The ePrivacy Directive (2002/58/EC) is European legislation focused on protecting privacy in electronic communications. It supplements the GDPR with specific rules for cookies.
What is the ePrivacy Directive?
The ePrivacy Directive regulates:
- The use of cookies and similar technologies
- Confidentiality of electronic communications
- Unsolicited communications (spam)
- Communications metadata
ePrivacy and cookies
Article 5(3) of the ePrivacy Directive states that storing information (cookies) on the user's device is only permissible:
- With the user's prior consent, OR
- Where it is strictly necessary for the provision of the service
Relationship with the GDPR
The ePrivacy Directive is lex specialis to the GDPR – it takes precedence in the area of electronic communications and cookies. The GDPR then governs the processing of personal data obtained through cookies.
ePrivacy Regulation
The EU is working on a new ePrivacy Regulation, which is intended to replace the current Directive and harmonise rules across the EU. The Regulation has been in the legislative process since 2017.