EU Privacy Law EU/EEA

ePrivacy Regulation: What Changes Are Coming and How to Prepare Now

The status of the EU ePrivacy Regulation after the Commission withdrew the 2017 proposal in 2025, what remains in force, and how to prepare for what follows.

Regulation

Proposed ePrivacy Regulation (COM/2017/010, withdrawn 2025)

Max Penalty

Current directive: set nationally; proposal contemplated GDPR-level fines

Enforcing Authority

National authorities under the current ePrivacy Directive

Official Source

eur-lex.europa.eu

Executive Summary

  • The ePrivacy Regulation was proposed in January 2017 to replace the 2002 ePrivacy Directive and align electronic communications privacy with the GDPR.
  • After eight years of stalled Council negotiations, the European Commission withdrew the proposal in its February 2025 work programme, citing no foreseeable agreement.
  • The 2002 ePrivacy Directive therefore remains fully in force: cookie consent, marketing opt-ins, and communications confidentiality rules are unchanged.
  • The Commission has signaled future digital-rules simplification, and cookie rules are an acknowledged candidate for reform, but no successor text exists yet.
  • The practical guidance is unchanged: comply with the directive plus GDPR consent standards, and track EDPB guidance rather than waiting for new law.

The ePrivacy Regulation is the reform that did not happen. Proposed by the European Commission in January 2017 as a directly applicable replacement for the 2002 ePrivacy Directive, it was meant to arrive alongside the GDPR in May 2018. Instead it spent eight years stalled in the Council of the EU, and the Commission formally withdrew the proposal in its February 2025 work programme. Understanding what that means, and does not mean, keeps compliance planning honest.

StatusProposal withdrawn by the Commission (2025)
Current lawePrivacy Directive 2002/58/EC remains in force
Proposal textEUR-Lex CELEX 52017PC0010
SuccessorNone proposed as of early 2026

What the proposal would have changed

The 2017 text aimed to align electronic communications privacy with the GDPR: a regulation instead of a directive, so one rule EU-wide; GDPR-level fines up to 4% of turnover instead of nationally set penalties; coverage of over-the-top services like messaging apps alongside telecoms; browser-level consent settings intended to reduce banner fatigue; and updated rules for metadata, machine-to-machine communications, and direct marketing. Successive Council presidencies rewrote the contested parts repeatedly, and positions never converged.

Why it failed, briefly

Three fault lines proved permanent. Member states disagreed on data retention for law enforcement, which the directive touches and governments would not loosen. Publishers and the advertising industry fought over whether cookie walls and legitimate-interest tracking would survive. And the browser-consent model raised questions about who controls defaults that nobody resolved. When the Commission audited its pending files in 2025, this one was listed for withdrawal with the annotation that agreement was not foreseeable.

What applies while there is no successor

Everything you already had to do. The ePrivacy Directive still requires prior consent for non-essential cookies and device access, national laws still set the penalties, and the GDPR still defines consent quality. If anything, enforcement has intensified under the existing framework: the CNIL’s nine-figure cookie fines and coordinated EDPB banner scrutiny all happened under the old directive. Waiting for new law was never a compliance strategy, and now there is no new law to wait for.

The sensible posture: build to the current rules, keep consent records solid, and monitor EDPB and national guidance for incremental tightening. Check where your own site stands with a free scan, and see the cookie compliance country guide for how national implementations differ.

Frequently Asked Questions

Is the ePrivacy Regulation in force?

No, and it never was. It remained a proposal from January 2017 until the European Commission withdrew it in its 2025 work programme after the Council failed to reach agreement. The 2002 ePrivacy Directive remains the law.

Why was the ePrivacy Regulation withdrawn?

The Commission's stated reason: no foreseeable agreement among member states, with the file stuck in Council since 2017. Contested issues included data retention, ad-funded business models, and how strictly to regulate cookie walls and browser-level consent.

What rules apply to cookies now?

Article 5(3) of the ePrivacy Directive, as implemented in each member state's national law, plus the GDPR's consent standards. Prior opt-in consent for non-essential cookies, with strictly-necessary exemptions, remains the rule.

Will cookie rules change in the future?

Probably, but on no fixed timetable. The Commission has flagged simplification of digital rules, and consent-fatigue criticism of cookie banners is widely acknowledged. Any successor would be a new legislative proposal starting the process from scratch.

What should compliance teams do now?

Treat the current directive as durable. Build consent flows that satisfy GDPR standards, watch EDPB guidance and national regulator positions such as the CNIL's, and avoid architecture that assumes machine-readable consent signals will become legally binding soon.

Regulatory Crosswalk

ePrivacy DirectiveGDPRUK PECR

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.