Let me know when you find a User Agent that can smack a CEO over the head with a virtual cluebat whenever he sells a list of email addresses that signed up to his site, because that's what the regulation is about and I certainly don't see how a UA could enforce it.
The user agent can refuse to store cookies, but it can't do much against supercookies (cookie-like features not knowingly implemented by the user agent programmers) or fingerprinting: you need something like legislation to curb practices like that.