You open a news site, and before the main headline even loads, a popup interrupts: “We value your privacy. Please choose whether to accept cookies.” You skim it quickly and click the largest, brightest button—Accept All. You shouldn’t feel guilty. According to statistics from European privacy non-profit noyb, roughly 90% of web users click “Accept” in the cookie banner era, despite only about 3% actually wanting to be tracked online. That 87-percentage-point gap isn’t genuine user agreement—it’s engineered consent.
In July 2026, over a dozen European civil society organizations—including noyb, EDRi, the Electronic Frontier Foundation (EFF), and European consumer organization BEUC—launched a campaign titled #KillTheCookieBanner. Within weeks, discussions flared across developer hubs from Hacker News to Lobsters, generating dozens of points and heated comment threads that proved even livelier than the annoying banners themselves.
Image: Campaign visual “Stop the tracking circus” — comparing the ad tech tracking industry to a circus. Source: killthecookiebanner.eu
Banners Were Not Invented by GDPR
Most web users assume cookie banners were spawned by GDPR. The real history traces back further.
In 2002, the European Union enacted the ePrivacy Directive (often called the “Cookie Law”), which governed storing data on user devices. A 2009 amendment introduced a key requirement: websites had to obtain user consent before placing cookies on a device (akin to slipping a signed receipt into your pocket). Though codified in 2009, the rule was widely ignored. Regulatory enforcement was nonexistent, and websites turned a blind eye for eight long years.
On May 25, 2018, the General Data Protection Regulation (GDPR) took effect, carrying severe non-compliance fines up to 4% of a company’s global annual turnover. Panicked websites across Europe scrambled overnight to slap cookie banners on every page. This created a persistent myth in tech circles that GDPR directly forced the banner boom. As veteran developer chrismorgan clarified on Lobsters, the initial wave of popups around 2017 actually stemmed from that 2009 ePrivacy rule ignored for nearly a decade—GDPR was simply the loud alarm clock that suddenly reminded everyone the old law existed.
Consider an analogy: a speed limit sign stood unmonitored for eight years until traffic police suddenly showed up with massive fine pads. Drivers slammed on the brakes—and whether speed bumps or toll booths were erected depended on who profited from building them.
Thus began the long battle of attrition between websites and web users.
Image: Official illustration for the section “Cookie banners are designed to trick you out of your rights.” Source: killthecookiebanner.eu
How the 90% “Consent” Rate Was Engineered
The legal intent was straightforward: “prohibit tracking by default; ask before tracking.” But the ad tech industry quickly discovered a lucrative loophole: asking could be engineered with dark patterns.
“Accept All” became a prominent, colorful primary button placed front and center. “Reject” was demoted to tiny gray text buried inside secondary configuration modals—or omitted entirely from initial prompts. Bombarded by dozens of banners every day, web users developed a muscle-memory reflex: blindly clicking the biggest button to make the dialog vanish.
From an engineering perspective, a cookie banner acts as a conversion rate optimization (CRO) funnel, leveraging the exact same UX dark patterns that e-commerce sites use to highlight “Add to Cart” buttons. Meanwhile, regulatory enforcement moved at a glacial pace: chrismorgan noted that enforcement agencies spent roughly five years “politely asking” non-compliant sites to adjust their designs rather than levying decisive penalties.
The gap between 90% clicking accept and 3% actually wanting to be tracked represents the primary business model of the entire cookie banner industry.
The EU’s Proposed Fix: Moving Consent to the Browser
In autumn 2025, the European Commission introduced proposed revisions to cookie rules within its Digital Omnibus reform package. Article 88b offered an elegant solution: shift consent management away from individual websites and into the browser.
Under this model, users specify their privacy preference (“Do Not Track”) once in browser settings. Every website automatically reads this standardized HTTP signal, eliminating the need for recurring consent banners. Technically, this concept is straightforward—browsers already transmit language preferences and time zones automatically without prompting users. California’s CCPA framework established a precedent with Global Privacy Control (GPC), supported natively by Firefox and Brave. The EU proposal also included pragmatic exceptions: users could whitelist favorite websites, and news publishers would receive broad exemptions.
Offense and Defense in the Lobbying Corridors
Then the counter-lobbying commenced.
Google published a report asserting that browser-level signals would severely impact online advertising revenues, framing the mechanism as a blanket opt-out against digital media. Industry trade groups cited figures claiming €40 to €50 billion in ad revenue was at stake—numbers produced by industry insiders that independent analysts could not verify. Regardless of exact figures, the incentive structure was obvious: behavioral advertising—targeting users based on browsing history—is the primary engine of modern digital publishing and ad networks.
The lobbying proved effective. EU member states including Germany, France, and Poland pressed the Council of the European Union to delete the provision. On June 18, 2026, the Council released its official position paper, revealing that Article 88b had been removed.
noyb founder Max Schrems wrote on LinkedIn on June 23:
“You couldn’t make this up: Google, Germany and France are lobbying to KEEP cookie banners, while the EU Commission proposed simple signals to replace them. Lobbying against the vast majority of voters’ wishes — and actually succeeding.”
In response, European civil society organizations launched #KillTheCookieBanner in July 2026. Notably, the campaign did not follow the formal “European Citizens’ Initiative” (ECI) process—which requires gathering one million verified signatures to compel legislative review. Instead, it serves as a direct grassroots call to action, encouraging citizens to email their national representatives and Members of the European Parliament (MEPs). As the submitter of the Lobsters discussion observed: “This isn’t a formal petition; it’s a call for citizens to write to their representatives without a single centralized mechanism.”
Image: Official illustration from the section on tracking industry lobbying to preserve cookie banners. Source: killthecookiebanner.eu
Dissenting Voices: Not All Opposition Comes from Advertisers
The debate surrounding cookie banners is far from monolithic; skeptics outside ad tech also express pragmatic concerns.
| Position | Stakeholder / Representative | Core Argument |
|---|---|---|
| Support Killing Banners | Privacy orgs (noyb, EDRi, EFF), majority of users | Banners are engineered harassment; 90% consent rate is illusory; regulators should enforce strict signal defaults. |
| Advertising Industry | Google, ad tech trade bodies | Behavioral ads fund free web content; mandatory browser signals constitute a de facto ban on targeted advertising. |
| Industry Insider Backlash | rkaw92 (AdTech developer) | The only real solution is banning behavioral ads entirely; consent was never freely given, and asking is inherently coercive. |
| Technical Skeptics | Sharparam | Websites routinely ignore standard browser headers (like language); why expect them to respect privacy signals without heavy enforcement? |
| Unconventional Counter-perspective | casperin | ”I actually prefer banners—they serve as a constant daily reminder of how many companies are malicious actors.” |
The commentary from rkaw92 was particularly sharp. As an active AdTech software engineer expected to defend the industry, his analysis cut deeper than many privacy advocates: consent for behavioral tracking was never freely given. He highlighted Google’s homepage behavior in Europe: opening Google Search displays a massive consent list requiring extensive scrolling just to find a hidden “Reject” option. While slightly more sophisticated than simple checkboxes, the fundamental goal remains making rejection as difficult as possible. He also offered a sobering prediction: if cookie banners are outlawed, websites will pivot to mandatory login walls—requiring users to sign in with a Google or social media account to access content. Single Sign-On (SSO) ecosystems operated by tech giants are themselves far more pervasive tracking mechanisms.
Technical skeptics highlight another practical reality: if websites frequently ignore standard browser headers like language preferences, there is little reason to believe ad networks will voluntarily honor privacy signals unless regulatory agencies institute strict enforcement mechanisms.
If Banners Disappear, Will Tracking Stop?
If browser signal legislation ultimately passes: users configure privacy settings once, banners disappear, websites are legally bound to respect opt-out signals, and one major channel for unauthorized data harvesting closes.
If the proposal is defeated: banner fatigue continues, and coerced “consent” remains the industry norm. However, data collection will not vanish simply because banners disappear—websites can pivot toward broader interpretations of “strictly necessary cookies,” paywalls, login requirements, or email newsletter gates to maintain user tracking. Banners are merely the interface; user tracking remains the underlying objective.
For users seeking immediate relief, two practical tools exist:
- Browser extensions like Consent-O-Matic, which configure privacy preferences once and automatically dismiss banners in the background, or uBlock Origin, which can filter banner DOM elements entirely.
- For EU residents, writing directly to local MEPs using campaign templates provided by civil privacy groups.
The legislative struggle is far from over. The European Parliament has yet to finalize its position, and a final consensus may not emerge until late 2026. While the Council struck Article 88b, Parliament retains the power to reintroduce browser signal mandates during upcoming tripartite negotiations.
The debate over cookie banners reflects a broader struggle across the modern web: banners are perhaps the one digital experience universally disliked by internet users. Yet between collective frustration and effective legal resolution lies a long corridor of corporate lobbying.
Cookie banners are merely a symptom. The real battle is over whether the concept of online “consent” retains any genuine meaning. That answer should become clear before the year ends.
Reference Links:
- Kill the Cookie Banner Civil Initiative (European Civil Society Campaign)
- Lobsters Discussion
- GDPR Local: Cookie Banner Reform Analysis
- EU Digital Omnibus Proposal (Article 88b)
- Cybernews: Anti-Cookie Banner Campaign Coverage