Home › Law library › ePrivacy cookie rule
EU
ePrivacy cookie rule
Directive 2002/58/EC on privacy and electronic communications (ePrivacy Directive), Article 5(3)
Sourced. Last verified 9 October 2026
European Union (EEA) Privacy
- Status
- In force since 2002; cookie consent rule as amended by Directive 2009/136/EC (transposed from 2011).
- Who it applies to
- Anyone storing or reading information on users' devices in the EU (cookies, pixels, SDKs, fingerprinting, local storage), whether or not the data is personal.
- Size thresholds
- None — applies regardless of size.
- Regulator
- National authorities designated in each Member State (often the DPA, sometimes telecoms/consumer regulators)
- Cookies and consent
- Prior consent, after clear and comprehensive information, is required to store or access information on a device. Exempt only: purely technical transmission, or what is strictly necessary for a service the user explicitly requested.
- Maximum penalty
- Set nationally; must be effective, proportionate and dissuasive (varies by country).
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Block non-essential cookies and trackers until the user gives consent.
- Explain each cookie's purpose and provider before asking for consent.
- Make refusing as easy as accepting and let users withdraw at any time.
- Treat tracking pixels, URL tracking and device identifiers as covered, not just cookies.
- Audit tags and SDKs regularly; keep proof of consent.
Recent changes
EDPB Guidelines 2/2023 (final 16 Oct 2024) confirm Art 5(3) covers pixels, URL tracking, IP-based tracking and IoT. Digital Omnibus (Nov 2025, pending) proposes low-risk exemptions and browser-level consent signals.
Sources
- Primary source: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02002L0058-20091219
- Second source: https://www.hunton.com/privacy-and-cybersecurity-law-blog/edpb-adopts-guidelines-on-scope-of-eprivacy-directive
- Regulator: National authorities designated in each Member State (often the DPA, sometimes telecoms/consumer regulators)
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].