ePrivacy is the common name of EU Directive 2002/58/EC, which governs privacy in the electronic communications sector. It is the source of the cookie rules: Article 5(3) requires informed consent before information is stored on or read from a user's device. It stands in a lex specialis relationship with the GDPR, taking precedence as the special rule for electronic communications and cookies.
Directive 2002/58/EC, commonly called ePrivacy, governs privacy in electronic communications in the EU: confidentiality of communications, traffic and location data, unsolicited commercial messages and cookies all fall within its scope. The cookie rule comes from Article 5(3): storing information on a user's device or reading information from it is only allowed after the user has been clearly and comprehensively informed and has given consent. Operations that are strictly necessary to carry out a transmission or to provide a service the user explicitly requested are exempt.
Its relationship with the GDPR follows the lex specialis principle: the GDPR sets the general framework for processing personal data, while ePrivacy lays down the special rules for electronic communications and cookies and takes precedence in that field. ePrivacy determines when consent is needed; the GDPR defines what valid consent looks like. As a directive it does not apply directly; each member state transposes the rules into national law, which is why cookie rules differ slightly between countries. A draft ePrivacy Regulation intended to replace the directive failed to find agreement for many years, and the European Commission formally withdrew the proposal in early 2025; the text in force remains Directive 2002/58/EC, no new regulation is expected in the near term, and sites should work to the current rules.
Frequently asked questions
What is the difference between the ePrivacy Directive and the GDPR?
The GDPR sets the general rules for processing personal data: legal bases, principles, rights and sanctions. ePrivacy contains special rules specific to electronic communications, of which cookie consent is the best known. Where they overlap, the special rule prevails: ePrivacy determines when a cookie requires consent, and the GDPR defines how that consent becomes valid. They are complementary texts, not competing ones.
When will the ePrivacy Regulation enter into force?
There is no foreseeable date, because the draft is no longer on the table: after years without agreement, the European Commission formally withdrew the proposed ePrivacy Regulation in early 2025. The text in force remains Directive 2002/58/EC, and the member states' national implementing laws stay valid. The practical conclusion for site owners is clear: there is nothing to wait for, and the current rules apply.
This content is for information only and is not legal advice.