Cookie control always should have been a browser control. The legal route always should have been to force it to be built into browsers that provide sane defaults, and make it illegal to circumvent what the browser declares as far as fingerprinting etc.
any sort of elevation prompt, IF I allow them to be popups or an icon in a toolbar, should always be in the same place and not cover the page.
They are asked _once_ during browser setup, same way on iOS users are asked once during setup if they want to allow Apps to track unique IDs (memory is hazy, they did that a couple years ago). And surprise surprise IIRC 96% of users said no.
Yeah I think it probably does mean you should be banned from asking in most cases. If you have a legitimate interest you don't need to ask. If you need to ask your interest is not actually legitimate and you know it.
Legitimate interest is not currently enough to read or write cookies. You need either consent or it must be "strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service." (or "sole purpose of carrying out the transmission of a communication over an electronic communications network", but that's harder to apply to cookies)
"legitimate interest" is legal basis in GDPR. ePD (which governs access to cookies) does not have such legal basis, only consent and the two exceptions.
Other processing (like after value is read) can happen under GDPR if the data is personal data.
My understanding is that ePD was obsoleted by GDPR.
Note that you don't comply with EU directives anyway - you comply with actual laws of actual countries, and the EU process helps them to mostly agree with each other. Did countries replace their ePD-based laws with GDPR-based laws? My understanding is they did.
No, it's not. ePD is lex specialis in relation to original Data Protection Directive (and later GDPR). DPD was replaced by GDPR, ePD was not. There has been talks about ePrivacy Regulation over the years, but it was shelved again in 2025.
ePD is still active and national laws implement it. GDPR itself is not implemented by national laws as it's EU regulation rather than EU directive. Member States primarily repealed their DPD-based laws after GDPR and implemented various things that GDPR allows (like Article 23 restrictions). Some countries may have explicitly imported GDPR into their own law due to how their own legalization works. Like that's why UK DPA was originally pretty much just copy of GDPR.
If people really cared, they’d choose browsers that have better control, but that’s obviously not a priority for them. Why do you think this sort of thing should be regulated to suit your preferences when most people don’t seem to agree with you?
Because everyone agrees - cookies banners are annoying and need to go away. Everyone is on the same page about this. The easiest way to make that happen is "move them into the browser".
How often do you get prompted for, say, secure DNS or HTTP? Almost never, because your browser has sane defaults and controls that. So, there you go.
I think that's a stretch. People can care, but be unwilling to spend the time researching it or accept the trade offs that come with small browsers (which are often unsupported for applications you might want to use).
There are many things someone might care about and at some point you have to prioritize. This topic in particular is practically a cold war where you always have to catch up on how things are, lest you loose it all. The required effort is disproportionate to the result.
any sort of elevation prompt, IF I allow them to be popups or an icon in a toolbar, should always be in the same place and not cover the page.