Encoding the usage of a particular (probably otherwise short-lived) technology in law is generally a pretty bad idea. Sure, have the EU write laws about cookies - the two outcomes are A) this becomes useless when people switch to a different tech stack that doesn’t use cookies B) we’re stuck using 30-year-old technology to try to get things done, at least for regulated industries like banking or government services. Like the IE regulatory situation in Korea but worse.