The European Union has a proposal on the table that could change one of the most repetitive experiences on today’s web: setting your privacy preferences once, from the browser or the operating system, and having websites automatically respect that choice. A coalition of 19 organizations, companies, and academic institutions grouped under the Kill the Cookie Banner campaign is demanding that this mechanism survive the negotiation of the EU’s Digital Omnibus.
The future of cookie banners, in 20 seconds: the key facts
- Article 88b proposes giving legal effect to automated privacy signals.
- Browsers and other agents could transmit consent, refusal, withdrawal, or objection.
- GPC and ADPC show the idea already has reference technologies behind it.
- The coalition wants preferences that can be set separately by company and purpose.
- The article is still being negotiated, and banners aren’t going away just yet.
The proposal is especially interesting from a technical standpoint because it changes where the interaction happens. Right now, each website deploys its own consent management platform, usually known as a CMP (Consent Management Platform). The user responds, and the page records which categories it’s allowed to activate.
The model the coalition is pushing for flips part of that process around.
The user’s browser, operating system, app, or agent could become the source of a standardized signal that communicates their preferences up front. When a page received a legally valid signal, it would have to act on it instead of unnecessarily asking the same question again.
This wouldn’t be a cookie blocker or a single universal opt-out. The proposal envisions a much more granular mechanism: allowing different decisions depending on which data controller is processing the data and for what purpose.
From Each Site’s Own CMP to a Signal Sent by the Browser
Today’s banners exist because of a mix of legal requirements and design decisions.
Cookies that are strictly necessary to provide certain services don’t require the same treatment as those used for advertising, measurement, or tracking. When an activity requires consent, that consent has to meet the conditions set out by the General Data Protection Regulation (GDPR).
The proposal in Article 88b isn’t trying to eliminate those requirements.
What it’s trying to change is the interface used to express that decision.
A simplified implementation could work like this:
User → browser or operating system → privacy signal → website or app → CMP/consent system
The page would receive the preference before deciding whether it needs to show any additional interface.
The Kill the Cookie Banner letter calls for signals that can represent four main actions: consenting, refusing, withdrawing a previous consent, and objecting to certain types of processing.
Consent transmitted this way would also still have to meet Article 4(11) of the GDPR. In other words, automating the communication wouldn’t lower the legal bar that makes consent valid.
| Layer | Current model | Proposed model |
|---|---|---|
| Browser | Loads the page and its controls | Also communicates preferences |
| Website | Asks the visitor | Interprets the signal first |
| CMP | Collects and stores the decision | Can process a prior decision |
| User | Configures each website | Sets preferences in advance |
| Persistence | Depends on each service | The refusal stands until changed |
| Purposes | Selected within the banner | Could be expressed via signals |
The technical difference looks small, but it could considerably change how the online consent industry operates.
CMPs wouldn’t necessarily have to disappear. They could evolve to interpret external signals, check their scope, store the corresponding evidence, and determine when additional interaction is still needed.
GPC and ADPC Already Preview Part of This Model
Europe wouldn’t have to start from scratch, either.
Global Privacy Control (GPC) lets browsers and other tools transmit a signal indicating certain user privacy preferences.
The concept is reminiscent of the old Do Not Track (DNT), though there’s one decisive difference: sending a technical header doesn’t do much good if websites aren’t legally required to honor it.
That was one of DNT’s biggest problems.
GPC currently has legal recognition in certain US jurisdictions. The European campaign cites it as proof that a signal automatically sent by the user can be built into a regulatory framework.
Article 88b wants to go beyond a simple opt-out.
The letter also mentions Advanced Data Protection Control (ADPC), developed with input from the Vienna University of Economics and Business and organizations like noyb.
ADPC aims to express more complex preferences, including consent for specific purposes or specific data controllers.
The coalition proposes that the future European standard build on existing technical work, but argues that the legal meaning of each signal should be defined by EU legislation, not by the technical standard itself.
Standards bodies should handle questions like interoperability, formats, and transmission, without redefining the rights established by the law.
A Refusal Would Have to Survive Later Visits
This is probably where the most significant change for the user experience shows up.
If a person uses their browser to signal that they’re refusing a particular type of processing, the coalition wants that refusal to remain valid until the user themselves decides to change it.
A website shouldn’t be able to ignore it by immediately showing another dialog asking essentially the same thing.
The signatories are asking for the signal to take priority over later requests related to the same processing, and for companies to be barred from working around it through interface changes, different wording, or repeated prompts.
This would directly tackle one of the problems with the current system: so-called consent fatigue.
When a person answers dozens or hundreds of similar prompts, the interaction turns into a mere formality. On top of that, some banners are designed with more steps to reject cookies than to accept them, something European data protection authorities have been scrutinizing for years.
With a persistent signal, the architecture would look different: the decision would be made in a layer mainly controlled by the user, and it would be transmitted automatically to services.
Chrome, Safari, and Edge Could Become a Critical Piece of the Puzzle
Moving preferences to the browser solves one problem but introduces another: who controls the browser.
Google Chrome, Apple Safari, and Microsoft Edge are all part of platforms run by some of the biggest tech companies in the world — the same tension already visible in past controversies, like when Firefox faced accusations of tracking users without consent despite enabling a privacy feature by default. Android and iOS add a second layer of control whenever the preference is managed at the operating-system level.
The letter pays specific attention to this risk.
The signatories want to prevent dominant companies or gatekeepers from designing the signals in ways that favor their own commercial interests or reinforce their market position.
The document explicitly cites Google as an example in relation to browsers, and calls for dominant platforms to allow preferences to be transmitted without additional interference.
It also asks that independent apps and agents be allowed to issue them.
This detail could become even more important as AI-based browsers and agents keep growing. If part of people’s browsing ends up being handled by assistants that visit services, compare information, or take actions on the user’s behalf, it will also be necessary to determine which privacy preferences should travel along with those operations.
The underlying technical principle would be the same: the choice should belong to the user and travel with their agent, rather than depending on the interface each page happens to design.
The Do Not Track Precedent Explains Why a Legal Obligation Is Needed
The history of the Internet already includes a similar attempt.
Do Not Track let users send an HTTP signal indicating they preferred not to be tracked. The major browsers ended up supporting it, but the system never achieved broad acceptance.
One of its weaknesses was that the signal, on its own, didn’t require services to act on it in any particular way.
Article 88b tries to avoid that problem by establishing a link between the technical signal and a legal obligation.
The coalition wants providers and other parties that access information stored on devices to be required to respect legally valid automated signals.
That’s the component that could turn a browser preference into something very different from just another option buried in a settings menu.
Banners Don’t Have an Expiration Date Yet
The project is far from becoming a feature that could be switched on tomorrow in Firefox, Chrome, or Safari.
Article 88b is part of the Digital Omnibus negotiation, and the September 10 letter exists precisely because its survival isn’t guaranteed. The Digital Omnibus talks are themselves part of a broader push in Brussels to ease GDPR and AI Act requirements in the name of driving innovation.
The signatories are asking the Irish Presidency of the Council to put the article back into its next compromise text. They’re also calling on member states, the European Parliament, and the Commission to support keeping a strengthened version of the proposal.
So it would be premature to say the EU has decided to get rid of cookie banners.
Even if it’s ultimately approved, the standard would still need to be finalized, implementations would need to be built, and browsers, operating systems, CMPs, ad platforms, apps, and websites would all need to adapt.
The change could be considerable precisely because the banner is only the visible part of a much larger technical infrastructure.
Behind it sit tag managers, ad platforms, analytics tools, CMPs, consent APIs, and systems tasked with storing every visitor’s decisions.
Kill the Cookie Banner proposes changing the entry point of that entire chain.
Instead of forcing every page to ask the user all over again what they want to do, the browser could arrive with the answer already in hand.
If Article 88b ultimately survives the European negotiation, the biggest change won’t be that an annoying pop-up disappears. It will be that privacy preference becomes an interoperable signal that technically travels with the user across the web.
Source: Redes Sociales

