Skip to content
Legiscope
Menu
Data Privacy

Cookie Banner Fatigue: Consent Rules and Narrow Exemptions

Why cookie banners frustrate users, when EU device-access consent is required, and which narrow exemptions may apply to necessary and audience-measurement cookies.

Cookie banners have become a familiar source of user frustration. The ePrivacy Directive’s Article 5(3), as amended in 2009, generally requires informed consent before storing information on, or accessing it from, a user’s device, subject to narrow exemptions. Tracking across visits or sites can be technically possible without a court order. When the resulting identifiers relate to an identifiable person, the GDPR’s personal-data rules also apply; the device-access rule is a separate question.

The friction is real for many users, but a defensible EU-wide time or cost total would need measured exposure and interaction data. The legal question for a site is more concrete: which device operations require consent, which narrowly qualify for an exemption, and whether the resulting data identify a person.

2026 Update — Recent Developments

Cookie enforcement remained active in 2025: the CNIL reported 21 sanctions concerning cookies and other trackers, including deposits without consent and failures to respect refusal or withdrawal.

Recent companion resources:

Repeated consent prompts can interrupt browsing and encourage hurried choices. The scale of that burden depends on how often a person encounters a banner and whether a site asks for consent when an exemption actually applies; it cannot be inferred from EU population figures alone.

The device-access rule comes from Article 5(3) of the ePrivacy Directive, amended in 2009. Consent is generally needed for non-exempt storage or access on a device, whether or not the operator knows the person’s name. Strictly necessary operations for a service requested by the user are exempt; some audience-measurement tools may also qualify under narrow national guidance and documented configuration. GDPR duties apply separately when the information processed is personal data.

Today, most cookie banners are used by organizations to:

  • Facilitate web analytics and understand user interactions with their websites.
  • Improve user experience by analyzing what content performs well or poorly.
  • Manage the performance of advertisements.

A site may observe visits through cookies, device identifiers and IP addresses without first obtaining a court order. Whether an IP address or another identifier is personal data depends on whether a person is identifiable in the circumstances. Consent for non-exempt device access does not depend on naming that person; if personal data are processed, the GDPR adds its own lawful-basis, transparency and rights requirements. Small sites should distinguish strictly necessary functions from analytics or advertising and check any claimed exemption against the actual tool configuration.

It is not to say that some businesses do not use cookies to operate user tracking on a massive scale. Some companies relying exclusively on advertising do share user data with very large pools of partners—sometimes hundreds of ad partners. In that case, cookie banners do offer privacy protections for users.

However, looking at the general scale of the internet, only a very small fraction of websites use mass-scale partnerships as their main economic model.

For users, repeated interactions with cookie banners lead to significant frustration and complete loss of vigilance. The consent fatigue results in users mindlessly accepting terms without proper consideration, thereby undermining the very intent of the regulations. This stands in contrast to the GDPR’s rigorous standards for valid consent, which require freely given, informed, and unambiguous agreement. The constant barrage of consent prompts not only reduces productivity but diminishes user satisfaction and erodes trust in online platforms.

FAQ

The ePrivacy device-access rule generally requires consent for non-exempt cookies and similar technologies; it does not prescribe a banner as the only interface. GDPR requirements also apply whenever personal data are processed, including in some exempt cookie uses. Strictly necessary device access is exempt from ePrivacy consent, while audience measurement is exempt only when the applicable narrow conditions are met; advertising trackers generally require consent.

No reliable EU-wide total can be inferred without measured banner exposure and interaction time. Repeated prompts can still impose real user friction.

Common consent problems include unclear information, pre-ticked choices, making refusal harder than acceptance, and continuing to read or write non-exempt trackers after refusal.

A browser-level signal could reduce repeated choices if a clear legal and technical method made it reliable across sites. A site should follow the currently applicable ePrivacy and GDPR rules rather than assume a browser setting automatically supplies valid consent.

Conclusion

Repeated banners can create consent fatigue. Their privacy value depends on meaningful choice, truthful information and actual respect for refusal; unnecessary prompts also burden users.

In contrast, regulations like the GDPR impose IT security obligations that, while seen as burdensome, contribute to long-term business robustness by ensuring the security of IT systems. For a broader overview, see our guide on what is GDPR and how it differs from cookie consent requirements.

Proposals to simplify consent interfaces may change, but current requirements still govern a site’s tracking choices. Clear information and a usable refusal path matter more than repeatedly displaying an avoidable prompt.

This situation calls for an urgent revision of the ePrivacy Directive—potentially transforming it into a regulation to ensure swift adoption. Clearer choices and careful use of existing narrow exemptions can reduce unnecessary prompts. Any broader exemption for analytics or advertising would require a change in the applicable rules; business size alone does not create one. Organizations seeking to understand their broader compliance obligations can consult our GDPR compliance checklist and guide on data privacy principles.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
02Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

International transfers require the appropriate Chapter V route. Adequacy decisions, including the EU–US Data Privacy Framework for covered recipients, fall under Article 45. Standard Contractual…

April 30, 2026
03Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — a useful reminder to examine whether the organisation supports the DPO’s actual tasks and…

July 7, 2026
04Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
05Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026
06Data Privacy

Cassie (Syrenis) Alternatives & Comparison 2026

Cassie (Syrenis) is positioned by its maker around consent and preference management, with publicly advertised ROPA and data-subject rights capabilities as well. If you are looking for an…

July 9, 2026
07Data Privacy

Consent Management Platforms Compared (2026)

Choosing the right consent management platform is one of the most consequential technical decisions an organisation makes for privacy compliance. A poorly configured CMP exposes you to enforcement…

March 28, 2026
08Data Privacy

Cookie Audit: How to Map Your Website's Cookies

A cookie audit is the foundational step for any website's GDPR and ePrivacy compliance. Without a complete, documented inventory of every cookie and tracking technology deployed on your site, your…

March 28, 2026