ePrivacy Directive
The ePrivacy Directive is a European Union law that sets privacy rules specifically for electronic communications, covering areas such as cookies, unsolicited marketing emails (spam), and communications traffic data. It works alongside broader EU data protection rules rather than replacing them. Because it is a directive, its requirements are applied through the national laws of individual EU member states, so specific rules can vary from country to country.
The ePrivacy Directive (formally Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002) concerns the processing of personal data and the protection of privacy in the electronic communications sector. It establishes sector-specific rules addressing matters such as traffic data, unsolicited communications, and the storing of or access to information on terminal equipment (commonly associated with cookie consent requirements). As an EU directive, it is not directly applicable in the manner of a regulation; it requires transposition into national law by member states, so implementation and enforcement can differ across jurisdictions. It is generally treated as lex specialis that complements broader EU data protection law rather than superseding it. This entry defines scope and origin only; it does not detail the directive's specific article-level obligations, its interaction mechanics with the GDPR, cookie-consent implementation standards, national transposition variations, or enforcement and penalty provisions, which fall outside this definition. Note also that developments such as the European Electronic Communications Code have affected the directive's application to certain services; readers should consult current authoritative texts for exact requirements.
Why it matters
The ePrivacy Directive matters because it governs privacy in a sector, electronic communications, where much everyday personal data processing actually occurs, including web tracking, direct marketing, and communications traffic data. For organisations operating in or targeting the EU, the directive is often the instrument that determines whether practices such as setting cookies or sending unsolicited marketing emails are permissible, and it does so through rules that are specific to this sector rather than through general data protection principles alone. Overlooking it is a common expert-level error, because teams sometimes assume that broader EU data protection law covers everything, when in fact sector-specific requirements apply in parallel.
Who it's relevant to
Inside ePD
Common questions
Answers to the questions practitioners most commonly ask about ePD.