Artifact GuideEU

EU ePrivacy Directive penalties and fines

This page helps frame ePrivacy enforcement exposure without inventing an EU-wide fine ceiling: Article 15a leaves penalty rules to Member States, while EU sources define the duties and risk patterns that national authorities enforce.

Built for privacy, legal, web engineering, marketing operations, analytics, consent-platform, and product teams that need defensible evidence for cookies, tracking technologies, direct marketing, and terminal-equipment access.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

The ePrivacy Directive does not publish an EU-level administrative fine table comparable to the GDPR. instead requires Member States to set penalties for infringements of their national ePrivacy provisions, including criminal sanctions where appropriate, and to give national bodies cessation and investigative powers. To assess a real case, identify the ePrivacy duty and affected Member State first, then find the current national penalty provision and competent authority before stating an amount, limitation period, appeal route, or procedure.

Section 1

What can be said at EU level

defines the EU-level enforcement structure but does not set a single maximum fine. It requires Member States to lay down penalty rules for national ePrivacy infringements and take the measures needed to implement them. It also requires competent national authorities, and where relevant other national bodies, to have powers to order cessation of infringements and obtain information needed to monitor and enforce national provisions.

also says penalties may cover the period of a breach even if the breach was later corrected. Remediation matters, but it does not erase the need to check the national penalty rule. For a real matter, record the alleged breach, affected Member State or States, national implementing law, competent authority route, available remedies, and any parallel GDPR issue.

  • Use as the EU-level anchor for penalties, cessation powers, investigative powers, and cross-border cooperation.
  • Treat national law as mandatory before naming a fine amount, criminal sanction, limitation period, appeal route, or authority.
  • Separate ePrivacy penalty exposure from GDPR exposure; the same facts can trigger both frameworks, but the legal basis for each enforcement step must be identified.
  • Avoid country tables unless each country entry is supported by a current national source.
  • Check the national transposition law and the competent national authority or other body named there before quoting the actual penalty exposure.
  • Keep the detection date, correction date, and evidence of remediation; permits penalties for the earlier breach period.
Section 2

Penalty triggers to test before assigning risk

The most common ePrivacy penalty assessment starts with Article 5(3): storing information on, or gaining access to information already stored in, a user's terminal equipment. EDPB guidance confirms that this is not limited to conventional browser cookies. Tracking pixels, tracked URLs, local storage, SDKs, identifiers, IoT reporting, and client-side code can all need analysis when they store or access terminal-equipment information.

Direct marketing is a separate trigger. Article 13 requires prior consent for automated calling systems, fax, and electronic mail marketing. Its limited existing-customer exception applies where the same natural or legal person obtained electronic contact details in the context of a sale and uses them for its own similar products or services, provided the customer received a clear, distinct, easy, and free objection opportunity when the details were collected and in every message. National law determines some choices for other unsolicited communications, so a cross-border campaign needs a country-level check.

  • Inventory every cookie, pixel, tag, SDK, local-storage item, mobile identifier, and tracked link that stores or accesses terminal-equipment information.
  • Classify each item by purpose, provider, first-party or third-party role, duration, recipient access, and whether it is active before consent.
  • For marketing, separate prospecting, existing-customer soft opt-in, service messages, and suppression-list processing.
  • Escalate any hidden identifier, pre-consent firing, unclear vendor purpose, or marketing list reuse before launch.
Section 3

Evidence that reduces enforcement exposure

Good evidence does not prove there can be no penalty, but it can make the risk analysis reviewable. Keep a point-in-time record showing what technology ran, why it ran, whether consent was required, which exemption was claimed if any, what the user saw, and whether the implementation matched the record.

For consent-required technologies, the strongest evidence is technical and user-facing: no pre-consent firing, an equal and understandable refusal path, no pre-ticked opt-in boxes, accessible withdrawal after consent, clear purpose descriptions, cookie duration, third-party access information, and logs that show the consent state used by each tag or SDK.

  • Save a cookie and tracker inventory with provider, purpose, duration, domain, country scope, and consent category.
  • Keep CMP configuration exports, screenshots of each banner layer, release history, geolocation rules, and automated tag-firing tests.
  • Retain consent logs that can show opt-in, refusal, withdrawal, timestamp, policy version, banner version, and the categories affected.
  • For claimed exemptions, document why the storage or access is strictly necessary for a user-requested service or solely needed for communication transmission.
  • For marketing, keep consent capture, source of contact details, suppression-list logic, opt-out wording, and proof that each message included an easy stop mechanism.
Section 4

Where teams overstate or understate fines risk

Teams overstate risk when they quote a GDPR maximum as if it were the ePrivacy Directive's own EU-wide fine ceiling. Teams understate risk when they treat cookies, SDKs, local storage, or tracked URLs as harmless because the data is not obviously personal data. Article 5(3) protects terminal-equipment information and can apply regardless of whether the accessed information is personal data.

The GDPR/ePrivacy boundary is also easy to misread. EDPB interplay material explains that Member States have flexibility over the body that enforces national ePrivacy rules, while data protection authorities remain competent for GDPR processing that is not governed by an ePrivacy special rule. Use two tracks: national ePrivacy enforcement for the storage/access or marketing rule, and GDPR analysis for personal-data processing before or after that special rule.

  • Do not state an EU-wide ePrivacy fine maximum unless a cited source in the page supports it.
  • Do not assume legitimate interest can replace Article 5(3) consent for placing or reading consent-required cookies or similar technologies.
  • Do not treat first-party analytics as automatically exempt; document the exact national conditions if relying on an audience-measurement exemption.
  • Do not rely on banner screenshots alone; match the user interface to network tests and consent-state logs.
  • Do not merge ePrivacy and GDPR findings in a way that hides which authority, power, or legal basis is being used.
Section 5

Penalty assessment checklist

Review this checklist before approving a launch, incident response, customer answer, or regulator response. It keeps the assessment inside what the EU sources support and leaves national penalty amounts to national legal review.

The output should be a short evidence pack, not a country table assembled from memory. For every amount or procedure, capture the national provision, version or effective date, covered actor and conduct, calculation method, competent decision-maker, and review or appeal route. If the file cannot identify that source, leave the claim out.

Does the EU ePrivacy Directive set one EU-wide fine amount?

No. The EU-level source requires Member States to set penalties for national ePrivacy infringements, but it does not provide one current EU-wide fine ceiling for this page to quote.

What evidence is most useful before discussing an ePrivacy fine?

Keep the national rule check, tracker inventory, consent-banner design, consent and withdrawal logs, network tests showing when tags fire, exemption rationale, and remediation history.

Does the GDPR maximum fine apply automatically to an ePrivacy Directive breach?

No. The ePrivacy Directive does not import one GDPR maximum as its own EU-wide fine ceiling. A GDPR penalty may be relevant where the facts also establish a separate GDPR infringement, but the ePrivacy penalty must be traced to the applicable Member State law and the authority authorized under that law to enforce it.

  • Identify the conduct: terminal-equipment storage or access, unsolicited direct marketing, traffic or location data handling, confidentiality of communications, or another ePrivacy rule.
  • Map the affected Member States and confirm that no penalty amount, calculation basis, competent authority, deadline, appeal route, or criminal exposure is stated without current national-source support.
  • For each national amount, record whether the provision uses a fixed cap, turnover, a per-offence or continuing-breach method, or another calculation only when the national text says so.
  • Attach the tracker inventory, CMP settings, network test, banner screenshots, consent logs, withdrawal path, and vendor-purpose record.
  • For each exemption, record the user-requested service, strict-necessity rationale, cookie duration, and why no additional non-exempt purpose is bundled.
  • For GDPR overlap, split Article 5(3) storage/access from subsequent personal-data processing, profiling, retention, data-subject rights, and security obligations.
  • Record remediation: disable pre-consent firing, add or equalize refusal controls, remove pre-ticked choices, shorten retention, update notices, stop unsupported marketing, and retest.
Recommended next step

This penalties guide helps separate EU rules, national enforcement, and GDPR overlap

Sorena can help convert this page into a cited tracker inventory, consent-evidence checklist, national-source request list, and remediation workflow for ePrivacy enforcement risk.

Primary sources

References and citations

edpb.europa.eu
Referenced sections
  • The taskforce report supports the warning that legitimate interest is not the legal basis for Article 5(3) placement or reading where consent is required.
"cannot be the legitimate interests"
edpb.europa.eu
Referenced sections
  • Consent guidance supports the evidence focus on free choice, clear affirmative action, informed consent, demonstrability, and easy withdrawal.
"clear affirmative action"
edpb.europa.eu
Referenced sections
  • The guidelines support the warning that Article 5(3) can cover information stored or accessed on terminal equipment beyond personal data and beyond cookies.
"both non-personal data and personal data"
edpb.europa.eu
Referenced sections
  • Supports the two-track analysis: a data protection authority directly enforces national ePrivacy rules only when national law grants that competence, while its GDPR competence remains for processing not governed by an ePrivacy special rule.
"only if national law confers this competence on them"
ec.europa.eu
Referenced sections
  • The opinion supports documenting exact exemption criteria and avoiding broad necessary-cookie claims for analytics, advertising, or multipurpose cookies.
"purpose and the specific implementation"
Related guides

Explore more topics

Are cookie walls allowed under the EU ePrivacy Directive?
FAQ answer on cookie walls under the EU ePrivacy Directive, covering freely given consent, refusal and withdrawal paths, banner evidence, and national-law caveats.
Do Analytics Cookies Require Consent under the EU ePrivacy Directive?
FAQ answer on analytics cookies under Article 5(3) ePrivacy, limited analytics exemptions, configuration evidence, consent logs, and national-law caveats.
ePrivacy cookie consent vs DSA advertising rules
Compare ePrivacy rules for device storage and access with DSA ad labels, advertiser disclosures, targeting information, profiling limits, and VLOP/VLOSE ad repositories.
ePrivacy Directive vs GDPR: cookies, communications, consent, and evidence
Compare the EU ePrivacy Directive and GDPR across subject matter, lex specialis overlap, terminal equipment, communications confidentiality, marketing, consent, enforcement, and evidence.
EU cookie banner requirements under the ePrivacy Directive
EU ePrivacy cookie banner requirements for non-exempt cookies and trackers: prior consent, reject choices, no pre-ticked boxes, withdrawal, analytics limits, cookie walls, and evidence logs.
EU ePrivacy analytics cookies: consent, exemption, and evidence guide
Source-backed guide to analytics cookies under EU ePrivacy: Article 5(3) scope, when consent is usually needed, limited analytics exemptions, consent records, and evidence gaps.
EU ePrivacy Applicability Test for Cookies, SDKs, Pixels, Communications, and Marketing
A concrete EU ePrivacy Directive applicability test for electronic communications services, terminal-equipment storage or access, cookies, SDKs, pixels, local storage, direct marketing, GDPR overlap, and evidence.
EU ePrivacy Article 5(3) terminal equipment test
A cited Article 5(3) test for cookies, pixels, local identifiers, device APIs, strictly necessary exceptions, and consent evidence.
EU ePrivacy Confidentiality of Communications: Article 5 controls
Article 5 confidentiality guide for EU ePrivacy communications, traffic data, metadata, terminal-equipment access, consent limits, and GDPR interplay.
EU ePrivacy consent-log evidence workflow for cookies and trackers
Build evidence that links each cookie or tracker decision to the banner shown, the user's signal, the live technical behavior, withdrawal, and later changes.
EU ePrivacy cookie banner UX test cases
Source-backed cookie banner UX tests for Article 5(3) ePrivacy consent: reject all, pre-ticked boxes, withdrawal, cookie walls, analytics toggles, and consent evidence.
EU ePrivacy Cookie Scope Classifier Workflow
Decide whether cookies, pixels, SDKs, local storage, identifiers, and analytics fall within Article 5(3), then document consent, an exemption, or escalation.
EU ePrivacy direct-marketing consent checklist
Checklist for ePrivacy Directive direct-marketing messages: consent, soft opt-in, sender identity, opt-out handling, proof records, suppression, and national-law caveats.
EU ePrivacy Directive compliance calendar for cookies, consent, and marketing
Source-backed ePrivacy calendar covering Directive milestones, Article 5(3) cookie reviews, consent evidence, direct marketing checks, and national-law follow-up.
EU ePrivacy Directive Compliance Checklist
A concrete ePrivacy checklist for terminal equipment access, cookie consent, exemptions, banner UX, direct marketing, confidentiality, GDPR interplay, and evidence records.
EU ePrivacy Directive Compliance Guide for Cookies, Marketing, and Communications
Practical ePrivacy Directive compliance checks for terminal equipment, communications confidentiality, cookie consent, exemptions, direct marketing, evidence, and national-law caveats.
EU ePrivacy Directive Cookies and Consent: Article 5(3), exemptions, and banner evidence
Cookie consent guide for the EU ePrivacy Directive: Article 5(3) scope, strictly necessary and transmission exemptions, consent UX, withdrawal, logs, analytics caveats, and GDPR interplay.
EU ePrivacy Directive direct marketing rules for electronic mail
Source-backed guide to Article 13 ePrivacy Directive rules for electronic mail marketing, prior consent, customer soft opt-in, opt-out handling, sender identity, and Member State caveats.
EU ePrivacy Directive Enforcement and Fines
Source-backed guide to ePrivacy Directive enforcement, national penalties, competent authorities, GDPR interplay, cookie-banner risk, and evidence limits.
EU ePrivacy Directive FAQ: cookies, consent, marketing, GDPR interplay
Answers to recurring EU ePrivacy Directive questions on Article 5(3), terminal-equipment access, cookie consent, exemptions, analytics, direct marketing, GDPR interplay, national enforcement, and evidence.
EU ePrivacy Directive Member State Cookie Rules
How to evidence EU ePrivacy cookie compliance when Article 5(3) is implemented through Member State law and national authority practice.
EU ePrivacy Directive Metadata and Location Data Guide
Source-backed guide to EU ePrivacy Directive rules for traffic data, location data, anonymisation, consent, value-added services, Article 5(3) overlap, and national-law limits.
EU ePrivacy Directive Requirements: cookies, communications and marketing
Source-backed map of EU ePrivacy Directive requirements for communications confidentiality, terminal-equipment access, consent, traffic and location data, and direct marketing.
EU ePrivacy Directive vs GDPR: cookies, communications, marketing, and evidence
Compare the EU ePrivacy Directive and GDPR by trigger, consent standard, lex specialis overlap, enforcement caveats, and evidence outputs for cookies, device access, communications, and marketing.
EU ePrivacy Directive vs UK PECR: cookies and direct marketing
Compare the EU ePrivacy Directive with current UK PECR rules for device storage and access, statutory exceptions, consent, electronic-mail marketing, soft opt-ins, and enforcement.
EU ePrivacy soft opt-in FAQ for email marketing
When Article 13(2) soft opt-in can support EU customer email marketing, including existing-customer, similar-offer, opt-out, sender-identity, suppression-list, and national-law checks.
EU ePrivacy soft opt-in marketing checklist
Source-backed checklist for using the EU ePrivacy Directive soft opt-in exception for customer email marketing, opt-outs, sender identity, suppression records, and national-law caveats.
EU ePrivacy soft opt-in marketing review workflow
Decide whether an electronic-mail marketing audience meets every Article 13 soft opt-in condition, or must be suppressed or supported by valid prior consent.
EU ePrivacy Strictly Necessary Cookie Exemptions
Source-backed guide to the Article 5(3) ePrivacy exemptions for transmission cookies, requested-service cookies, analytics caveats, evidence, and national-law checks.
Is a reject-all button required for EU ePrivacy cookie consent?
Standalone FAQ answer on EU ePrivacy reject-all and refuse options for cookie banners, including equal prominence, deceptive UX, consent evidence, withdrawal, and national-law caveats.
Strictly Necessary Cookies under the EU ePrivacy Directive
FAQ answer on when EU ePrivacy Article 5(3) allows cookies without consent, with cited examples, analytics caveats, evidence records, and national-law cautions.
What should CMP consent logs retain under the EU ePrivacy Directive?
FAQ answer on CMP consent logs for EU ePrivacy cookie consent: retained fields, consent validity signals, banner versioning, refusal and withdrawal events, proof limits, and national-law caveats.