The EU didn't have to do anything. The User Agent can already handle everything from denying cookies to blocking requests for certain resources.
The user agent can refuse to store cookies, but it can't do much against supercookies (cookie-like features not knowingly implemented by the user agent programmers) or fingerprinting: you need something like legislation to curb practices like that.