The ePrivacy Regulation is the reform that did not happen. Proposed by the European Commission in January 2017 as a directly applicable replacement for the 2002 ePrivacy Directive, it was meant to arrive alongside the GDPR in May 2018. Instead it spent eight years stalled in the Council of the EU, and the Commission formally withdrew the proposal in its February 2025 work programme. Understanding what that means, and does not mean, keeps compliance planning honest.
| Status | Proposal withdrawn by the Commission (2025) |
|---|---|
| Current law | ePrivacy Directive 2002/58/EC remains in force |
| Proposal text | EUR-Lex CELEX 52017PC0010 |
| Successor | None proposed as of early 2026 |
What the proposal would have changed
The 2017 text aimed to align electronic communications privacy with the GDPR: a regulation instead of a directive, so one rule EU-wide; GDPR-level fines up to 4% of turnover instead of nationally set penalties; coverage of over-the-top services like messaging apps alongside telecoms; browser-level consent settings intended to reduce banner fatigue; and updated rules for metadata, machine-to-machine communications, and direct marketing. Successive Council presidencies rewrote the contested parts repeatedly, and positions never converged.
Why it failed, briefly
Three fault lines proved permanent. Member states disagreed on data retention for law enforcement, which the directive touches and governments would not loosen. Publishers and the advertising industry fought over whether cookie walls and legitimate-interest tracking would survive. And the browser-consent model raised questions about who controls defaults that nobody resolved. When the Commission audited its pending files in 2025, this one was listed for withdrawal with the annotation that agreement was not foreseeable.
What applies while there is no successor
Everything you already had to do. The ePrivacy Directive still requires prior consent for non-essential cookies and device access, national laws still set the penalties, and the GDPR still defines consent quality. If anything, enforcement has intensified under the existing framework: the CNIL’s nine-figure cookie fines and coordinated EDPB banner scrutiny all happened under the old directive. Waiting for new law was never a compliance strategy, and now there is no new law to wait for.
The sensible posture: build to the current rules, keep consent records solid, and monitor EDPB and national guidance for incremental tightening. Check where your own site stands with a free scan, and see the cookie compliance country guide for how national implementations differ.