Back to Knowledge Hub

The ePrivacy Directive: Understanding Cookie Law

·1 min read

What is the ePrivacy Directive?

The ePrivacy Directive (2002/58/EC), often called the "Cookie Law," regulates electronic communications privacy in the EU. It predates the GDPR and specifically addresses cookies, tracking technologies, and electronic communications.

While the GDPR governs personal data broadly, the ePrivacy Directive specifically targets technologies that access or store information on user devices — making it the legal foundation for cookie consent requirements.

Key Requirements

Prior consent: National laws implementing Article 5(3) generally require consent before storing information on, or accessing information from, a device. The rule can apply whether or not the information is personal data.

Clear information: Users must be informed about what cookies do and why they are used.

Genuine choice: Where consent is required, the GDPR standard applies: it must be freely given, specific, informed, unambiguous, and withdrawable.

The narrow exceptions

Consent is not required where storage or access is used only to transmit a communication or is strictly necessary to provide a service expressly requested by the user. The test is necessity, not whether a technology is called first-party, functional, or analytics. Member-state implementation and regulator guidance still matter.

What is changing in 2026

The long-running 2017 proposal for an ePrivacy Regulation was withdrawn in 2025, so it is not an upcoming replacement. The European Commission's Digital Omnibus proposal includes possible changes to cookie rules, but as of August 2026 the legislative process is ongoing. Teams should implement today's directive and national law rather than design around an unadopted proposal.

A
Artur WachelkaFounder & CEO

Building transparent consent infrastructure for the modern web.