Tracking is currently a hot topic in the US as well, where a different approach, labeled Do Not Track is being pursued. I happen to be at the thick of it, so I thought I'd add that to the discussion.
Do Not Track (http://donottrack.us/) is fundamentally an opt-out from tracking rather then an opt-in, which makes it much harder to claim that it will threaten the ad industry, startups, puppies, or anything else [1]. It is an HTTP header which, if enabled, signals to advertisers and other trackers to stop tracking you across multiple third-party websites. First-party tracking is OK.
The Do Not Track option has already been implemented in Firefox 4. As of yesterday it is an Internet-Draft[2], and on the legislation side, Congresswoman Speier recently introduced a bill to give the Federal Trade Commission powers to enforce Do Not Track.[3]
I'm a computer scientist and this is my first major foray into the policy arena, and having worked with most of the people/entities involved in this effort, I have to say I've been pleasantly surprised how the disparate parts of the technology/policy/regulatory machinery started to work together.
I don't want to get into which approach is better, but just wanted to describe how we're doing it in the US. Feedback welcome.
[1] http://cyberlaw.stanford.edu/node/6592
[2] http://cyberlaw.stanford.edu/node/6633
[3] https://speier.house.gov/index.cfm?sectionid=48&itemid=6...