I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.
Check out: https://killthecookiebanner.eu/
It feels similar to how CA environmental regs become the national standard simply because the market is so large it’s not worth splitting on it. So they just slap a cancer warning on everything
It’s only broken to the extent that it collided with a messed up world where websites track even when they don’t need to and then send that to 2000 partners for more profit extraction on top of what the website does commercially.
Something is deeply fucked up there and it’s not the EU part. They just make a good scapegoat because the banner is what users see
Just like websites also give zero fcks about accept-language header... sure do geoip lookup, so much easier... not
No harvest data to 936 partners? No need for a banner!
There’s a perfectly valid and simple way to comply with the EU policies, including GDPR, and not impose annoying popups on your users: just don’t set cookies (if you need to have a login, you can ask for permissions at login time) and don’t collect personal data. That a lot of sites elect not to do that is an indication of how they treat the user, not of the brokenness of EU law.
The only mistake EU policymakers made was underestimating how willing companies were to deface their websites.