GDPR vs ePrivacy Directive
Last reviewed: · By Victor Humenhuk (CIPP/E certified)
The GDPR is the general law for all processing of personal data; the ePrivacy Directive (2002/58/EC, as amended in 2009) is the specific law for electronic communications, terminal equipment and unsolicited marketing. Where ePrivacy lays down a specific rule pursuing the same objective, it takes precedence as lex specialis and the GDPR imposes no additional obligation on that point - the relationship is set out in Article 95 GDPR. In practice, ePrivacy answers whether you need consent to place a cookie or send a marketing email, while the GDPR defines what valid consent is and governs everything you do with the data afterwards. ePrivacy is a directive implemented by national laws that differ between member states, whereas the GDPR applies directly across the EEA.
GDPR vs ePrivacy side by side
| Feature | GDPR | ePrivacy Directive |
|---|---|---|
| Instrument | Regulation (EU) 2016/679 - directly applicable | Directive 2002/58/EC, amended by 2009/136/EC - implemented by national law |
| Protects | Natural persons only | Subscribers and users, and the legitimate interests of subscribers who are legal persons (Art 1(2)) |
| Data covered | Personal data | Any information stored on or read from terminal equipment, plus communications content, traffic and location data - personal or not |
| Who is caught | Controllers and processors within Article 3 | Providers of publicly available electronic communications services for the confidentiality rules; anyone for Art 5(3) cookies and Art 13 marketing |
| Core lawful bases | Six bases in Article 6 | Consent is the default, with narrow exemptions |
| Consent standard | Article 4(11) and Article 7 | Takes its meaning from the GDPR - confirmed in Planet49 |
| Enforcement and fines | Articles 58 and 83, two fine tiers | National law; the regulator and the penalties vary by member state |
| Consistency across the EEA | High, with the one-stop shop | Low - no one-stop shop, so national rules apply country by country |
Which law governs cookies and similar technologies?
Article 5(3) of the ePrivacy Directive is the operative rule. Storing information, or gaining access to information already stored, on a user's terminal equipment requires the user's consent after clear and comprehensive information. There are only two exemptions: where the storage or access is carried out for the sole purpose of transmitting a communication over an electronic communications network, or where it is strictly necessary to provide a service explicitly requested by the subscriber or user.
Two consequences follow that candidates regularly get wrong. First, the rule bites on any information on the device, so it applies to device fingerprinting, pixels, SDKs and local storage, and it applies even where the information is not personal data - Planet49 (C-673/17) confirmed both points and also confirmed that a pre-ticked box is not consent. Second, you cannot substitute legitimate interests for that consent, because ePrivacy specifies consent for the storage and access step.
Once the read or write has happened, the GDPR takes over for the subsequent processing: you need a basis for the profiling or measurement, you owe transparency under Articles 13 and 14, and the individual keeps the GDPR rights. The EDPB set out this division of labour in Opinion 5/2019 on the interplay between the ePrivacy Directive and the GDPR.
Which law governs marketing messages?
Article 13 of the ePrivacy Directive governs the channel; the GDPR governs the underlying processing of the contact data.
| Channel | Rule | Source |
|---|---|---|
| Email and SMS | Prior consent, unless the soft opt-in applies | ePrivacy Art 13(1)-(2) |
| Automated calling machines and fax | Prior consent | ePrivacy Art 13(1) |
| Live telephone calls | National choice of opt-in or opt-out, usually with a screening register | ePrivacy Art 13(3) |
| Postal marketing | No ePrivacy consent rule; GDPR basis plus the right to object | GDPR Arts 6 and 21(2) |
The soft opt-in is narrow: the contact details must have been obtained in the context of a sale of a product or service to that person, the marketing must be for the sender's own similar products or services, and a free and simple means of refusing must be offered at collection and in every message. Whatever the channel, Article 21(2) of the GDPR gives an absolute right to object to direct marketing, with no balancing.
What happened to the ePrivacy Regulation?
The Commission proposed a Regulation in January 2017 to replace the Directive, align it with the GDPR and remove the national fragmentation. It never completed the legislative process: member states could not settle positions on cookie walls, analytics exemptions and data retention, and the file stalled for years before the Commission signalled its withdrawal in its 2025 work programme. Later reform proposals have floated moving the terminal-equipment rules into the GDPR itself, but nothing of that kind is in force.
For now the operative framework remains the 2002 Directive as amended in 2009, implemented through national laws such as the UK's PECR, and interpreted alongside the GDPR. That is why a cookie banner that satisfies one regulator may not satisfy another, and why the answer to 'is this compliant?' still starts with 'in which member state?'
Related study notes
- Privacy and Electronic Communications (ePrivacy) Directive
- Requirements of the ePrivacy Directive
- ePrivacy laws: unsolicited messages and cookies
- OBA, cookies and ePrivacy (Article 5(3))
- Module 1 · Directive vs Regulation, the EDPB and ePrivacy
Frequently asked questions
Does the ePrivacy Directive only apply to telecoms providers?
No. The confidentiality, traffic data and location data rules are aimed at providers of publicly available electronic communications services over public networks, but Article 5(3) on terminal equipment and Article 13 on unsolicited communications apply to any organisation setting cookies or sending marketing.
Do cookie rules apply if no personal data is involved?
Yes. Article 5(3) is drafted around information stored on or accessed from terminal equipment, not around personal data. Planet49 confirmed that the consent requirement applies regardless of whether the stored information is personal data.
Can I rely on legitimate interests for analytics cookies?
Not for placing or reading them. That step needs consent unless it falls within the strictly necessary exemption, which most member states read narrowly and which few third-party analytics tools satisfy. Some national regulators operate limited exemptions for tightly configured first-party audience measurement, so check the local implementation.
Which regulator enforces ePrivacy breaches?
It depends on the member state. In some countries the data protection authority enforces both regimes; in others the telecoms regulator handles parts of ePrivacy. The GDPR's Article 83 fine tiers and one-stop shop do not automatically apply to a purely ePrivacy breach, which is why national penalties differ so widely.
Test yourself
Try the free CIPP/E practice questions, or read the full CIPP/E study guide - free.