One-line definition
The ePrivacy Directive (officially Directive 2002/58/EC, as amended by Directive 2009/136/EC) is the EU law that governs privacy in electronic communications — setting the rules for cookies, tracking technologies, direct marketing by email and SMS, and the confidentiality of communications traffic data.
Real-life analogy
Think of the ePrivacy Directive as the house rules for entering someone's home.
- GDPR is the *building code*: it defines what a landlord may legally do with tenant information once inside the building — how data is stored, secured, shared, and deleted.
- ePrivacy is the *doorbell rule*: before you even step inside, you must ask permission, explain why you're there, and respect a "no thanks." Dropping a tracking cookie without consent is like walking through the front door uninvited.
Both rules apply to the same house, but they govern different moments: ePrivacy controls access and intrusion, GDPR controls handling and stewardship. That's why a cookie banner is an ePrivacy issue, while the privacy policy behind it is largely a GDPR issue.
Core formula
Lawful electronic marketing / tracking = Prior consent + Clear information + Easy refusal + Documented proof
Broken down:
| Element | What it means in practice |
|---|---|
| **Prior consent** | Opt-in *before* the cookie is set or the marketing email is sent (with narrow exceptions) |
| **Clear information** | Purpose, sender identity, and consequences stated in plain language |
| **Easy refusal** | Withdrawing consent must be as simple as giving it |
| **Documented proof** | You can show *who* consented, *when*, and *to what* — essential for enforcement defense |
For cookies specifically, the standard is informed, specific, and freely given consent — the same quality bar GDPR Article 4(11) sets for personal data. "By continuing to browse, you accept" is not valid consent under the current interpretation.
Comparison with related terms
| Term | Scope | Relationship to ePrivacy |
|---|---|---|
| **GDPR** | General personal data processing (lawful basis, rights, DPO, DPIA) | ePrivacy is *lex specialis*: for electronic communications, it overrides GDPR where they conflict. Consent definitions are aligned. |
| **Cookie Law** | Informal name for the 2009 amendment (Article 5(3)) | The cookie consent requirement is one article of ePrivacy, not the whole directive. |
| **DSA (Digital Services Act)** | Platform content moderation, transparency, ads to minors | Different regime; overlaps on ad transparency but not on consent mechanics. |
| **DMA (Digital Markets Act)** | Gatekeeper competition rules | Separate; can impose additional consent duties on large platforms. |
| **CCPA/CPRA** | California consumer privacy | Opt-out model vs. ePrivacy's opt-in model — the key structural difference. |
Key numbers to know:
- 2002 — original directive adopted (July 12, 2002).
- 2009 — amended via the "Citizens' Rights Directive," introducing the cookie consent rule.
- Article 13 — the direct marketing provision governing unsolicited email/SMS.
- Article 5(3) — the storage/access rule that created cookie banners.
- €20 million or 4% of global annual turnover — the GDPR-level fine ceiling that national regulators can apply to ePrivacy breaches where harmonized.
Use cases
1. Cookie consent banners (CMPs)
Every consent management platform exists because of Article 5(3). A compliant banner must offer "Reject All" at the same prominence as "Accept All," avoid pre-ticked boxes, and not use dark patterns like a greyed-out reject button. French regulator CNIL has fined operators for making refusal harder than acceptance.
2. Email and SMS marketing
Article 13 requires prior opt-in for B2C marketing. The soft opt-in exception applies only when: (a) you obtained the address in a sale context, (b) you market *similar* products, and (c) you offered an opt-out at collection and in every message. B2B rules vary by member state — Germany is strict, the UK historically permitted corporate opt-out.
3. Website analytics
Even "privacy-friendly" analytics needs scrutiny. If a tool sets a persistent identifier or reads device storage, consent is required. Some configurations using only aggregated, non-identifying measurement may fall outside Article 5(3), but the burden of proof is on the operator.
4. Ad retargeting and pixels
Meta Pixel, TikTok Pixel, and LinkedIn Insight Tag all write to device storage. Loading them before consent is a direct Article 5(3) violation. This is why many EU sites gate pixels behind CMP approval.
5. Cross-border DTC stores
A US-based Shopify or WooCommerce brand selling to EU customers is in scope. Geo-detecting EU visitors and serving a compliant banner is standard practice; ignoring it exposes the brand to complaints from national regulators and to platform-level enforcement.
6. Call and message metadata
Telecom operators and VoIP providers must erase or anonymize traffic data when no longer needed for billing, and cannot use it for marketing without consent. This is the "confidentiality of communications" pillar.
Misconceptions
"ePrivacy was replaced by GDPR."
False. GDPR *complemented* ePrivacy; it did not repeal it. The long-promised ePrivacy Regulation (proposed 2017) has stalled repeatedly, so the 2002 directive remains in force.
"A cookie banner makes me compliant."
No. The banner is the *mechanism*; compliance is the *outcome*. If rejecting is harder than accepting, if consent is bundled with terms acceptance, or if cookies fire before a choice is made, the banner is decorative.
"Consent is always required."
Not quite. Strictly necessary cookies (shopping cart, security, load balancing) are exempt. But "necessary" is interpreted narrowly — analytics and advertising never qualify.
"B2B email is exempt."
Depends on the member state. Some allow opt-out for corporate addresses; others require opt-in. There is no single EU-wide B2B rule.
"It only applies to EU companies."
It applies to anyone processing electronic communications data of people in the EU, regardless of where the company is established. Territorial scope follows the user, not the business.
"One consent covers everything."
Consent must be specific. Bundling cookie consent with newsletter signup, or with acceptance of T&Cs, invalidates it.
Related terms
- GDPR (General Data Protection Regulation) — the general data regime; defines consent quality standards.
- Consent Management Platform (CMP) — the tooling that captures and logs ePrivacy consent.
- Article 5(3) — the cookie and device storage rule.
- Soft opt-in — the narrow exception for existing customer email marketing.
- ePrivacy Regulation (ePR) — the proposed replacement, still in trilogue limbo.
- TCF (Transparency and Consent Framework) — IAB Europe's industry standard for consent signals; itself subject to regulatory scrutiny.
- Dark patterns — manipulative UI designs that regulators treat as invalidating consent.
- Legitimate interest — a GDPR lawful basis that does *not* override ePrivacy's consent requirement for cookies.
- Data Subject Access Request (DSAR) — the GDPR right that applies to data collected under ePrivacy-compliant consent.
For DTC and cross-border operators, the practical takeaway is simple: treat ePrivacy as the front door of your EU compliance posture. Get consent capture right, keep the proof, and make refusal genuinely easy — because that is where enforcement starts.