| Scope boundary | Is there processing of personal data in scope of the GDPR, and who is the controller, processor, or joint controller for that processing? | Is the activity connected to publicly available electronic communications services or public communications networks, communications confidentiality, traffic data, location data, terminal-equipment storage or access, or unsolicited communications? | Run both tests for cookies, SDKs, analytics, messaging, and marketing. ePrivacy may govern the communications or terminal-access step while GDPR governs any personal-data processing that follows. |
|---|
| Lawful basis and consent | GDPR Article 6 requires a lawful basis for personal-data processing. Consent is one basis, and Article 7 requires the controller to demonstrate consent and allow withdrawal. | ePrivacy Article 5(3) requires consent for storing information or gaining access to information in terminal equipment unless the directive's transmission or strictly necessary exception applies. Article 13 addresses consent and objection rules for direct marketing communications. | A consent banner or marketing opt-in may need to satisfy ePrivacy for the access or communication and GDPR for the later personal-data processing. Do not substitute a GDPR basis for an ePrivacy consent requirement. |
|---|
| Trigger | GDPR applies when cookie, SDK, tag, device, or analytics information is personal data, including where it can identify a person directly or indirectly. | ePrivacy Article 5(3) focuses on storing information or gaining access to information already stored in terminal equipment. The protected information can be personal or non-personal, and storage and access are separate triggers. | Classify terminal storage or access first, then classify the personal-data processing that follows. A technology can fall under ePrivacy without GDPR, and a strictly necessary ePrivacy use can still require a GDPR record when personal data is processed. |
|---|
| Core obligations | GDPR governs personal-data processing principles, transparency, security, rights, breach response, records, DPIAs, and transfers when communications data or location data relates to an identified or identifiable person. | ePrivacy contains specific rules for communications confidentiality, traffic data, and location data other than traffic data in the electronic communications context. | For messaging, network, telecom, or location features, do not rely only on a GDPR data map. Add the ePrivacy Article 5, 6, and 9 classification where the service and data type match the directive. |
|---|
| Evidence record | GDPR still requires a lawful basis, notice, rights handling, suppression controls, and accountability for personal data used in direct marketing. | ePrivacy Article 13 addresses unsolicited communications for direct marketing, including prior consent for automated calling systems, fax, and electronic mail, plus a limited own-similar-products electronic-mail scenario and national-law choices for other cases. | Keep the GDPR marketing-processing record and the ePrivacy channel rule together. If a rule turns on Member State implementation, flag it for local-law review rather than generalizing it. |
|---|
| Timing and deadlines | GDPR Article 32 requires security appropriate to risk, and Article 33 requires controller notification to the competent supervisory authority where feasible within 72 hours unless the breach is unlikely to risk individuals' rights and freedoms. | ePrivacy Article 4 requires providers of publicly available electronic communications services to take security measures and notify personal data breaches to the competent national authority without undue delay, with subscriber or individual notice where likely adverse effects apply. | A communications-service breach may need both GDPR and ePrivacy routing. Record which authority route, threshold, clock, subscriber notice, and evidence inventory applies under each source. |
|---|
| Enforcement | GDPR creates supervisory authorities, corrective powers, and administrative fine tiers, including up to EUR 20 million or 4 percent of worldwide annual turnover for specified infringements. | ePrivacy requires Member States to lay down penalties for infringements of national provisions adopted under the directive, and those penalties must be effective, proportionate, and dissuasive. | Do not invent national ePrivacy fine amounts or authority procedures from a GDPR comparison. Use GDPR fine tiers for GDPR issues and check Member State ePrivacy implementation for the local penalty route. |
|---|
| Overlap and reuse | When the same tool or workflow collects personal data and also touches terminal equipment, identify both the GDPR role and the ePrivacy trigger before you decide which records to keep. | When the same tool or workflow touches terminal equipment, electronic communications, direct marketing, traffic data, or location data, apply the relevant ePrivacy rule and then check whether any later personal-data processing needs a GDPR basis. | One product step can trigger two analyses, but the evidence should be separated by legal test. That keeps the cookie, communications, and personal-data questions from collapsing into one generic privacy review. |
|---|
| Practical decision rule | Identify any personal-data processing and the GDPR controller, processor, purpose, lawful basis, notice, rights, retention, security, and transfer controls. | For terminal access, communications, or electronic marketing, resolve the ePrivacy consent, exception, confidentiality, or channel rule before the activity occurs. | For a step that triggers ePrivacy, decide the ePrivacy gate first and the GDPR follow-on processing second. Record both outcomes before deployment. |
|---|