Gonna arguably talk out of my ass here, but as far as I understand the law, it doesn't dictate implementation details. You have to get consent to keep any sort of persistent session state on your users that can be used to track their browsing behavior. It doesn't say you need to do this by offering a popup that itself stores a cookie saying you do or don't want other cookies, but you're largely guaranteed browsers will support displaying a popup banner. You're not guaranteed browsers will send a non-standard header. Doing this is in the scope of browser developers and the IETF, whereas GPDR is in the scope of lawmakers. One of those groups decided to act and the other did not.
Comments
Gonna arguably talk out of my ass here, but as far as I understand the law, it doesn't dictate implementation details. You have to get consent to keep any sort of persistent session state on your users that can be used to track their browsing behavior. It doesn't say you need to do this by offering a popup that itself stores a cookie saying you do or don't want other cookies, but you're largely guaranteed browsers will support displaying a popup banner. You're not guaranteed browsers will send a non-standard header. Doing this is in the scope of browser developers and the IETF, whereas GPDR is in the scope of lawmakers. One of those groups decided to act and the other did not.