Germany’s Federal Commissioner for Data Protection and Freedom of Information (BfDI) has released new recommendations on cookie banners, backed by survey data that should surprise no one who has watched consent interfaces evolve over the past several years. Only 43 percent of German internet users say they clearly understand what cookies are and what they are used for. Sixty percent say they would reject cookies if they could do so with a single click.
What the Survey Actually Shows
The BfDI commissioned a nationwide representative survey as part of its Datenbarometer project. Beyond the low comprehension figure and the strong preference for one-click rejection, the results reveal clear demand for better tools. Sixty-six percent of respondents can imagine using a consent management service that lets them set preferences centrally and transmit them to websites. Seventy-one percent expect such a service to give them more control. Large majorities want their settings to apply across sites (83 percent) and dislike having to decide repeatedly on every individual page (81 percent). Seventy-eight percent also want these services to be reviewed and recommended by a public authority.
Germany already has a legal framework for consent management services under its Einwilligungsverwaltungsverordnung and has officially recognized a first provider. The BfDI sees this as a direction worth scaling at European level rather than leaving as a national experiment.
The Case for Machine-Readable Signals
The European Commission’s original Digital Omnibus proposal included a provision (Article 88b) that would have supported automated and machine-readable consent and objection signals. Users could have stored preferences in browsers, operating systems, or independent services and had those preferences communicated to websites. That language did not survive Council discussions. BfDI Commissioner Louisa Specht-Riemenschneider is now urging negotiators to put it back on the table.
“Germany has shown with its consent management regulation which direction is possible,” she said. “But we need a European solution. Especially on cookie consent, Europe could demonstrate what pragmatic data protection looks like. Leaving this topic out of the Digital Omnibus would be a missed opportunity.”
Machine-readable signals can reduce repetitive friction and help people who already know their general preferences avoid having to restate them on every visit. That is a legitimate usability and accessibility improvement. It does not, however, mean that a single universal preference should automatically govern every website in the same way.
Why a Single Universal Consent Mechanism Is the Wrong Goal
The strongest version of the “set it once and forget it” idea treats consent as a binary, portable switch that travels with the user across the entire internet. That model sounds elegant. It is also a poor fit for how data is actually used.
Websites differ dramatically in purpose, risk, and data practices. A news site that relies on advertising to remain free operates under different constraints than a banking portal, a health information service, or an e-commerce platform that needs certain functional cookies to complete a purchase. The same user may reasonably want different settings in those environments. A global “reject all non-essential” signal that overrides every site equally ignores those differences and collapses informed choice into a single blunt preference.
Cookie banners, when designed properly, force a moment of contextual decision-making. They surface the specific categories of cookies or tracking technologies in use on that site, the purposes attached to them, and the consequences of accepting or refusing. That site-level transparency remains valuable even if the current generation of banners is often poorly executed. Replacing the interface entirely with a universal signal risks removing the very information that makes consent meaningful.
The BfDI appears to recognize this tension. Its recommendations stress that any European rule should focus on the environments where attention fatigue and uninformed decisions are most common — primarily websites — and should not be expanded without clear need to every connected device. The authority also notes that consent management tools must still be capable of handling downstream processing, including profiling for advertising, in a way that remains compatible with the GDPR. In other words, centralization should support better decisions, not erase the need for them.
Banners Still Have a Job to Do
Criticizing bad cookie banners is easy and often justified. Many are designed to maximize acceptance rates through dark patterns, misleading hierarchies, or exhausting multi-layer options. Those designs undermine trust and fail the informed-consent standard.
Well-designed banners serve a different function. They create a visible, site-specific control point. They give users the chance to understand what a particular service is doing with their data in that moment. They also create an audit trail and a compliance artifact for the organization operating the site. Removing or fully automating that layer in favor of a single upstream preference would shift power toward intermediaries and away from the direct relationship between user and website.
There is room for both better interfaces and better technical signals. Machine-readable preferences can pre-populate or simplify banners. They can reduce the number of times a user has to confront the same decision. They should not replace the ability to make a different choice on a different site when the context warrants it.
Balancing Autonomy and Economic Reality
The BfDI is careful on this point. It argues that informational self-determination and legitimate economic interests should not be played against each other as zero-sum values. Any serious debate about stricter consent rules needs concrete evidence of how changes would affect advertising-funded business models and competition. Abstract claims in either direction are less useful than data.
That stance is realistic. Many valuable online services remain free to users because they are supported by advertising that depends on some level of data use. Pretending otherwise does not strengthen privacy. Designing consent systems that are clear, contextual, and technically interoperable does.
What Organizations Should Take From This
For companies operating in Europe, the signal from the BfDI is twofold. First, expect continued pressure to improve the quality of consent interfaces and to support emerging machine-readable preference standards if they are revived in the Digital Omnibus. Second, do not assume that the endgame is the disappearance of site-level consent in favor of a universal switch.
Practical steps remain straightforward: audit current banners for clarity and dark patterns, ensure rejection is as easy as acceptance, map which cookies and trackers are truly necessary, and prepare for the possibility that users will increasingly arrive with pre-set signals that still need to be respected and recorded in context. Investing in better banners is not a temporary compliance cost. It is a way of preserving informed choice in an environment that is moving toward more automation.
Germany’s data protection commissioner is not calling for the end of cookie banners. She is calling for banners and supporting mechanisms that actually work. A European framework that enables machine-readable preferences while preserving the ability to make different decisions on different sites would be an improvement. A framework that collapses every decision into one portable setting would not.