Digitalization & Data

Goodbye, Cookie Banners?

23/09/2026

WU researcher argues for privacy by architecture instead of cookie banners.

Cookie banners were designed to strengthen privacy, yet they often lead to “consent fatigue” rather than informed decision-making. With the European Union’s Digital Omnibus proposal, the future of cookie banners is once again under debate. Soheil Human, director of the WU Sustainable Computing Lab, argues that online privacy should be built into digital infrastructure rather than managed through endless pop-ups. The necessary technology, he argues, is already available today.

The problem with cookie banners

[Translate to English:] Portrait Soheil Human

© Dennis Parkash

For many internet users, privacy has become synonymous with clicking through endless consent requests. While cookie banners were introduced to give people greater control over their personal data, research shows that repeated requests often overwhelm users and encourage habitual acceptance rather than informed choices. According to WU researcher Soheil Human, the current consent model places an unrealistic burden on individuals. “People are expected to make countless privacy decisions every day, often without the time, context, or information needed to make informed choices,” he explains. “The real issue is not the cookie banner itself. The problem is that we still lack a standardized, user-centered infrastructure for communicating privacy choices online.”

A new approach to digital consent

To make this vision a reality, he proposes the Advanced Digital Protection Control (ADPC) specification, a technical standard that enables privacy preferences to be communicated automatically and in machine-readable form. Instead of repeatedly consenting to or refusing tracking on individual websites, users could manage their preferences through browsers, operating systems, apps, or other trusted tools, with online services required to respect those choices. “Privacy should be embedded as a standardized, rights-enabling layer of internet and software architecture. This is privacy by architecture,” says Human. Such a rights-first approach, he argues, could strengthen privacy rights, improve usability, and reduce compliance burdens for organizations. “If digital rights are to be meaningful, they need to be embedded into the architecture of digital systems rather than delegated to endless pop-ups and banners.”

The future of digital privacy in the EU

The ongoing debate around the European Commission’s Digital Omnibus proposal has brought the future of cookie banners back into the spotlight. While policymakers are exploring browser-level privacy controls as a way to reduce “cookie fatigue,” Human argues that the discussion points to a deeper structural challenge. Europe still lacks a shared privacy and digital rights infrastructure that allows people to exercise their rights effectively online. According to Human, the technological foundations already exist. “The question is no longer whether we can build rights-respecting digital infrastructure, but whether we are willing to make privacy and rights a fundamental layer of the digital environment,” Human says.

Further information

Human, Soheil (2026): A Rights-First Path to Privacy by Architecture: The Case for Advanced Digital Protection Control (ADPC). In: Privacy Technologies and Policy. 14th Annual Privacy Forum, APF 2026 (2026). Available at: https://doi.org/10.1007/978-3-032-35899-8_10

Back to overview