A Think Tank Says the Cookie Banner Isn't Working

If you've ever clicked "Accept All" on a cookie banner just to make it disappear, a new working paper from Bruegel, a Brussels-based economic think tank, suggests you're not alone, and that the system was arguably never designed to give you a real choice in the first place.

The paper argues that GDPR data consent, the legal mechanism meant to give European citizens control over how their personal data is collected and used, is in practice a "legal and technical fiction." While the General Data Protection Regulation requires that consent be freely given, specific, informed, and unambiguous, the researchers found that cookie banners routinely fail to meet that bar. Instead of clearly explaining what data is collected, who receives it, and why, most banners are built to nudge users toward quick acceptance rather than genuine understanding.

This isn't a fringe complaint. It's a direct challenge to one of the core assumptions underpinning EU data protection law: that ordinary people can meaningfully consent to complex data processing arrangements simply by clicking a button on a pop-up.

Why 'Consent' Rarely Means What You Think

The GDPR's consent requirement sounds straightforward on paper. Before a website can track you, share your data with advertisers, or build a profile of your browsing habits, it's supposed to ask permission in a way you can actually understand. In reality, cookie banners have become a kind of theater. Users are presented with dense legal language, pre-checked boxes, and interfaces designed to make "Accept All" the easiest path while burying the option to reject or customize settings several clicks deep.

This pattern isn't isolated to obscure corners of the internet. Even well-known consumer sites have faced scrutiny over how they structure consent. One recent example involved a popular online dictionary, dict.cc's sprawling consent banner, which listed more than 1,700 advertising and tracking partners behind a single consent request. The complaint filed over that banner illustrates the exact problem the Bruegel paper describes: it's technically possible to comply with the letter of GDPR while making genuine informed consent practically impossible. When a user is asked to evaluate over a thousand partners' data practices in a few seconds, "informed" consent stops meaning anything.

The scale of that example is unusual, but the underlying mechanics, vague disclosures, friction-heavy opt-outs, and defaults that favor data collection, are common across much of the web. The Bruegel paper's core argument is that this pattern isn't accidental. It's a predictable outcome of a legal framework that assumes users have the time, expertise, and attention span to parse consent requests that are, by design, difficult to parse.

What This Means For You

For everyday internet users in Europe, this research doesn't mean GDPR protections are worthless. The regulation has still forced companies to disclose more about their data practices than they otherwise would, and it gives regulators tools to investigate abuses after the fact. But it does mean you shouldn't treat a cookie banner as a meaningful checkpoint where your privacy is actually being protected in real time. Clicking "Accept" or "Reject" is rarely the moment your data becomes safe or unsafe. Much of the tracking infrastructure operates regardless of what box you check, and enforcement often only catches up months or years later.

That gap between legal consent and actual protection is exactly why privacy tools that operate independently of website-level agreements matter. A VPN won't stop a site's own tracking scripts, but it does limit what your internet service provider and network-level observers can see, and it can reduce the amount of identifying information tied to your browsing sessions. Browser extensions that block trackers, and privacy-focused browser settings, add another layer that doesn't depend on whether a company's cookie banner was designed honestly or not.

Practical Steps Worth Taking

Given that consent banners can't be fully trusted to reflect your actual privacy preferences, a few habits are worth adopting. Reject non-essential cookies whenever a genuine option is presented, even if it takes an extra click. Use browser settings or extensions that block third-party trackers by default rather than relying on site-by-site choices. Consider a VPN for an added layer of network privacy, particularly on public Wi-Fi or when accessing sensitive accounts. And when a consent banner feels deliberately confusing or lists an implausible number of "partners," as in the dict.cc case, that's a signal worth taking seriously rather than dismissing as boilerplate.

The Bruegel paper adds academic weight to something many users have long suspected: that GDPR data consent, as implemented across most of the web, doesn't function the way the law intended. Until enforcement or design standards catch up, the safest approach is to treat cookie banners as a formality rather than a safeguard, and to build your own privacy protections on top of them.