Regulations › European Union

ePrivacy Directive

ePrivacy Directive 2002/58/EC

In force cookies marketing communications
WhenApplies through each member state's national law; the cookie consent rule dates from the 2009 amendment.
Who enforces itNational data protection or telecoms authorities
Who it applies toAnyone storing or reading information on users' devices, and anyone sending electronic marketing, in the EU.

The source of EU cookie consent and electronic marketing rules, alongside the GDPR.

The law in brief

The ePrivacy Directive is the source of the EU's cookie consent rule and its rules on electronic marketing. It protects the confidentiality of communications and the information stored on people's devices, and it sits alongside the GDPR: where both apply, the ePrivacy rule is the more specific one.

Because it is a directive, it works through each member state's national law, so details such as enforcement and the soft opt-in vary by country.

Who it applies to

  • Anyone storing information, or gaining access to information already stored, on a user's device in the EU: cookies, local storage, pixels, fingerprinting, SDKs.
  • Anyone sending electronic marketing (email, SMS, automated calls) to people in the EU.
  • Providers of publicly available electronic communications services, for confidentiality, traffic and location data rules.
  • It applies whether or not the information is personal data.

What it requires

Consent for cookies and device access

Store information or gain access to information on a user's device only with consent given after clear and comprehensive information, unless it is strictly necessary for a service the user explicitly requested or for transmitting a communication.

Consent for electronic marketing

Send electronic marketing to individuals only with prior consent. An existing customer's contact details may be used for similar products and services if they had a chance to object when the details were collected and in every message.

No hidden senders

Do not disguise or conceal the sender's identity in electronic marketing, and give a valid address for opting out.

Traffic and location data

Communications providers must erase or anonymize traffic data when no longer needed, and process location data only when anonymized or with consent.

People's rights

Users must give consent before non-essential cookies and similar technologies are used, after clear and comprehensive information, and can withdraw it. Recipients of marketing must be able to opt out easily and free of charge in every message.

Enforcement and penalties

Set by national law and enforced by national data protection or telecoms authorities. Several authorities have imposed large fines for cookie consent failures, such as reject options that are harder to use than accept.

What's changing

Reform proposed, not adopted. The planned ePrivacy Regulation was withdrawn in 2025. The Commission's Digital Omnibus package, proposed in November 2025, would move the cookie rules for personal data into the GDPR and encourage browser-level consent signals. Until adopted, the directive and national laws apply.

What to do first

  1. Audit every cookie, pixel, SDK and tag on your sites and apps, and classify each as strictly necessary or not.
  2. Block non-essential technologies until consent, and make rejecting as easy as accepting.
  3. Record consent and let users change their choice at any time.
  4. For email and SMS marketing, get prior consent or rely on the soft opt-in for existing customers where national law allows it.
  5. Check national variations in each country you target.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

  • 7 Sep 2026 Enforcement Action decided Moderate 49 EU-IE Data Protection Commission

    Irish DPC welcomes court conviction of Brown Thomas for ePrivacy breaches

    The enforcement action underscores the consequences of non‑compliance with ePrivacy rules for electronic marketing in Ireland. The Dublin Metropolitan District Court convicted Brown Thomas Arnotts Limited on 7 September 2026 for multiple breaches of Regulation 13 of the ePrivacy Regulations. The company pleaded guilty to five sample charges, including failures to provide a valid opt‑out address and sending marketing without valid consent. The court ordered the company to pay €1,000 to a local charity and €1,000 towards DPC legal fees.

    Penalty: ordered Brown Thomas Arnotts Limited to pay a charitable donation of €1000 to local charity Little Flower Penny Dinners and €1000 towards the legal fees of the DPC.

    Source: Data Protection Commission (Ireland). ePrivacy Directive in the regulations library.

Sources