FAQ

A consent banner or cookie banner is commonly a visual banner on a website, in an app or elsewhere (Smart TVs, cars, etc.) that requests you to consent to being tracked online. Usually, you are asked to consent to e.g. cookies being installed on your device or your personal data being used for multiple purposes.

In the EU, tracking users is by default illegal. Because companies want to use cookies and/or your personal data, they therefore need you to waive your rights by giving your consent. This is primarily done to track your behavior and to earn money with targeted advertising based on your profile.

If these banners are misleading, more people click on “accept”, “consent” or “yes” – which means that a company is usually able to earn more money. An important industry metric to measure this, is the consent rate. Through various tricks and nudging techniques, companies manage to raise the consent rate to 90% and more, even though only 1-10% (depending on the study) of people want to be tracked.

Instead of having thousands of different banners that interrupt your usage of online services, an automated signal would allow you to set your choices in a browser, a browser extension or in your operating system. Your choices are simply transmitted automatically by a signal to websites, apps or other interfaces you interact with. For these choices, cookie banners are no longer necessary.

Yes, there is a number of existing frameworks (such as ADPC, navigator.consent or consenter), which could be instantly implemented in the EU.

The technology to communicate your choices is more than 30 years old and proven. For example, every time you visit a website, your browser sends your language preferences in the background so you automatically see a website in your language.

Furthermore, companies already use automated signals between themselves to communicate privacy choices, typically via the IAB TCF system. However, they do not allow users to participate in this automated system – making it extremely annoying for users to communicate their choices. Article 88b would basically extend this existing signal infrastructure to the end user.

Article 88b is therefore only a duty to accept choices via existing and proven technology.

No, automated signals are not meant to change the conditions of consent. They are meant to automate the transmission of user choices when they are asked for consent. You will have an agent or browser that will manage your choices – based on your wishes, your settings, learnings from your decisions or third-party consent or block lists.

In November 2025, the European Commission proposed changes to EU legislation (via the“Digital Omnibus”) and suggested the adoption of automated signals to reduce consent banners. EU legislators are currently discussing this as a proposed Article 88b GDPR. Some companies are lobbying heavily against this solution, because they fear that they will no longer be able to mislead users into clicking ‘consent’ using dirty tricks.

An automated privacy signal is just another signal that e.g. your browser or an app sends to a server. This is not new. Browsers, apps and devices already exchange choices automatically. For example, your browser communicates your language settings to a website, so that you automatically see a website it in the language you understand. Another example of an existing automated privacy signals is Global Privacy Control, which is now the law in a number of US states.

Yes, that is the aim. Your browser or a plug-in will just take care of it. Think of it like a spam filter for your emails that automatically decides which emails are spam and which ones are worth reading.

No, the proposal by the European Commission even exempts publishers from Article 88b GDPR.

Even if publishers comply with Article 88b, studies suggest that users are more likely to consent to data usage by their trusted newspaper, than e.g. by big tech companies. This could even lead to a competitive advantage for publishers.

This would create equal opportunities for anyone seeking consent. It avoids rewarding aggressive and deceptive practices, which are not only annoying to users but lead to a financial advantage over competitors that are playing fair.

No, automated signals can be implemented in many ways. They could be managed in browsers, but also via third-party extensions, apps, operating systems and other software.

Importantly, the law should make sure that automated signals are not controlled and defined by one company, browser, operating system or platform, as this favors abuse. This especially is the case given the enormous market dominance of a small number of browser vendors and operating systems.

Spread the word and reach out to Members of the European Parliament here. You can also reach out to the Government of the country you reside in, trying to contact the people in charge of deciding about the national position on automated privacy signals.