On November 19, 2025, the European Commission introduced the Digital Omnibus Package, a significant legislative proposal aimed at modernizing the General Data Protection Regulation (GDPR) and the ePrivacy Directive. For developers and site owners like myself, this represents a fundamental shift in how we manage user state and technical consent.

Below is a technical breakdown of the upcoming changes and how they impact the architecture of jasperbernaers.com.

A The technical evolution of consent: from UI to signal

The core objective of the reform is to address "consent fatigue" by moving away from repetitive UI-based interactions toward machine-readable signals.

1. Integration of article 88a and 88b (GDPR)

The proposal effectively absorbs cookie-related rules into the GDPR framework through two new pivotal articles:

Article 88b marks a paradigm shift: consent enforcement moves from the user interface layer to the infrastructure layer. A site that ignores a navigator.globalPrivacyControl signal will be in the same legal position as one that ignores a user's manual opt-out.

2. The new "whitelist" for low-risk cookies

To streamline web performance, the Commission has proposed a "whitelist" of situations that no longer require a consent prompt. These include:

Practical implication: Privacy-first analytics like Simple Analytics — which collect no personal data and use no cookies — fall squarely within the proposed whitelist. No consent banner required.

3. High-stakes enforcement

By moving these rules firmly under the GDPR, the maximum penalties for non-compliant tracking — such as firing tags before consent or using "dark patterns" — are now harmonized at 4% of global annual turnover or €20 million, whichever is higher.

The enforcement risk is no longer theoretical. Recent rulings from the Belgian DPA and France's CNIL have already fined organizations for asymmetric consent UI design. The Omnibus Package codifies these precedents into hard law.

B Implementation on jasperbernaers.com

To align with these emerging standards and current best practices from the EDPB Cookie Banner Taskforce, the technical implementation on this site follows these strict protocols:


Sources & Further Reading

Jasper Bernaers


More articles

Actionable Steps to Decrease Your Security Risk Practical cloud security steps deployable in hours — MFA, Defender for Identity, endpoint protection, DKIM/SPF. The Multi-Factor Authentication Struggle and the Solution Why MFA adoption is stalling and how to fix it across your organization. Microsoft is Delivering Automated Security Operations (SecOps) How Microsoft M365 E5 delivers automated SecOps for any organization. How to Build a Zero Trust Modern Workplace with Microsoft 365 A practical guide to deploying Zero Trust architecture with M365. Technical High-Level Modern Workplace Implementation with M365 E3/E5 A technical deep-dive into implementing a modern workplace with Microsoft 365. Top 10 Security Recommendations While Working From Home Essential security measures every remote worker and organization should apply.