all visits rather than only those in which tracking was consented to.

The legal situation is not entirely clear-cut. France's CNIL classifies Matomo cookieless as consent-exempt. German supervisory authorities tend to interpret Section 25 TDDDG more strictly. In practice, many data protection lawyers consider the risk to be low with proper cookieless configuration including IP anonymization and self-hosting. We recommend discussing this individually with a data protection advisor.

Costs depend on the scope: Font migration and analytics switch can typically be done within a few days. Cleaning up third-party services depends on how many services are embedded. We are happy to provide you with an individual quote.

Typically not without consent. Google Ads tracking sets cookies and accesses the user's device. For shops with advertising budgets, we recommend a hybrid approach: cookieless analytics for the baseline, Server-Side Tracking for conversion tracking – with a minimalist consent banner only for marketing tools.

Yes, Section 25 TDDDG refers not only to cookies but to any access to information on the user's device – which typically includes local storage, session storage, and IndexedDB. What matters is not the technology but whether the storage is technically necessary. A shopping cart entry in session storage is generally consent-free in our experience, whereas a marketing identifier in local storage usually is not. So when checking your shop in DevTools, review not just cookies but also the storage area.