Cookie banners have become a familiar source of user frustration. The ePrivacy Directive’s Article 5(3), as amended in 2009, generally requires informed consent before storing information on, or accessing it from, a user’s device, subject to narrow exemptions. Tracking across visits or sites can be technically possible without a court order. When the resulting identifiers relate to an identifiable person, the GDPR’s personal-data rules also apply; the device-access rule is a separate question.
The friction is real for many users, but a defensible EU-wide time or cost total would need measured exposure and interaction data. The legal question for a site is more concrete: which device operations require consent, which narrowly qualify for an exemption, and whether the resulting data identify a person.
2026 Update — Recent Developments
Cookie enforcement remained active in 2025: the CNIL reported 21 sanctions concerning cookies and other trackers, including deposits without consent and failures to respect refusal or withdrawal.
Recent companion resources:
- GDPR consent wording examples
- Cookies CNIL : conformité bandeau (FR)
- Cookie consent compliance guide
The Productivity Cost of Cookie Banners
Repeated consent prompts can interrupt browsing and encourage hurried choices. The scale of that burden depends on how often a person encounters a banner and whether a site asks for consent when an exemption actually applies; it cannot be inferred from EU population figures alone.
Do Cookie Banners Really Improve Privacy?
The device-access rule comes from Article 5(3) of the ePrivacy Directive, amended in 2009. Consent is generally needed for non-exempt storage or access on a device, whether or not the operator knows the person’s name. Strictly necessary operations for a service requested by the user are exempt; some audience-measurement tools may also qualify under narrow national guidance and documented configuration. GDPR duties apply separately when the information processed is personal data.
Today, most cookie banners are used by organizations to:
- Facilitate web analytics and understand user interactions with their websites.
- Improve user experience by analyzing what content performs well or poorly.
- Manage the performance of advertisements.
A site may observe visits through cookies, device identifiers and IP addresses without first obtaining a court order. Whether an IP address or another identifier is personal data depends on whether a person is identifiable in the circumstances. Consent for non-exempt device access does not depend on naming that person; if personal data are processed, the GDPR adds its own lawful-basis, transparency and rights requirements. Small sites should distinguish strictly necessary functions from analytics or advertising and check any claimed exemption against the actual tool configuration.
It is not to say that some businesses do not use cookies to operate user tracking on a massive scale. Some companies relying exclusively on advertising do share user data with very large pools of partners—sometimes hundreds of ad partners. In that case, cookie banners do offer privacy protections for users.
However, looking at the general scale of the internet, only a very small fraction of websites use mass-scale partnerships as their main economic model.
For users, repeated interactions with cookie banners lead to significant frustration and complete loss of vigilance. The consent fatigue results in users mindlessly accepting terms without proper consideration, thereby undermining the very intent of the regulations. This stands in contrast to the GDPR’s rigorous standards for valid consent, which require freely given, informed, and unambiguous agreement. The constant barrage of consent prompts not only reduces productivity but diminishes user satisfaction and erodes trust in online platforms.
FAQ
Are cookie banners legally required under GDPR?
The ePrivacy device-access rule generally requires consent for non-exempt cookies and similar technologies; it does not prescribe a banner as the only interface. GDPR requirements also apply whenever personal data are processed, including in some exempt cookie uses. Strictly necessary device access is exempt from ePrivacy consent, while audience measurement is exempt only when the applicable narrow conditions are met; advertising trackers generally require consent.
How much time do Europeans spend on cookie banners each year?
No reliable EU-wide total can be inferred without measured banner exposure and interaction time. Repeated prompts can still impose real user friction.
Why are most cookie banners non-compliant with GDPR?
Common consent problems include unclear information, pre-ticked choices, making refusal harder than acceptance, and continuing to read or write non-exempt trackers after refusal.
What would make cookie consent less disruptive while remaining compliant?
A browser-level signal could reduce repeated choices if a clear legal and technical method made it reliable across sites. A site should follow the currently applicable ePrivacy and GDPR rules rather than assume a browser setting automatically supplies valid consent.
Conclusion
Repeated banners can create consent fatigue. Their privacy value depends on meaningful choice, truthful information and actual respect for refusal; unnecessary prompts also burden users.
In contrast, regulations like the GDPR impose IT security obligations that, while seen as burdensome, contribute to long-term business robustness by ensuring the security of IT systems. For a broader overview, see our guide on what is GDPR and how it differs from cookie consent requirements.
Proposals to simplify consent interfaces may change, but current requirements still govern a site’s tracking choices. Clear information and a usable refusal path matter more than repeatedly displaying an avoidable prompt.
This situation calls for an urgent revision of the ePrivacy Directive—potentially transforming it into a regulation to ensure swift adoption. Clearer choices and careful use of existing narrow exemptions can reduce unnecessary prompts. Any broader exemption for analytics or advertising would require a change in the applicable rules; business size alone does not create one. Organizations seeking to understand their broader compliance obligations can consult our GDPR compliance checklist and guide on data privacy principles.