ePrivacyDirective 2002/58/EC

EU ePrivacy Directive Cookies, Communications, and Marketing Rules

This hub explains the current Directive 2002/58/EC baseline: communications confidentiality, service security and breach handling, traffic and location data, terminal-equipment access, caller privacy, directories, and direct marketing.

By Sorena AIUpdated 2026-07No signup required
ePrivacy quick scan
Directive 2002/58/EC
Communications layer
Article 5 protects confidentiality of communications and related ; traffic and location-data use cases must be separated from ordinary website tracking and checked against the provider role and purpose.
Terminal-equipment layer
Article 5(3), as amended in 2009, covers storing information or gaining access to information already stored on ; EDPB technical guidance treats the scope as broader than cookies and not limited to personal data.
Consent and exemption layer
Consent must meet GDPR conditions where ePrivacy refers to consent. Exemptions are narrow: transmission-only access or access for an information society service explicitly requested by the user.
Marketing layer
Direct marketing by automated calling systems, fax, or electronic mail generally needs prior consent, while the customer requires collection during a sale, own similar products or services, and easy free opt-out.
Provider and national-law layer
Providers of publicly available electronic communications services also face security, breach-notification, traffic-data, location-data, caller-identification, and directory duties. National transposition determines the operational procedure, authority, remedy, and penalty.

Start with applicability and the regulated operation. Then follow the grouped guides for communications-provider duties, terminal-equipment and cookie controls, marketing permissions, evidence, deadlines, and country-specific enforcement review.

Key dates
2002/58
Directive
Art. 5
Confidentiality
Art. 5(3)
Devices
Art. 13
Marketing
ePrivacy questions this hub helps answer
Is the issue communications confidentiality?
Separate the secrecy of electronic communications from later personal-data processing; ePrivacy protects communications and even where the GDPR also applies.
Does Article 5(3) apply?
Check whether a cookie, SDK, pixel, local storage, identifier, IoT report, or similar technique stores information or gains access to information on a user's .
Can you rely on an exemption?
Use the narrow transmission and tests before treating a cookie as essential; advertising, cross-site tracking, and most analytics need consent or a jurisdiction-specific exemption analysis.
Which marketing path applies?
starts with prior consent for automated calls, fax, and electronic mail, with a only for a customer's electronic contact details, the sender's own similar products or services, and easy free objection at collection and in each message.
Is this an EU rule or a national implementation detail?
Use the Directive for the EU baseline, then identify the Member State law that governs the operation. National law and authority practice supply the territorial test, consent-interface detail, rules for channels not fully harmonized by , breach procedure, competent authority, penalties, and remedies.
Which legal dates matter?
Directive 2002/58/EC was adopted on 12 July 2002 and originally required national transposition by 31 October 2003. Directive 2009/136/EC introduced the current Article 5(3) consent wording and required its national measures by 25 May 2011. Those dates explain the legal history; current duties still come from each Member State's implementing law.
Confidentiality
Terminal equipment
Marketing consent
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Feb 21, 2026
Updated
Jul 25, 2026

The Directive works through Member State implementing law. The Commission approved withdrawal of the proposed ePrivacy Regulation on 16 July 2025, and the withdrawal notice was published on 6 October 2025. Its draft rules and fine levels are not current law; validate each implementation and enforcement conclusion for the relevant country.

Focused ePrivacy guidance

Choose the rule for the channel or device operation

Start with the direct-marketing channel or the storage or access operation, then apply the relevant national law. Keep the later assessment under the General Data Protection Regulation (GDPR), which governs personal-data processing, as a separate step.

Choose the direct-marketing permission route

sets the rules for unsolicited marketing by email, text, fax, and automated calling. Check the channel, recipient, and national law before choosing prior consent, the existing-customer , or another permitted route. Keep consent, sender identity, objections, and suppression-list evidence together.

Review ePrivacy direct-marketing rules

Test storage or access on terminal equipment

The covers storing information on, or reading information from, a person's phone, computer, or other . Record what each cookie, tracking pixel, software development kit (SDK), local identifier, or device application programming interface (API) stores or reads. Use an exemption only when every condition fits.

Run the Article 5(3) terminal-equipment test

Check the customer soft opt-in

The customer is a narrow exception to prior email-marketing consent. Use it only when the seller obtained the contact details during a sale, markets its own similar products or services, and offers a free, easy objection at collection and in every message. Check the applicable national law.

Review the soft opt-in conditions
ePrivacy Timeline

Track cited-source ePrivacy milestones and guidance

Use the timeline to separate the Directive adopted on 12 July 2002, the 2009 amendments due for national transposition by 25 May 2011, GDPR-era consent interpretation, and EDPB Article 5(3) guidance. Withdrawn Commission proposals, including the 2017 ePrivacy Regulation proposal withdrawn in 2025, and later proposals are not binding law.

Loading timeline...
Recommended reading path

Choose the next ePrivacy decision

Start with the operation and applicable national implementation. Then move to communications-provider duties, terminal-equipment controls, marketing permissions, evidence, deadlines, or a focused comparison.

1

Start here: scope, rule, and national law

Identify the regulated operation, the relevant actor, the Directive article, and the Member State implementation that supplies operational and enforcement detail.

2

Communications confidentiality and data

Cover confidentiality, provider security and breach duties, traffic and location data, and the boundaries between ePrivacy and later GDPR processing.

3

Classify each storage or access operation, test the two narrow exemptions, and validate banner, analytics, and consent behavior against national practice.

EU ePrivacy Article 5(3) terminal equipment test
A cited Article 5(3) test for cookies, pixels, local identifiers, device APIs, strictly necessary exceptions, and consent evidence.
Read guide
EU ePrivacy Cookie Scope Classifier Workflow
Decide whether cookies, pixels, SDKs, local storage, identifiers, and analytics fall within Article 5(3), then document consent, an exemption, or escalation.
Read guide
EU ePrivacy Directive Cookies and Consent: Article 5(3), exemptions, and banner evidence
Cookie consent guide for the EU ePrivacy Directive: Article 5(3) scope, strictly necessary and transmission exemptions, consent UX, withdrawal, logs, analytics caveats, and GDPR interplay.
Read guide
EU ePrivacy Strictly Necessary Cookie Exemptions
Source-backed guide to the Article 5(3) ePrivacy exemptions for transmission cookies, requested-service cookies, analytics caveats, evidence, and national-law checks.
Read guide
EU ePrivacy analytics cookies: consent, exemption, and evidence guide
Source-backed guide to analytics cookies under EU ePrivacy: Article 5(3) scope, when consent is usually needed, limited analytics exemptions, consent records, and evidence gaps.
Read guide
EU cookie banner requirements under the ePrivacy Directive
EU ePrivacy cookie banner requirements for non-exempt cookies and trackers: prior consent, reject choices, no pre-ticked boxes, withdrawal, analytics limits, cookie walls, and evidence logs.
Read guide
EU ePrivacy cookie banner UX test cases
Source-backed cookie banner UX tests for Article 5(3) ePrivacy consent: reject all, pre-ticked boxes, withdrawal, cookie walls, analytics toggles, and consent evidence.
Read guide
4

Direct marketing and soft opt-in

Choose the channel-specific permission route, prove every soft-opt-in condition, identify the sender, and operate free objection and suppression controls.

5

Implementation, evidence, and enforcement

Turn the legal classification into owned controls, replayable consent records, recurring reviews, and a Member State enforcement file without inventing an EU-wide fine table.

6

Compare frameworks or answer a specific question

Keep the ePrivacy trigger distinct from GDPR, DSA advertising, and UK PECR work, or use the FAQ for a focused answer.

Next step

Turn ePrivacy scope into owned product, marketing, and evidence work

This hub is the shared starting point for privacy, legal, product, analytics, marketing, and engineering teams. Confirm the technical operation first, then assign the ePrivacy rule, consent status, exemption rationale, jurisdiction check, and retained evidence.

What this unlocks
  • Start with one concrete operation: message transmission, traffic or location-data use, cookie, SDK, pixel, local-storage item, device identifier, analytics tag, social plug-in, marketing email, SMS, automated call, or suppression-list process.
  • For terminal-equipment access, record the technology, purpose, first-party or third-party role, lifespan, data flow, whether access happens before consent, and whether the claimed exemption is transmission-only or for a user-requested service.
  • For consent flows, keep the banner text, purpose list, accept and reject paths, withdrawal mechanism, consent log, version history, and evidence that no consent-required tags fire before a valid affirmative action.
  • For direct marketing, keep the source of permission, the (2) sale context for any , the identity of the person that collected and later used the contact details, product-similarity rationale, opt-out shown at collection and in each message, suppression-list operation, and Member State law or regulator guidance used for the channel.
  • For a publicly available electronic communications service, keep the Article 4 security-risk assessment, subscriber risk information, breach chronology, national-authority notification, affected-subscriber decision, remedial action, and breach inventory separately from any GDPR incident record.
EU ePrivacy Directive artifact preview
Share it internally
Download the timeline export to align legal, product, engineering, and commercial teams on milestones and deadlines.