EU Digital Omnibus: Are Cookie Banners Actually Going Away?

TL;DR The Digital Omnibus was supposed to kill the cookie banner. The browser signal that would have done it was cut from the Council text in June 2026. What survives is a six month memory for refusals and consent rules moving into the GDPR. Here is what changes and what does not.

For most of the past year the answer people wanted was yes. The European Commission's Digital Omnibus proposal contained a mechanism that would have let your browser carry your cookie preference for you, so websites would stop asking. Headlines were written. Cookie banner obituaries were drafted.

That mechanism is no longer in the Council's text. The rest of the package is still moving, and it does change things, just not the part everyone was watching.

Will the Digital Omnibus get rid of cookie banners?

No, not in the version currently on the table. The article that would have required websites to read a browser level consent signal was removed from the Council's compromise text in June 2026. Banners stay. What changes is how consent works underneath them, and how long a refusal has to be respected.

Worth being blunt about this, because a lot of advice published earlier in 2026 assumed the opposite. If you postponed a consent project because banners were going away, that assumption no longer holds.

What is the Digital Omnibus, in one paragraph?

It is a package the European Commission proposed in November 2025 to simplify the EU's digital rulebook, bundling amendments to the GDPR, the ePrivacy Directive, the Data Act and several other instruments into one legislative vehicle. The Commission framed it as cutting administrative cost for businesses. You can follow its progress on the European Parliament's legislative train tracker, and the Commission's own announcement of the package sets out the intent.

The cookie part is a small slice of a very large proposal, which is part of why it has been traded away so easily in negotiation.

What does Article 88a change for cookie consent?

Article 88a moves the rules on storing and reading data on a user's device out of the ePrivacy Directive and into the GDPR itself. It requires that refusing a consent request takes a single click, and that once someone refuses, you cannot ask again for the same purpose for at least six months. Enforcement consolidates under data protection authorities.

Two of those are practical changes you can feel. Single click refusal formalises what the EDPB already expected, so a compliant banner today probably already satisfies it. The six month memory is the genuinely new obligation, and it is the one most existing setups would fail, because plenty of tools re-prompt after 30 or 90 days by default.

The exemptions are narrower than the headlines suggested. Aggregated audience measurement gets an exception, but only where a service measures its own audience. Analytics that shares data with third party platforms or feeds an advertising ecosystem stays consent dependent, which covers most real world Google Analytics setups. IAPP's analysis of the package is a good read if you want the detail.

What happened to the browser consent signal?

Article 88b was the interesting one. It would have required websites to accept a machine readable consent preference sent by the browser, with phase in periods measured in years. Set your preference once, in your browser, and stop being asked on every site.

According to reporting on the Council's fifth compromise text published on 18 June 2026, that article was removed entirely, with Germany, France and Poland among the member states pushing for it and heavy industry lobbying in the background. Industry estimates put the cost of browser level consent at 40 to 50 billion euros a year in lost advertising revenue, a figure privacy groups dispute.

Whatever you think of the lobbying, the practical read is simple. The mechanism that would have made banners unnecessary is out, and the obligations that make banners harder to run are in.

Does the ePrivacy Directive still apply?

Yes, for now. The Digital Omnibus does not formally repeal Article 5(3) of the ePrivacy Directive, which is the rule your national cookie law is built on today. That leaves a transitional period where national implementations and the new GDPR based framework could overlap.

In other words, nothing about your current obligations has changed. The rules you were following last month are the rules today.

When would any of this take effect?

The package is still in trilogue negotiation between the Parliament, Council and Commission, with a final vote expected later in 2026. After that comes entry into force and then transition periods. Nothing in it applies to your website right now.

Text also changes in trilogue. Article 88b was in the Commission's proposal and is out of the Council's position, and other provisions could move in either direction before a final vote. Treat any specific number in this post as the state of play in September 2026, not settled law. We are a consent platform, not your lawyers, and anything with real money attached deserves a proper legal read.

What should you actually do now?

Four things, none of them dramatic.

1. Keep the banner, and make it a good one

Banners are not going anywhere this decade. A banner with equal weight accept and reject buttons on the first layer already meets the direction of travel. Our guide to improving consent rates without dark patterns covers what that looks like in practice.

2. Check how long you store a refusal

This is the concrete homework. Find out what your current tool does when someone declines, and how soon it asks again. If the answer is 30 days, you are already out of step with where the rules are heading. Six months is a sensible default to move to now, and it costs you very little, because someone who refused last month was not going to accept this month either.

3. Be honest about your analytics exemption

If you were planning to lean on the audience measurement exception, check whether your analytics actually stays in house. Most does not. A quick look at which cookies require consent is a faster route to the answer than reading the recital.

4. Do not pick a platform that cannot adapt

The browser signal is out of this text, but the idea is not dead. Global Privacy Control already exists, some jurisdictions already require honouring it, and the concept keeps resurfacing. A platform where signal support is a config change rather than a rewrite is worth more than one that is optimised for today's rules only.

What does this mean for Norway?

Norway is in the EEA, so GDPR changes reach Norwegian law through incorporation into the EEA agreement rather than directly, which usually adds a delay. The cookie rule itself currently sits in the Electronic Communications Act. If consent rules move into the GDPR, the Norwegian implementation has to follow, and that takes time.

The practical answer for a Norwegian site owner is that nothing changes this year. Our GDPR compliance guide reflects the rules as they stand, and we will update it when there is something to update.

How we are preparing

Two things. Consentify already stores a refusal rather than re-prompting on a short cycle, so the six month rule is a setting rather than an architecture problem. And because consent decisions are recorded server side rather than only in a cookie, adding support for an incoming browser signal is a matter of reading one more input, not rebuilding how consent is stored.

That is not a prediction that browser signals are coming back. It is just what being ready looks like if they do.

The short version

  • Cookie banners are not going away
  • Consent rules are moving from ePrivacy into the GDPR, under Article 88a
  • Refusals will have to be remembered for at least six months
  • The browser level consent signal was cut from the Council text in June 2026
  • Nothing applies yet, and the text can still change before a final vote

If your banner is compliant today, you are in reasonable shape. If you are not sure whether it is, a free GDPR scan tells you what your site loads before anyone agrees, which is the part regulators actually look at.

Want a banner that keeps up with the rules instead of chasing them? Try Consentify free, one domain, no watermark, no time limit.
Free scan, no account

Does any of this apply to your site?

Find out in ten seconds. The scan shows which trackers fire before your visitors have agreed to anything.

  • Results in about 10 seconds
  • No account needed
  • Shareable report link

Frequently asked questions

Is the Digital Omnibus law yet?

No. As of September 2026 it is still in trilogue negotiation between the European Parliament, the Council and the Commission, with a final vote expected later in 2026. Nothing in it applies to your website today, and the text can still change.

Will I still need a cookie banner after the Digital Omnibus?

Yes. The provision that would have replaced banners with a browser level consent signal was removed from the Council's text in June 2026. Consent is still required before non essential cookies load, so the banner stays.

What is the six month rule?

Under the proposed Article 88a, once a visitor refuses consent for a purpose, you cannot ask again for that purpose for at least six months. Many consent tools currently re-prompt after 30 or 90 days, so this is the change most setups would need to make.

Does the Digital Omnibus apply in Norway?

Not directly. Norway is in the EEA, so GDPR changes are incorporated into Norwegian law through the EEA agreement, which normally adds a delay. Norwegian cookie rules currently sit in the Electronic Communications Act and would need to follow separately.

Free forever, no credit card

Get your cookie banner live in 5 minutes

Paste one script tag into your site and you're covered. No plugin to install, no code to write, nothing to pay.

  • 1 domain
  • 5,000 pageviews/mo
  • All integrations
  • GDPR, CCPA and ePrivacy
Start for free

No credit card. Free forever.

Compare plans
Written by Consentify
Helping you stay GDPR compliant, one banner at a time.