Skip to main content
Category: Privacy Regulations

ePrivacy Directive

Also known as: ePD, Directive 2002/58/EC, EU ePrivacy Directive
Simply put

The ePrivacy Directive is a European Union law that sets privacy rules specifically for electronic communications, covering areas such as cookies, unsolicited marketing emails (spam), and communications traffic data. It works alongside broader EU data protection rules rather than replacing them. Because it is a directive, its requirements are applied through the national laws of individual EU member states, so specific rules can vary from country to country.

Formal definition

The ePrivacy Directive (formally Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002) concerns the processing of personal data and the protection of privacy in the electronic communications sector. It establishes sector-specific rules addressing matters such as traffic data, unsolicited communications, and the storing of or access to information on terminal equipment (commonly associated with cookie consent requirements). As an EU directive, it is not directly applicable in the manner of a regulation; it requires transposition into national law by member states, so implementation and enforcement can differ across jurisdictions. It is generally treated as lex specialis that complements broader EU data protection law rather than superseding it. This entry defines scope and origin only; it does not detail the directive's specific article-level obligations, its interaction mechanics with the GDPR, cookie-consent implementation standards, national transposition variations, or enforcement and penalty provisions, which fall outside this definition. Note also that developments such as the European Electronic Communications Code have affected the directive's application to certain services; readers should consult current authoritative texts for exact requirements.

Why it matters

The ePrivacy Directive matters because it governs privacy in a sector, electronic communications, where much everyday personal data processing actually occurs, including web tracking, direct marketing, and communications traffic data. For organisations operating in or targeting the EU, the directive is often the instrument that determines whether practices such as setting cookies or sending unsolicited marketing emails are permissible, and it does so through rules that are specific to this sector rather than through general data protection principles alone. Overlooking it is a common expert-level error, because teams sometimes assume that broader EU data protection law covers everything, when in fact sector-specific requirements apply in parallel.

Who it's relevant to

Data protection officers and privacy leads
DPOs and privacy leads whose organisations operate in or target EU markets need to account for the ePrivacy Directive as sector-specific rules that apply alongside broader EU data protection law, not in place of it. Because the directive is transposed into national law, obligations can differ across member states, so DPOs should consult current authoritative national texts rather than assuming a single uniform standard.
Marketing and digital teams
Teams responsible for cookies, web tracking, and email marketing are directly affected, as the directive addresses the storing of or access to information on terminal equipment (commonly associated with cookie consent) and unsolicited communications. This entry does not set out the specific implementation standards, which vary by national transposition and should be checked against current requirements.
Legal and compliance professionals
Legal and compliance staff should note that the directive is generally treated as lex specialis complementing broader EU data protection law, and that developments such as the European Electronic Communications Code have affected its application to certain services. This entry defines scope and origin only and does not cover article-level obligations, interaction mechanics with the GDPR, or enforcement and penalty provisions.

Inside ePD

Directive instrument (not a regulation)
The ePrivacy Directive is an EU directive, meaning it sets out obligations that individual EU Member States must transpose into their own national laws. As a result, the precise wording, scope, and enforcement of its requirements typically vary from one Member State to another, unlike a directly applicable regulation.
Confidentiality of communications
It addresses the confidentiality of electronic communications and related traffic data carried over public communications networks and publicly available electronic communications services, generally requiring that interception or surveillance not occur without a lawful basis under applicable national law.
Rules on terminal equipment access (cookies and similar technologies)
It contains provisions governing the storing of information on, or gaining access to information already stored on, a user's terminal equipment, commonly the legal foundation cited for consent requirements around cookies and similar tracking technologies in the EU.
Traffic and location data handling
It sets conditions on the processing of traffic data and location data generated by the use of electronic communications services, addressing when such data may be retained or used and when it should be erased or made anonymous.
Unsolicited communications (marketing)
It addresses unsolicited electronic communications for direct marketing purposes, generally establishing rules around prior consent or, in limited circumstances, existing customer relationships, as transposed and interpreted at the national level.
Relationship to the general data protection regime
It operates alongside the broader EU data protection framework and is generally treated as lex specialis for the electronic communications matters it covers, meaning its specific rules take precedence in those areas while the general regime continues to apply elsewhere.

Common questions

Answers to the questions practitioners most commonly ask about ePD.

Is the ePrivacy Directive the same thing as the GDPR, or has it been replaced by it?
No. The ePrivacy Directive and the EU GDPR are distinct instruments that operate alongside each other. The ePrivacy Directive addresses privacy and confidentiality in electronic communications specifically, while the GDPR is the general framework for processing personal data. Where both could apply, the ePrivacy Directive is generally treated as the more specific rule (lex specialis) for matters it covers, such as the confidentiality of communications and the use of storage or access on a user's device, while the GDPR continues to govern the broader personal data processing that may follow. The GDPR did not repeal the ePrivacy Directive. Note that transposition into national law and enforcement details differ across Member States, and this answer does not cover the proposed ePrivacy Regulation or its status.
Does the ePrivacy Directive only apply to cookies?
No. Cookies are the most widely discussed application, but the Directive's provisions on storing information on, or gaining access to information already stored in, a user's terminal equipment are worded in a technology-neutral way and can extend to comparable techniques beyond traditional cookies. The Directive also covers matters such as the confidentiality of communications and rules relevant to unsolicited electronic communications. Treating it purely as 'the cookie law' understates its scope. This answer does not detail every provision or how each is transposed nationally, and specific obligations depend on the applicable national implementing law.
When do we need consent before placing cookies or accessing information on a user's device?
The Directive generally requires consent for storing or accessing information on a user's terminal equipment, subject to limited exemptions typically recognised for what is strictly necessary to provide a service the user has requested or solely to carry out transmission of a communication. Whether a particular cookie or technology falls within an exemption depends on its purpose and on the applicable national implementing law. The standard and mechanics of consent are generally read in light of the GDPR's consent requirements where personal data is involved. This is not a determination for any specific tool, and you should assess each identifier or technology against its actual purpose.
How does the ePrivacy Directive relate to the consent standard we already apply under the GDPR?
Where the ePrivacy Directive requires consent, that consent is generally interpreted by reference to the meaning of consent under the GDPR, so practices such as pre-ticked boxes or implied consent are typically not sufficient. In practice this means a single, consistent approach to obtaining and evidencing consent can serve both, but the legal trigger differs: the ePrivacy requirement is tied to storing or accessing information on the device, while the GDPR governs the subsequent processing of any personal data. Organisations should be able to demonstrate how consent was obtained. This answer does not address which lawful basis applies to downstream processing, which must be assessed separately.
Which team should own compliance with the ePrivacy Directive, governance or security?
Responsibility typically spans both. Governance functions generally own the policies, purposes, cataloguing of identifiers and technologies in use, and the accountability evidence, while security and engineering functions implement the technical controls and the consent mechanisms. Legal or the data protection function usually determines how the applicable national implementing law is interpreted. The point is coordination without collapsing the distinction: governance defines what is permitted and documents why, and technical teams enforce it. Accountability here means being able to show demonstrable evidence of how decisions were made and applied, not merely a stated intention to comply.
Because implementation is national, what does that mean for a business operating across multiple Member States?
The ePrivacy Directive is a directive, so it takes effect through each Member State's national transposing law rather than applying uniformly of its own force. As a result, specific requirements, exemptions, and enforcement practices can vary between countries, and a compliant approach in one Member State is not automatically compliant in another. Organisations operating across several jurisdictions generally need to map the relevant national implementing laws for each market rather than assume a single EU-wide rule. This answer does not cover cross-border enforcement mechanics, the identity of competent authorities, or any penalties, which are set at national level and should be confirmed locally.

Common misconceptions

The ePrivacy Directive is the EU cookie law that applies uniformly across the EU.
It is a directive, so its cookie-related and other requirements must be transposed into national law by each Member State. The practical rules, consent standards, and enforcement therefore differ between countries rather than being uniform.
The ePrivacy Directive has been fully replaced by the general data protection framework.
The two operate together. For the electronic communications and terminal-equipment matters it covers, the ePrivacy Directive generally applies as the more specific instrument, while the general data protection regime continues to govern other processing. This entry does not resolve how any specific overlap should be interpreted in a given jurisdiction.
Complying with cookie consent under this directive alone guarantees lawful processing of the resulting personal data.
Obtaining consent for storing or accessing information on terminal equipment does not by itself establish that all downstream processing of any personal data collected is lawful. Separate obligations under the general data protection framework may still apply, and compliance depends on jurisdiction and implementation.

Best practices

Confirm the specific national transposition law applicable to each Member State in which you operate, rather than assuming a single EU-wide standard, because the directive's requirements vary by country.
Map which of your activities fall under the directive's specific areas (confidentiality of communications, terminal-equipment access, traffic and location data, direct marketing) and treat those under the applicable national ePrivacy rules.
Distinguish the terminal-equipment consent question (governed by the ePrivacy rules) from the separate lawfulness of any personal data processing that follows, and address each obligation on its own terms.
Maintain demonstrable evidence of how consent for cookies and similar technologies is obtained and recorded, since accountability generally requires evidence rather than stated intent.
Coordinate with legal counsel where the ePrivacy rules and the general data protection framework overlap, as the interaction between the two depends on jurisdiction and interpretation.
Do not rely on this definition for matters it does not cover, including cross-border transfer mechanics, retention periods, and enforcement penalties, which are out of scope here and should be assessed against the applicable national and EU instruments.