Glossary · Privacy & compliance

What is the ePrivacy Directive (EU cookie law)?

The ePrivacy Directive (Directive 2002/58/EC, amended in 2009) is the EU law on privacy in electronic communications whose Article 5(3) requires consent before storing information on, or reading it from, a user's device — which is why it's called the "cookie law."

Also called: EU cookie law, Directive 2002/58/EC, Article 5(3)

Updated

What does Article 5(3) require?

Storing or accessing information on a user's terminal equipment requires their consent, with two exemptions: when it's for the sole purpose of carrying out a transmission, or when it's strictly necessary to provide a service the user explicitly requested. Consent has to meet the GDPR standard: freely given, specific, informed and unambiguous.

It isn't only about cookies. The European Data Protection Board's Guidelines 2/2023 on the technical scope of Article 5(3) read it broadly, covering localStorage, tracking pixels, URL-based tracking and some cases of scripts accessing device information.

How it's enforced

As a directive, it's implemented through national laws — France's rules are enforced by the CNIL, Germany's through the TTDSG (now TDDDG), the UK's through PECR — so details vary. The CNIL, for instance, allows an audience-measurement exemption for analytics that meets strict conditions (limited purpose, anonymous statistics, no cross-site tracking, limited cookie lifetime).

Example

A site sets an analytics cookie on first load, before the visitor makes a choice. That's storage on the device for a non-essential purpose without consent — the most common ePrivacy violation. The same site loading analytics only after consent, or using analytics that stores and reads nothing on the device, avoids this specific problem.

What's changing

  • The proposed ePrivacy Regulation, meant to replace the directive since 2017, was withdrawn by the European Commission in 2025.
  • In November 2025 the Commission proposed, in its Digital Omnibus package, to move the cookie rules for personal data into GDPR and add a list of low-risk purposes exempt from consent. As a proposal it doesn't change the law until adopted and applicable — Article 5(3) and national laws still apply.
  • The UK has diverged: PECR now exempts statistical cookies with an opt-out.

ePrivacy and VisitTrack

VisitTrack's cookieless mode is built around Article 5(3): it writes no cookie, localStorage or sessionStorage entry, and the visitor id is derived on the server from a daily-salted hash, so nothing identifying is stored on or read back from the device. Standard mode stores a first-party id and, in the EU, generally needs consent. Hybrid mode applies cookieless behavior to EU/EEA, UK and Swiss visitors only. This is general information, not legal advice — check with counsel.

Frequently asked questions

What is the difference between GDPR and the ePrivacy Directive?

GDPR governs processing personal data in general. The ePrivacy Directive's Article 5(3) specifically governs storing or reading information on a user's device, whether or not it's personal data. Cookie consent comes from ePrivacy; the standard for valid consent comes from GDPR.

Does the ePrivacy Directive apply to localStorage?

Yes. Article 5(3) covers any storage of or access to information on the device, not only cookies, so localStorage, sessionStorage and similar technologies are in scope.

Related terms

Tools and guides

See which channels actually bring paying customers

VisitTrack is cookie-free analytics with revenue attribution built in. One script tag, no consent banner, live in two minutes. 14 days free, no card required.