Two European laws govern what your website may do with a visitor’s browser, and they divide the work. The ePrivacy Directive decides when consent is needed for cookies, trackers, and electronic marketing. The GDPR decides what valid consent means and governs everything that happens to personal data afterward. Compliance requires satisfying both at once, which is why understanding the boundary matters.
| Regulation | Directive 2002/58/EC, amended by 2009/136/EC |
|---|---|
| Key provision | Article 5(3): prior consent for device storage/access |
| Max penalty | Set per member state; CNIL cookie fines up to EUR 150M |
| Official text | EUR-Lex CELEX 32002L0058 |
The division of labor
The ePrivacy Directive is lex specialis: for electronic communications matters it overrides the general GDPR rules (GDPR Article 95 and recital 173 manage the boundary). Practical consequences:
- Cookie consent comes from ePrivacy. Article 5(3), as amended in 2009, requires prior informed consent before storing or accessing information on terminal equipment, with narrow exemptions for transmission and strict necessity.
- Consent quality comes from GDPR. The directive borrows the GDPR’s consent definition, so all the Article 4(11) and Article 7 requirements (freely given, specific, informed, unambiguous, withdrawable) apply to cookie banners.
- The device rule ignores personal data. ePrivacy protects the terminal equipment itself. A tracking script needs consent even if you argue no personal data is involved, which defeats the most common excuse.
- Marketing opt-ins come from ePrivacy Article 13. Email and SMS marketing require prior consent, with the soft opt-in exception for existing customers being marketed similar products, always with a working opt-out.
Why the enforcement path differs
Because ePrivacy is a directive, each member state transposed it into national law and designated its own enforcer. That has a strategic consequence regulators have exploited: the GDPR’s one-stop-shop mechanism, which routes cross-border cases to the company’s lead authority, does not apply to national ePrivacy enforcement. France’s CNIL used exactly this route for its December 2021 decisions against Google (EUR 150 million) and Facebook (EUR 60 million) over reject-button asymmetry, bypassing the Irish lead-authority bottleneck entirely. Any national authority can do the same to any site its residents visit.
Compliance in one pass
Audit against both layers simultaneously: inventory every cookie, script, and pixel; classify each as strictly necessary or consent-required under ePrivacy; then verify the consent collected meets GDPR standards and that nothing fires before it. A free scan automates the inventory and the pre-consent check. For what may replace the directive, see our ePrivacy Regulation status page, and for banner mechanics, the consent management guide.