EU cookie compliance faces pressure as regulators tighten scrutiny and reform stalls
Two recent developments are reshaping the EU’s cookie compliance landscape. The EDPB has made it harder for data protection authorities to dismiss organised complaints on procedural grounds, while the Council’s latest Digital Omnibus compromise removed a proposal that could have allowed browser-level consent signals to replace cookie banners.
Two recent developments could affect how organisations approach cookie consent and compliance in the European Union. The first concerns the enforcement of existing GDPR rules, while the second involves proposed changes to the EU’s rules on cookies and other terminal equipment.
Together, they suggest that cookie banners are likely to remain an important compliance issue, while complaints about potentially unlawful consent practices may face fewer procedural barriers.
EDPB makes dismissal of organised complaints more difficult
On 14 July 2026, the European Data Protection Board (EDPB) published Binding Decision 1/2026, following a dispute between the Austrian and Belgian data protection authorities over a complaint concerning the cookie banner of Flemish public broadcaster VRT.
The complaint had been filed by a data subject represented by noyb, a European digital rights organisation. The Belgian authority had proposed dismissing the complaint, arguing that the use of a standardised process by noyb amounted to an abuse of the right to lodge a complaint under the GDPR.
The Austrian authority disagreed, triggering the GDPR’s consistency mechanism under Article 65. The EDPB ultimately concluded that the Belgian authority had not demonstrated that the complaint constituted an abuse of rights.
The Board found that the data subject had provided a valid mandate under Article 80(1) of the GDPR. It also rejected the argument that the involvement of an organisation using standardised procedures made the complaint abusive.
As a result, the Belgian authority was instructed to assess the complaint on its merits, including whether VRT’s cookie banner complied with applicable data protection requirements.
The decision does not introduce new substantive requirements for cookie consent. Instead, it affects how complaints can be handled by supervisory authorities. Organised complaints supported by civil society organisations may therefore be more likely to proceed to substantive examination rather than being dismissed because of the way they were submitted.
What the decision means for cookie compliance
The EDPB decision does not change the existing GDPR requirements governing valid consent. Organisations still need to ensure that consent is freely given, specific, informed and unambiguous.
The decision does, however, weaken the assumption that a complaint can be dismissed simply because it forms part of a broader or standardised campaign.
For organisations operating in the EU, this means that the practical implementation of cookie banners may receive closer scrutiny. In particular, organisations should review whether users can reject non-essential cookies as easily as they can accept them and whether the consent process relies on design choices that could influence users’ decisions.
The decision also reinforces the importance of being able to demonstrate how consent was obtained. Maintaining records of the consent mechanism, its configuration and the version of the banner presented to users can help organisations respond to regulatory inquiries.
Digital Omnibus proposal loses browser-level consent provision
At the same time, negotiations over the EU’s Digital Omnibus are changing the prospects for a longer-term solution to what has become known as “cookie banner fatigue”.
The European Commission’s proposal would move rules on cookies and similar technologies from the ePrivacy Directive into the GDPR through proposed new Articles 88a and 88b.
Article 88a would introduce several requirements, including the ability to refuse consent through a single click. It would also restrict organisations from asking users to provide consent again for the same purpose for six months after a refusal, subject to the final wording of the legislation.
Article 88b would have introduced a different approach. It proposed the use of machine-readable consent signals that could be provided through a browser or other technology, allowing users to express preferences centrally rather than responding to individual cookie banners on every website.
That provision was removed from the Council’s fifth compromise text in June 2026. The removal means that, at least in the Council’s current position, browser-level consent signals would not replace website-level consent mechanisms.
The legislative process is not yet complete. The European Parliament and Council still need to agree on the final text, meaning the provision could potentially return during subsequent negotiations.
Cookie banners are therefore likely to remain
The combination of these developments points to two parallel trends.
First, organisations should not assume that cookie banners will disappear in the near term. The proposed browser-level alternative is currently absent from the Council’s position, while negotiations on the Digital Omnibus continue.
Second, existing cookie consent practices are likely to remain an area of regulatory and civil society scrutiny. The EDPB’s decision makes it harder to rely on procedural arguments to prevent certain organised complaints from reaching substantive review.
For organisations, the practical response is to review the consent mechanism itself rather than rely on uncertainty surrounding future legislation.
This includes checking whether rejection is as straightforward as acceptance, whether consent is requested for clearly defined purposes, whether users can change their preferences, and whether consent records can demonstrate what users were shown and what choices they made.
The final shape of the Digital Omnibus remains uncertain, but neither development provides a basis for delaying compliance with the rules that already apply.
