Regulations
What is the ePrivacy Directive, and how does it apply to cookies?
The ePrivacy Directive is an EU law protecting privacy in electronic communications. For websites, Article 5(3) is especially important because it governs storing information on a visitor’s device or accessing information already stored there.
Directive 2002/58/EC was adopted on 12 July 2002 and later amended. EU countries implement its requirements through national law.
The device-storage rule generally requires clear information and consent before storage or access, unless an exception applies. The exceptions concern:
Operations used solely to transmit a communication.
Storage or access strictly necessary to provide a service explicitly requested by the user.
The rule extends beyond conventional cookies. Local storage, tracking pixels and other techniques may fall within its scope depending on how they operate. It can apply even when the information is not personal data.
The EDPB’s technical-scope guidelines, finalised on 16 October 2024, explain this coverage.
Where personal data is also processed, GDPR requirements apply alongside the national ePrivacy rules. This is why cookieless tracking consent requirements depend on the technology’s behaviour, not its label.
Türkçe
English