Technology · Digital regulation
European Commission targets cookie consent law in deregulation push
Brussels plans to scrap the 2009 e-Privacy Directive that spawned ubiquitous pop-up banners, but privacy advocates warn the move could weaken protections against surveillance advertising.
The European Commission is preparing to dismantle one of the most visible, and widely resented, pieces of European technology regulation: the 2009 revision of the e-Privacy Directive that made cookie consent banners a fixture of every website. Officials are working on an omnibus simplification package due in December that could eliminate the requirement for sites to ask permission before placing non-essential cookies on a visitor's device, a rule that has generated billions of pop-ups but little evidence of informed consent.
The move forms part of Commission President Ursula von der Leyen's broader deregulation agenda. In February 2025, the executive withdrew a long-stalled proposal for an e-Privacy Regulation that had been under negotiation since 2017, citing the inability of EU institutions to reach compromise on a text covering everything from online advertising to national security. Now the Commission is returning to the problem from a different angle: not a new regulation, but the removal of the existing directive's most burdensome provisions.
How cookie banners became the internet's wallpaper
Cookies are small text files that allow websites to recognise returning visitors, keep users logged in, remember shopping-cart contents and build profiles for targeted advertising. The 2009 revision of the e-Privacy Directive required sites to obtain consent before storing or accessing any non-essential cookie. The intention was to give users control over tracking. The result was a deluge of banners that most people dismiss without reading.
Peter Craddock, a data lawyer with Keller and Heckman, described the dynamic bluntly: "Too much consent basically kills consent. People are used to giving consent for everything, so they might stop reading things in as much detail, and if consent is the default for everything, it's no longer perceived in the same way by users." The phenomenon, known as consent fatigue, means the mechanism designed to protect privacy has become a ritual that protects no one.
The Commission's own focus group with industry and civil society on 15 September explored two main ideas: expanding the categories of cookies exempt from consent, and allowing users to set preferences once, for example in their browser settings, rather than on every site they visit. A note circulated to participants, seen by reporters, shows the executive is serious about reducing the friction that has made the current regime unworkable.
Member states and industry push for a lighter touch
Denmark, which holds the rotating presidency of the Council of the European Union, tabled a proposal in May to drop consent banners for cookies that collect data for "technically necessary functions" or "simple statistics." The suggestion reflects a growing view among national governments that the current rules are disproportionate. The Council's position matters because any legislative change will need agreement from both the Council and the European Parliament.
Industry groups have gone further. IAB Europe, which represents the digital advertising ecosystem, argues that cookie regulation should be folded into the General Data Protection Regulation (GDPR). The e-Privacy Directive imposes strict consent requirements; the GDPR adopts a risk-based approach, allowing companies to calibrate safeguards to the sensitivity of the data processing. Franck Thomas, policy director at IAB Europe, said this would let businesses rely on legal bases such as legitimate interest, providing flexibility without abandoning privacy protection. "Our call for simplification should not be confused with a light touch approach on data protection," he added, "but everyone agrees we need to maintain this balance between safeguarding privacy rights and preserving the competitiveness of the European tech industry."
The failed regulation that preceded the repeal
The Commission's current strategy is haunted by the failure of the e-Privacy Regulation. Proposed in 2017, it aimed to replace the directive with a directly applicable regulation, aligning it with the GDPR and extending its scope to new communications services such as WhatsApp and Skype. Negotiations dragged on for years, bogged down by disagreements over metadata protection, national security exemptions and the treatment of online advertising. In February 2025, von der Leyen withdrew the proposal entirely, a "prized scalp" of her simplification drive, as one Brussels observer put it.
Birgit Sippel, the German Social Democrat MEP who drafted the Parliament's joint position on the regulation before its withdrawal, is among the fiercest critics of the new approach. "Under the banner of so-called simplification, the Commission now envisages to withdraw not only the e-Privacy Regulation proposal but potentially even the existing e-Privacy Directive ... without a serious analysis of the risks," she said. "If e-privacy is dismantled, Europeans will be left with nothing but the Charter to defend themselves" from state surveillance and commercial ad targeting, "while U.S. tech giants enjoy a carte blanche to exploit our data for profit."
Privacy advocates see a trap in the simplification narrative
Civil society organisations are mobilising against what they view as a strategic retreat. Itxaso Domínguez de Olazábal, policy adviser at European Digital Rights, dismissed the focus on cookie banners as a distraction. "Focusing on cookies is like rearranging deckchairs on the Titanic, the ship being surveillance advertising," she said. The law already exempts cookies that are strictly necessary to deliver a service the user explicitly expects, remembering items in a shopping cart, for instance. Expanding that category to cover analytics or personalisation, she argued, would "risk smuggling in analytics or personalization for adtech" under the guise of essential functionality.
The concern is structural. The e-Privacy Directive is lex specialis to the GDPR: it provides specific rules for electronic communications that override the general regulation. Removing it would leave a gap that the GDPR's broader principles, lawful basis, purpose limitation, data minimisation, may not fill in practice, particularly regarding metadata and device fingerprinting. The Charter of Fundamental Rights, which Sippel invoked, guarantees privacy and data protection, but it is a constitutional backstop, not an operational rulebook.
The GDPR alternative and its limits
Moving cookie governance into the GDPR framework is the industry's preferred solution, but it is not a simple transplant. The GDPR's Article 6 lists six lawful bases for processing personal data. Consent is one; legitimate interest is another. Under the e-Privacy Directive, consent is effectively mandatory for non-essential cookies. Under the GDPR, a website operator could argue that analytics or even certain advertising functions fall under legitimate interest, subject to a balancing test against the user's rights. That test is fact-specific, open to interpretation, and ultimately enforced by national data protection authorities, 27 of them, with varying resources and appetites for enforcement.
The European Data Protection Board has issued guidelines on the interplay between the two instruments, but they are non-binding. If the directive disappears, the board would likely need to produce new guidance on how the GDPR applies to cookie-like technologies. That process takes years. In the interim, regulatory uncertainty could be worse than the current regime for both companies and users.
What comes next: the Digital Fairness Act
The Commission has signalled that the cookie overhaul is only the first act. In 2026 it intends to present a Digital Fairness Act, described as a consumer-protection instrument targeting manipulative design, unfair personalisation and other dark patterns in digital markets. That legislation will reopen many of the same battles, what counts as fair, who decides, and whether European rules can constrain business models built on behavioural surveillance. The advertising industry, privacy groups and national regulators are already positioning for that fight.
Sources
People mentioned
Franck Thomas
Itxaso Domínguez de Olazábal
Peter Craddock
Organisations
European Commission · European Parliament · Council of the European Union · IAB Europe · European Digital Rights · Keller and Heckman