Skip to Content
OPINION

Can we solve the cookie banner problem in the EU?

Upcoming trilogue negotiations will determine whether browser-based privacy choices can help solve the EU's cookie banner problem.

Published
Subscribe to IAPP Newsletters

Contributors:

Sebastian Zimmeck

Associate professor of computer science; founder Global Privacy Control

Weslyean University

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains. 

People are tired of cookie banners and dark patterns that nudge them into sharing their personal data. What began as a well-intentioned effort under the ePrivacy Directive and General Data Protection Regulation to give EU citizens control over their digital lives became an annoyance and, even worse, facilitates data exploitation. Instead of meaningful and effective personal data protection, a right declared in the EU's Charter of Fundamental Rights, cookie banners are causing consent fatigue and mislead EU citizens to surrender their personal data to ad networks and data brokers.

In November 2025, the European Commission published its Digital Omnibus, a bid to simplify digital laws and increase the competitiveness of the EU. Part of the Digital Omnibus is a new GDPR Article 88b, which allows people to express their privacy choices automatically through technical means, such as a browser setting, rather than manually interacting with banners. This idea is not new. There is a success story on the other side of the Atlantic. California, Colorado, Connecticut and several other U.S. states have adopted a privacy choice setting, the Global Privacy Control, that is now implemented on at least 385,000 websites and supported by various privacy-friendly browsers and browser extensions.

Regrettably, in June 2026, the Council of the EU removed Article 88b from its position paper after intense lobbying from media and advertising industry groups. Lobbyists claimed businesses would not be able to effectively obtain consent and would lose a third of their ad revenue should the provision be adopted. However, the economic impact is exaggerated. Publishers' revenues only increase by about 4% for targeted ads compared to contextual or generic ads. Indeed, none of the U.S. states that adopted GPC so far is experiencing a disruption of the online ad ecosystem. A phased and careful rollout is key. Further, a recent economic analysis showed that adopting browser-level consent mechanisms would boost consumer welfare in the U.S. by USD4.60 per user-week relative to the status quo. Users would be spending less time making their privacy choices and the impact of dark patterns would be reduced as well.

The fate of Article 88b depends on the upcoming trilogue between the European Parliament, Council and Commission. Privacy-friendly browser makers and a coalition of civil society organizations have already called on the EU to keep the provision. They are right. It is now time to address the cookie banner problem and give people a real privacy choice.

EU legislators and regulators have the authority to make the GPC binding in the EU. They can map the setting to a specific set of rights under EU law. They should do so. The GPC already has broad adoption on the web. It is enforceable in several U.S. states and will be required as a mandatory browser setting per California law starting next year. Thus, every browser will have a GPC setting. But what will it mean in the EU? 

Defining the GPC's meaning is a task that the responsible EU authorities should take on with verve. A good interpretation would be the refusal or withdrawal of consent and objection to cross-context ad targeting, which aligns with the requirements of Article 88b. At a minimum, for these purposes, websites should no longer be allowed to show cookie banners.

A critic might object that Article 88b requires automated means for both declining as well as giving consent, the latter of which GPC is not capable to express. Those critics would be right. As it was initially developed for the opt-out regime applied by U.S. state privacy laws, the GPC specification does not provide for an opt-in option, i.e., giving consent. However, Article 88b does not require that giving and declining consent must be accomplished by the same mechanism. As it stands, the GPC can help people to refuse and withdraw consent. Further, the GPC specification is not set in stone. Should EU authorities require that in order for the GPC to apply in the EU it would also need to enable people to give consent, the editors of the GPC specification at the W3C would certainly take note and work toward alignment of law and specification. As the law evolves so will the GPC specification.

The Digital Omnibus represents a historic opportunity for the EU to establish a new pragmatism while maintaining the high level of data protection and privacy it awards to its citizens. By integrating the GPC standard, the EU can take a first step away from a system of manual, exhausting, and often misleading consent interfaces to an era of automated and effective data choice that will put us on a path to solve the cookie banner problem in the EU.

Sebastian Zimmeck published an analysis of the application of GPC under current EU law together with Harshvardhan Pandit, Frederik Zuiderveen Borgesius, Cristiana Teixeira Santos, Konrad Kollnig and Robin Berjon.
CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Sebastian Zimmeck

Associate professor of computer science; founder Global Privacy Control

Weslyean University

Tags:

Law and regulationAdvertising and marketing

Related Stories