Cookie Banners Have a Climate Bill: The EU Omnibus vs the Notice Receipt Approach
Surveillance advertising broadcasts you to an estimated 200 servers on every page load. Digital identifiers are used as meta-data to digitally resolve your id before you even get a chance to learn about it. The notice-receipt approach is the lighter, treaty-backed alternative.
By Mark Lizar — Interoperability Expert Group (225IEG) / Transparency Lab
Every time you load an ordinary web page, an auction happens that you never see. Your presence, and a package of signals about you, is broadcast to an estimated 200 servers so they can bid, in real time, on the right to show you an advert. Multiply that by the number of pages loaded across the internet every second and you are looking at one of the largest continuous data-processing operations ever built. It runs day and night. It runs for people who never clicked "accept." And almost nobody has asked the obvious question: what does it cost the planet to run surveillance at that scale?
That is the question I want to put on the table. Not privacy as a values argument, though it is one. Energy. The surveillance advertising machine is a physical thing made of data centres, and data centres burn power. The way we have chosen to govern personal data has quietly committed us to running the most wasteful possible version of the internet.
There is a lighter way to do this. It already exists as a standard. And the choice in front of regulators right now, framed most sharply as the EU Omnibus versus the Notice Receipt approach, is a choice between preserving that machine and replacing it.
The machine you are paying to run
Real-time bidding is the engine of programmatic advertising. When a page loads, an ad exchange broadcasts a bid request describing the impression, and the audience, to a large fleet of bidders. Each one evaluates the request, decides what you are worth, and responds, all inside the fraction of a second before the page finishes rendering. The figure often cited is an estimated 200 servers touched per page load. I want to be honest about that number: it is an estimate that circulates in the industry, and it needs an independent, citable source before anyone should lean on it in a regulatory filing. But the direction is not in doubt. The architecture is designed to broadcast, and broadcasting is expensive.
Underneath the auction sits a second permanent cost: cookie syncing. Because every tracking company assigns you a different identifier, they spend an enormous amount of effort continuously matching their ID for you against everyone else's. This cross-domain reconciliation never stops. It is pure overhead, energy spent solely to keep a decentralised surveillance network's records aligned, producing nothing a person asked for.
And beneath that sits the third cost: the centralised databases. Profiles, identity graphs, consent logs held by intermediaries, all of it stored, replicated, queried, and defended around the clock. My working estimate is that something on the order of 90%-plus of this infrastructure exists not to deliver a service to you but to track you. I'll flag it plainly: that "estimated 90%+ tracking overhead" figure is not yet backed by a published methodology, and I say so deliberately, because I would rather advance a hedged claim I can later prove than an absolute one I cannot.
Put the three together, the broadcast, the syncing, the storage, and you have a system whose environmental footprint is dominated by the tracking, not the transaction.
The three vectors, and their very different footprints
It helps to see that there is not one way to govern personal data online. There are three, and they carry dramatically different environmental costs.
The first is personal control, where an individual holds and manages their own identifiers directly, peer to peer, with no central intermediary in the loop. This is the lightest footprint of the three. Nothing has to be broadcast or reconciled because there is no third party that needs to resolve who you are.
The second is the current data-protection model, which is where most of the internet sits today. Here your identity is resolved by third parties, continuously, through exactly the RTB, cookie-sync, and centralised-database machinery described above. This is the heaviest footprint, the estimated 90%-plus tracking overhead lives here.
The third is co-regulated use of digital identification through the exchange of a Notice Receipt: controller-identifies-first/public network facing, backed by public contorller-id registries, so an individual can verify who is accountable before any tracking begins. This is the pragmatic path, and my estimate is that it removes something on the order of 70 to 90 per cent of the energy the analogue data-protection model wastes online. Again, estimated, and again, easily an area of formal study.
The point is not that one number is exact. The point is the hierarchy is real: personal control is the most efficient, the current data-protection model is the most wasteful, and the Notice Receipt is the standards-based route from the second to something close to the first.
The black-boxed cost of user-ID-first authentication
There is a hidden driver underneath all of this that nobody names, so let me name it: user-ID-first authentication.
The entire surveillance model rests on identifying the individual before doing anything else. To identify you first, you need a vast, permanently running machine that almost never gets counted as an environmental cost: credential databases holding usernames and passwords, authentication services running OAuth, SAML and OpenID Connect, password-reset systems, session management, identity resolution, and a whole defensive layer built to fend off credential-stuffing attacks against all of it.
Every single login draws power. A database lookup, a token generated, a multi-factor challenge, none of it is free, and multiplied across billions of logins a day it becomes a standing energy load that we have simply decided not to look at. It is black-boxed: real, large, and invisible on every balance sheet.
Here is the part that should stop a policymaker cold. Much of that authentication machinery is legally standing on air. A great deal of it rests on tick-box acceptance of terms and conditions, and the courts have now told us that tick-box acceptance is not consent. A one size fits all policy model that is unregulated. So we are burning enormous amounts of energy to run identify-first infrastructure whose legal foundation has been knocked out from under it, managed increasing by ai and not people.
Controller-identified-first inverts the digital order to represent the physical order, what is expected by context and dissolves the whole extra infrastructure cost. The controller publishes who it is, in public, before it asks you for anything. You verify the controller first. Identity linkage happens only if and when you choose it. The default is anonymous, so most interactions never touch the heavy authentication stack at all. You do not need a black-boxed user-ID machine to run the internet. You needed it only because you insisted on identifying people before you would tell them who you were.
The recursive consent paradox, in plain terms
This brings us to the strangest flaw in the current model, and it is worth stating simply.
Two rulings frame it. In May 2025, the Brussels court, in the IAB Europe case, treated tick-box acceptance as a contract. Back in January 2023, the Meta / Facebook decision established that a contract is not the same legal basis as consent. Line those up and you get the trap: the tick-box is a contract, a contract is not consent, and therefore the consent foundation the whole advertising machine rests on is invalid.
It gets more circular still. The mechanisms sold to "manage consent" are themselves data intermediaries that need consent to operate, consent they obtain through the very tick-box that has just been ruled invalid. Consent infrastructure that requires consent to run cannot bootstrap itself. That is the recursive paradox.
The Notice Receipt breaks the loop by not needing consent to operate in the first place. The controller identifies itself publicly, at a well-known transparency address anyone can read. The individual verifies that controller before handing over a single piece of data. Consent, when it is given, is recorded in a bilateral receipt that both sides hold, generated after verification, not before. There is no paradox because the transparency layer never depended on consent to exist. It is just a fact you can read, like a shopfront sign.
Where the Notice Receipt comes from, and why it is credible
None of this is invented from scratch. The Notice Receipt has a lineage worth stating, because credibility here rests on standing, not novelty. It began as the Kantara Consent Receipt, was taken into ISO/IEC 29184:2020 as Annex B, was adopted as the technical specification ISO/IEC TS 27560:2023, was extended through the ANCR work on the authorisation exchange, and now takes the form of the ISO/IEC TS 27560 Notice Receipt Extension. That is a decade of standards work, not a manifesto.
It also has a treaty behind it. The Notice Receipt operationalises Council of Europe Convention 108+, the international data-protection treaty ratified by more than fifty states including EU members, Canada, and major Commonwealth nations. That matters because, unlike an EU-only instrument, a treaty gives you a legal foundation that travels. The Notice Receipt implements it directly: controller identification before collection (Article 8), proportionate and risk-based disclosure (Article 5), data-subject rights access and a notice event log (Article 9), records of processing (Article 10), and surveillance-risk disclosure on cross-border flows (Article 14). When a standard can point to a ratified treaty and name the articles it delivers, you are no longer arguing about opinion. You are arguing about implementation.
EU Omnibus, or the Notice Receipt
So here is the fork in the road. The EU Omnibus debate is, at bottom, a choice about whether to preserve the existing architecture or replace it. Preserving surveillance-by-default preserves its energy footprint: the broadcasts, the syncing, the databases, the black-boxed authentication, all of it kept running because the underlying model is left in place. I want to be careful here, because I have not seen a published environmental assessment of the specific Omnibus provisions, and I will not pretend one exists. What I will say is that any path which leaves the identify-first, broadcast-everything architecture standing also, by definition, leaves its estimated footprint standing.
The Notice Receipt is the transformative alternative rather than the incremental one. It does not tune the surveillance machine. It removes the reason the machine exists.
What decision-makers can do now
This is not theoretical, and it is not years away. There are concrete moves available today.
Regulators can require controllers to publish a Controller Identification Record at a public, well-known transparency endpoint; adopt the ISO/IEC TS 27560 Notice Receipt Extension as the reference for compliant notice; coordinate with Convention 108+ supervisory authorities so the approach travels across borders; and begin requiring environmental-impact reporting on data-processing infrastructure, so the energy cost of tracking finally shows up somewhere it can be counted.
Standards bodies can accelerate the review and uptake of the ISO/IEC TS 27560 work; support registration of the well-known transparency endpoint at the IETF so it becomes a stable, universal address; and build environmental-impact reporting into the standards themselves rather than treating it as an afterthought.
Enterprises can pilot controller-identifies-first architecture on a single new product, publish a Controller Identification Record as a public demonstration of transparency leadership, and, importantly, start measuring the energy their own authentication and tracking infrastructure consumes. You cannot manage what you refuse to look at.
Researchers can do the single most useful thing of all: build the methodology. Quantify, rigorously and independently, the energy consumed by RTB and cookie-sync infrastructure against the energy consumed by bilateral receipts. Develop carbon-cost models for digital transparency. Establish a "privacy impact label" so that, one day, a service's data architecture carries an energy rating the way a fridge does. When that study exists, the estimates in this article stop being estimates.
I have been careful throughout to hedge the numbers, because they deserve to be earned rather than asserted, and asserting transparency you cannot inspect is exactly the failure I spend my time fighting. But the shape of the argument does not depend on the last decimal. We built an internet that identifies you first, broadcasts you to hundreds of servers, and runs a permanent global machine to keep track of who you are, and we did it on a consent foundation the courts have now emptied out. There is a lighter architecture sitting on the shelf, backed by a treaty and a decade of standards. The question is no longer whether it works. The question is whether we are willing to stop paying to run the wasteful one.
Mark Lizar is the founder of the Interoperability Expert Group (225IEG) and Transparency Lab, and works on international standards for digital transparency, notice, and consent within ISO/IEC and Council of Europe processes. Contact: [email protected]
References
- ISO/IEC TS 27560:2023 (Notice Receipt / consent record) and the Notice Receipt Extension work
- ISO/IEC 29184:2020, Annex B (Consent Receipt lineage)
- Kantara Initiative Consent Receipt specification
- Brussels court ruling, IAB Europe (May 2025)
- Meta / Facebook decision (January 2023)
- Council of Europe Convention 108+ (Modernised Convention 108)