EU Council Draft Cuts Cookie Re-Ask Wait to Four Months

Affiliate disclosure: This post contains affiliate links. If you buy through them, I may earn a commission at no extra cost to you. Full disclosure

EU governments are weighing a draft that would shorten the wait before websites can re-ask visitors who refused cookies from six months to four.

According to PPC Land’s October 10 report on Council document 13886/26, ambassadors take the text up on Sunday, October 11. If you sell to European shoppers from a Shopify store, the number decides how often your consent banner reappears and how many of your retargeting audiences you can refill. If you ship only inside the US, almost none of this touches you today.

This is the kind of rule change that moves ad-audience size without anyone emailing you about it. At Ecommerce Paradise I track these because a banner setting quietly shapes your Meta and Google Ads numbers. Below is what the draft says, how the six-month figure became four, what it does to a store owner’s math, and five checks to run this week. I am not a lawyer, and nothing here is legal advice.

Selling into Europe starts with a clean legal entity, so form your LLC with Northwest Registered Agent, the best LLC formation service for ecommerce owners. You pay the same renewal price as year one, unlike cheap formation mills that bury upsells in year two. Form your LLC with Northwest →

EU Council Draft Cuts the Cookie Re-Ask Wait to Four Months

The draft sits in Council document 13886/26, a 163-page text marked LIMITE and dated October 2, according to PPC Land. After a visitor refuses cookies for a given purpose, a site would have to wait four months before asking again. The Commission’s November 19, 2025 proposal and the Irish Presidency’s September 3 text both said six months, per the same report.

The draft carves out exceptions in recital 45. A site can ask sooner after launching a new service, after making substantial changes, or after losing the record of a refusal, for example when the visitor deletes cookies.

It also adds a new consent-free purpose. Cookies could be placed without consent to measure how contextual advertising is displayed and performs, as long as the data is pseudonymised, not used for profiling or programmatic buying, and not linked to a visitor’s past or future activity. The recital names frequency capping and measurement cookies, according to PPC Land.

Three other pieces matter for the shape of the rule:

First, the centralised browser refusal signal, Article 88b in the Commission’s proposal, is gone. The Council removed it in June. Second, Article 18 of the draft asks the Commission to report on privacy-enhancing technologies within 12 months of adoption. Third, PPC Land reports the cookie rules stay in Article 5(3) of the ePrivacy Directive, not the GDPR as the Commission proposed, with member states designating their GDPR supervisory authorities to enforce them and 24 months allowed for transposition after adoption.

That third point conflicts with earlier coverage. Sealmetrics’ explainer, last updated September 21, describes the rules moving into the GDPR as a new Article 88a. The October 2 text appears to have reversed that placement, but the draft is not public, so I am relying on PPC Land’s reading of it.

The vote itself is unsettled. A Coreper meeting on October 7 ended without a vote, per PPC Land. Fabien Lehagre, a HomeServe France executive, attributed that failure to the Data Act chapter of the package rather than to cookies. MLex reported on October 5 that the draft would shorten the repeat-request wait, though its full text is paywalled.

The same draft carries wider GDPR changes: a narrower definition of personal data, a legitimate-interest basis tied to AI, and breach notification moving from 72 to 96 hours for high-risk breaches only. If you ever handle a customer-data incident, that last one is real money and real exposure. My coverage of the ASOS breach through customer messaging platforms shows how fast that clock matters.

Digital Omnibus Cookie Rules: From a Six-Month Ban to Four

The Commission published the Digital Omnibus on November 19, 2025. As summarized by iubenda on December 23, it proposed equal-weight accept and reject buttons, a central browser or operating-system privacy switch, and no repeat request for at least six months after a refusal. It also floated consent exemptions for security and basic, first-party, aggregated audience measurement.

The fight was over the browser switch. The Council’s fifth compromise text on June 18 dropped Article 88b, which would have required sites to honor machine-readable consent signals. PPC Land reported on June 28 that a study called “Gone in one click,” produced on behalf of Google by Implement Consulting Group, estimated browser-level consent would cut consent rates by 60 to 65 percent. That, the study said, would cost European businesses 40 to 50 billion euros a year in advertiser revenue.

The privacy side rejected those figures. According to the same report, noyb said Germany, France and Poland pushed for removing Article 88b, and called the Google-linked paper’s numbers “completely far-fetched.” Max Schrems, chair of noyb, said: “Cookie banners are not an invention of data protection, but of the tracking industry.”

The ad industry fought on a second front. Alliance Digitale asked on May 21 for the repeat-request ban to be deleted entirely. It did not get that, but it got a shorter interval, per PPC Land. The EDPB and EDPS had gone the other way in a February 11 joint opinion supporting an automated consent signal, according to PPC Land’s June report.

Enforcement did not pause while Brussels argued. The CADE Project summary points to EDPB Binding Decision 1/2026, which came out of a noyb complaint about the cookie banner of Belgian public broadcaster VRT. It says the decision adds no new substantive consent requirements and mostly changes how complaints are handled. Current obligations stand: non-essential cookies still need valid consent, and refusing must be as easy as accepting, according to GDPR Local’s June 24 guide.

Counterpoint: the shorter wait is a win for advertisers on paper and a loss for privacy groups, but the coverage I found treats the browser signal as the main fight, and that one is dropped for now. The European Parliament has not published a position on Article 88b, so it could return in trilogue.

What Four-Month Cookie Consent Means for EU-Facing Stores

My read is that this change is smaller than the headline suggests. A refuser who comes back between month four and month six gets one extra prompt. That is a nudge, not a new tracking permission.

Here is hypothetical math, labeled as such. Say your store sees 10,000 EU visitors a month and 60 percent refuse tracking at the banner. That is 6,000 refusers. If 1,000 of them return after month four and 5 percent say yes on the second ask, you gain 50 tracked visitors you did not have. On a high-ticket store with a 1 percent conversion rate and a $2,000 average order, those 50 people are worth about $1,000 in expected revenue before ad costs. Real, but not a plan.

The bigger variable is the one nobody is voting on this week: how many people refuse in the first place. A banner with a hidden reject button gets you consent you cannot defend. The cheapest way to protect your audiences is a banner that treats accept and reject equally, because that is already the standard, per GDPR Local. If you want a tool that handles that setup, I walked through how to set up Termly for an ecommerce store. Termly is my redirect for a cookie consent platform.

The contextual-ad measurement exemption is mostly a publisher story. My read is that your Meta pixel and Google tag are not contextual ad measurement. They are cross-site tracking that still needs consent. The aggregated first-party analytics exemption floated in the Commission’s version would help, but Sealmetrics notes that GA4 would likely still need consent because it sends data to Google and builds individual profiles. I’d treat the contextual exemption as irrelevant to a store owner and the analytics question as unresolved.

For retargeting, the pain point is audience size. If a large share of your EU traffic refuses, your Meta past-buyer exclusions and AI ad tests run on thinner data. Paid clicks are not getting cheaper either, as my breakdown of ChatGPT ad click costs at six times Google’s showed. When tracked audiences shrink and click prices rise, owner-controlled channels carry more weight. Email is the obvious one, and the flows every store should have running work without a third-party cookie.

Scenarios and thresholds, because stores differ:

If EU visitors are under 5 percent of your traffic, a banner fix and a policy check are enough, and the vote changes nothing you do. If they are 5 to 20 percent, you have a real audience-size issue and should audit tags before Q4 spend peaks. If they are above 20 percent, you are an EU-facing business, and consent design belongs in your conversion work next to your Google tag and GTM container setup. Those cutoffs are my rule of thumb, not a legal test.

US-based owners should keep the other side in view. State privacy and tracking rules carry their own risk, which is why I wrote about California’s SB 690 and pixel lawsuits. The same pressure shows up in FTC and state scrutiny of personalized pricing. The pattern across all of them is the same: regulators care less about what you collect than about whether you can show a clean consent record.

That is the part that gets heavy for a solo operator. Banner, tag stack, email consent, privacy policy, checkout apps, and the legal entity behind it all have to line up. Shopify keeps adding automation, such as automated store policies, but you still own the result. If you would rather not run that compliance layer yourself, my team builds and runs the whole high-ticket store through the turnkey done-for-you service.

Want to work through your banner, tags and EU traffic with other store owners and me inside the community? Join the Skool community →

Cookie Banner Checklist for Shopify Stores Before the Vote

Nothing here needs to wait for Brussels. Run these five checks this week:

  1. Pull your EU share. Open your Shopify analytics, filter sessions by country for the last 90 days, and write down the EU percentage. That number tells you which of the three scenarios above you are in. Cross-check where your organic landing pages draw visitors with SEMRush.
  2. Test your banner like a regulator would. Reject must sit one click away with the same visual weight as accept, and nothing can be pre-ticked. If you want a managed fix, the Termly setup guide shows the settings, and the cost comparison in TermsFeed pricing shows the alternative.
  3. List every tag that fires behind the banner. Meta pixel, Google tag, TikTok pixel, heatmaps, chat widgets. Confirm each one waits for consent, and if your Google tag now runs as a GTM container, check the consent settings there first.
  4. Keep email consent separate from cookie consent. A shopper who refuses cookies can still opt in to email, so make sure your signup form records that choice in Klaviyo or Omnisend. Log it in your CRM too if you use HubSpot.
  5. Set a reminder to check the outcome of the October 11 ambassador talks, then the Parliament position. Do not rebuild anything until a text is adopted, and book a discovery call if you want a second set of eyes on your setup.

Frequently Asked Questions

Is the four-month rule law yet?
No. It is a Council working draft. Ambassadors are expected to take it up on October 11, the Parliament still has to agree, and PPC Land reports 24 months for transposition after adoption.

Does this apply to my US-based Shopify store?
Only if you target or track visitors in the EU. A store that ships only within the US has little exposure to this rule, though state rules like the ones in my SB 690 post can apply. Ask a lawyer about your facts.

Do I need a cookie banner today?
If you serve EU visitors and use non-essential cookies, current rules require valid consent, per GDPR Local. A tool like Termly covers the mechanics, but compliance still depends on how you configure it.

Does the draft help my Meta pixel or Google Analytics?
No. The new exemption covers contextual ad measurement with pseudonymised data and no profiling, and the analytics exemption in the Commission’s version would not cover Google-hosted profiling, per Sealmetrics.

What happened to the browser-level consent signal?
The Council dropped Article 88b on June 18. The Parliament has not published a position, so it could come back in negotiations, according to PPC Land and GDPR Local.

Does EU exposure change which niche I should pick?
For most high-ticket stores selling heavy goods inside the US, no. My read is that heavy-goods freight and returns keep most of them domestic. The high-ticket niches list helps you pick categories that ship domestically. My free niches resource goes further.

Should I redesign my banner now to prepare?
Fix reject parity and tag gating now, since both are required today. Hold the rest until a final text exists.

Want my team to build and run your high-ticket store, consent setup included? See the turnkey done-for-you service →

That is the one to watch tonight and tomorrow. If ambassadors sign off on October 11, the next stop is the Parliament. Subscribe to the YouTube channel for daily breakdowns. More breaking news coming through the day.

Related Articles

If this was useful, these go deeper:

Free 1,000+ high-ticket niches list

Still deciding what to sell?

Grab the free list of 1,000+ niches that work for high-ticket dropshipping, sorted by category.

Free. Unsubscribe any time.