The ePrivacy Directive, formally Directive 2002/58/EC on privacy and electronic communications, is the European Union law that decides when a website, app or advertiser may store information on a person's device or read information already there. It is the legal source of the cookie banner. It exists because the General Data Protection Regulation (GDPR) and its predecessor protect personal data in general, while communications raise a narrower question: whether anyone may touch the equipment and messages a person uses to communicate at all.
What the directive covers
The text runs to 21 articles, most aimed at telecoms operators. Article 5(1) protects the confidentiality of communications, barring interception or surveillance without consent. Article 6 limits how providers use traffic data, the records of who contacted whom and when. Article 9 restricts location data. Article 13 requires prior consent for unsolicited marketing by email, SMS and automated calls, with a "soft opt-in" for existing customers. Article 15(1) lets member states restrict these rights for national security and crime prevention, the foothold for data retention laws.
For advertising, one sentence dominates. Article 5(3), as amended in 2009, states that storing information, or gaining access to information already stored, in the terminal equipment of a subscriber or user "is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information." Two exemptions follow: storage or access for the "sole purpose" of transmitting a communication, and storage or access "strictly necessary" for a service the user explicitly requested.
How Article 5(3) works in practice
The rule is technology-neutral. It applies to cookies, but also to local storage, software development kits (SDKs) in apps, device fingerprinting and tracking pixels. The European Data Protection Board (EDPB) adopted Guidelines 2/2023 in November 2023 covering tracking links, pixels, unique identifiers and local processing, with a final version in October 2024.
Article 5(3) applies whether or not the information is personal data. The GDPR's Article 4(11) defines what valid consent means; the ePrivacy Directive decides when it is needed. A session cookie that keeps a shopping basket alive falls under the strictly necessary exemption. An advertising cookie, an analytics script from a third party or a retargeting pixel does not, so the site must ask first.
In the transaction flow, the question arises before any bid request exists. A consent management platform (CMP) displays the banner, records the choice and blocks or releases tags accordingly. In programmatic channels, IAB Europe's Transparency and Consent Framework (TCF) encodes that choice in a TC String passed to vendors. Purpose 1 of the TCF, "store and/or access information on a device", is the ePrivacy permission. The other purposes, covering later use of the data, are GDPR territory. That division explains why legitimate interest cannot cover the cookie itself, only later processing.
Enforcement is national. Each member state transposed the directive into its own law: Article 82 of the French Data Protection Act, section 25 of Germany's Telecommunications Digital Services Data Protection Act (TDDDG), and statutory instrument 336 of 2011 in Ireland. Because the ePrivacy Directive sits outside the GDPR's one-stop-shop mechanism, a national regulator can fine a company headquartered in another member state directly. That is why France's data protection authority, the CNIL, has fined Google, Amazon and Meta for cookie breaches without routing cases through Dublin.
Origin and evolution
The directive replaced Directive 97/66/EC of December 15, 1997, which covered only traditional telecoms. The 2002 version, adopted on July 12, 2002 with a transposition deadline of October 31, 2003, extended the rules to internet services. Its original Article 5(3) was an opt-out: sites had to inform users and offer "the right to refuse".
Directive 2009/136/EC, adopted on November 25, 2009, replaced that right to refuse with prior consent. Member states had until May 25, 2011 to transpose it. Recital 66 suggested that consent could be expressed through browser settings, an idea that resurfaced in every later reform. The European Electronic Communications Code, Directive (EU) 2018/1972, widened the directive's confidentiality rules from December 21, 2020 to number-independent messaging services such as WhatsApp and webmail.
The Court of Justice of the European Union (CJEU) then shaped its practical meaning. In Planet49 (C-673/17), on October 1, 2019, the Court held that a pre-ticked checkbox does not amount to valid consent, that Article 5(3) applies regardless of whether data is personal, and that users must be told how long cookies last and whether third parties can access them. In StWL Stadtische Werke Lauf (C-102/20), on November 25, 2021, it treated advertisements displayed inside email inboxes as direct marketing under Article 13.
Enforcement and money
The CNIL has been the most active enforcer. It fined Google 100 million euros and Amazon 35 million euros on December 10, 2020, then Google 150 million euros and Facebook 60 million euros at the end of 2021, in both cases because refusing cookies took more effort than accepting them. On September 1, 2025, it fined Google 325 million euros over Gmail inbox ads and an account-creation flow in which rejecting advertising cookies took six clicks against two to accept. The same day it fined a SHEIN subsidiary 150 million euros for placing ten cookies before consent and continuing to place them after refusal. Orange had been fined 50 million euros in December 2024 partly for reading cookies after consent was withdrawn.
Courts have also extended liability down the supply chain. On December 11, 2025, the Frankfurt Higher Regional Court held a third-party cookie provider directly liable under section 25 TDDDG, even though the websites, not the provider, were supposed to collect consent.
The regulation that never arrived
On January 10, 2017, the European Commission proposed an ePrivacy Regulation, COM(2017) 10, to replace the directive with directly applicable rules and GDPR-level fines of up to 4 per cent of global turnover. Parliament adopted its negotiating mandate in October 2017. The Council took until February 10, 2021, and trilogue talks began on May 20, 2021 without producing agreement. The Commission listed the proposal for withdrawal in its 2025 work programme for lack of foreseeable agreement. It approved the withdrawal on July 16, 2025, and the notice appeared in the Official Journal on October 6, 2025. The 2002 directive remains in force, transposed 27 different ways.
Why it matters for marketers
The directive determines how much of the European audience can be measured and targeted at all. Every refusal removes a user from cookie-based retargeting, frequency capping and attribution. Coverage of the changing consent landscape has documented how banner design, tag blocking and platform enforcement now interact. Analytics vendors have a narrower path: the CNIL updated its consent exemption for audience measurement on July 4, 2025, requiring first-party cookies, truncated IP addresses and a 13-month cookie lifespan.
Limitations and disputes
The central criticism is consent fatigue. noyb, the Vienna-based privacy group, says studies show only 3 to 10 per cent of people want to be tracked, while banner designs push consent rates as high as 90 per cent. Industry groups counter that weakening banners would shift revenue to platforms with logged-in users.
Fragmentation is a second problem. Analytics exemptions differ between member states, and separate ePrivacy and GDPR regulators produce parallel enforcement. Browser signals are a third. A May 2026 study found that Global Privacy Control has limited effect on banners under Article 5(3), because the directive requires consent even where no data is sold or shared.
Not the same as
GDPR. Regulation (EU) 2016/679 governs processing of personal data in general and defines consent. The ePrivacy Directive is a more specific law covering device access and communications, including non-personal information.
ePrivacy Regulation. The 2017 proposal meant to replace the directive. It never passed and was formally withdrawn in 2025.
PECR. The UK's Privacy and Electronic Communications Regulations 2003 transposed the directive. After Brexit, the Data (Use and Access) Act 2025, which received Royal Assent on June 19, 2025, added consent exemptions for statistics and website appearance and raised maximum fines from 500,000 pounds to 17.5 million pounds or 4 per cent of turnover.
Recent developments
The Commission published the Digital Omnibus, COM(2025) 837, on November 19, 2025. It proposed moving cookie consent into the GDPR through a new Article 88a when personal data is involved, and an Article 88b obliging websites to honour machine-readable consent signals from browsers, with media services exempt. The Netherlands warned that new exceptions would allow more tracking without consent than current rules. The EDPB and the European Data Protection Supervisor (EDPS) backed the browser signal in February 2026 but warned that splitting device rules between two laws "may lead to legal uncertainty".
France's Alliance Digitale called for deleting Article 88b in May 2026. The Council removed it on June 18, 2026, after a Google-commissioned study by Implement Consulting Group estimated a browser-level mechanism could cost European businesses 40 to 50 billion euros a year, a figure noyb called "completely far-fetched". On September 3, 2026, the Irish presidency's compromise returned cookie rules to Article 5(3) of the directive, with six exemptions including contextual advertising measurement, one-click refusal and a six-month bar on asking again. A week later, 19 organisations asked for the browser signal back.
As of October 9, 2026, the Council still has no negotiating mandate. According to Agence Europe, a compromise dated October 5 cut the re-request bar to four months, and a vote by member states' ambassadors in the Committee of Permanent Representatives (Coreper) scheduled for October 7 was postponed to October 11 under pressure from Germany and France. Trilogue talks with Parliament have not started.
Timeline
- December 15, 1997 - Directive 97/66/EC sets data protection rules for the telecoms sector.
- July 12, 2002 - Directive 2002/58/EC adopted; published July 31, 2002.
- October 31, 2003 - Transposition deadline; UK PECR in force from December 11, 2003.
- November 25, 2009 - Directive 2009/136/EC replaces the right to refuse with prior consent in Article 5(3).
- May 25, 2011 - Transposition deadline for the 2009 amendments.
- April 8, 2014 - CJEU invalidates the Data Retention Directive in Digital Rights Ireland.
- January 10, 2017 - Commission proposes the ePrivacy Regulation.
- October 1, 2019 - CJEU rules in Planet49 that pre-ticked boxes are not consent.
- December 10, 2020 - CNIL fines Google 100 million euros and Amazon 35 million euros over cookies.
- December 21, 2020 - European Electronic Communications Code extends the directive to messaging services.
- February 10, 2021 - Council agrees its ePrivacy Regulation mandate.
- November 25, 2021 - CJEU treats inbox ads as direct marketing in StWL.
- November 2023 - EDPB adopts Guidelines 2/2023 on the technical scope of Article 5(3); final version October 2024.
- February 11, 2025 - Commission work programme lists the ePrivacy Regulation for withdrawal.
- June 19, 2025 - UK Data (Use and Access) Act 2025 amends PECR.
- July 4, 2025 - CNIL updates its audience measurement exemption.
- September 1, 2025 - CNIL fines Google 325 million euros and a SHEIN subsidiary 150 million euros.
- October 6, 2025 - Withdrawal of the ePrivacy Regulation published in the Official Journal.
- November 19, 2025 - Commission proposes the Digital Omnibus.
- December 11, 2025 - Frankfurt Higher Regional Court holds a third-party cookie provider liable.
- February 10, 2026 - EDPB-EDPS joint opinion on the Digital Omnibus.
- June 18, 2026 - Council compromise drops Article 88b.
- September 3, 2026 - Council compromise returns cookie rules to Article 5(3).
- October 7, 2026 - Coreper vote on the Council mandate postponed.
Related PPC Land coverage
- Explaining GDPR - The data protection regulation that defines the consent standard Article 5(3) relies on.
- Explaining consent management platform - How banners, TC Strings and tag blocking implement cookie consent.
- Explaining legitimate interest - Why the GDPR's flexible legal basis cannot cover setting a cookie.
- EDPB to adopt guidelines on Technical Scope of ePrivacy Directive's Article 5(3) - Guidelines 2/2023 and the tracking techniques they cover.
- EU scraps privacy and AI liability rules as Commission unveils 2025 work plan - The announcement that ended eight years of ePrivacy Regulation talks.
- Google fined EUR 325 million by French regulator for Gmail ads and cookie violations - The CNIL decision on inbox ads and an asymmetric cookie flow.
- French regulator fines SHEIN's subsidiary EUR 150 million for cookie violations - Cookies placed before consent and after refusal.
- French privacy watchdog fines Orange EUR 50m for unauthorized email advertising - Inbox ads and cookies read after consent withdrawal.
- French data regulator updates cookie exemption rules for websites - CNIL's July 2025 criteria for consent-free audience measurement.
- German court holds third-party cookie providers liable without consent - The Frankfurt ruling under section 25 TDDDG.
- Cookie consent in Europe is changing - what marketers need to know - Enforcement, CMPs and the Omnibus from an advertiser's perspective.
- GPC could cut EU consent banners - but law must catch up first - A study on browser signals under Article 5(3).
- Europe proposes machine-readable consent signals for GDPR compliance - Early reporting on the browser signal later numbered Article 88b.
- Netherlands raises serious concerns about EU Digital Omnibus privacy changes - The Dutch government's objections to wider cookie exemptions.
- Europe's privacy watchdogs reject Commission's plan to narrow GDPR protections - The EDPB-EDPS joint opinion and its view of the split regime.
- French ad industry draws a line in the sand on EU cookie overhaul - Alliance Digitale's 17 recommendations on the Omnibus.
- EU Council drops cookie signal after Google lobbying - EUR 40-50 bn at stake - The June 2026 removal of Article 88b and the disputed revenue estimate.
- EU Council draft drops unconditional opt-out from GDPR AI clause - The September 2026 text returning cookie rules to Article 5(3).
- 19 groups ask EU to re-insert the cookie banner fix Google lobbied out - The civil society campaign to restore the browser signal.
Summary
Who. The European Parliament and Council adopted the directive; national authorities such as France's CNIL and Germany's state regulators enforce it; the CJEU interprets it. Its obligations fall on website and app operators, ad tech vendors that place or read identifiers, telecoms operators and email marketers.
What. Directive 2002/58/EC sets EU rules on confidentiality of communications, traffic and location data and unsolicited marketing. Its Article 5(3) requires informed consent before storing or reading information on a user's device, except where strictly necessary or needed to transmit a communication.
When. Adopted on July 12, 2002 and amended on November 25, 2009, when prior consent replaced an opt-out. A planned replacement regulation was proposed in 2017 and withdrawn in 2025. As of October 2026, Council negotiations on Digital Omnibus amendments remain unresolved.
Where. Across the European Economic Area, through national transposition laws that differ in detail. The UK applies its own version through PECR, amended in 2025.
Why. It exists to protect the private sphere of a person's device and communications independently of whether personal data is processed. For advertising, it is the rule that produces cookie banners and determines what share of European traffic can be tracked, measured and targeted.
Discussion