- Login cookies? No notification required.
- Tracking via fingerprinting? You need to ask.
- User says no to the tracking? You have to allow them to continue using your service.
It’s pure bullshit what most sites do, based on the UK interpretation of the cookie law. Luckily, that’s gone soon (both due to the EU GDPR, and due to Brexit)
https://www.howtogeek.com/166507/why-most-web-services-dont-...
There's a few startups working on platforms to make adding E2E encryption easier, but I doubt the EU is planning to mandate everyone use their services.
The plan sounds nice from a distance (who in tech is anti-encryption?) but closer inspection reveals problems. All legislation can do is ban certain activities. You want to release a new dating app, or add a basic messaging feature to your Q&A site, and you're not a crypto expert with 3 months to spend adding E2E encryption? Should it be illegal for you to release your app without encryption?