
Anu Bradford‘s book, The Brussels Effect: How the European Union Rules the World (Oxford, 2019), hardly exaggerates the EU’s influence. Many EU regulations have global reach, especially in respect to personal privacy. And for that we should be grateful, because the US and China mostly don’t give a shit.
On the other hand, every cookie notice you hate is a stain on the EU’s reputation as a protector of personal privacy in the digital world. They know that, of course, which is why the European Parliament is working on fixes.
They want their regulations to actually protect personal privacy, rather than just serving as ideals that the adtech business—which relies on tracking to personalize its messages—nods toward while violating the spirit of those regulations with impunity.
Naturally, pro-tracking lobbyists in the advertising industry and its dependents (such as publishing) are working overtime to preserve easements that allow tracking to continue.
On the other side—the one that includes most of online humanity—an estimated 1.77 billion people block ads and the tracking that guides them. I called this the biggest boycott in world history way back in 2015, when the number was just 200 million.
EU lawmakers need to listen to those people and not just to lobbyists who euphemize the failure of “consent” by calling it “cookie fatigue” and “consent fatigue.”
Cookie banners grew out of compliance with the ePrivacy Directive, especially its 2009 amendment requiring consent for storing or accessing information on personal devices, subject to limited exceptions. Their use surged after May 25, 2018, when the General Data Protection Regulation (GDPR) became enforceable. Neither law requires that every website display a banner. Even where cookie information is required, it need not take the form of a pop-up. Italy’s privacy regulator explicitly makes that distinction. Yet banners became the standard interface for a vast consent-management business.
Here is a key fact that the EU (and all of us) need to keep in mind: To the adtech industry, personal privacy is a bug, not a feature. They are rewarded for surveillance, not for regulatory obedience. So they feign obedience to regulatory requirements while circumventing them. Their recommendation for the Omnibus is to eliminate their need to circumvent regulations by changing those regulations to support continued surveillance, under the guise of “improving” consent mechanisms.
Here is another key fact: So long as only the web server side sets all the rules, provides all the mechanisms, and keeps all the records, consent itself is meaningless. Persons interacting with these mechanisms can do no more than what the mechanisms allow. Again, they aren’t meant to work for the person. At all. They are completely one-sided, unfair, and broken by design.
All this matters right now because the EU is working on a new Digital Omnibus, which was proposed in November 2025 and remains unfinished. Parliament’s legislative record lists it as awaiting a committee decision. The separate AI Omnibus has already been adopted, which can make headlines confusing. The legislation we are concerned with here is COM(2025) 837, procedure 2025/0360(COD).
For a while, there was an anti-tracking section of the Omnibus called Article 88b, which would have required sites and services to recognize people’s automated, machine-readable privacy choices. It would also have let people express those choices through their own software, instead of repeatedly confronting interfaces biased to allow rather than prevent unwelcome tracking.
Alas, the Council presidency removed 88b from the Omnibus’ compromise text in June. Its explanation cited concerns about evidence and technical challenges.
Max Schrems and noyb (which means “none of your business”) challenged the deletion of 88b:
As part of the ‘Digital Omnibus’, the European Commission now finally wanted to get rid of cookie banners and replace them with an automated signal. However, Google and some of the very EU Member States that are actually calling on the EU to “simplify” and “cut red tape” – including Germany and France, for example – are now standing in the way. In the Council’s latest position paper of 18 June, the plan to abolish the cookie banner has been scrapped. This baffling outcome is likely to continue to cost European users a great deal of hassle, frustration and billions of clicks per year.
That paragraph is followed by links to Google’s (formerly) secret lobbying paper and four other helpful documents:
- Proposal and reasoning of the European Commission (see Article 88b)
- Council position of 18 June (published by Politico)
- Google’s lobbying paper against Article 88b
- Mlex report on Poland’s position
- Digital Omnibus background by noyb
Added Max,
Cookie banners are not an invention of data protection, but of the tracking industry. Without consent, there is no snooping online. Now there are fears that a simpler way of saying ‘yes’ or ‘no’ will result in a loss of revenue for Google and the like. That is why the tracking industry is currently lobbying as hard as it can to keep the cookie banner. Clearly, it wants to retain the ability to directly manipulate users’ choices.
On September 10, a coalition of nineteen organizations, businesses and academics, including noyb, the European Consumer Organisation (BEUC), and European Digital Rights (EDRi), called for restoring a strong 88b. Their Kill the Cookie Banner campaign adds public pressure to their legislative work. Customer Commons
noyb and the Sustainable Computing Lab are also working on a browser signal called Advanced Data Protection Control (ADPC) that goes farther than Global Privacy Control (GPC) in communicating detailed privacy choices.
Customer Commons, which I co-founded, and on the board of which I serve, published a 7900-word submission to the EU Parliament arguing for retaining 88b and supporting contract as a lawful basis for protecting personal privacy.
As I said in this earlier Customer Commons post, 88b by itself is not enough, because it still operates inside the old and broken consent framework. Also, from The Only Way to Get Privacy Online: No regulation to make organizations respect personal privacy will work…The only way we will get privacy is with contracts, which are laws that two parties make for themselves.
Those contracts would also be backed by standing contract laws everywhere. No need for even more regulation.
The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) also support automated choices as a way to make people’s decisions effective.
It helps that we now have a standard for establishing contract-based personal privacy: IEEE 7012-2025, the Standard for Machine-Readable Personal Privacy Terms, nicknamed MyTerms. It was published in January (after nine years of work), and is available to read and download for free.
Here is how it works:

The possible agreements are all contracts posted on the website of a disinterested nonprofit (such as Customer Commons and MyData Global)— much as a choice of personal copyrights are posted at Creative Commons. (Which we thank for serving as a model.)
The person, acting as the first party, proffers their choice of an agreement to a site or service (broadly called an “entity” in the standard), acting as the second party, both using agents. (These can be as simple as browser and web server plugins, or as advanced as AI agents on both sides.)
If both sides agree, they keep identical records of their agreement, to support later auditing and support dispute resolution, if necessary. (This would typically be done using ODR: a mature discipline already working in the world.)
If the second party declines to agree, the first party is free to keep a record of that.
The first small collection of draft agreements is described on the MyTerms Alliance site. The alliance was created by a partnership of Customer Commons (based in the US) and MyData Global (based in the EU).
The most basic draft agreement is SD-BASE, which stands for “services only.” This is what any of us expect when we walk into an establishment (store, church, government office) in the natural world. In none of those places do we expect to walk out covered in tracking beacons. Nor should we expect to do the same online.
With a clear contractual commitment to personal privacy, trust becomes a cooperative fact rather than a corporate promise.
The commercial possibilities are substantial. Companies can learn directly what customers want and what kinds of relationships they are willing to enter. Customers can express demand without submitting to surveillance. Corporate offerings can be based on first-hand knowledge rather than surveillance-based guesswork.
We can have market intelligence that flows both ways, based on genuine rather than coercive relationships. To look down future paths MyTerms opens up for business (and much more), read what Nitin Badjatia, Iain Henderson, Jamie Smith and I have been writing about.
The difference between what’s possible in the surveillance economy and what MyTerms enables is like the difference between mainframes and PCs, LANs and the Internet, landlines and smartphones. Or, at the most basic level, freedom and captivity.
We will also get what I predicted in The Intention Economy: working proof that free customers are more valuable than captive ones—to themselves, to businesses, and to society.
As of today, there is technical work to build on. Advanced Data Protection Control, developed by noyb and the Sustainable Computing Lab, provides a way to communicate privacy choices automatically. We can also start fitting ADPC and MyTerms together.
The initial parliamentary amendment deadline passed in July, but Parliament has not adopted its position. The Parliament and Council must now develop their respective positions and ultimately agree on a text. There is no final adoption date (that I know of anyway).
Our submission to Parliament and the Council makes a detailed case. We urge the co-legislators to:
- Restore Article 88b and make individuals’ automated refusals effective.
- Protect people’s ability to choose the software that represents them.
- Require accountability for how signals are received and honored.
- Ensure the framework can accommodate person-originated privacy agreements, drawing on existing work that includes MyTerms.
If you are in the EU, find your MEP, share our submission, and ask them to support a strengthened Article 88b, while also welcoming person-originated contracts that protect privacy.
There isn’t a better way for Europe to use its regulatory powers for the good of us all.

























