We’ve all been there. You want to quickly look something up online—but before the information you’re looking for appears, a cookie banner pops up first. “Accept All,” “Settings,” or—often much less conspicuous—the option to reject cookies. If you just want to keep reading, you often click “Accept” as quickly as possible. The main thing is that the window goes away.
Cookie banners are actually supposed to let users decide what happens to their data. But this very system is now facing increasing criticism. The EU had already announced changes that could eliminate cookie banners in many cases. Now, this planned reform is once again in jeopardy. While the industry is critical of abolishing them, consumer advocates, NGOs, and researchers are calling for exactly the opposite: “Kill the Cookie Banner!”
This also raises the question: Are cookie banners actually an effective way to protect privacy—or have they simply become a way for people to click away data protection notices?
What do cookies actually have to do with data protection?
Cookies are small files that websites can store on a user's device. They can be quite useful, for example, to save settings or to recognize users when they visit the site again.
It becomes more problematic when such technologies are used to track people's behavior online. Which websites are visited? Which products are viewed? What interests can be inferred from this? This information can be used, among other things, for personalized advertising.
The General Data Protection Regulation, or GDPR for short, is intended to ensure that users have more control over their personal data. This also includes determining whether certain data may be collected or shared with third parties.
A cookie banner is not generally required in this context. If a website uses only data that is strictly necessary for its operation, it does not need to obtain consent for each instance of use.
In practice, however, most people still encounter these prompts almost every time they visit a website.
When Data Privacy Leads to Consent Fatigue
It is precisely this constant process of giving or withholding consent that has been given a name: “consent fatigue.”
Anyone who is confronted with a cookie banner every time they visit a new website will eventually have had enough. Instead of clicking through various settings and carefully checking which data will be processed, people often just click “Accept All.”
This is particularly evident from the figures cited in the current debate. According to the campaign website, up to 90 percent of users consent to the collection of personal information. At the same time, only a much smaller proportion actually say they want to be tracked online.
This is precisely where critics of the current system see a problem: Consent given via the cookie banner does not necessarily reflect a person's actual preference.
The call for change is therefore not coming solely from data privacy advocates. The European Consumer Organization (BEUC), data privacy organizations such as Max Schrems’ noyb, and representatives from the academic community also support the “Kill the Cookie Banner!” campaign.
Itxaso Dominguez de Olazabal of European Digital Rights (EDRi) sums up the criticism: “Privacy is a fundamental right; people shouldn’t have to click through a flood of banners just to exercise it.”
The EU had already been considering another solution
The EU had already announced far-reaching changes last year. The basic idea: Users should not have to be asked again on every single website.
Instead, a one-time setting in the browser could determine whether someone consents to tracking or not. The decision would thus be made centrally and would not have to be repeated constantly.
Technically, this seems entirely feasible. Browsers already have settings that allow users to control access to their location, camera, or microphone, for example. Cookies can also generally be disabled. However, this does not provide complete protection against every form of tracking.
A corresponding amendment had been planned as part of the so-called “Digital Omnibus,” a legislative package aimed at simplifying European digital regulations. However, it no longer appears in the current drafts.
Industry Opposes Abolition – NGOs Sound the Alarm
The NGOs involved have sharply criticized this development. According to them, the tracking industry is trying to preserve the existing cookie banners. Several EU member states, including Germany, France, and Poland, are said to have blocked the European Commission’s original proposal under pressure from the business community.
What is noteworthy here is the industry's shift in stance. The sector, which once vehemently criticized the introduction of cookie banners in some cases, now appears to be skeptical about their elimination.
The reason is obvious: A central setting that allows users to easily opt out of tracking could result in significantly fewer people consenting to the use of their data. For businesses, however, such data is economically valuable because it enables more targeted advertising.
This creates a conflict between two interests: data protection that is as simple as possible on the one hand, and economic interests in the use of data on the other.
Technically, an alternative would be possible
A look at existing options shows that an alternative solution does not necessarily have to fail due to technical limitations.
Harshvardhan Pandit of Trinity College Dublin pointed out the “Do Not Track” setting, which has been available in browsers for quite some time. The problem is that websites are not required to honor this setting. In practice, very few do.
California also offers a possible alternative. There, the Global Privacy Control (GPC) allows users to enable or disable tracking centrally through their browser.
It seems, therefore, that the technical feasibility exists, at least in part. The political implementation, however, appears to be more difficult.
All Eyes on Ireland
This also turns attention to Ireland. The country holds the EU Council presidency through the end of the year and can influence the political agenda to a certain extent.
At the same time, Ireland has close economic ties to the technology sector in this debate. Nearly all major U.S. technology companies have their EU headquarters there—including Google, Apple, and Meta.
In addition, the Irish Data Protection Commission has been criticized in the past for what critics view as lax enforcement of the GDPR.
It does not automatically follow from this that Ireland prioritizes the interests of technology companies over data protection. However, the economic importance of the industry explains why the country’s role is being closely monitored.
Fewer banners, more real decisions?
Ultimately, the debate over cookie banners is about more than just an annoying pop-up window on the screen.
If people have to decide anew every time they visit a website whether their data may be processed, the exact opposite of the desired effect may occur: The constant prompts will eventually lead to a point where hardly anyone pays attention anymore.
A privacy system shouldn't pressure people into clicking "Accept" as quickly as possible. It should allow them to make an informed decision—without having to navigate through numerous settings every time they visit a website.
Perhaps that is precisely where the greatest weakness of today's system lies. If people agree to data protection out of convenience, even though they don't actually want to be tracked, it's hard to argue that this system works particularly well.
After all, the situation has now become downright paradoxical: A tool that is supposed to give people more control over their data apparently leads many people to click away that control as quickly as possible.
That’s not a particularly convincing model for data protection. And perhaps that’s why we should discuss not only how cookie banners can be modified or eliminated, but also why we’ve created a system in the first place where data protection has become a daily clicking routine for many people.




