Lawmakers are generally hestitant to prescribe specific technological implementations because technology moves faster than laws. Imagine if radio spectrum regulations hadn't applied to wifi because they'd specifically specified TV/radio.
You can do this somewhat abstractly. By saying "when storing user data it must inform the user agent the purposes of that data using a standard mechanism". Then for http you can bless some RFC and the standard way.