LW IT Solutions
« Blog Overview /Data Privacy / App Tracking Transparency After the German Antitrust...
This post in other languages:

App Tracking Transparency After the German Antitrust Decision: One Prompt Instead of Two

Contents
  1. What the decision contains
  2. The objection was to the gradient, not the gate
  3. Two prompts in a row multiply
  4. What still has to be kept apart
  5. Four months, and what fits into them

The Bundeskartellamt closed its Apple proceeding on 17 August 2026, four years and two months after opening it. Most of the coverage treated it as a story about Apple. The part worth reading twice is the third commitment, and it is really a story about arithmetic.

Until now an app in Germany that wanted both an advertising identifier and a lawful basis for its own processing had to ask two separate times. That is no longer required. The two requests may share one surface.

Two panels compared: on the left three shrinking bars for 100, 40 and 30 percent across two consecutive prompts, on the right two bars where the second is hatched and open-ended because the merged rate is not yet known
The left column is a product of two rates. The right column is a single rate that has to be measured rather than derived.

What the decision contains

The proceeding ran under Section 19a of the German Competition Act, the provision that lets the authority apply tighter rules to companies of paramount significance for competition across markets. Apple was designated as such in April 2023. A preliminary assessment followed in February 2025, a market test in December 2025, and the binding commitments this August.

Three things were promised. Apple will bring the consent prompts shown for its own services and those shown for third-party apps much closer together. It will remove symbols and wording that may discourage. And app publishers get more room to combine the request Apple demands with the request data protection law demands. The commitments hold for seven years, an independent trustee monitors them, and the implementation deadline is four months from service of the decision.

The objection was to the gradient, not the gate

This distinction gets lost easily. The authority did not find fault with the idea of asking before an identifier is shared. It found fault with asking third parties in a harsher way than Apple asked on its own behalf: different wording, different visual weight, different framing for what is, functionally, the same permission. Under Section 19a that is self-preferencing, regardless of how good the privacy argument behind it is.

Which is why the remedy is symmetry rather than removal. The prompt stays. It simply has to look the same whoever is asking.

Two prompts in a row multiply

The commercial weight of the third commitment comes from a property of sequential funnels that is obvious once written down and easy to forget in a dashboard. A second prompt never applies to the whole population. It applies to whatever the first prompt left behind.

before
  app start
    -> ATT prompt                Apple wording, Apple buttons
       allow / ask app not to track
    -> consent prompt            own wording, own purposes
       accept / reject
    = two decision points, two places to lose people

after, permitted but not required
  app start
    -> one surface carrying both requests
       ATT permission ........ the Apple API still reports the status
       processing purposes ... still recorded as consent under the GDPR
    = one decision point, two recorded permissions

Put numbers on it. Forty per cent allow tracking, and of those, three quarters accept the processing purposes. The population that ends up with both permissions is thirty per cent, not forty and not seventy-five. Halving the number of prompts does not automatically raise that figure, but it does remove one of the two places where it can fall.

What still has to be kept apart

Sharing a surface is not the same as sharing a permission. ATT governs access to the advertising identifier on the device. Consent under the GDPR governs the purposes for which personal data is processed. The scopes differ, the legal consequences of a refusal differ, and the records that have to be kept differ.

A merged dialogue therefore still has to produce two separately storable outcomes, and the refusal of one must not silently be read as the refusal of the other. Anyone building this should expect the consent record to become the harder half of the job: one interaction now writes two states, and a log that collapses them into a single boolean will not survive an audit.

Four months, and what fits into them

The deadline runs against Apple, not against app publishers, and nothing forces a merge. There is time to prepare the measurement rather than the dialogue. Two things are worth having in place before the new prompt appears.

The first is a baseline. Whatever the current two-step rates are, they will stop being comparable the moment the flow changes, and there is no way to reconstruct them afterwards. The second is an event for each permission separately, because the interesting question after the change is not how many people accepted but whether the two permissions still diverge the way they used to. If they stop diverging, the merged prompt has quietly turned two decisions into one – which is convenient, and not what the commitment says.

Lukas Wojcik

Lukas Wojcik

Systems architect and technology enthusiast specializing in scalable tracking solutions, GMP Stack (GA4 & GTM), and robust backend architectures. Advocate for clean code and privacy-first design.

Get in Touch

Briefly describe your project or inquiry for a tailored response. This site is protected by reCAPTCHA.

ALL ARTICLES & CATEGORIES

CCTV

Follow this category by RSS

Data Privacy

Follow this category by RSS

Digital Analytics

Follow this category by RSS

Digital Marketing

Follow this category by RSS

IT & Networks

Follow this category by RSS

Raspberry PI

Follow this category by RSS

Smart Home

Follow this category by RSS

Web Development

Follow this category by RSS

Wordpress Hacks

Follow this category by RSS