CIPP/E Study Guide
Ch 1.8 - LED & ePrivacy Directive

Related legislation: LED & ePrivacy

Alongside the GDPR, the EU adopted the Law Enforcement Directive (LED) for processing by criminal-law authorities - in force 5 May 2016, with transposition due by 6 May 2018. The ePrivacy Directive governs processing across public communications networks (confidentiality, traffic data, spam, cookies). The GDPR is not meant to add obligations on top of ePrivacy, and a proposed ePrivacy Regulation remains under review.

The Law Enforcement Directive protects data processed by competent authorities for prevention, investigation, detection or prosecution of criminal offences or execution of criminal penalties. It entered into force 5 May 2016, with member states required to transpose it by 6 May 2018. It harmonises rules but does not prevent member states providing higher safeguards. Note it is a directive, so it must be transposed - unlike the GDPR.

The ePrivacy Directive sets rules for processing across public communications networks, dealing with confidentiality, traffic data, spam and cookies. The GDPR is not intended to impose additional obligations on top of the ePrivacy Directive, which therefore needs review. A proposed ePrivacy Regulation is under review; despite a narrower scope than the GDPR, its lengthy adoption reflects the complexity of electronic-communications policy.

LED vs ePrivacy Directive
FeatureLaw Enforcement DirectiveePrivacy Directive
Subject matterProcessing by criminal-law authoritiesProcessing across public communications networks
Instrument typeDirective (must be transposed)Directive
In force5 May 2016 (transpose by 6 May 2018)2002/58/EC
Relationship to GDPRSeparate companion to the GDPRGDPR adds no obligations on top of it

Key terms - quick answers

What is “Law Enforcement Directive”?
LED (Directive (EU) 2016/680) - protects data processed by competent authorities for prevention, investigation, detection or prosecution of criminal offences; a directive, not a regulation.
What is “ePrivacy Directive”?
Directive 2002/58/EC on processing personal data across public communications networks - covers confidentiality, traffic data, spam and cookies.
What is “ePrivacy Regulation”?
A proposed regulation to replace the ePrivacy Directive, still under review; narrower in scope than the GDPR.