Credit institutions and banks are subject to comprehensive compliance and regulatory requirements. In addition to traditional financial regulations, they must also comply with legal requirements relating to data protection, digital accessibility and the legally compliant operation of their websites.
This makes the findings of a recent analysis by decareto all the more surprising: despite stringent regulatory requirements, numerous websites operated by German credit institutions exhibit significant shortcomings in their implementation of data protection regulations. Many of the websites examined fail to adequately meet key requirements of the General Data Protection Regulation (GDPR) and the Telecommunications and Digital Services Data Protection Act (TDDDG).

25 major banks analysed
For the study, decareto analysed the websites of 25 major credit institutions and banks in Germany with regard to their technical data protection configuration. The focus was on compliance with the consent requirements under Section 25 of the TDDDG – in particular:
- the use of consent banners and consent management platforms
- loading of external services
- setting of cookies
- completeness of privacy policies
The results show that data protection breaches are widespread despite the presence of consent banners and comprehensive privacy policies.
80% of consent banners are incorrectly configured
A consent banner, also known as a cookie banner, is used to obtain and manage consent for data processing operations on websites that require consent, and is intended to ensure that such processing only takes place after the user has given valid consent.
All the banks examined use consent management software. However, the technical implementation of the consent banner often fails to meet legal requirements.
On 20 out of 25 websites (80 per cent), services or cookies requiring consent were already activated on the first page view – even before visitors had given their consent. As a result, the consent banner loses its intended protective function.
76% set non-essential cookies without consent
Cookies are one of several technologies used to store or retrieve information on end devices. According to the TDDDG, only cookies that are strictly necessary for the basic functioning of the website (e.g. a shopping basket) are permitted.
The analysis revealed that 19 of the 25 credit institutions and banks (76 per cent) store non-essential cookies even before users have given their consent.
According to the case law of the European Court of Justice and the Federal Court of Justice, such cookies may, in principle, only be set after valid consent has been given.
Particularly concerning: a large proportion of the websites in question give the impression, via a cookie banner, that they are waiting for the user’s decision, yet are already processing personal data beforehand.
80% load external services before consent is given
Even more frequently than cookies, external third-party services are integrated without consent, as not all services requiring consent also set cookies.
20 out of 25 credit institutions and banks (80 per cent) loaded at least one external service requiring consent as soon as the page was accessed.
These are predominantly services in the following areas:
- Web analytics
- Marketing
- Advertising
- Tag management
These technologies regularly transfer personal data to third-party providers and therefore often require prior consent.
Lack of transparency in privacy policies on 72% of banking websites
In addition to the technical analysis, Decareto also examined the privacy policies of the credit institutions and banks.
The result: 18 out of 25 websites (72%) contained external services that were not mentioned, or not clearly mentioned, in the respective privacy policy.
This constitutes a potential breach of the information obligations under Article 13 of the GDPR, which requires data controllers to transparently identify all recipients of personal data.
Google services dominate the integrated technologies
The investigation reveals a clear concentration on a small number of major technology providers.
Among the most frequently identified services are:
| Rank | Service | Provider | Main purpose |
| 1 | Google Tag Manager | tag management | |
| 2 | Google Ads | advertising | |
| 3 | Google Adsense | advertising | |
| 4 | Meta Pixel | Meta | advertising / conversion tracking |
| 5 | Usercentrics | Usercentrics | consent management |
| 6 | Microsoft Advertising | Microsoft | advertising |
| 7 | Matomo | Matomo | web analytics |
| 8 | Google Analytics | web analytics | |
| 9 | LinkedIn Insight Tag | marketing & analytics | |
| 10 | Dynatrace | Dynatrace | performance monitoring |
Google’s strong dominance is striking. Almost half of the 10 most frequently identified services come directly from Google.
In addition, marketing and tracking technologies from Meta, Microsoft and LinkedIn, as well as analytics tools such as Matomo and Dynatrace, are regularly used.
Data transfers to the US remain a relevant issue
Even following the introduction of the EU-US Data Privacy Framework in July 2023, data transfers to the US remain a sensitive issue under data protection law.
Although the European Commission’s adequacy decision permits data transfers to certified US companies, the use of many tracking, marketing and analytics services still requires prior consent in accordance with Section 25 of the TDDDG and, in many cases, Article 6(1)(a) of the GDPR.
Regardless of the permissibility of international data transfers, the correct technical implementation of consent solutions therefore remains crucial.
Overall assessment of the banks’ websites
The overall assessment of the websites examined is correspondingly critical.
- 5 out of 25 banks (20 per cent) achieved the top grade A.
- B = 7, C = 4, D = 7, E = 2
This means that the majority of the bank websites examined exhibit technical or organisational data protection shortcomings.
Key findings of the analysis
- 76% set unnecessary cookies without consent.
- 80% load external third-party services before consent is given.
- 72% do not fully disclose identified external services in their privacy policy.
- 80% of consent banners do not fully fulfil their protective function
- Google accounts for 4 of the 10 most frequently identified third-party services.
About the analysis
For the analysis, decareto examined the websites of 25 major German credit institutions in July 2026. The decareto platform for website compliance analysis was used for this purpose. The assessment covered the technical implementation of consent mechanisms, the use of external services, the setting of cookies, and the transparency of privacy policies. The assessment was based on the requirements of the GDPR, the TDDDG, and current European and German case law regarding the use of technologies requiring consent.
The following credit institutions and banks were examined
Aareal Bank AG, Deutsche Apotheker- und Ärztebank (apoBank), BayernLB – Bayerische Landesbank, Berliner Volksbank, comdirect, Commerzbank, DekaBank, Deutsche Bank, Deutsche Pfandbriefbank, DKB (Deutsche Kreditbank), DZ BANK, Hamburger Sparkasse (Haspa), Hamburg Commercial Bank (HCOB), Helaba – Landesbank Hessen-Thüringen, HypoVereinsbank (UniCredit Bank GmbH), ING Deutschland, L-Bank (Landeskreditbank Baden-Württemberg), N26, NRW.BANK, Landwirtschaftliche Rentenbank, Santander Consumer Bank, TARGOBANK, UmweltBank, Volkswagen Bank, Vontobel.





