---
title: "EU ePrivacy Directive FAQ: cookies, consent, marketing, GDPR interplay"
canonical_url: "https://www.sorena.io/artifacts/eu/eprivacy-directive/faq"
source_url: "https://www.sorena.io/artifacts/eu/eprivacy-directive/faq/items/page/2"
author: "Sorena AI"
description: "Answers to recurring EU ePrivacy Directive questions on Article 5(3), terminal-equipment access, cookie consent, exemptions, analytics, direct marketing, GDPR interplay, national enforcement, and evidence."
published_at: "2026-05-09"
updated_at: "2026-07-24"
keywords:
  - "EU ePrivacy Directive"
  - "Article 5(3)"
  - "cookies"
  - "terminal equipment"
  - "cookie consent"
  - "direct marketing"
  - "GDPR interplay"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# EU ePrivacy Directive FAQ: cookies, consent, marketing, GDPR interplay

Answers to recurring EU ePrivacy Directive questions on Article 5(3), terminal-equipment access, cookie consent, exemptions, analytics, direct marketing, GDPR interplay, national enforcement, and evidence.

*EU ePrivacy Directive FAQ* *Cookies, consent, marketing*

## EU ePrivacy Directive FAQ

Standalone answers for product, privacy, engineering, analytics, and marketing teams working through EU ePrivacy questions.

Covers terminal-equipment access, consent and exemptions, cookie-banner risks, direct marketing, GDPR overlap, national-law caveats, and evidence records.

Use this FAQ to decide whether a communications feature, cookie, SDK, pixel, analytics tool, directory, caller feature, or direct-marketing campaign needs consent, can rely on a narrow exemption, or needs a Member State review. The ePrivacy Directive is Directive 2002/58/EC as amended. It supplies the binding EU baseline but is implemented through national law, so local scope, procedure, enforcement, and remedies can differ. The Commission formally withdrew its 2017 proposal for an ePrivacy Regulation on 6 October 2025; the proposal never replaced the Directive and creates no current duty or deadline.

## Definitions

### EU ePrivacy Directive

**Term:** ePrivacy Directive

The ePrivacy Directive is Directive 2002/58/EC on privacy and electronic communications, as amended. It sets EU rules for communications confidentiality, service security and personal data breaches, traffic and location data, terminal-equipment storage or access, caller privacy, directories, and unsolicited direct marketing. Member States implement and enforce those rules through national law.

**Why it matters here:** Use the Directive and the applicable national transposition as the current legal baseline. EDPB, WP29, Commission, CJEU, and national-authority materials explain or interpret parts of that baseline but do not turn the withdrawn 2017 ePrivacy Regulation proposal into law.

Sources:

- [Directive 2002/58/EC on privacy and electronic communications](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32002L0058&ref=sorena.io)
- [Official Journal notice withdrawing COM(2017) 10 final](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52025XC05423&ref=sorena.io)

## Browse sub-FAQ modules

### [Are cookie walls allowed under the EU ePrivacy Directive?](/artifacts/eu/eprivacy-directive/faq/cookie-walls.md)

FAQ answer on cookie walls under the EU ePrivacy Directive, covering freely given consent, refusal and withdrawal paths, banner evidence, and national-law caveats.

- 2 items

### [Do Analytics Cookies Require Consent under the EU ePrivacy Directive?](/artifacts/eu/eprivacy-directive/faq/analytics-cookies.md)

FAQ answer on analytics cookies under Article 5(3) ePrivacy, limited analytics exemptions, configuration evidence, consent logs, and national-law caveats.

- 4 items

### [EU ePrivacy soft opt-in FAQ for email marketing](/artifacts/eu/eprivacy-directive/faq/soft-opt-in.md)

When Article 13(2) soft opt-in can support EU customer email marketing, including existing-customer, similar-offer, opt-out, sender-identity, suppression-list, and national-law checks.

- 3 items

### [Is a reject-all button required for EU ePrivacy cookie consent?](/artifacts/eu/eprivacy-directive/faq/reject-all-button.md)

Standalone FAQ answer on EU ePrivacy reject-all and refuse options for cookie banners, including equal prominence, deceptive UX, consent evidence, withdrawal, and national-law caveats.

- 4 items

### [Strictly Necessary Cookies under the EU ePrivacy Directive](/artifacts/eu/eprivacy-directive/faq/strictly-necessary-cookies.md)

FAQ answer on when EU ePrivacy Article 5(3) allows cookies without consent, with cited examples, analytics caveats, evidence records, and national-law cautions.

- 3 items

### [What should CMP consent logs retain under the EU ePrivacy Directive?](/artifacts/eu/eprivacy-directive/faq/cmp-consent-logs.md)

FAQ answer on CMP consent logs for EU ePrivacy cookie consent: retained fields, consent validity signals, banner versioning, refusal and withdrawal events, proof limits, and national-law caveats.

- 4 items

Browse all indexed questions: [/artifacts/eu/eprivacy-directive/faq/items](/artifacts/eu/eprivacy-directive/faq/items.md)

## All FAQ items

*Page 2 of 2. Showing 5 of 20 items.*

### [How should analytics and evidence records be handled?](/artifacts/eu/eprivacy-directive/faq/strictly-necessary-cookies.md#how-should-analytics-and-evidence-records-be-handled)

*Module: [Strictly Necessary Cookies under the EU ePrivacy Directive](/artifacts/eu/eprivacy-directive/faq/strictly-necessary-cookies.md)*

Do not classify analytics cookies as strictly necessary under the general Article 5(3) exemptions merely because the site operator needs measurement. WP29 states that first-party analytics are often useful but are not strictly necessary for a user-requested website feature because the user can still access the site when those cookies are disabled.

- Keep a cookie inventory with name, provider, domain, first-party or third-party status, purpose, duration, storage/access method, and data sent from the terminal equipment.
- For each claimed exemption, record the requested user action, the exact service feature, why the feature fails without the cookie, and why the duration is no longer than needed.
- Separate essential purposes from analytics, ads, social plug-ins, A/B testing, personalization, attribution, fraud measurement for advertising, and product-improvement purposes.
- Keep evidence of banner behavior for non-essential cookies: no consent-required cookies before consent, no pre-ticked boxes, a real reject path, and consent withdrawal that is as easy as giving consent.
- Refresh the assessment when cookie features, vendors, retention periods, domains, user journeys, Member State coverage, or terminal-equipment access techniques change.

Sources for this answer:

- [WP29 Opinion 04/2012 on Cookie Consent Exemption](https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2012/wp194_en.pdf?ref=sorena.io) - Supports the analytics caveat and the principle that doubts should be resolved by seeking consent rather than stretching an exemption.
- [EDPB Guidelines 05/2020 on consent](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_202005_consent_en.pdf?ref=sorena.io) - Grounds the quality standard for consent where a cookie does not fit an Article 5(3) exemption.
- [EDPB Cookie Banner Taskforce report](https://www.edpb.europa.eu/system/files/2023-01/edpb_20230118_report_cookie_banner_taskforce_en.pdf?ref=sorena.io) - Grounds evidence expectations for essentiality, banner behavior, reject options, legitimate-interest confusion, withdrawal, and national-law caveats.
- [European Commission ePrivacy overview](https://digital-strategy.ec.europa.eu/en/library/eprivacyeu-towards-future-proof-legal-framework-online-privacy?ref=sorena.io) - Commission context for the ePrivacy framework and protection of privacy in electronic communications.

### [What should CMP consent logs retain?](/artifacts/eu/eprivacy-directive/faq/cmp-consent-logs.md#what-should-cmp-consent-logs-retain)

*Module: [What should CMP consent logs retain under the EU ePrivacy Directive?](/artifacts/eu/eprivacy-directive/faq/cmp-consent-logs.md)*

Retain the consent event, refusal event, and withdrawal event at purpose level, tied to the exact banner or preference-centre version shown to the user. Article 5(3) is triggered by storing information on, or gaining access to information in, terminal equipment; the log therefore needs to connect the user's choice to the cookies, pixels, SDKs, local storage, identifiers, or similar technologies deployed at that time.

- Keep affirmative consent, refusal, no-choice/default state, later preference changes, and withdrawal as separate states or events so the record does not turn silence into consent.
- Store the banner and preference-centre version that presented the choice, including the accept, reject, settings, and withdrawal routes available at that time.
- Link each consent purpose to the live vendor, cookie, pixel, SDK, local-storage, or identifier inventory used by the site or app.
- Record whether strictly necessary items were separated from analytics, advertising, personalisation, and other optional purposes.
- Retain only the proof needed to demonstrate the consent workflow; avoid expanding the consent log into a separate behavioural tracking dataset.

Sources for this answer:

- [Directive 2002/58/EC, Article 5(3)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02002L0058-20091219&ref=sorena.io) - Grounds the need to connect CMP records to storage of, or access to, information in user terminal equipment.
- [EDPB Guidelines 2/2023 on Article 5(3) ePrivacy Directive](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-22023-technical-scope-art-53-eprivacy-directive_en?ref=sorena.io) - Supports including non-cookie technologies such as pixels, local storage, identifiers, and similar terminal-equipment access in the consent-log scope.
- [EDPB Guidelines 05/2020 on consent](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_202005_consent_en.pdf?ref=sorena.io) - Supports keeping enough records to demonstrate valid consent without excessive additional data collection.

### [Which validity signals should the log preserve?](/artifacts/eu/eprivacy-directive/faq/cmp-consent-logs.md#which-validity-signals-should-the-log-preserve)

*Module: [What should CMP consent logs retain under the EU ePrivacy Directive?](/artifacts/eu/eprivacy-directive/faq/cmp-consent-logs.md)*

A log is useful only if it captures consent quality, not just a positive flag. Preserve signals showing that the user saw clear purpose information, made a granular affirmative choice, could refuse optional cookies or trackers, and could later withdraw without undue effort.

- Consent was recorded by a clear affirmative action for named purposes rather than by inactivity or a preselected default.
- Purpose-level and vendor-level choices match the CMP configuration and the cookie or tracker inventory active at the timestamp.
- Reject, continue-without-consenting, or equivalent refusal handling was available where the banner requested consent.
- Withdrawal was available through a visible, accessible route and was not materially harder than the original consent action.
- The CMP blocked or suppressed optional tags, pixels, SDK calls, and storage until the relevant consent state allowed them.

Sources for this answer:

- [EDPB Guidelines 05/2020 on consent](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_202005_consent_en.pdf?ref=sorena.io) - Grounds the validity checks for freely given, specific, informed, unambiguous consent and easy withdrawal.
- [EDPB Cookie Banner Taskforce report](https://www.edpb.europa.eu/system/files/2023-01/edpb_20230118_report_cookie_banner_taskforce_en.pdf?ref=sorena.io) - Supports checking reject options, pre-ticked boxes, misleading banner design, essential-cookie classification, and withdrawal routes.
- [CJEU Planet49 judgment](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62017CJ0673&ref=sorena.io) - Supports treating pre-ticked cookie consent as insufficient and preserving the information provided to users for cookie consent.

### [How should consent logs connect to vendor and cookie inventories?](/artifacts/eu/eprivacy-directive/faq/cmp-consent-logs.md#how-should-consent-logs-connect-to-vendor-and-cookie-inventories)

*Module: [What should CMP consent logs retain under the EU ePrivacy Directive?](/artifacts/eu/eprivacy-directive/faq/cmp-consent-logs.md)*

The CMP log should not stand alone. It should point to the inventory that explains which cookies, pixels, SDKs, local-storage entries, tags, or identifiers were present, which were strictly necessary, which required consent, and which vendor or controller received resulting data.

- Keep inventory version, CMP configuration version, tag-manager container version, and banner text version in the same evidence trail.
- Map each optional vendor or tracker to purpose, category, storage/access type, data recipient, and consent dependency.
- Document why each strictly necessary item fits the narrow exemption instead of placing it in the consented-purpose bucket.
- Run periodic scans or deployment checks, but require owner documentation for purposes because scanner output alone cannot prove essentiality.
- Trigger review when a vendor, purpose, country rollout, cookie lifetime, SDK behaviour, or withdrawal flow changes.

Sources for this answer:

- [EDPB Cookie Banner Taskforce report](https://www.edpb.europa.eu/system/files/2023-01/edpb_20230118_report_cookie_banner_taskforce_en.pdf?ref=sorena.io) - Supports maintaining cookie lists and documenting purpose and essentiality rather than relying only on scanning tools.
- [WP29 Opinion 04/2012 on Cookie Consent Exemption](https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2012/wp194_en.pdf?ref=sorena.io) - Supports separating strictly necessary cookies from cookies that need consent under Article 5(3).
- [EDPB Guidelines 2/2023 on Article 5(3) ePrivacy Directive](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-22023-technical-scope-art-53-eprivacy-directive_en?ref=sorena.io) - Supports covering tracking pixels, tracked URLs, unique identifiers, local processing, and IP-based tracking scenarios where Article 5(3) can apply.

### [What are the limits of CMP consent-log proof?](/artifacts/eu/eprivacy-directive/faq/cmp-consent-logs.md#what-are-the-limits-of-cmp-consent-log-proof)

*Module: [What should CMP consent logs retain under the EU ePrivacy Directive?](/artifacts/eu/eprivacy-directive/faq/cmp-consent-logs.md)*

A CMP log proves that the system recorded a stated choice under a particular configuration. It does not by itself prove that consent was valid, that the banner was lawful, that all trackers were disclosed, that optional tags were actually blocked, or that the right national authority would accept the implementation.

- Do not treat a consent string as proof that the banner was clear, balanced, or granular.
- Do not use consent logs to justify setting optional cookies before the user chooses.
- Do not infer country-specific penalties or regulator positions from the EU-level sources alone.
- Escalate for national-law review when deploying in a new Member State, changing refusal or withdrawal design, or relying on an exemption.
- Set and document a retention period based on the need to demonstrate consent and handle disputes, then delete or aggregate records when that need ends. The EU-level sources cited here do not prescribe one universal CMP-log retention period.

Sources for this answer:

- [EDPB Opinion 5/2019 on ePrivacy Directive and GDPR interplay](https://www.edpb.europa.eu/sites/default/files/files/file1/201905_edpb_opinion_eprivacydir_gdpr_interplay_en.pdf?ref=sorena.io) - Supports the distinction between national ePrivacy rules for terminal-equipment access and GDPR assessment of later personal-data processing.
- [EDPB Cookie Banner Taskforce report](https://www.edpb.europa.eu/system/files/2023-01/edpb_20230118_report_cookie_banner_taskforce_en.pdf?ref=sorena.io) - Supports the caveat that taskforce positions are a minimum threshold and do not replace case-by-case authority analysis or national requirements.
- [European Commission factsheet, Stronger privacy rules for electronic communications](https://digital-strategy.ec.europa.eu/en/library/stronger-privacy-rules-electronic-communications?ref=sorena.io) - Provides Commission context that device information and electronic-communications privacy are complementary to GDPR personal-data protection.

## FAQ Pagination

- Canonical index (page 1): [/artifacts/eu/eprivacy-directive/faq/items](/artifacts/eu/eprivacy-directive/faq/items.md)
- Page 1 rule: `/page/1` is intentionally not generated; use the canonical index markdown URL.
- Current page: 2 of 2

Pages: [1](/artifacts/eu/eprivacy-directive/faq/items.md) | [2](/artifacts/eu/eprivacy-directive/faq/items/page/2.md)

[Previous page](/artifacts/eu/eprivacy-directive/faq/items.md)

*Recommended next step*

*Placement: before sources*

## Convert ePrivacy answers into product, marketing, and consent controls

Sorena can help map cookies, SDKs, pixels, marketing sends, consent flows, national-law caveats, and evidence records against the cited ePrivacy sources.

- [Open Research Copilot for EU ePrivacy Directive](/solutions/research-copilot.md): Ask questions tied to cited sources about Article 5(3), consent banners, exemptions, direct marketing, and GDPR interplay using the cited sources on this page.
- [Talk through EU ePrivacy implementation](/contact.md): Review your cookie inventory, consent evidence, direct-marketing controls, and country-law validation queue with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/eu/eprivacy-directive/faq/items/page/2.md
