Around 3% of people want tracking. EU governments dropped the plan to end cookie banners.
A civil-society coalition wants EU browsers to send a machine-readable privacy signal instead of showing consent pop-ups. The Council deleted the provision on June 18.
noyb, the EFF and BEUC want browsers to answer cookie banners automatically. Their Kill the Cookie Banner campaign cleared 1,000 points on Hacker News, which is a lot of pent-up feeling for a page about EU legislative procedure. The mechanism they’re asking for already sits in the European Commission’s draft law. EU member states cut it out in June.
The provision was Article 88b of the Digital Omnibus, the Commission’s November 2025 package of amendments to GDPR, the ePrivacy Directive and a stack of other digital laws. It would have required sites to accept a machine-readable yes or no sent by the browser, and required browser makers above SME size to send one. In its June 18 negotiating position, the Council of the EU deleted the article outright. Germany, France and Poland pushed for that, according to noyb, after a Google-commissioned study put the cost to European advertisers at 40 to 50 billion euros a year.
Why the banners exist at all
Cookie banners are not a GDPR invention. The rule that produces them is Article 5(3) of the ePrivacy Directive, on the books since 2002 and rewritten in 2009 to require consent before a service stores or reads anything on a user’s device. GDPR arrived later and set the bar for what valid consent means: freely given, specific, informed, unambiguous. Put those together and every site dropping a tracking cookie needs a per-site yes, collected before the cookie lands.
That default is the coalition’s whole argument. “Online tracking is prohibited by default,” the campaign writes, and the banner exists to move people off the default. Max Schrems said it more bluntly in noyb’s June post: “Cookie banners are not an invention of data protection, but of the tracking industry.”
The gap between what people click and what they want is where the campaign leads. Up to 90% say yes, it claims, while only around 3% actually want to be tracked. noyb’s own post gives a range of 3 to 10%. Either figure leaves a delta big enough to explain why dark-pattern complaints have been noyb’s staple for five years, and why the same design question keeps recurring in EU tech law. Age verification hit it too: does the site do the checking, or does the device?
One more piece of context matters here. The Commission withdrew the ePrivacy Regulation in February 2025 after eight years of Council deadlock, so the Digital Omnibus became the replacement vehicle. Its Article 88a moves cookie consent out of ePrivacy and into GDPR, which hands enforcement to data protection authorities rather than telecoms regulators.
What a browser signal actually does
Concretely: two lines. The Global Privacy Control spec defines an HTTP request header, Sec-GPC: 1, plus a matching DOM property, navigator.globalPrivacyControl. A browser with the setting on sends the header with every request. A site reads it and takes it as a refusal, with no modal and no click to record.
If that sounds like Do Not Track, it should, because DNT tried the same trick and lost. The W3C’s Tracking Protection Working Group shut down in January 2019 and republished the spec as a Working Group Note, which is the standards-body equivalent of a shrug. Honoring DNT was voluntary. Advertisers didn’t, browsers eventually pulled the toggle, and Safari dropped it in 2019 on the grounds that a rarely-set header is itself a fingerprinting signal. Firefox removed its checkbox in February 2025.
GPC differs in the one way that changed the outcome: it has a legal hook. California’s attorney general states that the CCPA requires businesses to treat a user-enabled global privacy control as a legally valid request to opt out. That’s not theory. In August 2022 the AG’s office announced a $1.2 million settlement with Sephora, the first public CCPA enforcement action, partly because the retailer failed to process opt-out requests sent via GPC. Colorado made recognizing universal opt-out signals mandatory from July 1, 2024, and Connecticut counts the signal as a valid consumer request as well.
Adoption is real but lopsided. GPC ships in Brave, Firefox and DuckDuckGo, plus extensions including EFF’s Privacy Badger, and the project claims over 150 million users. It became an official work item of the W3C Privacy Working Group in November 2024. Chrome isn’t on the supported list.
Who deleted it, and why
Google paid for the study that did the damage. Implement Consulting Group’s “Gone in one click,” published in March 2026 with a disclaimer naming Google as commissioner, projected that browser-level consent would cut consent rates by 60 to 65% and cost European businesses between 40 and 50 billion euros in annual advertiser revenue, roughly a third of ad spend. noyb calls those numbers “completely far-fetched” and points out that the study ignores two things: the Commission’s text allowed per-site and per-purpose choices rather than one global switch, and media services were carved out of Article 88b entirely.
Schrems’s reaction to the deletion: “You really have to let that sink in: the European Commission finally wants to get rid of cookie banners, but Google and some EU Member States are now determined to keep them.”
IAB Europe, the trade body for the European ad industry, asked for the article to be dropped in its February 2026 position paper. Its stated reasons deserve a fair hearing even if the conclusion doesn’t land: people answer more conservatively when asked one global question than when a specific publisher asks them, and a browser-level switch concentrates control in the handful of companies that ship browsers. That second objection is the strongest one on the table, and it isn’t only an industry talking point. Chrome holds roughly two thirds of the browser market and belongs to an advertising company. The same Commission that fined Google 890 million euros in July under the Digital Markets Act would be writing Google’s browser into the consent flow for the entire European web. Meanwhile the ad industry is opening new inventory inside chatbots, where no cookie banner has ever appeared.
Hacker News went straight to the DNT precedent, predictably. “There is one. It’s a DNT header. Knucklehead websites ignore it,” wrote one commenter in the thread. The Sephora settlement is the answer to that: a signal with a regulator behind it behaves differently from a signal with a working group behind it.
What this means for you
For a site operator the technical work is small and already specified. Reading Sec-GPC off the request, or checking navigator.globalPrivacyControl on the client, takes a few lines. The awkward part is wiring that answer into whatever your CMP does today, so a signalled refusal suppresses the banner instead of sitting next to it. Three steps get you most of the way:
- Read
Sec-GPCon inbound requests and treat a value of1as a refusal for sale-or-share purposes. - Suppress the consent modal when the signal is present rather than rendering it anyway.
- Stop re-prompting after a no, which Article 88a(4)(c) would make mandatory for six months.
Don’t expect banners to vanish even if Parliament restores the provision. Osborne Clarke’s read is that “the long-awaited end of cookie banners as such is not yet in sight,” because the information duties and the requirement that withdrawal be as easy as consent both survive the rewrite. Article 88a would apply six months after entry into force, Article 88b within 24 months. Nothing changes for a European site this year.
California is the part worth acting on now. GPC is already binding there, in Colorado and in Connecticut, and the state privacy agency ran a joint enforcement sweep with all three attorneys general in September 2025. If your site sells or shares data and takes US traffic, honoring the header is compliance work with a deadline that’s already passed, not a bet on Brussels. The Brussels bet stays open: Parliament hasn’t taken a position, trilogue runs later in 2026, and it’s the only body left that can put Article 88b back. That’s exactly who the campaign is aimed at. “Contact your relevant representative in the European Parliament or national government and express your frustration!” is the whole ask.
Share this article
Quick reference
- Digital Omnibus
- The European Commission's November 2025 package of amendments to GDPR, the AI Act and other digital laws, pitched as cutting compliance paperwork for businesses.
- ePrivacy Directive
- The 2002 EU directive, rewritten in 2009, that requires consent before a service stores or reads anything on your device. It's the reason cookie banners exist.
Sources
- Kill the Cookie Banner! — Kill the Cookie Banner coalition
- EU Member States (and Google) suddenly want to keep cookie banners! — noyb
- EU Council drops cookie signal after Google lobbying, EUR 40-50 bn at stake — PPC Land
- Digital Omnibus reshapes EU cookie rules but leaves banner fatigue largely intact — Osborne Clarke
- Global Privacy Control specification — W3C
- Attorney General Bonta Announces Settlement with Sephora as Part of Ongoing Enforcement of the CCPA — California Department of Justice
- IAB Europe's Position on the Draft Digital Omnibus on the Digital Acquis — IAB Europe
- Simpler digital rules to help EU businesses grow — European Commission
- Tracking Protection Working Group (closed) — W3C
Frequently Asked
- Do cookie banners come from GDPR?
- No. The consent requirement is Article 5(3) of the ePrivacy Directive, in force since 2002 and rewritten in 2009. GDPR came later and defines what valid consent has to look like.
- What was Article 88b of the Digital Omnibus?
- A proposed GDPR article requiring sites to accept a machine-readable yes or no from the browser, and requiring browser makers above SME size to send one. The Council deleted it from its negotiating position on June 18, 2026.
- Is Global Privacy Control legally binding anywhere?
- Yes. California treats it as a valid opt-out under the CCPA, and Colorado and Connecticut recognize universal opt-out signals too. California fined Sephora $1.2 million in 2022 partly for ignoring GPC.
- Would a browser signal make cookie banners disappear?
- Not entirely. Osborne Clarke notes that information duties and the rule that withdrawing consent must be as easy as giving it would both survive, so some interface remains.
- Can the deleted provision still come back?
- The European Parliament has not taken a position yet and could restore it. The final text gets settled in trilogue between Parliament, Council and Commission, expected later in 2026.