The EU’s GDPR, a landmark privacy regulation, was one of the best developments for the internet in a long time. The European Union’s General Data Protection Regulation (GDPR) came into effect in 2018, offering the strongest privacy protections in the tech sector ever. Although the regulation only applies to EU citizens, many tech giants decided it was easier to comply globally, so everyone benefited.
See also: Ireland: TikTok fined for GDPR violation

The heart of the GDPR includes four restrictions on the collection, storage and processing of personal data:
- There must be a specific, legitimate reason for processing the data
- Personal data must be encrypted
- You have the right to receive a copy of your data
- You can request the deletion of your data
Cookies are small text files that can be stored on devices to allow websites to track whether users have visited the website before and whether they have been exposed to an advertising banner for that website. While cookies can be useful, such as for recognizing repeat users and automatically logging them in, they can also be used for less ethical purposes.
See also: Digital Identity and GDPR: Compatibility and Challenges

Due to the potential for misuse and privacy breaches, GDPR requires websites to ask for consent to store cookies on devices, resulting in annoying pop-ups on almost every website a person visits. Many websites engage in malicious compliance by offering a choice between accepting cookies and managing them, often presenting a confusing series of options that pressure users to simply agree.
The EU has acknowledged that this practice does not provide consumers with a real choice, as most people click the accept button simply to dismiss the pop-up. Future regulations will allow users to set a single cookie preference in their browser, which all websites will have to respect.
Instead of clicking accept or reject in cookie pop-ups for every website they visit in Europe, users will be able to set their preferences at the browser level. The EU states: “People can set their privacy preferences centrally — for example via their browser — and websites must respect them. This will drastically simplify users’ online experience.”
See also: Germany wants to exclude Big Tech from the FiDA system

Additionally, companies will no longer need to ask for consent for innocuous uses, such as automatically logging users in when they have opted in. The new rules are expected to take effect sometime next year, with an interim change requiring websites to offer a simple yes/no option instead of the complicated options presented today.
