North End LawPublications · northend.law · Sergio Maldonado

LinkedIn · January 25, 2026

Combining Privacy Protection with a Smooth Internet Browsing Experience Through Built-in Opt-Out Signals

(You are reading a GenAI-free article, solely relying on auto-correct for some expressions and typos. A previous, longer version of this article was shared with Masters of Privacy subscribers. Image source: Canva)

During our recent live podcast recording session, we speculated about the potential of built-in browser signals to give us all back the smooth internet browsing experience we once enjoyed.

We definitely seem to be getting closer, but I wonder whether by the time we manage to properly address all of the possible legal scenarios (through user-controlled tools, as opposed to website-specific banners) the entire effort will be rendered futile by a higher, all-encompassing level of automation that condemns websites, interfaces, and even browsers, to obsolescence.

In any case, it is worth the analysis. As an initial goal, we are limiting our geo-jurisdictional scope to the EU, the UK, and the US (with California primarily in mind). This means that we need to cover both opt-out and opt-in scenarios.

As it affects the EU/UK perspective, opt-out scenarios are useful in the GDPR’s enforcement of a right to “withdraw consent” when previously given, but also as a means to decline it in the first place. As for California and other US jurisdictions, opt-outs must simply be respected in the context of targeted advertising.

Putting aside the specificities/anomalies of “very large online platforms” or “gatekeepers” related to targeted ads or cross-platform profiling (in the EU’s Digital Services Act and Digital Markets Act respectively) and news publishers (in the carte blanche to deploy a “consent or pay” choice), prior consent is currently required in the EU and the UK for any kind of data processing that involves reading or writing to or from the individual’s device (through the ePrivacy Directive and PECR(1) respectively).

Many US states will also revert to an opt-in regime when children, teenagers, or sensitive data categories are involved. Adding to this, and while the loophole remains, lawsuits filed under the California Invasion of Privacy Act (anti-wiretapping) are also forcing many data controllers to follow an opt-in approach for basic website optimization or session replay activities.

While the observance of opt-out choices has until recently been met through footer links, exclusion features and clear language, the need for express (or, more qualified, “explicit”(2)) consent requirements in the EU have given rise to the ubiquitous consent banner. Sadly, US websites have also started to deploy the pop-up in order to address the gaps mentioned above.

I will refrain from making the case against consent banners and Consent Management Platforms today, as I have already spent considerable time on the subject.

Enter the Global Privacy Control

As also many times discussed here, the GPC signal is now enabled by default in a few browsers and, thanks to California’s “Opt Me Out Act” (Assembly Bill 566), it will also be supported by Chrome, Edge, and Safari by January 2027. This represents a major milestone in automated privacy controls and individual agency - previous efforts under the P3P (Platform for Privacy Preferences) and DNT (Do Not Track) standards did not manage to overcome the obvious conflicts of interests and hidden complexity.

Given that some twelve state privacy laws now require compliance with a “universal opt-out signal”, US consumers will experience a level of consistency between data protection rights and actual website practices that, despite leading the charge, EU citizens have not yet enjoyed.

But that does not mean that the opportunity will be entirely missed in the old continent. In fact, a very strong case can be made for EU/UK institutions and supervisory authorities to seize it. After all, some of the challenges it presents are partially shared with the US regulatory framework.

Luckily, the EU Commission is aware. As part of its recent Digital Omnibus reform package, it proposed a change to both the GDPR and the ePrivacy Directive which could result in the enforcement of a single, machine-readable “reject-all” signal(3).

If we combine this with a simultaneously proposed exemption (from consent) for basic analytics purposes(4), pretty much aligned with the exceptions that some data protection agencies have been carving out for over ten years, we can find an even greater level of alignment with the US: both sets of ePrivacy rules are primarily concerned with targeted advertising and third parties (independent data controllers) at this point - with an important caveat: European companies using sophisticated pieces of Marketing Technology (e.g., a Customer Data Platform) will not be able to rely on the new exemption, even though such vendors act as data processors working on first-party data. The ever-present Google Analytics epitomizes this - however innocuous website stats are deemed, the tool’s deep integration with ad measurement and optimization on the search engine’s platform condemns its customers to obtain valid consent.

Fitting the square peg in the round hole

The most obvious problem with relying on a built-in opt-out signal is the absence of a tool to automate the opposite choice: an opt-in (as the absence of a clear “no” does not amount to an express, or an explicit “yes”). This does not appear to present a major challenge for consumers (I doubt that many will choose to put serious effort into consenting to profiling and targeted advertising), but it could seriously hamper the ability of many online services to make a living.

The problem is shared across all three jurisdictions. It concerns all data types and individuals in the EU or the UK, but it also affects special categories of data and minors in the US. If the only alternative is deploying a consent banner that can cover the missing angle, we will end up with a clash of two potentially conflicting signals.

Perhaps compelled by the needs of the advertising ecosystem (more about them below), Consent Management Platforms have been quick to assimilate GPC opt-outs as part of the overall consent workflow, thus avoiding inconsistencies or redundancies. But I wonder whether this is fair to consumers - consent banners are compliance tools entirely handled and configured by data controllers, whereas GPC signals provide far greater individual agency. Subsuming GPC signals within CMPs results, I would argue, in the dilution of this newly found level of empowerment in favor of the status quo: acceptance by inertia, consent for fear of further interruptions, convenience over control.

More importantly, ceding power to website-operated choice mechanisms will tip the balance in the very likely case of conflicting signals, which deserves separate analysis.

Battle of the signals

What do current laws say about potential conflicts? California’s CPRA regulations give opt-out signals like GPC precedence(5), although they allow the website owner to notify individuals of the conflict, offering them a choice to make up their mind.

Since the system has not yet been put into practice in Europe, no guidelines are yet available as to how to resolve such a scenario. However, it may very well be the case that the most recent time stamp takes precedence, and this will compel all website operators to double-down on consent pop-ups under the excuse of making up for the missing opt-in signal, in the hope of overriding pre-existing signals.

To make things more complicated, the EU’s commitment to supporting news publishers is now embodied in an unfortunate exception, mostly consistent with their “consent or pay” joker card: “The obligation [...] should not undermine the possibility for media service providers to request consent by data subjects” (Recital 46 of the Digital Omnibus, expanding on article 88(b)).

To ensure fairness in the resolution of this conflict (with data subjects in control and data controllers being forced to adapt to their pre-defined preferences), browsers should not only support GPC, but also allow for the deployment of additional tools discarding consent banners altogether (unless consumers are actively willing to engage with them or, why not, automate their express consent across the board). Many such tools have been made available in the past few years, mostly hoping to simplify browsing while automatically declining consent requests (e.g., the Consent-O-Matic extension or Brave’s built-in CMP filter). It is however possible that these systems overcompensate against a measured evaluation of the trade-offs by discerning consumers. And this is where the new IEEE P7012 standard (Machine-Readable Terms), “MyTerms”, could fit very nicely.

MyTerms expands the possibilities of user-defined preferences well beyond a binary opt-out signal. By forcing website operators to read an individual’s set conditions for the processing of their personal information, these could very well allow for certain kinds of personalized advertising or optimization tasks. However, nothing in the current EU, UK, or US legislative proposals suggests that it will be enforceable in the short term. A similar “clamp” would be required for it to work as intended: widespread technical support backed by legal consequences.

As a final, but important, obstacle, the advertising industry -mostly through the IAB- has already put considerable effort into standardizing the manner in which GPC signals are propagated through the AdTech chain. Although there is a system in place to communicate opt-out choices through much more constrained server-side calls, these choices have been assimilated into the IAB’s TCF (EU-centric Transparency and Consent Framework) and GPP (Global Privacy Platform). Both rely heavily on the use of consent banners - and this is only logical given how publishers maintain the first point of contact with their audiences and how they will be allowed to circumvent built-in signals in the EU. The same is true of Google, an ubiquitous actor in this market (in the form of a publisher, a set of AdTech building blocks, an analytics platform, and the leading browser - see below). The advertising giant has chosen to supervise compliance across its own stack through the CMP-enforced “Consent Mode”.

Conclusion

As Alan Chapell concluded last week, it remains widely optimistic to hope for the end of consent banners. It is clear that the current level of inertia, the widespread adoption of CMPs, the advertising industry’s reliance on their inner works, and the EU’s soft spot for publishers provide sufficient reasons for GPC signals, MyTerms policies and other user-centric mechanisms to never fulfill their promise. To all of these Alan added the very valid point of competition concerns: Why would Google-owned Chrome help dismantle a status quo that benefits them greatly?

At the end of the day, defaults matter. There is a considerable difference between being prompted during the browser’s initial installation to make a decision on third-party trackers and having to dig deeper in the browser settings to enable the GPC signal. There will not be wide adoption without convenience, and, in its absence, any discussion about conflicting signals or improved browsing experiences and better privacy is irrelevant.

We may have to wait for truly agentic browsers to shape content and features on the fly, rendering user interfaces, consent prompts or dark patterns obsolete. And even then someone, somewhere, will come up with an ingenious solution to ensure that individuals consent to third party data processing.

But I am sure that we can hope for it all to be much safer and less intrusive over time: we need some data to make advertising work (here’s where non-marketers start pontificating about contextual ads...), and everyone is getting smarter about doing more with less - the whole point of differential privacy and other Privacy Enhancing Technologies.

Would that not be a balanced outcome? Advertisers, publishers and platforms being able to rely, by default, on mostly anonymous or aggregated data to ensure relevance, performance, and competition (by opening ad inventory to smaller, niche or local suppliers). Individuals empowered with a choice to make more or less precise information available to them, in their own terms, in a single place and for all websites. And everybody relieved of the yoke of consent pop-ups: insufferable for users and practically impossible for companies to maintain in full technical or regulatory compliance.

Thoughts?

Additional context

  • Should you care, I published a first iteration of these ideas back in November (“An opt-out that beats the opt-in at its own game”), in the context of widespread adoption of EU-style CMPs in the US.
  • Definitely worth reading: “Can the GPC standard eliminate consent banners in the EU?” (December 2025, by Sebastian Zimmeck, Cristiana Santos , Harshvardhan J. Pandit, Frederik Zuiderveen Borgesius, Konrad Kollnig, Robin Berjon). Especially interesting: an exploration on how the GPC standard could be applied to other GDPR legal bases (legitimate interest, contractual).

Footnotes

(1): Privacy and Electronic Communications Regulations 2003 - these restrictions remain in place after the UK Data (Use and Access) Act 2025 (DUAA).

(2): The GDPR imposes the higher “explicit” standard (beyond the default “express” consent requirement) on very specific scenarios: a derogation for international data transfers (exceptional, in the absence of adequacy or appropriate safeguards); the processing of special categories of data; and automated individual decision‑making, including profiling, with legal or similarly significant effects.

(3): Specifically, the proposed article 88b would support “a standardized, machine-readable signals (like browser settings or icons) that automatically convey a user's consent or refusal for personal data processing on websites and apps, requiring controllers to implement interfaces that honor these choices for a set period, moving beyond traditional "cookie banners" to a more integrated, automated system for managing data preferences”. Recital 46 explains it in greater detail, starting with the following statement: “Data subjects should have the possibility to rely on automated and machine-readable indications of their choice to consent or refuse a consent request or object to the processing of data.”

(4): Article 88a.3) in the same proposal (Digital Omnibus - GDPR updates): “Storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person without consent, and subsequent processing, shall be lawful to the extent it is necessary for any of the following: [...] c) creating aggregated information about the usage of an online service to measure the audience of such a service, where it is carried out by the controller of that online service solely for its own use."

(5): 11 CCR § 7025(c)(3): "If the opt-out preference signal conflicts with a consumer's business-specific privacy setting that allows the business to sell or share their personal information, the business shall process the opt-out preference signal as a valid request to opt-out of sale/sharing, but may notify the consumer of the conflict and provide the consumer with an opportunity to consent to the sale or sharing of their personal information."

© Sergio Maldonado. Originally published on LinkedIn. Republished by North End Law Corporation with the author's permission. Informational only; not legal advice.