If you don't want to be tracked. TURN. COOKIES. OFF.
There is a reason all web browsers come with per-domain cookies policies. We don't need a cookie law. We need some common sense. Everyone is looking to make this someone else's responsibility. Guess what: Your digital security and privacy is your responsibility. I hate this entire debate because:
1) Cookies serve a very, very valuable purpose in website development. Client-side storage is used in basically every major website on the internet.
2) This is hardly low-hanging fruit, and we have much, much bigger problems.
3) Who is the arbiter of what "allowed use" cookies are? We're going to have someone who actually decides, for individual websites, whether cookie use is proper or not? Is it going to work like a DMCA take-down request? An individual sends a request to review a website's cookie policies, and that IT department will have to submit a technical analysis and provide reasons for their cookie usage when a user feels their rights have been violated?
4) You know where this is going? Every single website that you register on is just going to give you a EULA-type agreement when you create an account. New to Facebook? Enter your username, click this checkbox that says "I accept your terms", and that's it.
Normal users will just roll with basically any terms you present to them. Making this entirely ineffective except for the small minority of people, like many here, who are hyper vigilante about digital privacy.
For the people this is meant to protect, they will likely never even think about it and opt-in anyway.
5) I completely reject the notion of getting politicians to dictate requirements to the tech industry in terms of how to handle the web stack. Let the politicians get back to blaming each other for X failures and make Y promises to the public, and get out of my internet.