Keep your cookie banner. The Digital Omnibus cookie reform is still a proposal.
Someone on your team forwards a headline saying the EU is getting rid of cookie banners, and asks whether you can switch off the consent tool that keeps part of your traffic out of analytics. I would not. The EU's Digital Omnibus, which the European Commission said would "reduce the number of times cookie banners pop up" 1, is still a proposal, and even after a deal its cookie rules would take between six months and two years to apply, depending on which draft wins. Until then your banner has to meet today's rules, and they are being enforced. In the first half of 2026, France's regulator sanctioned websites whose banners accepted everything in one click but made visitors open a settings screen to refuse 4.
Is the Digital Omnibus cookie reform law yet?
No. The Commission published it on 19 November 2025 1. By August 2026, according to the Parliament's own tracker, Parliament's committees had received more than 1,750 amendments and not voted, and the member states had cancelled a June vote on the Council's negotiating position because they still disagreed 2. The Council has circulated new drafts since, the latest public one dated 3 September 2026, and TechTimes reported on 25 September 2026 that a revised text from 21 September was under discussion. Even when the Council agrees, Parliament still has to agree its own position before the three institutions negotiate the final text.
Does your legal documentation match what you ship?
Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, then proposes the edits for your team to approve and publish.
Get startedWhat would the reform change for cookie banners?
Neither version ends the banner. An advertising pixel that builds retargeting audiences links a visit to what the person does later, so it needs consent under both. An analytics tool that profiles visitors across sites does not produce the aggregated statistics both versions exempt, so it needs consent too. Osborne Clarke's analysis of the Commission's text concluded that "the long-awaited end of cookie banners as such is not yet in sight".
The two drafts on the table are the Commission's proposal and the Council's 3 September 2026 working draft, an internal document the privacy campaign group noyb published. The Commission would move the cookie rule for personal data into the GDPR, one text for the whole EU. The Council strikes that out and keeps the rule in the ePrivacy Directive (the EU law behind cookie banners), which each country writes into its own law, so the rules would still differ from country to country. For your banner, they compare like this:
- One-click refusal. Both require that a visitor can refuse "with a single-click button or equivalent means".
- No re-asking. Both forbid asking again for the same purpose for at least six months after a refusal.
- Analytics. The Commission exempts aggregated audience measurement done by the site "solely for its own use". The Council exempts anonymous aggregated measurement, which a provider may run on your behalf if the data is not shared with or combined with data from third parties, and adds a separate exemption for audience measurement done under the EU's media freedom law.
- Advertising. The Commission has no exemption. The Council adds a narrow one for measuring how an ad performs, only if the ad was chosen from the page being viewed and nothing is linked to the visitor's past or future activity.
- Browser signal. The Commission proposed that websites must honour a consent choice sent automatically by the visitor's browser. noyb reported in June 2026 that Germany, France and Poland pushed to remove it, and the Council's drafts no longer contain it.
- Timing. The Commission's cookie rule would apply six months after the regulation enters into force. The Council gives member states 24 months after adoption to change their national laws.
What rule applies to your cookie banner today?
Today's rule is Article 5(3) of the ePrivacy Directive. Storing information on a visitor's device, or reading information already there, needs consent unless it is necessary for one of the specific purposes the Directive lists 3. In France there are two, and the CNIL reads both narrowly: trackers whose only purpose is to carry an electronic communication, and trackers strictly necessary to provide a service the user expressly asked for 5. The rule covers more than cookies. The European Data Protection Board, the EU body of national privacy regulators, applies it to tracking pixels, local storage and identifiers read from the device 3, on your marketing site and inside your logged-in app alike, which is also why some "cookieless" analytics still needs consent.
Each country enforces its own version, and I use the CNIL, France's regulator, as the benchmark because it publishes the clearest rules and enforces them most visibly. It says refusing must be as easy as accepting, and its own example of a compliant banner has a "refuse all" button on the first screen, at the same level and in the same style as "accept all" 5.
The sanctions in 2026 show what it checks. On 6 July 2026 the CNIL reported 23 sanctions issued since January under its simplified procedure, a fast track for straightforward cases 4. The cookie cases came from its own online checks of websites, including ticket sellers, and the banners failed in three ways:
- Cookies set before any choice. Cookies that need consent, such as advertising cookies, were placed before the visitor had done anything.
- Refusal harder than acceptance. "Accept all" was a button on the banner, while refusing meant clicking "personnaliser" and using a separate screen to switch cookies on or off.
- An incomplete banner. It did not say what the cookies were for, who was responsible, or how to refuse or withdraw consent.
Fines under the fast track are capped at 20,000 euros and reported without the company's name 4. The money is small, but the CNIL found these banners through its own checks of websites, and each of the three failures is visible to anyone who opens the site.
What should you do if you run a website or app with EU visitors?
If you run a product with visitors in the EU, keep your consent banner and check it against the rules in force today. Each of these checks also holds under both Omnibus drafts.
- Count the clicks. Open your site in a private browser window. If accepting takes one click and refusing takes two, fix that first.
- Watch your browser's network tab before you click anything. Any analytics or advertising request that fires before a choice is a problem today. When I scanned Product Hunt launches, most sites that set tracking cookies did it without asking.
- Keep your analytics consent unless your setup already meets a national exemption. In France that means the CNIL's four conditions: measurement only for your own site, anonymous statistics, no following people across sites or apps, and no sharing with third parties or combining with other data 5.
- Do not pay for "Omnibus-ready" yet. A banner tool sold on that promise is built for a text that is still being rewritten, and the Council circulated new drafts in June and twice in September 2026.
When a final text is agreed, re-check four things: one-click refusal, the six-month rule, the analytics and advertising exemptions, and whether any browser signal survived. Each of them is also a sentence in your Cookie Policy. Lawcel, the compliance tool we build, reads your product's code changes and flags when a document like that no longer matches what the product does, and a change to how your banner works is one of the code changes it can catch.
Tags
FAQ
References
- European Commission, press release IP/25/2718: Simpler EU digital rules and new digital wallets (19 November 2025) - accessed 2 Oct 2026
- European Parliament, Legislative Train: The Digital Omnibus Regulation Proposal (information updated as of 1 August 2026) - accessed 2 Oct 2026
- EDPB Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive (Version 2.0, adopted 7 October 2024) - accessed 2 Oct 2026
- CNIL, La CNIL a prononcé 23 nouvelles sanctions depuis janvier au titre de la procédure simplifiée (6 July 2026) - accessed 2 Oct 2026
- CNIL, Questions-réponses sur les lignes directrices modificatives et la recommandation « cookies et autres traceurs » - accessed 2 Oct 2026
About the author
Ulf Aslak Lai
Co-founder, Chief Technology Officer
Ulf is Co-founder and CTO at Lawcel. He leads engineering architecture for connectors, analysis pipelines, and the safeguards needed when automation touches regulated customer content.
- Platform architecture
- Data governance
- ML/AI systems
Related articles
Is legitimate interest enough for product analytics? Check what your tool stores on the device first.
Not on its own. Two rules apply to analytics, in order. Article 5(3) of the ePrivacy Directive, the rule behind cookie banners, governs storing or reading anything on the visitor's device and offers consent or one of two narrow exemptions, never legitimate interest. GDPR Article 6 governs the analysis you run afterwards, and there legitimate interest is available if you can pass the balancing test.
GDPROnly 17% of Product Hunt launches ask when they set tracking cookies
I scanned 458 products that launched on Product Hunt over 30 days in July and August 2026, loading each site from an EU location with an empty cookie jar. 292 stored tracking cookies, but only 50 of those (17%) did that after obtaining my consent. Filtering for EU based startups didn't improve this static significantly (26%).
GDPREmail tracking pixels need consent in France, even if you are not based there
Open-tracking pixels need the recipient's consent in France, wherever the sender is based. Two uses are exempt, securing a sign-in and checking deliverability, and only in emails the recipient asked for and only if the pixel records little more than the last-open date. Standard provider tracking records more, so it needs consent or switching off.
GDPRAn unsubscribe must stop marketing email from every tool you use, under EU and UK law
Under EU and UK law, every marketing email must offer a free, easy way out, and an opt-out has to take effect in every tool that sends the marketing it covers: the newsletter, CRM sequences and product email. Withdrawing consent must be as easy as giving it, so if one tick put someone on several lists, one step should take them off all of them.