EU Privacy Law EU/EEA

ePrivacy Directive vs. GDPR: Where Cookie Law Meets Data Protection

How the ePrivacy Directive and GDPR fit together: which law governs cookies, consent standards, marketing rules, and who enforces what.

Regulation

Directive 2002/58/EC (ePrivacy), as amended by 2009/136/EC

Max Penalty

Set nationally; CNIL has issued cookie fines up to EUR 150 million

Enforcing Authority

National authorities designated per member state (e.g., CNIL in France)

Official Source

eur-lex.europa.eu

Executive Summary

  • The ePrivacy Directive (2002/58/EC) is lex specialis to the GDPR: where both could apply to electronic communications, the ePrivacy rules take precedence.
  • Article 5(3) requires prior consent before storing or accessing information on a user's device, which is why cookie banners exist; the GDPR supplies the definition of what valid consent means.
  • Consent under ePrivacy is required regardless of whether the cookie contains personal data; the rule protects the device, not just the data.
  • Being a directive, ePrivacy was implemented differently in each member state, with national laws and national enforcers, unlike the directly applicable GDPR.
  • France's CNIL has used national ePrivacy powers for its largest cookie fines: EUR 150 million against Google and EUR 60 million against Facebook in December 2021.

Two European laws govern what your website may do with a visitor’s browser, and they divide the work. The ePrivacy Directive decides when consent is needed for cookies, trackers, and electronic marketing. The GDPR decides what valid consent means and governs everything that happens to personal data afterward. Compliance requires satisfying both at once, which is why understanding the boundary matters.

RegulationDirective 2002/58/EC, amended by 2009/136/EC
Key provisionArticle 5(3): prior consent for device storage/access
Max penaltySet per member state; CNIL cookie fines up to EUR 150M
Official textEUR-Lex CELEX 32002L0058

The division of labor

The ePrivacy Directive is lex specialis: for electronic communications matters it overrides the general GDPR rules (GDPR Article 95 and recital 173 manage the boundary). Practical consequences:

  • Cookie consent comes from ePrivacy. Article 5(3), as amended in 2009, requires prior informed consent before storing or accessing information on terminal equipment, with narrow exemptions for transmission and strict necessity.
  • Consent quality comes from GDPR. The directive borrows the GDPR’s consent definition, so all the Article 4(11) and Article 7 requirements (freely given, specific, informed, unambiguous, withdrawable) apply to cookie banners.
  • The device rule ignores personal data. ePrivacy protects the terminal equipment itself. A tracking script needs consent even if you argue no personal data is involved, which defeats the most common excuse.
  • Marketing opt-ins come from ePrivacy Article 13. Email and SMS marketing require prior consent, with the soft opt-in exception for existing customers being marketed similar products, always with a working opt-out.

Why the enforcement path differs

Because ePrivacy is a directive, each member state transposed it into national law and designated its own enforcer. That has a strategic consequence regulators have exploited: the GDPR’s one-stop-shop mechanism, which routes cross-border cases to the company’s lead authority, does not apply to national ePrivacy enforcement. France’s CNIL used exactly this route for its December 2021 decisions against Google (EUR 150 million) and Facebook (EUR 60 million) over reject-button asymmetry, bypassing the Irish lead-authority bottleneck entirely. Any national authority can do the same to any site its residents visit.

Compliance in one pass

Audit against both layers simultaneously: inventory every cookie, script, and pixel; classify each as strictly necessary or consent-required under ePrivacy; then verify the consent collected meets GDPR standards and that nothing fires before it. A free scan automates the inventory and the pre-consent check. For what may replace the directive, see our ePrivacy Regulation status page, and for banner mechanics, the consent management guide.

Frequently Asked Questions

Which law requires cookie consent, GDPR or the ePrivacy Directive?

The ePrivacy Directive. Article 5(3) requires consent before storing or reading information on a user's device unless strictly necessary for the service. GDPR defines what valid consent looks like, so both apply together in practice.

Does cookie consent apply to cookies without personal data?

Yes. Article 5(3) protects the terminal equipment itself, so consent is needed even for cookies carrying no personal data, unless they are strictly necessary. The same applies to localStorage, fingerprinting scripts, and SDK identifiers.

Which cookies are exempt from consent?

Two exemptions: cookies used solely to transmit a communication, and cookies strictly necessary for a service the user explicitly requested, such as session, cart, and load-balancing cookies. Analytics and advertising cookies do not qualify.

Who enforces the ePrivacy rules?

Each member state designates an authority in its implementing law. Often it is the data protection authority, as with France's CNIL, which lets the regulator fine cookie violations under national ePrivacy law without the GDPR's cross-border one-stop-shop mechanism.

Do the ePrivacy rules cover more than cookies?

Yes: confidentiality of communications, traffic and location data rules for telecom providers, and Article 13's electronic direct marketing rules, including the opt-in requirement for email and SMS marketing and the soft opt-in exception for existing customers.

Regulatory Crosswalk

GDPRUK PECRePrivacy Regulation (proposed)

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.