---
title: "EU ePrivacy Directive compliance calendar for cookies, consent, and marketing"
canonical_url: "https://www.sorena.io/artifacts/eu/eprivacy-directive/deadlines-and-compliance-calendar"
source_url: "https://www.sorena.io/artifacts/eu/eprivacy-directive/deadlines-and-compliance-calendar"
author: "Sorena AI"
description: "Source-backed ePrivacy calendar covering Directive milestones, Article 5(3) cookie reviews, consent evidence, direct marketing checks, and national-law follow-up."
published_at: "2026-05-09"
updated_at: "2026-07-16"
keywords:
  - "EU ePrivacy Directive"
  - "ePrivacy compliance calendar"
  - "Article 5(3)"
  - "cookie consent"
  - "terminal equipment"
  - "consent banner"
  - "direct marketing"
  - "ePrivacy"
  - "compliance calendar"
  - "cookies"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# EU ePrivacy Directive compliance calendar for cookies, consent, and marketing

Source-backed ePrivacy calendar covering Directive milestones, Article 5(3) cookie reviews, consent evidence, direct marketing checks, and national-law follow-up.

*Artifact Guide* *EU*

## EU ePrivacy Directive deadlines and compliance calendar

Track the cited dates that define the ePrivacy Directive baseline, then run recurring reviews for cookies, terminal-equipment access, consent logs, direct marketing, and Member State transposition rules.

Built for privacy, legal, product analytics, web engineering, marketing operations, consent-management, and regional compliance owners who need a practical calendar without unsupported deadline claims.

This calendar helps separate fixed ePrivacy source milestones from recurring operating checks. The Directive and its 2009 amendment provide the dated legal baseline; day-to-day compliance depends on current cookie, consent, direct-marketing, and national-law reviews rather than invented future filing dates.

## Fixed source milestones to keep in the calendar

Record these dates as legal-history anchors, not as new implementation deadlines. They explain which version of the ePrivacy baseline a cookie, terminal-equipment, or direct-marketing control is being mapped against.

Do not add a future ePrivacy Regulation effective date. The Commission proposed an ePrivacy Regulation on 10 January 2017, but formally withdrew that proposal in October 2025. Later amendment proposals remain proposals unless and until adopted; the nationally implemented Directive remains the operating baseline.

- 12 July 2002: Directive 2002/58/EC was adopted as the privacy and electronic communications Directive.
- 31 July 2002: Directive 2002/58/EC was published in the Official Journal.
- 31 October 2003: Member States were required to bring into force provisions necessary to comply with Directive 2002/58/EC.
- 25 November 2009: Directive 2009/136/EC amended Directive 2002/58/EC, including the Article 5(3) terminal-equipment rule and Article 13 direct-marketing rule.
- 25 May 2011: Member States were required to adopt and publish laws implementing Directive 2009/136/EC amendments.
- 10 January 2017: the Commission proposed an ePrivacy Regulation to update the current rules; use this as historical reform context, not as operative law.
- 6 October 2025: an Official Journal notice listed COM(2017) 10 final among withdrawn Commission proposals; remove any implementation plan that assumes the 2017 proposal will become law.
- 19 November 2025: the Commission adopted a separate Digital Omnibus proposal that includes amendments to Directive 2002/58/EC; track it as pending legislation, not as a current compliance deadline.

Sources for this answer:

- [Directive 2002/58/EC (ePrivacy Directive)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32002L0058&ref=sorena.io) - Supports the 12 July 2002 adoption date, 31 July 2002 Official Journal publication date, and 31 October 2003 Member State transposition date.
- [Directive 2009/136/EC amendments to Directive 2002/58/EC](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02009L0136-20201221&ref=sorena.io) - Supports the 25 November 2009 amending Directive, its Article 5(3) and Article 13 changes, and the 25 May 2011 implementation date.
- [Commission proposal COM(2017) 10 final](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52017PC0010&ref=sorena.io) - Supports the 10 January 2017 ePrivacy Regulation proposal context and prevents treating the proposal as an enacted compliance deadline.
- [Official Journal notice withdrawing the 2017 proposal](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52025XC05423&ref=sorena.io) - Confirms that COM(2017) 10 final and procedure 2017/0003(COD) were withdrawn in 2025.
- [EUR-Lex procedure 2025/0360(COD)](https://eur-lex.europa.eu/procedure/EN/2025_360?ref=sorena.io) - Tracks the 2025 Digital Omnibus proposal, including proposed amendments to Directive 2002/58/EC; it is a legislative procedure rather than current law.

## Cookie and terminal-equipment review cadence

Run this review whenever a website, app, SDK, tag manager, analytics configuration, advertising pixel, local-storage feature, connected-device flow, or user-agent identifier changes. Article 5(3) is triggered by storing information or gaining access to information already stored in a subscriber's or user's terminal equipment, not only by traditional browser cookies.

The review record should classify each technology as consent-required, strictly necessary for the user-requested service, necessary only for transmission, or blocked pending legal review. Keep the technical test tied to actual storage or access operations, not vendor labels.

- Inventory cookies, pixels, URLs containing tracking parameters, SDK identifiers, local storage, device identifiers, and IoT reporting paths before each release.
- For each item, record whether it stores information, accesses stored information, or only participates in transmission.
- For an exemption claim, document the exact service requested by the user and why the storage or access is strictly necessary to provide it.
- For audience-measurement tools, check national regulator conditions before relying on an exemption; CNIL's public guidance, for example, lists limits such as single-site scope, IP truncation, no cross-checking, opt-out, and a 13-month tracker lifetime.
- Reopen the calendar item when a vendor changes purposes, retention, domains, identifiers, local processing, or downstream sharing.

Sources for this answer:

- [EDPB Guidelines 2/2023 on Article 5(3) ePrivacy Directive](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-22023-technical-scope-art-53-eprivacy-directive_en?ref=sorena.io) - Supports treating Article 5(3) as a technical storage/access assessment covering cookies, pixels, local processing, IoT reporting, and unique identifiers.
- [WP29 Opinion 04/2012 on Cookie Consent Exemption](https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2012/wp194_en.pdf?ref=sorena.io) - Supports the two exemption tests for transmission-only cookies and strictly necessary cookies for a user-requested information society service.
- [CNIL Sheet 16: Use analytics on your websites and applications](https://www.cnil.fr/en/sheet-ndeg16-use-analytics-your-websites-and-applications?ref=sorena.io) - Supports using national regulator guidance for analytics-cookie exemption conditions and flags that ePrivacy analytics positions may vary nationally.

## Consent banner and consent-log calendar items

Review consent banners and consent logs at each banner redesign, CMP configuration change, new purpose/vendor launch, regional rollout, or complaint. The calendar item should prove that consent-required storage or access is off by default and that the user's choice is captured with enough context to demonstrate consent quality.

The banner check should cover both ePrivacy placement or reading of cookies and any later GDPR-governed processing that follows from the storage or access event. Do not rely on the GDPR one-stop-shop mechanism for issues that fall only under the ePrivacy Directive.

- Confirm that consent-required cookies, pixels, SDKs, and similar technologies are not placed or read before a positive user action.
- Keep evidence that consent was freely given, specific, informed, and unambiguous, with purpose, vendor, timestamp, user interface version, region, and withdrawal path.
- Check whether the first layer gives a real refuse or reject path when an accept path is presented.
- Remove pre-ticked choices and any inactivity, scrolling, or silence-as-consent pattern.
- Review button contrast, link design, and wording for misleading pressure toward acceptance.
- Maintain a withdrawal route that remains findable after the first consent decision.

Sources for this answer:

- [EDPB Guidelines 05/2020 on consent](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_202005_consent_en.pdf?ref=sorena.io) - Supports the consent-quality checks for freely given, specific, informed, unambiguous consent and withdrawal evidence.
- [EDPB Cookie Banner Taskforce report](https://www.edpb.europa.eu/system/files/2023-01/edpb_20230118_report_cookie_banner_taskforce_en.pdf?ref=sorena.io) - Supports practical banner review points on reject options, pre-ticked boxes, misleading design, legitimate-interest framing, and withdrawal access.

## Direct-marketing and national-law checks

Schedule a direct-marketing check before every new email, SMS, automated-calling, fax, or similar electronic-marketing program, and repeat it when countries, message types, lead sources, or customer-relationship assumptions change. Article 13 distinguishes prior consent for certain channels, a limited existing-customer electronic-mail path for similar products or services, and Member State choices for other direct-marketing communications.

Because the Directive is implemented through national law, the calendar should not treat a single EU-wide banner or marketing setting as final. Regional owners should maintain a country-by-country note for cookie placement, analytics exemptions, enforcement authority guidance, direct-marketing opt-in or opt-out rules, and legal-person protections.

- Before each campaign, verify the channel, recipient type, country, source of electronic contact details, relationship to prior sale, product similarity, and opt-out wording.
- For the existing-customer electronic-mail path, keep proof that the same organization collected the contact details in a sale context and gave a clear, distinct, free, easy objection opportunity at collection and in each message.
- Block campaigns that hide the sender identity, lack a valid address for cessation requests, or route recipients to non-compliant marketing pages.
- Check whether national legislation chooses consent or opt-out for direct-marketing communications outside the Article 13(1) and 13(2) cases.
- For B2B audiences, verify the national rules protecting legitimate interests of subscribers other than natural persons.

Sources for this answer:

- [Directive 2009/136/EC amendments to Directive 2002/58/EC](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02009L0136-20201221&ref=sorena.io) - Supports the amended Article 13 rules for automated calling, fax, electronic mail, customer soft opt-in, sender identity, cessation address, and national-law choices.
- [Directive 2002/58/EC (ePrivacy Directive)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32002L0058&ref=sorena.io) - Supports the original Article 13 direct-marketing structure and the need to track Member State implementation.
- [EDPB Cookie Banner Taskforce report](https://www.edpb.europa.eu/system/files/2023-01/edpb_20230118_report_cookie_banner_taskforce_en.pdf?ref=sorena.io) - Supports treating national law transposing the ePrivacy Directive as the applicable framework for cookie placement or reading complaints.

## Calendar evidence to keep current

The calendar should be short enough for operating teams to maintain, but it must preserve the reason a control was approved. Each row should link a source, a control owner, the affected countries, and the evidence that shows the current product or marketing behavior matches the rule.

Reopen a row when a source changes, a national authority updates guidance, a vendor changes its technology, a new tracking method appears, a consent interface changes, or a marketing program expands into a new country or channel.

- Source anchor: Directive article, guidance document, national-regulator page, and source URL with the date the source was checked.
- Technical proof: tag inventory, CMP configuration, blocked-by-default test, browser storage capture, SDK configuration, or network trace.
- Consent proof: banner version, language, region, purposes, vendor list, accept/reject/withdrawal paths, and consent-log fields.
- Marketing proof: campaign approval, contact-source evidence, opt-out copy, suppression-list operation, sender identity, and cessation address.
- National-law proof: country owner, local rule summary, regulator guidance, and the next scheduled recheck trigger.

Sources for this answer:

- [EDPB Guidelines 2/2023 on Article 5(3) ePrivacy Directive](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-22023-technical-scope-art-53-eprivacy-directive_en?ref=sorena.io) - Supports keeping technical evidence for storage, access, terminal equipment, and emerging tracking techniques.
- [EDPB Guidelines 05/2020 on consent](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_202005_consent_en.pdf?ref=sorena.io) - Supports consent-log evidence for demonstrability and withdrawal controls.
- [CNIL Sheet 16: Use analytics on your websites and applications](https://www.cnil.fr/en/sheet-ndeg16-use-analytics-your-websites-and-applications?ref=sorena.io) - Supports documenting local analytics-cookie exemption conditions instead of assuming one EU-wide operating rule.

*Recommended next step*

*Placement: before sources*

## Keep cookie, consent, marketing, and national-law reviews current

Sorena can convert this calendar into cited-source review rows, owner assignments, release checks, consent evidence requests, and country-specific follow-up for ePrivacy work.

- [Open Research Copilot for EU ePrivacy Directive](/solutions/research-copilot.md): Ask questions tied to cited sources about Article 5(3), cookie exemptions, consent evidence, direct marketing, and Member State implementation checks.
- [Talk through ePrivacy implementation](/contact.md): Review your cookie calendar, consent logs, direct-marketing checks, national-law coverage, and source gaps with Sorena.

## Primary sources

- [Directive 2002/58/EC (ePrivacy Directive)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32002L0058&ref=sorena.io) - Primary legal baseline for ePrivacy Directive adoption, publication, Member State transposition, Article 5(3), and Article 13 direct-marketing context.
  - Quote: "privacy and electronic communications"
- [Directive 2009/136/EC amendments to Directive 2002/58/EC](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02009L0136-20201221&ref=sorena.io) - Amending Directive source for Article 5(3) consent language, Article 13 direct-marketing updates, and the 25 May 2011 implementation date.
  - Quote: "by 25 May 2011"
- [Commission proposal COM(2017) 10 final](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52017PC0010&ref=sorena.io) - Commission proposal source for ePrivacy Regulation reform context without treating the proposal as an enacted future deadline.
  - Quote: "10.1.2017"
- [EDPB Guidelines 2/2023 on Article 5(3) ePrivacy Directive](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-22023-technical-scope-art-53-eprivacy-directive_en?ref=sorena.io) - Technical scope guidance for storage/access to terminal equipment, including cookies, pixels, local processing, IoT reporting, and unique identifiers.
  - Quote: "technical scope of Art. 5(3)"
- [EDPB Guidelines 05/2020 on consent](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_202005_consent_en.pdf?ref=sorena.io) - Consent guidance for evidence that consent is freely given, specific, informed, unambiguous, demonstrable, and withdrawable.
  - Quote: "free, specific, informed and unambiguous"
- [EDPB Cookie Banner Taskforce report](https://www.edpb.europa.eu/system/files/2023-01/edpb_20230118_report_cookie_banner_taskforce_en.pdf?ref=sorena.io) - Cookie-banner enforcement coordination source for reject options, pre-ticked boxes, misleading design, essential-cookie classification, and national-law framing.
  - Quote: "Cookie Banner Taskforce"
- [WP29 Opinion 04/2012 on Cookie Consent Exemption](https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2012/wp194_en.pdf?ref=sorena.io) - Source for transmission-only and strictly necessary cookie exemption criteria under Article 5(3).
  - Quote: "Cookie Consent Exemption"
- [CNIL Sheet 16: Use analytics on your websites and applications](https://www.cnil.fr/en/sheet-ndeg16-use-analytics-your-websites-and-applications?ref=sorena.io) - National regulator example showing that analytics-cookie exemptions depend on local conditions and may vary by Member State.
  - Quote: "may be subject to national variation"

## Related Topic Guides

- [Are cookie walls allowed under the EU ePrivacy Directive?](/artifacts/eu/eprivacy-directive/faq/cookie-walls.md): FAQ answer on cookie walls under the EU ePrivacy Directive, covering freely given consent, refusal and withdrawal paths, banner evidence, and national-law caveats.
- [Do Analytics Cookies Require Consent under the EU ePrivacy Directive?](/artifacts/eu/eprivacy-directive/faq/analytics-cookies.md): FAQ answer on analytics cookies under Article 5(3) ePrivacy, limited analytics exemptions, configuration evidence, consent logs, and national-law caveats.
- [ePrivacy cookie consent vs DSA ads obligations: scope-bounded comparison](/artifacts/eu/eprivacy-directive/eprivacy-vs-dsa-ads.md): Compare ePrivacy cookie and tracking-consent duties with DSA ads workstreams without merging consent, transparency, and evidence obligations.
- [ePrivacy Directive vs GDPR: cookies, communications, consent, and evidence](/artifacts/eu/eprivacy-directive/eprivacy-directive-vs-gdpr.md): Compare the EU ePrivacy Directive and GDPR across subject matter, lex specialis overlap, terminal equipment, communications confidentiality, marketing, consent, enforcement, and evidence.
- [EU cookie banner requirements under the ePrivacy Directive](/artifacts/eu/eprivacy-directive/eu-cookie-banner-requirements.md): EU ePrivacy cookie banner requirements for non-exempt cookies and trackers: prior consent, reject choices, no pre-ticked boxes, withdrawal, analytics limits, cookie walls, and evidence logs.
- [EU ePrivacy analytics cookies: consent, exemption, and evidence guide](/artifacts/eu/eprivacy-directive/analytics-cookies.md): Source-backed guide to analytics cookies under EU ePrivacy: Article 5(3) scope, when consent is usually needed, limited analytics exemptions, consent records, and evidence gaps.
- [EU ePrivacy Applicability Test for Cookies, SDKs, Pixels, Communications, and Marketing](/artifacts/eu/eprivacy-directive/applicability-test.md): A concrete EU ePrivacy Directive applicability test for electronic communications services, terminal-equipment storage or access, cookies, SDKs, pixels, local storage, direct marketing, GDPR overlap, and evidence.
- [EU ePrivacy Article 5(3) terminal equipment test](/artifacts/eu/eprivacy-directive/article-5-3-terminal-equipment-test.md): A cited Article 5(3) test for cookies, pixels, local identifiers, device APIs, strictly necessary exceptions, and consent evidence.
- [EU ePrivacy Confidentiality of Communications: Article 5 controls](/artifacts/eu/eprivacy-directive/confidentiality-of-communications.md): Article 5 confidentiality guide for EU ePrivacy communications, traffic data, metadata, terminal-equipment access, consent limits, and GDPR interplay.
- [EU ePrivacy consent-log evidence workflow for cookies and trackers](/artifacts/eu/eprivacy-directive/consent-log-evidence-workflow.md): Build an ePrivacy consent-log workflow that records cookie and tracker decisions, banner versions, consent signals, withdrawals, vendor evidence, and audit-ready outputs.
- [EU ePrivacy cookie banner UX test cases](/artifacts/eu/eprivacy-directive/banner-ux-test-cases.md): Source-backed cookie banner UX tests for Article 5(3) ePrivacy consent: reject all, pre-ticked boxes, withdrawal, cookie walls, analytics toggles, and consent evidence.
- [EU ePrivacy Cookie Scope Classifier Workflow](/artifacts/eu/eprivacy-directive/cookie-scope-classifier-workflow.md): Classify cookies, pixels, SDKs, local storage, device identifiers, and analytics tracers under Article 5(3) ePrivacy rules, with consent and exemption evidence outputs.
- [EU ePrivacy direct-marketing consent checklist](/artifacts/eu/eprivacy-directive/direct-marketing-consent-checklist.md): Checklist for ePrivacy Directive direct-marketing messages: consent, soft opt-in, sender identity, opt-out handling, proof records, suppression, and national-law caveats.
- [EU ePrivacy Directive Compliance Checklist](/artifacts/eu/eprivacy-directive/checklist.md): A concrete ePrivacy checklist for terminal equipment access, cookie consent, exemptions, banner UX, direct marketing, confidentiality, GDPR interplay, and evidence records.
- [EU ePrivacy Directive Compliance Guide for Cookies, Marketing, and Communications](/artifacts/eu/eprivacy-directive/compliance.md): Practical ePrivacy Directive compliance checks for terminal equipment, communications confidentiality, cookie consent, exemptions, direct marketing, evidence, and national-law caveats.
- [EU ePrivacy Directive Cookies and Consent: Article 5(3), exemptions, and banner evidence](/artifacts/eu/eprivacy-directive/cookies-and-consent.md): Cookie consent guide for the EU ePrivacy Directive: Article 5(3) scope, strictly necessary and transmission exemptions, consent UX, withdrawal, logs, analytics caveats, and GDPR interplay.
- [EU ePrivacy Directive direct marketing rules for electronic mail](/artifacts/eu/eprivacy-directive/direct-marketing-rules.md): Source-backed guide to Article 13 ePrivacy Directive rules for electronic mail marketing, prior consent, customer soft opt-in, opt-out handling, sender identity, and Member State caveats.
- [EU ePrivacy Directive Enforcement and Fines](/artifacts/eu/eprivacy-directive/enforcement-and-fines.md): Source-backed guide to ePrivacy Directive enforcement, national penalties, competent authorities, GDPR interplay, cookie-banner risk, and evidence limits.
- [EU ePrivacy Directive FAQ: cookies, consent, marketing, GDPR interplay](/artifacts/eu/eprivacy-directive/faq.md): Answers to recurring EU ePrivacy Directive questions on Article 5(3), terminal-equipment access, cookie consent, exemptions, analytics, direct marketing, GDPR interplay, national enforcement, and evidence.
- [EU ePrivacy Directive Member State Cookie Rules](/artifacts/eu/eprivacy-directive/member-state-cookie-rules.md): How to evidence EU ePrivacy cookie compliance when Article 5(3) is implemented through Member State law and national authority practice.
- [EU ePrivacy Directive Metadata and Location Data Guide](/artifacts/eu/eprivacy-directive/metadata-and-location-data.md): Source-backed guide to EU ePrivacy Directive rules for traffic data, location data, anonymisation, consent, value-added services, Article 5(3) overlap, and national-law limits.
- [EU ePrivacy Directive penalties and fines: national enforcement caveats](/artifacts/eu/eprivacy-directive/penalties-and-fines.md): Source-backed guide to ePrivacy Directive penalty exposure, national transposition caveats, cookie enforcement evidence, consent defects, and GDPR overlap limits.
- [EU ePrivacy Directive Requirements: cookies, communications and marketing](/artifacts/eu/eprivacy-directive/requirements.md): Source-backed map of EU ePrivacy Directive requirements for communications confidentiality, terminal-equipment access, consent, traffic and location data, and direct marketing.
- [EU ePrivacy Directive vs GDPR: cookies, communications, marketing, and evidence](/artifacts/eu/eprivacy-directive/eprivacy-vs-gdpr.md): Compare the EU ePrivacy Directive and GDPR by trigger, consent standard, lex specialis overlap, enforcement caveats, and evidence outputs for cookies, device access, communications, and marketing.
- [EU ePrivacy Directive vs UK PECR: scope-bounded cookie and marketing comparison](/artifacts/eu/eprivacy-directive/eprivacy-vs-uk-pecr.md): Compare EU ePrivacy Directive rules with a UK PECR workstream requiring separate source review for cookies, terminal equipment, direct marketing, consent, soft opt-in, and evidence.
- [EU ePrivacy soft opt-in FAQ for email marketing](/artifacts/eu/eprivacy-directive/faq/soft-opt-in.md): When Article 13(2) soft opt-in can support EU customer email marketing, including existing-customer, similar-offer, opt-out, sender-identity, suppression-list, and national-law checks.
- [EU ePrivacy soft opt-in marketing checklist](/artifacts/eu/eprivacy-directive/soft-opt-in-marketing.md): Source-backed checklist for using the EU ePrivacy Directive soft opt-in exception for customer email marketing, opt-outs, sender identity, suppression records, and national-law caveats.
- [EU ePrivacy soft opt-in marketing review workflow](/artifacts/eu/eprivacy-directive/soft-opt-in-marketing-review-workflow.md): Review whether an EU electronic-mail marketing send can rely on the ePrivacy soft opt-in, with checks for customer relationship evidence, similar products, opt-out, sender identity, suppression records, and national-law caveats.
- [EU ePrivacy Strictly Necessary Cookie Exemptions](/artifacts/eu/eprivacy-directive/strictly-necessary-exemptions.md): Source-backed guide to the Article 5(3) ePrivacy exemptions for transmission cookies, requested-service cookies, analytics caveats, evidence, and national-law checks.
- [Is a reject-all button required for EU ePrivacy cookie consent?](/artifacts/eu/eprivacy-directive/faq/reject-all-button.md): Standalone FAQ answer on EU ePrivacy reject-all and refuse options for cookie banners, including equal prominence, deceptive UX, consent evidence, withdrawal, and national-law caveats.
- [Strictly Necessary Cookies under the EU ePrivacy Directive](/artifacts/eu/eprivacy-directive/faq/strictly-necessary-cookies.md): FAQ answer on when EU ePrivacy Article 5(3) allows cookies without consent, with cited examples, analytics caveats, evidence records, and national-law cautions.
- [What should CMP consent logs retain under the EU ePrivacy Directive?](/artifacts/eu/eprivacy-directive/faq/cmp-consent-logs.md): FAQ answer on CMP consent logs for EU ePrivacy cookie consent: retained fields, consent validity signals, banner versioning, refusal and withdrawal events, proof limits, and national-law caveats.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/eu/eprivacy-directive/deadlines-and-compliance-calendar.md
