Earlier quoted context omitted.
Well, yeah, but isn't the EU also responsible for all the trash cookie-consent notifications I get from every website now? Overall, I'm happy they're actively involved. The hands-off attitude in the US is terrible.
No, it's the builders of the consent notifications who are responsible for that. They are often skirting or even breaking EU law to make it a headache to refuse. The GDPR says, for example, that refusal should be just as easy as acceptance. Having to click to another screen to do that is... not that. In reality a cookie consent notification can just as well be a small widget somewhere with an accept and refuse button…
You don't need cookie popups! Really. You don't.
You only need to get consent to track users with software you don't run yourself. Or when you sell your data off to other companies.
Both are, unfortunately, the norm. But there's absolutely no technical reason to have these in place. Non at all. Plenty of alternatives for tracking that doesn't need consent. Or just not sell your customers' data off.
I would be infuriated if I found the bakery down the street is selling its security footage with my face on it, next to my sales and spending in that bakery. I'd expect them to at least warn me about this at the door. So I can then buy my bread elsewhere. That's what a consent banner is!