Skip to content
GlanceDeskJurisdiction

Home › Law library › ePrivacy cookie rule

EU

ePrivacy cookie rule

Directive 2002/58/EC on privacy and electronic communications (ePrivacy Directive), Article 5(3)

Sourced. Last verified 9 October 2026

European Union (EEA) Privacy

Status
In force since 2002; cookie consent rule as amended by Directive 2009/136/EC (transposed from 2011).
Who it applies to
Anyone storing or reading information on users' devices in the EU (cookies, pixels, SDKs, fingerprinting, local storage), whether or not the data is personal.
Size thresholds
None — applies regardless of size.
Regulator
National authorities designated in each Member State (often the DPA, sometimes telecoms/consumer regulators)
Cookies and consent
Prior consent, after clear and comprehensive information, is required to store or access information on a device. Exempt only: purely technical transmission, or what is strictly necessary for a service the user explicitly requested.
Maximum penalty
Set nationally; must be effective, proportionate and dissuasive (varies by country).

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

EDPB Guidelines 2/2023 (final 16 Oct 2024) confirm Art 5(3) covers pixels, URL tracking, IP-based tracking and IoT. Digital Omnibus (Nov 2025, pending) proposes low-risk exemptions and browser-level consent signals.

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].