This may be a stupid question. but I have not seen it discussed so I will ask it.
Cookies are already under the control of the end-user, why does the site operator need to ask/worry at all? if the user does not like the cookies can't they just delete them?