The Digital Omnibus: Europe Tries to Eat the Cookie Banner

Published Category: Data Privacy 33 min read 6,579 words by James Nicholson

It is seven in the morning in Hobart and you would like to know how long to steep a Darjeeling. Not a big ask. You type the question into your phone, tap the first result, and a box slides up from the bottom of the screen and covers the recipe. "We value your privacy." There is a large green button that says "Accept all", and a small grey link that says "Manage options".

You are a principled person, so you tap the grey link. It opens a list of purposes, each with a toggle. Some toggles are already on, and say "legitimate interest", a phrase that has never once made a toggle sound more legitimate. Below the purposes is a list of "partners". It scrolls. It keeps scrolling. You pass a company whose name sounds like a Scandinavian furniture range, then another that sounds like a cough medicine. By the time you reach the bottom, the kettle has boiled, cooled and been reboiled, and you have read more names than were on the guest list at your cousin's wedding. The tea question is still unanswered, somewhere behind the box.

So you do what nearly everybody does. You go back to the top and tap the green button.

Tomorrow the same site asks you again.

You are not alone. Brussels finds the box annoying too. In the documents it published on 19 November 2025, the European Commission calls a fix for "consent fatigue and proliferation of cookies banners" "long-overdue", and says the banners are "perceived as a nuisance to internet users". Its own staff working document estimates that people in the EU spend about 334 million hours a year on cookie banners, and cites industry studies in which 54% of users accept everything and 26% reject everything, often just to get to the content. Neither number describes an informed choice.

The Commission's answer is part of a large package called the Digital Omnibus. It proposes to take the cookie rule out of the ePrivacy Directive, where it has lived since 2002, and put it into the GDPR as a new Article 88a. It adds a short list of purposes that would need no consent at all, including some audience measurement. It requires a single-click "no". It bans asking again for six months after a refusal. And, in a new Article 88b, it tries for the third time in twenty years to let your browser answer the question for you.

The most important sentence in this article: as of November 2025, this is a proposal. It is not law. The press release says the proposals "will now be submitted to the European Parliament and the Council for adoption", and both of those can, and usually do, rewrite things. Nothing on your site needs to change because of this text this month.

What you can do now is read the text, because it tells you which tags the Commission thinks are low risk. So we will start with the rule you click through every day, go down to what Article 88a actually says (not always what the Commission's summaries say), take the audience measurement exemption apart clause by clause, look at why browser signals have failed twice, and then sit with a (made-up) shop owner in Ghent while she sorts her tags into two piles.

Let's get into it.

Part 1: The Rule You Click Through Every Day

You already know the rule, even if you have never read it. Every banner you have dismissed exists because of one paragraph of a 2002 directive, last revised in 2009. People call it the "cookie law". It is Article 5(3) of the ePrivacy Directive, and here is what it says:

Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information…

"Terminal equipment" is legal language for your phone, your laptop, or anything else at the end of the line. The rule is about the device, not about the data. It does not ask whether the information is personal or sensitive. It asks whether somebody put something on your device, or took something off it.

Then come two exceptions, and only two. Consent is not needed for storage or access "for the sole purpose of carrying out the transmission of a communication over an electronic communications network", or where it is "strictly necessary" for a service the user "explicitly requested". The shopping cart cookie that remembers your basket is the textbook case of the second. Everything else needs a yes.

Not only cookies

The name "cookie law" misleads. The rule covers any way of storing or reading information on the device. The European Data Protection Board (EDPB), the committee of all the EU data protection authorities, spelled this out in its Guidelines 2/2023. A cookie counts because the site "instructs the terminal equipment to proactively send information on each subsequent Hypertext Transfer Protocol ('HTTP') call". JavaScript that makes the browser "send asynchronous requests with the targeted information" also "clearly falls within the scope". So does a tracking pixel: adding an identifier to an image URL is, in the EDPB's words, a "gaining of access".

That covers most of a tag manager container. If a script runs in the browser and sends something back, assume the rule applies.

Two laws for one click

Here is the part that makes cookie compliance so expensive. Article 5(3) governs the moment of storing or reading. What you do with the data afterwards (analyse it, build a profile, send it to an ad platform) is "subsequent processing", and that is governed by the GDPR. The EDPB's cookie banner taskforce confirmed the split in 2023: national ePrivacy law for the placement, the GDPR for the processing.

The two laws do not work the same way. The ePrivacy Directive is a directive, so each member state writes its own version, and in some countries a different authority enforces it. The same taskforce noted that the GDPR's one-stop-shop, which lets one lead authority handle a company's cross-border cases, "does not apply to issues that fall under the ePrivacy Directive". The Commission's proposal puts it plainly: the "dual regime" has "led to different national authorities being competent to supervise the rules of the two legal frameworks".

So one click on one banner can touch 27 national cookie laws, the GDPR, and two kinds of regulator. The tools that manage this, which I covered in Consent Management: The What and Why, exist because the rule lives in two places.

Part 2: Why the Banner Got So Bad

The working document is frank about the old rule. In a 2022 evaluation, only 3 of 30 national authorities said Article 5(3) worked "well". Among businesses, 62% called it a problem. The document describes the consent requirement as "overly rigid, covering even non-intrusive practices such as creating statistics about the use of websites".

The mechanism is simple. Article 5(3) has one main door (consent) and two very narrow side doors. There is no door marked "low risk". So a site that wants a visitor counter needs a yes, the same yes that an ad network needs to follow you across the web. Once you have built a banner to ask for one, it costs nothing to ask for everything in the same box. The working document records stakeholders saying exactly this: because consent is always required, it "creates an incentive to collect consent also for intrusive processing purposes".

A rule meant for the rare dangerous tag ended up justifying a banner for every tag.

The fix that never arrived

Europe has known this for a long time. In 2017 the Commission proposed an ePrivacy Regulation, which would have replaced the directive with one law for the whole EU. It never passed. In February 2025, the Commission said it would withdraw it, with the note "No foreseeable agreement".1

Meanwhile, regulators tidied up the banners themselves. The EDPB taskforce agreed that pre-ticked boxes do not give valid consent. It found that "a vast majority of authorities" treat a banner with an accept button but no reject option on any layer as an infringement. It said legitimate interest cannot be the legal basis for placing cookies at all. That is useful guidance, and it pushed banners towards an honest "no". But guidance cannot add a new side door to a law. Only a change to the law can.

Part 3: What Article 88a Actually Says

A Bosch-style town wall where a gatekeeper makes travellers sign a huge book at the main gate, while four small side doors are guarded by a heron with a lantern, an owl with a key, a fox with an abacus and a hedgehog with a shield, and a router blinks above the gate.
Fig. 1 — Four side doors, one main gate, generated by OpenAI GPT Image.

The Digital Omnibus touches the GDPR, the Data Act, the AI Act, NIS2 and more. The cookie part is small: one new sentence in the ePrivacy Directive, and two new articles in the GDPR. I quote the text directly, because the Commission's summaries simplify it in ways that change the meaning.

The move

First, the proposal adds one sentence after Article 5(3) of the ePrivacy Directive:

This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.

That sentence is the eviction notice. Where a person's device is involved and personal data is in play, the old rule steps aside. The new rule takes over, in a new Article 88a of the GDPR. Its first paragraph will look familiar:

Storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person is only allowed when that person has given his or her consent, in accordance with this Regulation.

So the main gate stays. The Commission's FAQ stresses that "Access to terminal equipment" stays "based on users' consent". What changes is the side doors.

There is a catch in that first sentence, and it matters later. The old rule covered "information". The new one covers "personal data". Recital 47 says the old Article 5(3) "should remain applicable" where the information "does not constitute or lead to the processing of personal data". So the two-law system does not disappear. It moves. Personal data goes to the GDPR; everything else stays with 27 national cookie laws.2

The four side doors

Article 88a(3) is the new list. Storing or reading personal data on the device "without consent, and subsequent processing, shall be lawful to the extent it is necessary for any of the following":

(a) carrying out the transmission of an electronic communication over an electronic communications network; (b) providing a service explicitly requested by the data subject; (c) creating aggregated information about the usage of an online service to measure the audience of such a service, where it is carried out by the controller of that online service solely for its own use; (d) maintaining or restoring the security of a service provided by the controller and requested by the data subject or the terminal equipment used for the provision of such service.

Points (a) and (b) are the two old exceptions, lightly reworded. The old (b) said "strictly necessary"; the new list says "to the extent it is necessary". Whether regulators read that as a looser test is an open question, and I would not bet the banner on it yet.

Points (c) and (d) are new. Security gets its own door, so a bot-protection cookie on a login form no longer has to argue that it is "strictly necessary". Audience measurement gets a door too, under three conditions that Part 4 takes apart.

Two details are easy to miss. First, the words "and subsequent processing": for these four purposes, one test covers both the cookie and what you do with the data afterwards. Second, recital 44 calls this a "limitative list". It is closed. If your purpose is not on it, you need consent, and any processing for other purposes needs its own basis under Article 6 of the GDPR.

The Commission's working document estimates that for "an estimated 60% of used cookies", consent "will not be required any longer". That number rests on a 2020 industry estimate that about 30% of cookies are used for advertising tracking, which the Commission rounded up to 40% to be safe. The same document also admits the proposal "will not lead to the complete disappearance of cookie banners". Both sentences are in the same section, a page apart. I believe the second one.

Three new rules for the banner that remains

Where consent is still needed, Article 88a(4) sets three rules:

(a) the data subject shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means; (b) if the data subject gives consent, the controller shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the data subject; (c) if the data subject declines a request for consent, the controller shall not make a new request for consent for the same purpose for a period of at least six months.

The Commission's summaries do not match these exactly.

The FAQ says "Websites must respect citizens choices for at least six months." The article is more precise. The six-month bar applies after a refusal. After a yes, the bar lasts as long as the consent is valid, which may be shorter or longer than six months. And the six months is a minimum ("at least"), not a timer: nothing in (c) says you must ask again on day 183.3

The working document says users must be able to "give or refuse" consent with a single click. The article requires a single click only to refuse, "or equivalent means". A one-click "Accept all" is what nearly every banner has already. The new rule is about the other button.

Recital 45 gives the reason for (c): people who refuse "may consent just in order to avoid repeating requests". That is the reboiled kettle, in legal English.

Bigger fines

Moving the rule also moves the penalties. GDPR Article 83(5) allows fines of up to €20 million or 4% of worldwide annual turnover. The FAQ spells out the point: "Any infringement to users' rights can now lead to a fine of up to 4% of the global turnover of the company." Whatever else the proposal does, it does not make cookie mistakes cheaper.

Part 4: The Audience Measurement Exemption, Clause by Clause

A Flemish market square at dusk where one baker tallies customers on a slate at his door, while a second baker writes customers' names in a book and hands it through a back window to a stranger who copies it into a larger book, and a cup of tea steams on a windowsill.
Fig. 2 — Counting is not the same as keeping, generated by OpenAI GPT Image.

This is the door most readers of this blog care about. Here it is again:

(c) creating aggregated information about the usage of an online service to measure the audience of such a service, where it is carried out by the controller of that online service solely for its own use;

Imagine two bakers on the same street. The first stands at his door with a slate and makes a chalk mark for every customer. At the end of the day he knows he had 212 customers, and that Tuesday is slower than Saturday. The second baker writes each customer's name and face in a book, then passes the book out of the back window to a man in a velvet hat, who copies it into a bigger book with entries from every bakery in town.

Both bakers "measure their audience". The Commission's FAQ describes the exemption as covering "counting website visits". Article 88a(3)(c) is clearly written for the first baker. The question for your analytics tool is how far it is from the first baker, and how close to the second. The text gives three tests.

Test 1: "aggregated information about the usage"

The output must be aggregated: counts, trends and totals about how the service is used. Your page-views-by-day chart qualifies. A replay of one visitor's session, or a report of what one named customer clicked, does not.

The hard part is that almost every analytics tool collects data per visitor and aggregates it later. To count "unique users", a tool must recognise the same browser on a second visit, and that means an identifier. The article describes the purpose ("creating aggregated information"). It does not say how long an identifier may live, or whether the raw data may be kept. Until regulators say, the closer your tool stays to counts, the stronger your case.

Test 2: "carried out by the controller of that online service"

The controller is the organisation that decides why and how personal data is processed. On your website, that is you. So the exemption is for you measuring your own site. It is not for a third party measuring your visitors for its own reasons.

You do not have to write your own analytics software. Recital 44 says a controller "may mandate a processor, such as a market research company, to carry out the processing on its behalf". A processor is a supplier that handles data only on your instructions. So a hosted tool can, in principle, qualify, provided the supplier is acting as your processor for this data and not as a controller in its own right.4

Test 3: "solely for its own use"

The word "solely" carries the most weight. The statistics must be for your use and nobody else's. Data that also feeds an advertising system, a vendor's benchmark, or a cross-site profile fails this test, even if you only ever look at the aggregate charts yourself.

A Flemish-style winter village feast where robed officials at the head of a long table carve an enormous banner-shaped biscuit into slices while villagers lean in with plates, and a glowing laptop sits among the bread and cheese.
Fig. 3 — The first slice is a proposal, generated by OpenAI GPT Image.

What "own use" has meant so far

These tests are not new. France has had an audience measurement exemption for years, and the CNIL (the French regulator) has published its conditions. Its developer guide lists them: the purpose is limited to audience measurement and A/B testing; no cross-checking with other data; the tracker is limited "to a single site or application editor"; the last byte of the IP address is removed; and the tracker lives no longer than 13 months. Its French-language guidance, as captured on 18 November 2025, adds that exempt trackers must work "pour le compte exclusif de l'éditeur" (exclusively on the publisher's behalf), must not pass data to third parties, and must not use the same identifier across several sites.

The CNIL's conclusion, in plain words: "Most large audience measurement offerings do not fall within the scope of the exemption, regardless of their configuration."

That was said under French law, not about the proposal. But (c) uses the same three ideas (aggregate, own site, own use), so as of November 2025 the CNIL's list is the best guide to how a regulator may read it. Notice one difference: the CNIL includes A/B testing. Article 88a(3)(c) does not mention it.5

The UK went another way. Its Data (Use and Access) Act 2025, passed in June, adds an exception for collecting information "for statistical purposes" to improve a website, where the information is not shared except to help with those improvements. The UK version has a condition the EU text lacks: the user must be given "a simple means of objecting". The EU proposal has no opt-out for exempt measurement at all. If your statistics fit (c), the visitor is not asked.

Now, Google Analytics

I have written about Google Analytics and the GDPR before, in Is Google Analytics GDPR Compliant? and The Impact of GDPR on Google Analytics. Those posts were about sending data to the United States. This is a different test. I will not tell you GA4 passes or fails, because neither the final text nor a regulator's reading of it exists yet. I can show you where each clause bites.

Aggregated? GA4's reports are aggregates. But Google's cookie documentation says the _ga cookie lasts 2 years and is "Used to distinguish users". That is a per-browser identifier that lives nearly twice as long as the CNIL's 13-month limit.6 You can shorten it in the tag settings. Whether a regulator will accept a long-lived identifier behind aggregate charts is the first open question.

Controller, and own use? Here the settings matter more than the tool. GA4 has a group of data sharing settings. If the "Google products & services" setting is on, Google says it is, "for GDPR purposes, an independent controller of such data". An independent controller using your visitors' data for its own purposes is the second baker's man in the velvet hat. With that setting on, "solely for its own use" is very hard to argue. The "modeling contributions & business insights" setting shares data that is "aggregated with data from other websites and apps", which is someone else's use too.

Google's page also says that with all sharing settings off, "your Analytics data is only used to provide and maintain the Analytics service". That is a much better starting position, but the next question is what the property is connected to.

Connected to ads? Google's cookie page says that when GA4 is linked to a Google Ads account, the tags "set additional cookies" to give Google Ads "a more reliable way to measure interactions". That is advertising measurement. It is not audience measurement for your own use, and it is not on the list. A GA4 property with Ads linking, audience sharing or remarketing turned on is doing at least one thing that needs consent.

So the answer for GA4 has two layers. As many sites run it (Ads linked, sharing on), it fails (c) on "own use". A stripped-down property (no links, no sharing, short cookie lifetime) is a candidate that a regulator might accept, or might not. Plan for both. If you run consent mode, note that the proposal changes nothing about Google's own consent policy for its ad products. That is a contract with Google, not a law.

The critics

Not everyone thinks this door is narrow. On the day the proposal came out, noyb, the privacy group led by Max Schrems, called the package "the biggest attack on European's digital rights in years". On the device rules, noyb said "the general direction of changes is understandable", but that the wording is "extremely permissive". Its one concrete example was the security door, which it said "would also allow excessive 'searches' on user devices for (tiny) security purposes".

I think both sides have a point. The audience measurement door looks narrow to me. The security door is short, and its only limits are "necessary" and a service the user asked for. Expect both to change in negotiation.

Part 5: Browser Signals, Third Time Lucky?

A Bruegel-style harbour town at night where a watchtower keeper signals with a coloured lantern, shopkeepers close their shutters in reply, and one printer's shop stays open and lit while the printer waves at the tower, with an hourglass and a small glowing screen in the tower window.
Fig. 4 — The printer did not have to look up, generated by OpenAI GPT Image.

The second new article answers the question everyone asks at the fortieth banner of the week: why can't I just tell my browser once?

Article 88b says controllers "shall ensure that their online interfaces allow data subjects to" give consent, refuse consent and object "through automated and machine-readable means", and that they "shall respect the choices made". In plain terms: set your preference once, in the browser or some other tool, and websites must read it and obey it.

Recital 46 says this could live "in the settings of a web browser or in the EU Digital Identity Wallet". The explanatory memorandum adds that the wording is technology-neutral, "so that also other tools, e.g. agentic AI, could support users in making consent choices".7 It is the first legislative text I have seen that imagines an AI agent clicking "Reject all" for you, and I rather like it.

Three catches

There is no standard yet. Article 88b(4) asks the European standards bodies to write standards "for the interpretation of machine-readable indications of data subjects' choices", and sites that follow them get a presumption of compliance. The working document says the standards need a "common vocabulary" of purposes, which is a polite way of saying this will be a long argument.

Media services are exempt. Article 88b(3) says the duty to respect signals does not apply "to controllers that are media service providers when providing a media service". The recital gives the reason: "the importance of independent journalism" and the need "not to undermine the economic basis for that". A news publisher could keep asking every visitor directly, whatever their browser says. This carve-out applies only to signals. It is not an exemption from consent, and it does not appear in Article 88a at all.

The clocks are long. Article 88a would apply six months after entry into force. The duty for sites to respect signals (88b(1) and (2)) would apply after 24 months, and the duty for browser providers that are not SMEs (88b(6)) after 48 months. As of November 2025, nobody knows when those clocks start. The browser part lands four years after the law starts.

A vertical timeline counted from an unknown entry-into-force date. Six months later, Article 88a applies: the consent rule moves into the GDPR, four consent-free purposes, single-click refusal, a six-month bar after a no, and GDPR fines. Twenty-four months later, sites must accept and respect machine-readable choices, under standards still to be written, with media services exempt. Forty-eight months later, web browsers that are not SMEs must give users the means to send those choices. Until then, Article 5(3) of the ePrivacy Directive and national law still apply.
Fig. 5 — Three clocks, none of them started. Drawn from Articles 88a(5), 88b(5) and 88b(7) of COM(2025) 837, 19 November 2025.

We have been here before

The Commission knows this idea has history. The memorandum points back to a 2009 recital that "already encouraged" consent through "the appropriate settings of a browser", to Article 21(5) of the GDPR, which already lets people object "by automated means using technical specifications", and to the withdrawn 2017 Regulation, which "proposed user choice management by web-browser settings". So this is at least the third attempt in European law alone.

The best-known attempt outside the law was Do Not Track, a browser header asking sites not to track you. Nobody had to obey it. In January 2019 the W3C working group closed its work on the standard, noting that "there has not been sufficient deployment of these extensions (as defined) to justify further advancement". A signal without a duty to obey it is a suggestion.

The current attempt is Global Privacy Control (GPC). It works the same way (an HTTP header called Sec-GPC, plus a JavaScript property, navigator.globalPrivacyControl), but it has a law behind it. The GPC project's home page quotes Xavier Becerra, speaking as California's Attorney General: the CCPA "requires businesses to treat a user-enabled global privacy control as a legally valid consumer request to opt out", and in September the California regulator fined a retailer partly for ignoring it, as I covered in CCPA Grows Up. In October, California went a step further: a new law, AB 566, requires browser makers to build an opt-out signal into the browser, from 1 January 2027.

Article 88b has the same shape: a duty on sites to obey, then a duty on browsers to offer. But GPC carries one message ("do not sell or share"), and an EU signal would need to carry consent and refusal for different purposes. Do not assume GPC will be the EU standard. Do assume your CMP will need to read a signal from the browser.8

Part 6: Annelies Sorts Her Tags

Meet Annelies. Annelies runs a small online shop in Ghent that sells Tasmanian leatherwood honey to Europeans who have discovered it. (Annelies is invented for this article. The honey is real, and I will defend it against any jam in Flanders.) She wants to know what the proposal would mean for her site. Her rule: change nothing yet, but know exactly what she would change.

Monday: make the list

She writes every tag and cookie into a spreadsheet: name, vendor, purpose, and what it sends where. She checks each one in the browser's developer tools as well as her CMP's scan, because the EDPB taskforce noted that scanners can list cookies but "do not allow to check the nature of the cookies". Her list:

  1. A cart cookie from her shop platform.
  2. A login session cookie for her customer accounts.
  3. A bot-protection cookie on the checkout and login pages.
  4. A language preference cookie (Dutch, French or English).
  5. GA4, linked to her Google Ads account, with the data sharing settings left at the defaults she accepted years ago.
  6. The Google Ads conversion tag.
  7. The Meta pixel.
  8. A session recording tool she installed once to watch where people got stuck.
  9. A chat widget that loads on every page.
  10. Her CMP's own cookie, which stores each visitor's choice.

Tuesday: one tag, one question at a time

For each row, she asks the questions in the order the article asks them. First, does the tag store or read personal data on the device? If not, the old national rule still applies and Article 88a is not the test. If it does, she works down the list of purposes, one question at a time.

A vertical decision flow. Step 0: does the tag store or read personal data on the device? If not, national ePrivacy law still applies. If yes: is it needed to send the communication, needed for a service the user explicitly asked for, or needed to keep that service or device secure? Each yes means no consent is needed. Then audience measurement, where all three must be true: the output is aggregated, the controller carries it out, and it is solely for its own use. Any no leads to the final box: consent is needed, refusal must be possible with a single click, no new request while a consent is valid, and no new request for at least six months after a refusal.
Fig. 6 — One tag, one question at a time. Drawn from Article 88a of the GDPR as proposed in COM(2025) 837, 19 November 2025. A proposal, not law.

Rows 1 and 2, cart and login: (b), a service the customer explicitly asked for. These were already exempt under the old rule. No change.

Row 3, bot protection: (d), "maintaining or restoring the security of a service". Today she has filed it under "strictly necessary" and hoped. Under 88a it has its own door, as long as it only protects the pages it runs on.

Row 4, language: (b). The EDPB taskforce already recalled the old guidance that cookies retaining "the preferences expressed by users, regarding a service, should be deemed essential". No change.

Row 10, the CMP's own cookie: if it stores only a yes or no per purpose, with no visitor ID, it may not be personal data at all, and then step 0 sends it back to the old national rule. There, the EDPB taskforce recalled old guidance that cookies which keep a user's preferences "should be deemed essential". If it does carry an ID, she needs it to remember a refusal for six months, as the proposal would require. She files it under (b), with a note to check the final text.

Row 5, GA4: her property is linked to Google Ads, and "Google products & services" sharing is on. It fails "solely for its own use" before she even reaches the cookie lifetime, so it stays behind consent. She notes what would make it a candidate (unlink Ads, turn off sharing, shorten the cookie) and that unlinking Ads costs her the conversion import. That is a business decision for later.

Rows 6 and 7, Google Ads and Meta: advertising. Not on the list, under any reading. They stay behind consent.

Row 8, session recording: one visitor's session is the opposite of "aggregated information". Consent. She also realises she has not opened the tool in five months, and removes it on the spot. It is the only change she makes this week, and it has nothing to do with the proposal.

Row 9, chat widget: the chat is a service a customer can "explicitly request", but only once they open it. Her widget loads and sets cookies on every page, before any request. She notes that it should load only when a visitor clicks the chat button, which is good practice today as well.

Wednesday: count the result

Of ten rows, three were already exempt, one (security) gets a clearer home, one (the CMP's own cookie) probably fits (b), one is gone, and three stay behind consent: GA4, Google Ads and Meta. The chat widget becomes exempt only if she changes how it loads. Her banner does not disappear. It gets shorter and more honest.

Thursday: the banner rules

Next she checks her CMP against the three rules in 88a(4).

Single-click refusal. Her banner has "Accept all" and "Manage options" on the first layer. Refusal is possible, but only on the second layer, after three more taps. The EDPB taskforce found that most authorities already treat a banner with no refusal option on any layer as an infringement; hers is not that bad, but it is a long way from "a single-click button". She adds "Reject all" to the first layer now, at the same level and the same size as "Accept all". This is the one proposal rule that is safe to adopt early, because it only takes her further from the line regulators draw today.

Remembering a no. Her CMP forgets a refusal after 30 days and shows the banner again. Under 88a(4)(c) that would become unlawful. She does not change it yet (the final number may move), but she checks that her CMP can store a longer refusal period per purpose.

Remembering a yes. Her CMP re-prompts everyone whenever she adds a vendor. Under 88a(4)(b), she may not ask again "for the same purpose" while the consent is valid, so that habit might become a problem. Her note: group vendors by purpose, and re-prompt only when a purpose is new.

She also confirms her CMP keeps a "withdraw consent" icon on every page, because GDPR Article 7(3) already says it must be "as easy to withdraw as to give consent".

Friday: plan for signals

Last, she asks her CMP vendor two questions in writing. Does the CMP read Sec-GPC today? And will it follow the EU standards under 88b when they exist? She is not a media service, so that exemption does not help her. She sets a quarterly reminder to check the legislative progress, and closes the spreadsheet.

What to Do This Week

None of this is law yet. Most of it is good practice already, so it is worth doing anyway.

  1. Inventory every tag and cookie on your site. Record the vendor, the purpose, the lifetime and where the data goes. Check the CMP's scan against the browser's developer tools.
  2. Map each one to Article 88a(3): (a) transmission, (b) a service the user asked for, (c) own-use aggregated audience measurement, (d) security, or "consent". Anything you cannot map is "consent".
  3. Fix mislabelled "essential" cookies now. The EDPB taskforce already calls this out. If a tag only makes sense for advertising or profiling, it was never essential.
  4. Run your analytics tool through the three tests of 88a(3)(c): aggregated output, carried out by you or your processor, solely for your use. In GA4, write down the state of every data sharing setting and every product link. Do not change them yet; know what you would change.
  5. Add a "Reject all" button to the first layer of your banner if it does not have one. Most EU regulators already treat a banner with no refusal option on any layer as an infringement, and the proposal would make one click the standard.
  6. Check your CMP's re-prompt behaviour: how long a refusal is remembered, how long a consent lasts, and whether adding a vendor re-prompts everyone. Confirm it can store a refusal period per purpose.
  7. Load on-demand widgets on demand. A chat, a map or a video embed that the user has not asked for yet is not "explicitly requested".
  8. Ask your CMP vendor about signals: whether it reads Sec-GPC today, and whether it will follow the 88b standards.
  9. If you are a publisher, check whether you are a "media service provider" under the European Media Freedom Act definition the proposal borrows. The signal exemption depends on it.
  10. Put a quarterly reminder in your calendar to check the text as it moves through Parliament and Council. Plan against the final text, not this one.

Final Thoughts

Think back to the recipe site, the grey link and the scrolling list of partners. The Commission looked at the same box and came to the same conclusion as you: the box is not a choice. It is a toll.

The proposal does not abolish the box. It keeps consent as the main gate, adds a few side doors for low-risk uses, and sets rules for the gate: one click to say no, and no asking again for six months. The analytics door is narrower than the Commission's summaries suggest. It is built for the baker with the slate, not the baker with the book. And the browser signal that would make the box unnecessary is years away and does not bind news sites.

So the one takeaway: the proposal rewards sites that already know what each tag does, and why. If you can map every tag to a purpose today, you can adapt to whatever text is adopted. If you cannot, no law will make your banner shorter.

Make the list this week. Add the reject button. Then wait for the final text, and read it the same way we read this one, clause by clause.

Now, if you'll excuse me, I finally found out how long to steep the Darjeeling. Three minutes. The tea is excellent. I did not accept the cookies.

Notes

  1. The Commission also called the 2017 text "outdated in view of some recent legislation". Eight years from proposal to withdrawal is a useful reminder that a Commission proposal is the start of a process, not the end of one. ↩

  2. The proposal also changes the GDPR's definition of personal data. It adds that information "shall not be personal for a given entity where that entity cannot identify the natural person", taking into account the means "reasonably likely to be used by that entity". If a cookie ID stops being personal data for some company under that test, it does not escape the consent rule. It falls back to the old Article 5(3), which covers any "information", personal or not. ↩

  3. The Commission's FAQ and the article text were both published on 19 November 2025. Where a summary and the legal text differ, the text is what Parliament and Council will amend, and what a court would read. When you brief your team, quote the article. ↩

  4. Recital 44 gives the example of "a media service provider" mandating "a market research company". The Commission's working document goes further and lists "audience measurement when carried out by a media service provider" as its own purpose. The article text does neither: it has one purpose, (c), and it does not mention media or processors. Recitals help interpret an article, but they cannot add to it, so this is one to watch in the negotiations. ↩

  5. A/B testing splits visitors into groups and shows each group a different version of a page. It needs to remember which group each browser is in, which usually means a cookie. The CNIL treats it as part of audience measurement. Article 88a(3)(c) talks only about measuring "the audience", so an A/B testing tool may need its own argument, or consent. ↩

  6. In practice, browsers shorten it. Google's own page notes that browsers limit first-party cookies when a visitor does not return: "maximum of 400 days for Chrome and 7 days for Safari". The Safari limit comes from Intelligent Tracking Prevention, which deletes script-set cookies after 7 days without interaction, as I covered in Safari 26: Fingerprints Off the Glass. I would expect a regulator to look at the lifetime you set, not at what a browser did to it. ↩

  7. The explanatory memorandum is the Commission's own explanation at the front of a proposal. It is not part of the law, but it shows what the drafters intended. The "agentic AI" line is in its passage on cookie banners and browser settings. ↩

  8. GPC's specification describes the signal as a request not to sell or share personal information with third parties. That is an opt-out, which fits California's law. EU cookie law is opt-in: silence is not consent. An EU standard would have to let a browser say "no" to some purposes and "yes" to others, which one header value cannot do. ↩

end of article · 6,579 words · 27 November 2025

James Nicholson, smiling, in round tortoiseshell glasses and a white T-shirt.

James Nicholson

James is a technology consultant in Hobart, Tasmania, and runs NEOBADGER. He works where technology, regulation and the people organisations serve meet: AI harnesses, development, data and compliance.

The story

Further reading

3 more articles on Data Privacy.