Table of Contents

In March 2025, Spain’s data protection authority (AEPD) fined a major telecommunications provider €3.94 million for placing tracking cookies without valid consent — a violation not of the GDPR, but of the national law implementing the EU ePrivacy Directive. Months earlier, France’s CNIL closed out a wave of cookie-consent enforcement actions against publishers and ad-tech vendors, with fines reaching into the tens of millions of euros across the sector. These actions share a common thread: they were brought under ePrivacy rules, not GDPR — a distinction that trips up even experienced compliance teams.

The ePrivacy Directive (2002/58/EC, as amended by 2009/136/EC) is the EU’s oldest active digital privacy law, predating the GDPR by sixteen years. It is also, in practical terms, the law that actually governs cookie banners, consent management platforms, and tracking technology deployment across the European Economic Area. Understanding how it operates — and how it diverges from country to country — is essential for any organization running a website, app, or marketing stack that touches EU users.

ePrivacy Directive Text

1. What the ePrivacy Directive Actually Regulates

The ePrivacy Directive is frequently called the “Cookie Law,” but that nickname undersells its scope. The Directive governs the confidentiality of electronic communications generally, and it does so as lex specialis to the GDPR — meaning that where the two laws overlap, ePrivacy’s specific rules take precedence over GDPR’s general rules.

Substantively, the Directive covers:

  1. Storage and access to information on terminal equipment (Article 5(3)) — the legal basis for cookies, local storage, device fingerprinting, SDKs, and any technology that reads or writes data on a user’s device.
  2. Confidentiality of communications (Article 5(1)) — protection against interception, surveillance, and unauthorized listening to electronic communications, now cited heavily in U.S. wiretapping litigation analogues like CIPA.
  3. Traffic and location data (Articles 6 and 9) — rules for telecom and ISP handling of call records, browsing metadata, and geolocation data.
  4. Unsolicited communications (Article 13) — consent requirements for direct marketing via email, SMS, and automated calling systems.
  5. Directories and caller ID (Articles 12 and 8) — consent and opt-out rules for public directories and calling-line identification.
  6. Security of publicly available electronic communications services (Article 4) — breach notification obligations for telecom providers, distinct from GDPR’s Article 33.

For most compliance teams outside the telecom sector, Article 5(3) is where nearly all operational risk concentrates. It is the provision requiring prior, informed consent before a website or app stores or accesses information on a user’s device — the legal foundation underneath every cookie banner in the EU.

2. Why the ePrivacy Directive Still Matters Alongside GDPR

A persistent misconception is that the GDPR “replaced” the ePrivacy Directive in 2018. It did not. The GDPR and the ePrivacy Directive operate concurrently, governed by Article 95 of the GDPR itself, which states that the GDPR does not impose additional obligations where the ePrivacy Directive already sets out specific rules for the same purpose.

In practice, this means:

  • Cookie consent is governed by ePrivacy (as implemented nationally), not by GDPR’s consent standard directly — though the GDPR’s definition of valid consent (Article 4(11) and Article 7) is imported by reference into most national ePrivacy transpositions.
  • A cookie banner can be non-compliant with ePrivacy even if the underlying data processing would otherwise satisfy GDPR’s legitimate interest basis — because ePrivacy does not recognize legitimate interest as a lawful basis for non-essential cookies.
  • Enforcement can proceed under either framework, and regulators increasingly cite both in the same decision, as CNIL and the Italian Garante have done in recent tracking-pixel and consent-string enforcement actions.

This dual-track structure is precisely why organizations that treat GDPR compliance as a proxy for cookie compliance frequently fail ePrivacy-specific audits — the legal basis analysis is different, and “legitimate interest” cookie banners remain one of the most commonly cited defects in EU enforcement actions.

3. Article 5(3) in Practice: The Consent Standard for Cookies and Tracking

Article 5(3), as amended in 2009, requires that storage of or access to information on a subscriber’s or user’s terminal equipment is only permitted where the user has given consent, having been provided with clear and comprehensive information, with two narrow exceptions:

  1. Technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
  2. Technical storage or access strictly necessary to provide an information society service explicitly requested by the user (the “strictly necessary” exception, commonly relied on for session cookies, load-balancing cookies, and shopping cart functionality).

Everything outside those two exceptions — analytics cookies, advertising pixels, social media embeds, A/B testing tools, most CDN and personalization scripts — requires consent that meets the following standard, as clarified by the European Data Protection Board (EDPB) and national regulator guidance:

  1. Freely given — no cookie walls that block site access unless the user accepts non-essential tracking (a position the EDPB and CNIL have both taken, though national application varies).
  2. Specific and granular — consent to one purpose or vendor category cannot be bundled into a single accept-all mechanism without an equally prominent reject option.
  3. Informed — the banner or layer must disclose the purposes of processing, the categories of data, and the identities of any third parties before consent is given, not after.
  4. Unambiguous, via a clear affirmative action — pre-ticked boxes, continued scrolling, or implied consent from browsing do not qualify. This point was settled definitively by the CJEU in Planet49 (Case C-673/17, 2019).
  5. Withdrawable as easily as it was given — most national regulators now require a persistent mechanism (a “manage cookies” link or icon) allowing withdrawal at any time, not merely at first visit.

Regulators have also converged on a “reject all” symmetry requirement: if a banner offers a one-click “Accept All” button, it must offer an equally prominent, equally accessible “Reject All” option in the same interaction layer. Belgium’s APD, France’s CNIL, and Spain’s AEPD have all issued fines specifically for asymmetric banners where rejection required more clicks than acceptance.

4. National Transposition: Why Compliance Isn’t Uniform Across the EU

Because the ePrivacy Directive is a directive rather than a regulation, each EU member state transposes it into domestic law individually, and enforcement style, guidance detail, and penalty structures diverge meaningfully.

Country Implementing Law Regulator Notable Enforcement Posture
France Data Protection Act (amended), CNIL cookie guidelines CNIL Most active cookie enforcement body in the EU; detailed technical guidance and recurring sector-wide sweeps of publishers and ad-tech vendors.
Spain LSSI (Information Society Services Act) + LOPDGDD AEPD High fine volumes; frequent action against telecom and media companies for asymmetric consent banners.
Germany TTDSG (Telecommunications-Telemedia Data Protection Act) State-level DPAs (e.g., Berlin, Bavaria) TTDSG explicitly codifies the “strictly necessary” exception and consent requirements independently of GDPR; state-by-state enforcement creates regional variance.
Italy Privacy Code (Legislative Decree 196/2003, as amended) Garante Active enforcement against dark-pattern cookie banners and undisclosed tracking pixels; frequent joint GDPR/ePrivacy decisions.
Ireland ePrivacy Regulations 2011 (S.I. No. 336/2011) Data Protection Commission Lower enforcement volume historically, though DPC scrutiny has increased given the concentration of major tech headquarters in Ireland.
Netherlands Telecommunications Act, Article 11.7a Autoriteit Persoonsgegevens Detailed technical guidance on tracking walls and cookie wall prohibitions.

For organizations operating across multiple EU jurisdictions, this fragmentation is the single biggest operational challenge in ePrivacy compliance. A consent banner configuration validated for German TTDSG requirements may not satisfy CNIL’s granularity expectations, and vice versa — which is why most mature compliance programs rely on a consent management platform capable of geo-targeted rule sets rather than a single static banner deployed globally.

5. The ePrivacy Regulation: Status and Why It Hasn’t Replaced the Directive

The European Commission proposed a Regulation to replace the Directive in January 2017, intended to modernize the framework, align terminology with GDPR, and — critically — apply uniformly across all member states without national transposition. As of this writing, the ePrivacy Regulation remains stalled in the EU legislative process. Trilogue negotiations between the Parliament, Council, and Commission have repeated failed to reach consensus, principally over provisions addressing metadata processing, tracking walls, and the interplay with the GDPR’s legitimate interest basis.

Practical implication: organizations should not plan compliance programs around an anticipated ePrivacy Regulation timeline. The current Directive-plus-national-transposition structure remains the operative legal framework, and there is no reliable indication of near-term adoption. Compliance teams should treat any ePrivacy Regulation news as directional rather than actionable until formal adoption occurs.

6. Enforcement Landscape: What Regulators Are Actually Penalizing

Reviewing recent enforcement actions across the EU reveals a consistent pattern of the specific defects that trigger fines:

  1. Cookies set before consent is captured — the most commonly cited violation; scripts firing on page load rather than after an affirmative consent signal.
  2. Asymmetric accept/reject design — “Accept All” as a single click, “Reject” buried in a secondary settings panel.
  3. Misclassified “strictly necessary” cookies — analytics, advertising, or personalization cookies mislabeled as essential to avoid the consent requirement.
  4. Consent walls without a genuine alternative — blocking all site access unless tracking is accepted, absent a paid or reduced-tracking alternative.
  5. Consent signal not honored downstream — vendors and subprocessors continuing to fire tags despite a recorded rejection, often due to tag manager misconfiguration.
  6. Absence of a persistent withdrawal mechanism — no visible way to revisit or change consent choices after initial banner interaction.

Notably, several 2024–2026 enforcement actions in France and Italy have extended ePrivacy scrutiny to server-side tagging implementations, where organizations attempted to route consent-gated data flows around client-side blocking mechanisms. Regulators have made clear that server-side architecture does not exempt an organization from Article 5(3) obligations — the consent requirement attaches to the storage and access event itself, regardless of where the resulting data processing occurs.

7. Building an ePrivacy-Compliant Consent Framework

A defensible ePrivacy compliance program generally includes the following components:

  1. Cookie and tracker audit. A full technical inventory of every cookie, pixel, SDK, and local storage mechanism deployed across the site or app, categorized by purpose (strictly necessary, functional, analytics, advertising) and by vendor.
  2. Legal basis mapping. Confirming that only genuinely necessary technologies fall under the Article 5(3) exception, with documented justification for each classification.
  3. Consent management platform deployment. A CMP capable of blocking non-essential scripts prior to consent, presenting granular category and vendor-level choices, and honoring the IAB Transparency & Consent Framework (TCF) where programmatic advertising is involved.
  4. Geo-targeted rule configuration. Distinct banner logic for jurisdictions with divergent requirements (e.g., stricter symmetry rules in France versus baseline requirements elsewhere), rather than a single global configuration.
  5. Consent signal propagation. Ensuring that a rejection is technically enforced downstream — through tag manager triggers, server-side consent mode, or CMP-vendor API integration — not merely recorded in a database.
  6. Persistent consent management access. A permanently visible mechanism (icon, footer link) allowing users to review or withdraw consent at any time after the initial interaction.
  7. Consent logging and audit trail. Timestamped records of what was presented, what was chosen, and under what banner version, sufficient to demonstrate compliance if a regulator requests evidence.
  8. Periodic re-audit. Tracking technology inventories drift constantly as marketing and analytics vendors are added; audits should recur at minimum quarterly for any organization running an active marketing stack.

8. Penalties: What’s at Stake

Jurisdiction Maximum Penalty Framework
France (CNIL) Up to 4% of global annual turnover or €20 million, aligned with GDPR maximums when processed jointly; standalone ePrivacy fines have ranged from tens of thousands to tens of millions of euros depending on scale.
Spain (AEPD) Fines under LSSI can reach €30,000–€150,000 per infraction category independent of GDPR fines, with GDPR-aligned penalties applied where both frameworks are engaged.
Germany TTDSG violations can trigger fines up to €300,000 independently, in addition to any GDPR-based penalty where personal data processing is also implicated.
Italy (Garante) Penalties generally follow GDPR’s 4% / €20 million framework where cookie violations are processed jointly with data protection violations.

Beyond formal fines, ePrivacy enforcement actions frequently carry reputational and litigation exposure — cookie consent screenshots and banner configurations are now routinely used as exhibits in follow-on GDPR complaints and, increasingly, in U.S. wiretapping-style litigation that draws analogical arguments from EU consent standards.

Frequently Asked Questions

Is the ePrivacy Directive the same thing as the GDPR?

No. The ePrivacy Directive (2002/58/EC) and the GDPR are separate legal instruments that apply concurrently. The ePrivacy Directive specifically governs cookies, tracking technologies, and electronic communications confidentiality, and takes precedence over GDPR’s general rules wherever the two overlap.

Does the ePrivacy Directive apply to companies outside the EU?

Yes, if the organization’s website, app, or service is directed at or accessed by users located in the EU. National implementing laws generally apply based on the location of the end user’s terminal equipment, not the organization’s place of establishment.

Can a company rely on “legitimate interest” for cookie consent under ePrivacy?

No. Article 5(3) of the ePrivacy Directive does not recognize legitimate interest as a lawful basis for storing or accessing information on a user’s device for non-essential purposes. Consent is the required basis except for the two narrow “strictly necessary” exceptions.

What happened to the proposed ePrivacy Regulation?

The ePrivacy Regulation, proposed by the European Commission in 2017 to replace the Directive, remains stalled in the EU legislative trilogue process as of this writing. The current Directive and its national transpositions remain the governing framework, with no confirmed adoption timeline.

Are cookie walls (forcing acceptance to access a site) legal under the ePrivacy Directive?

Most EU data protection authorities, including CNIL and the EDPB, take the position that consent obtained under a strict cookie wall — with no alternative access path — is not freely given and therefore not valid, though enforcement approaches vary somewhat by member state.

How does the ePrivacy Directive apply to mobile apps and SDKs?

The same Article 5(3) consent standard applies to any storage or access to information on a device, which extends beyond browser cookies to mobile SDKs, device fingerprinting, and any similar tracking technology embedded in an application.

How Captain Compliance Helps

Captain Compliance’s consent management platform is built to handle exactly the fragmentation described above: geo-targeted banner logic that adapts to French, German, Spanish, and Italian requirements independently, IAB TCF-validated architecture for programmatic advertising, automated cookie and tracker scanning, and consent signal enforcement that propagates through your tag manager rather than stopping at the banner. If your organization is running a single global cookie banner across EU markets with divergent transposition requirements, that configuration is very likely out of compliance somewhere. Schedule a demo below to see how Captain Compliance maps your existing tracking stack against ePrivacy requirements jurisdiction by jurisdiction.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.