The 90% Consent Illusion: Who's Blocking Your Right to Ditch Cookie Banners

The 90% Consent Illusion: Who's Blocking Your Right to Ditch Cookie Banners

PrivacyGDPREUCookieTech Policy

Sources:HN + web research · HN

In the autumn of 2025, the European Commission quietly slipped a proposal into the “Digital Omnibus” reform package: allowing users to configure their privacy preferences once in their web browser, eliminating the need to face annoying cookie banners every time they visit a new website. This sensible proposal, however, triggered an invisible war over the following months.

On June 18, 2026, the Council of the European Union published a position paper—in which the automated browser signal clause was deleted. Where did the pressure to remove it come from? Google published a report claiming that browser-level consent signals would have a “significant negative impact on online advertising revenues.” Meanwhile, member states such as Germany and France also sided with the opposition.

The situation seems absurd: why was a reform designed to free ordinary users from constant cookie banner harassment rejected? Let us take a closer look at the full story behind this event.

Kill The Cookie Banner Campaign Visual Figure: Kill The Cookie Banner campaign homepage. Source: killthecookiebanner.eu

You might assume that cookie banners are mandated by EU law. The exact opposite is true.

EU law (the ePrivacy Directive and the GDPR) takes the stance that online tracking is prohibited by default. Websites must obtain explicit user consent before storing tracking cookies or using device fingerprinting technologies. In other words, the law originally stood on the user’s side—your privacy is protected by default.

However, the tracking industry faced a fundamental dilemma: if they strictly followed the “prohibited by default” rule, the vast majority of users would never voluntarily opt into tracking. Thus, they invented a tool: the cookie consent banner.

Its real purpose is to persuade you to surrender your rights.

This gave birth to the Cookie Banner Provider (Consent Management Platform, or CMP) industry. Companies like OneTrust, Cookiebot, and Usercentrics specialize in selling pop-up banners to websites. Their business model relies on getting users to click “Accept”—websites pay them, and they craft banner designs to ensure as many people as possible click “Accept.”

90% vs 3%: What the Numbers Reveal

The Kill The Cookie Banner campaign highlights a striking pair of statistics: under the current cookie banner system, as high as 90% of people click “Accept”, but only about 3% of users actually want to be tracked.

In other words, that 87% “consent” is a manufactured, illusory consent.

Cookie Banner Statistics Comparison Figure: Comparison between cookie banner acceptance rates and actual user intent. Source: killthecookiebanner.eu

Why does this happen? If you closely inspect almost any cookie banner, you will find its design packed with “Dark Patterns”:

  • The “Accept All” button is typically large, vividly colored, and placed in the most prominent position.
  • “Reject All” is hidden behind fine print, grey buttons, or submenus requiring scrolling and extra clicks.
  • Some banners offer no “Reject All” option at all—forcing you to manually toggle off dozens of third-party partner switches one by one.
  • Even if you select reject, some websites trigger an identical pop-up asking you to choose all over again.

An HN user named whstl shared a firsthand experience during the discussion that illustrates the reality vividly: a cookie banner vendor told a client in a meeting, “In Europe, you can remove the ‘Reject All’ button—the probability of getting sued is low anyway. But we recommend keeping it in California, as enforcement risks are lower there.” Immediately after saying this, they added: “Don’t tell anyone we said this.”

And this happened while the camera was still running. That is the most candid reflection of the industry.

Clicking “Reject” Doesn’t Work Either: Banners Are a Front

The deeper problem is that even when you take the trouble to click “Reject”, tracking in many cases has already occurred.

HN user xp84 offered a blunt explanation: “Think about it. All those third-party tracking scripts are already loaded onto the page before you even see the banner. How could something you do inside a sandbox—usually a banner UI provided by a third party—magically force all other code on the page to behave? Unless the website spent immense effort bringing all third-party code into the banner’s control system, but how could marketing departments, which live by copy-pasting third-party scripts everywhere, have that kind of technical capability?”

This observation lays bare the biggest lie of cookie banners: it gives you the illusion of having a choice, but in reality, your choice was bypassed before the banner even appeared.

Not to mention, even when you click “Reject”, some websites do not save your decision—they store a short-lived cookie recording your “Reject” preference so the banner pops up again a few days later.

The Real Solution: Let the Browser Speak for You

The solution proposed by the European Commission in autumn 2025 was elegant and straightforward in logic.

Currently, your browser automatically transmits various parameters every time you visit a website: your preferred language, screen resolution, and time zone. This happens automatically without requiring manual setup on every site.

Why shouldn’t privacy preferences work the same way? You set “I do not want to be tracked” once in your browser settings, and the browser automatically sends this signal with every web request—problem solved.

This is the core idea of Article 88b. It stipulates that websites must respect automated privacy signals sent by browsers—known as “browser-level consent signals.”

Browser Automated Signal Diagram Figure: Workflow of browser-level privacy signals. Source: killthecookiebanner.eu

This proposal is far milder than many imagine. The text explicitly specifies that users can still grant individual consent for specific websites. Media organizations are also fully exempt—they are not bound by this clause. The core objective of this reform is simply to lower the barrier for “Reject” to match that of “Accept”—currently, the gap in effort between the two is huge.

A similar mechanism already exists under California’s CCPA law, known as “Global Privacy Control” (GPC). Browsers like Firefox and Brave already support it, but because it lacks legal enforcement power in Europe, many websites simply ignore it.

Who Is Blocking This Reform?

Why was such a logically sound proposal rejected?

The answer is simple: money.

Tracking-based advertising is a massive industry. Google plays a central role in it—its entire advertising model relies on tracking user behavior across websites. If browsers send a default “reject tracking” signal, the vast majority of users will likely never alter that setting, causing the audience for targeted ads to plummet off a cliff.

Google issued a report claiming that browser-level consent signals would have a “significant negative impact on online advertising revenues.” They framed the reform as equivalent to a “blanket rejection of ad tracking.”

However, the European Commission and privacy advocacy groups refuted this: first, the proposal retains the user’s right to grant per-site consent; second, news media outlets are exempt. Third-party tracking would not simply “collapse” as Google claimed.

Then the story took an interesting turn. Germany and France—countries that traditionally present themselves as strict defenders of privacy and frequently champion stronger data protection at the EU level—joined the opposition against Article 88b. Their stated justification was “simplifying regulation and cutting red tape.”

On June 18, 2026, in the position paper released by the Council of the EU, Article 88b was officially removed.

Max Schrems, founder of the privacy organization noyb, posted a comment on LinkedIn dripping with irony: “You couldn’t make this up: Google, Germany, and France are now lobbying to keep cookie banners, while the European Commission had actually proposed a solution to replace them with simple signals. Lobbying against the will of the vast majority of voters—and actually succeeding.”

A System That Has Been Gamed

Perhaps most ironically, the cookie banner industry itself was born out of malicious compliance with the GDPR.

noyb (None Of Your Business) has repeatedly pointed out that the tracking industry invented cookie banners as a vehicle to get users to surrender their privacy rights under the guise of “informed consent.” The problem is—when a banner appears for 0.5 seconds and users are bombarded with dozens of them every day, the concept of “informed consent” becomes a complete joke.

HN user chrismorgan raised a compelling legal comparison: why not simply declare that “clicking a checkbox or button does not constitute informed consent”?

He cited an example from Victoria, Australia, where residential tenancy agreements must use a standardized government template rather than custom landlord agreements. If cookie notices were standardized in a similar way—rather than letting every website build its own trap-filled pop-up—only then could genuine “informed consent” exist.

Yet as he noted himself: “It is impossible to convince someone when their livelihood depends on not understanding something.”

The Battle Is Not Over

As of July 2026, although Article 88b was removed by the Council of the European Union, it is not dead yet. The European Parliament has not reached a final decision. The Kill The Cookie Banner campaign is calling on citizens to take action and contact their Members of the European Parliament (MEPs).

If Article 88b is ultimately adopted, it will provide website operators with a 24-month transition period to adapt. More importantly, it represents a shift in principle: privacy should not be a right that consumers must fight for anew on every single site—it should be a default setting configured once at the browser level.

Those pop-ups asking “Accept or Reject” every day are essentially exploiting your fatigue and impatience.

What needs to be “killed” is the entire commercial apparatus built on “pretending to ask for consent.” In the European Commission’s proposal, we caught a glimpse of a simpler alternative: returning privacy control to you, embedded in the browser, operating automatically just like your language preferences. Google and the tracking industry are fighting with all their might to block it.

The outcome of this fight will define the future of online privacy for everyone—whether we continue to endure endless pop-ups designed as traps, or finally set our preference once and enjoy quiet forever.

Right now, on the screen where you are reading this article, there is likely a small banner waiting for you in the corner. Take a close look at where it hid the “Reject” button.

Reference links:

  • Kill The Cookie Banner Official Website
  • HN Discussion (item?id=49057175)
  • EU Digital Omnibus Reform Proposal
  • GDPR Local: Cookie Banner Reform Analysis
  • Secure Privacy: Article 88a Changes Detailed