TermsBox
PricingBlog
LoginGet Started
PricingBlogLogin
Get Started
  1. Home
  2. Blog
  3. ePrivacy Regulation: Status, Rules, and What It Means for You
Legal Compliance

ePrivacy Regulation: Status, Rules, and What It Means for You

Understand the ePrivacy Regulation: its status after withdrawal, how it differs from the ePrivacy Directive, and what cookie and tracking rules apply now.

TermsBox Team|July 26, 202613 min read

The ePrivacy Regulation was meant to be the GDPR's companion law for cookies, tracking, and electronic communications, and after eight years of negotiation it never arrived. In February 2025 the European Commission formally withdrew the proposal, leaving the 2002 ePrivacy Directive as the law that still governs every cookie banner in Europe. If you run a website with EU or UK visitors, that history matters because it determines exactly which rules you must follow today. This guide covers what the ePrivacy Regulation was, why it failed, and what applies in its place, though you should consult a qualified attorney for advice specific to your business.

What Is the ePrivacy Regulation?

The ePrivacy Regulation was a proposed European Union law intended to replace Directive 2002/58/EC (the ePrivacy Directive) and govern the confidentiality of electronic communications, cookies, tracking technologies, and direct marketing across all EU member states. The European Commission published the proposal on 10 January 2017, alongside the GDPR's application date, with the aim of having both instruments take effect on 25 May 2018.

That never happened. The proposal spent years in trilogue negotiations between the European Commission, the European Parliament, and the Council of the European Union without the three institutions reaching agreement. On 11 February 2025, the Commission included the ePrivacy Regulation in its list of withdrawn proposals in the 2025 Commission Work Programme, citing "no foreseeable agreement" between the co-legislators.

The distinction that made the ePrivacy Regulation significant was its legal form:

  • A directive sets an objective that each of the 27 member states must transpose into national law, and each national parliament can implement it slightly differently.
  • A regulation applies directly in every member state on the day it takes effect, with no transposition step and far less national variation.

This is why the current landscape is fragmented. France, Germany, Spain, and the Netherlands each enforce their own transposition of the ePrivacy Directive, with different guidance on what counts as valid consent, how long consent lasts, and whether "reject all" must appear on the first banner layer.

Why the ePrivacy Regulation Failed

Understanding the deadlock helps explain why the rules you follow now are unlikely to change quickly. Three issues repeatedly blocked agreement.

Cookie Walls and Consent Signals

The Parliament pushed for a ban on cookie walls, the practice of denying site access unless a visitor accepts tracking. Several member states in the Council resisted, arguing that publishers relying on advertising revenue need an alternative to a subscription model. Related drafts proposed letting browsers carry a machine-readable consent signal, which advertisers and publishers opposed on the grounds that a browser-level default would effectively opt everyone out.

Metadata and Communications Content

The Regulation would have extended confidentiality rules to over-the-top services such as WhatsApp, Signal, Facebook Messenger, and Skype, which the 2002 Directive did not clearly cover. Negotiations stalled over how far providers could process communications metadata for security, network optimisation, and statistical purposes without consent.

Child Sexual Abuse Material Detection

Later drafts collided with separate EU work on detecting child sexual abuse material in messaging services. Strict confidentiality rules for communications content raised questions about whether voluntary scanning by providers would remain lawful, which required a temporary derogation (Regulation (EU) 2021/1232) and further complicated the file.

The result: after eight years, the Commission concluded the proposal had been overtaken by other legislation, including the Digital Services Act, the Digital Markets Act, and the Data Act.

The Law That Actually Applies: The ePrivacy Directive

With the ePrivacy Regulation withdrawn, Directive 2002/58/EC, as amended by Directive 2009/136/EC, remains in force. The provision that affects almost every website is Article 5(3), which requires that storing information, or gaining access to information already stored, on a user's terminal equipment is only allowed if the user has given consent after receiving clear and comprehensive information.

Two exemptions apply under Article 5(3):

  1. Transmission exemption: storage carried out for the sole purpose of transmitting a communication over an electronic communications network.
  2. Strictly necessary exemption: storage strictly necessary to provide a service explicitly requested by the user, such as a shopping cart cookie, a session authentication token, or a load-balancing cookie.

Analytics cookies do not qualify as strictly necessary under most national interpretations. Neither do advertising, personalisation, social media embed, or A/B testing cookies. The cookie policy generator covers the disclosure side of this, but disclosure alone does not satisfy Article 5(3): you also need prior consent before the cookie is set.

Note that Article 5(3) applies to any information stored on or read from a device, not only cookies. Local storage, session storage, IndexedDB, device fingerprinting, and pixel tags all fall within scope, which is why "we do not use cookies" is rarely an accurate defence.

ePrivacy Regulation vs GDPR: How They Interact

The relationship between ePrivacy rules and the GDPR confuses many site owners, and getting it wrong leads to using the wrong legal basis. ePrivacy is lex specialis to the GDPR: where both could apply, the more specific ePrivacy rule takes precedence, as confirmed in Recital 173 of the GDPR and in the European Data Protection Board's Opinion 5/2019.

Aspect ePrivacy Directive GDPR
Legal form Directive, transposed into 27 national laws Regulation, directly applicable
Scope Any information on a device, including non-personal data Personal data only
Cookie consent Article 5(3) requires prior consent Defines the consent standard (Article 4(11), Article 7)
Legitimate interest available No, for device storage Yes, under Article 6(1)(f) for other processing
Penalties Set by each member state Up to 20 million EUR or 4% of global annual turnover (Article 83)

The practical consequence: you cannot rely on legitimate interest to set analytics or advertising cookies. Article 5(3) requires consent, full stop. Legitimate interest under GDPR Article 6(1)(f) may cover what you do with the data after you have lawfully obtained it, but it cannot substitute for the consent needed to place the cookie in the first place.

The standard of consent comes from the GDPR. Article 4(11) defines consent as freely given, specific, informed, and an unambiguous indication of the data subject's wishes given by a statement or clear affirmative action. Pre-ticked boxes, continued scrolling, and implied consent fail that standard, as the Court of Justice of the European Union confirmed in Planet49 (Case C-673/17, 1 October 2019).

What the ePrivacy Regulation Would Have Changed

Because drafts circulated for years, the proposal shaped a lot of industry expectations. Several changes were close to agreed before the withdrawal, and they are worth knowing because elements may resurface in future legislation.

  • Broader consent exemptions: first-party audience measurement and security updates would have been exempt from consent in most drafts, removing analytics banners for self-hosted statistics.
  • Direct browser settings: users could have expressed consent preferences through browser or operating system settings, with sites required to honour them.
  • Scope over OTT services: messaging and VoIP apps would have been explicitly covered by confidentiality rules on content and metadata.
  • GDPR-level fines: the draft aligned penalties with GDPR Article 83, up to 20 million EUR or 4% of global annual turnover, replacing today's national variation.
  • Uniform national rules: one text across all 27 member states, ending the current situation where a compliant French banner may not satisfy German requirements.

None of this is law. Treating draft provisions as if they were in force, particularly the analytics exemption, is a common and costly mistake.

Enforcement Under the Current Rules

The absence of an ePrivacy Regulation has not slowed enforcement. National data protection authorities enforce their own transposition of the Directive, and cookie-specific penalties have been substantial.

  • CNIL (France) fined Google 150 million EUR and Facebook 60 million EUR in January 2022 for making refusing cookies harder than accepting them, applying Article 82 of the French Data Protection Act (the national transposition of Article 5(3)).
  • CNIL fined Amazon Europe Core 35 million EUR in December 2020 for placing advertising cookies without prior consent.
  • The ICO (UK) enforces the Privacy and Electronic Communications Regulations 2003 (PECR), which survived Brexit and continue to mirror the Directive's consent rules, with fines up to 500,000 GBP under PECR plus UK GDPR exposure.
  • The Garante (Italy) and AEPD (Spain) have both issued repeated decisions on Google Analytics transfers and non-compliant banners.

The pattern in these cases is consistent. Regulators focus on whether refusing is as easy as accepting, whether cookies fire before any interaction with the banner, and whether the information given before consent is genuinely specific about purposes and recipients.

Practical Compliance Steps While the ePrivacy Regulation Remains Withdrawn

Since the applicable rules are stable for the foreseeable future, you can build a compliance setup that will not need rework. Work through these steps in order.

  1. Scan your site and inventory every tracking technology. Include cookies, local storage, pixels, tag manager containers, and embedded third-party scripts. You cannot obtain informed consent for trackers you have not identified.
  2. Classify each item by purpose. Strictly necessary, functional, analytics, and advertising. Only the first category avoids the Article 5(3) consent requirement.
  3. Block non-essential scripts before consent. This is where most implementations fail. A banner that displays while Google Analytics has already fired provides no legal protection.
  4. Give "reject all" equal prominence to "accept all." Same layer, same visual weight, same number of clicks. This is the single most litigated point in cookie enforcement.
  5. Log consent records. Store what the user consented to, when, and the banner version shown. GDPR Article 7(1) puts the burden of demonstrating consent on you.
  6. Provide a withdrawal mechanism. Article 7(3) requires that withdrawing consent be as easy as giving it, usually a persistent preferences link in the footer.
  7. Refresh consent periodically. The CNIL recommends re-asking at most every six months; several other authorities suggest 12 months. Storing consent indefinitely is not defensible.
  8. Document everything in your privacy and cookie policies. List cookie names, purposes, providers, and retention durations, then keep the list current as your stack changes.

TermsBox handles steps one, three, and eight together: the scanner detects the cookies and third-party services actually running on your site, the consent management platform blocks non-essential scripts until consent is given, and the generated cookie policy is populated from real scan results rather than a static template.

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.

Generate Now

Special Rules Beyond Cookies

The ePrivacy Directive covers more than device storage, and these obligations are also unaffected by the Regulation's withdrawal.

Direct Marketing and Email

Article 13 requires prior opt-in consent for unsolicited electronic communications, including email, SMS, and automated calling systems. The one exception is the soft opt-in: you may email existing customers about similar products or services if you obtained their address in the context of a sale, told them at collection, and offer an opt-out in every message.

Every marketing email must identify the sender and provide a valid address for opt-out requests. Concealing the sender's identity is prohibited outright.

Confidentiality of Communications

Article 5(1) prohibits listening, tapping, storage, or other kinds of interception of communications and related traffic data without user consent, except where legally authorised. For most website operators this becomes relevant with session replay tools, chat transcripts, and call recording, all of which need a consent assessment.

Location and Traffic Data

Articles 6 and 9 restrict how providers may process traffic data and location data, generally requiring erasure or anonymisation once no longer needed for transmission or billing. If your product handles precise geolocation, this sits alongside the GDPR obligations rather than replacing them.

What Comes After the ePrivacy Regulation

The Commission did not abandon the underlying policy goals when it withdrew the proposal. Two workstreams are worth tracking.

The Digital Omnibus simplification package, announced in 2025, revisits cookie consent fatigue and proposes handling consent signalling through machine-readable browser preferences and expanded exemptions for low-risk measurement. The Digital Fairness Act, in preparation over the same period, targets dark patterns in online interfaces, which directly touches banner design choices such as pre-selection and asymmetric buttons.

Neither is in force. Until one becomes applicable law, planning should assume the ePrivacy Directive plus national implementations remain the standard. Building on the current rules with a clearly documented privacy policy and a properly gating consent banner also positions you well for the likely direction of future legislation, since the trend in every draft has been toward stricter blocking and clearer refusal options rather than looser ones.

Sites operating outside the EU are not exempt. The Directive follows the user, so a US-based e-commerce store serving customers in Germany falls within scope in the same way the GDPR applies extraterritorially under Article 3(2). Geo-targeting the banner to EU and UK visitors is a legitimate approach, provided the detection is reliable and defaults to showing the banner when the visitor's location is uncertain.

Frequently Asked Questions

Is the ePrivacy Regulation in force?

No. The European Commission withdrew the ePrivacy Regulation proposal in February 2025 after more than eight years without agreement between the Parliament and the Council. The 2002 ePrivacy Directive (2002/58/EC), as amended in 2009, remains the law in force across the EU.

What is the difference between the ePrivacy Regulation and the ePrivacy Directive?

The Directive is EU legislation that each member state must transpose into national law, which produced 27 slightly different cookie rulebooks. The proposed Regulation would have applied directly in every member state without transposition, creating one uniform rule set the way the GDPR did.

Does the ePrivacy Regulation replace the GDPR?

No. ePrivacy rules are lex specialis, meaning they take precedence over the GDPR only on the specific matters they cover, such as storing information on a user's device and confidentiality of communications. The GDPR still governs the processing of any personal data that follows.

Do I still need cookie consent if the ePrivacy Regulation was withdrawn?

Yes. Article 5(3) of the ePrivacy Directive still requires prior consent before storing or accessing any information on a user's device, apart from strictly necessary cookies. National regulators such as the CNIL and the ICO continue to enforce this and issue fines.

Would the ePrivacy Regulation have ended cookie banners?

Not entirely. Draft versions expanded the exemption list and allowed some consent signalling through browser settings, but consent would still have been required for advertising and analytics cookies from third parties. The withdrawal means the current banner requirements remain unchanged.

What replaces the ePrivacy Regulation now?

The Commission signalled that cookie and tracking rules will be addressed through the Digital Omnibus simplification package and the Digital Fairness Act rather than a standalone regulation. Until any of that becomes law, the ePrivacy Directive and national implementing laws apply.

Related Tools

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app

Related Articles

Legal Compliance

What a Data Subject Is: GDPR Definition, Rights, and Examples

Learn what a data subject is under GDPR, who qualifies, the rights they hold, and what your business must do to handle data subject requests correctly.

July 27, 202614 min read
Legal Compliance

Cybersecurity Data: What It Is and How to Protect It

Learn what cybersecurity data is, the types your business handles, and the legal requirements for protecting it under GDPR, CCPA, and other privacy laws.

July 27, 202611 min read
Legal Compliance

Data Breach in Cyber Security: Causes, Laws, and Response

Understand what a data breach in cyber security is, how breaches happen, which notification laws apply, and how to prevent and respond to an incident.

July 27, 202613 min read

Ready to Create Your Legal Documents?

Generate professional privacy policies, terms of service, and more in minutes. Free to start, no credit card required.

View All Generators

On This Page

  • What Is the ePrivacy Regulation?
  • Why the ePrivacy Regulation Failed
  • Cookie Walls and Consent Signals
  • Metadata and Communications Content
  • Child Sexual Abuse Material Detection
  • The Law That Actually Applies: The ePrivacy Directive
  • ePrivacy Regulation vs GDPR: How They Interact
  • What the ePrivacy Regulation Would Have Changed
  • Enforcement Under the Current Rules
  • Practical Compliance Steps While the ePrivacy Regulation Remains Withdrawn
  • Special Rules Beyond Cookies
  • Direct Marketing and Email
  • Confidentiality of Communications
  • Location and Traffic Data
  • What Comes After the ePrivacy Regulation
  • Frequently Asked Questions
TermsBox

Scan your website, auto-generate legal documents, add a consent banner, and stay compliant. One platform for everything.

Product
  • Cookie Scanner
  • Consent Banner
  • Cookie Policy Generator
  • Pricing
Generators
  • Privacy Policy Generator
  • Terms and Conditions Generator
  • EULA Generator
  • Disclaimer Generator
  • Return and Refund Policy Generator
Company
  • About
  • Contact
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
GDPR
ePrivacy
CCPA
LGPD
Google Consent Mode v2
IAB TCF 2.2
© 2026 TermsBox. All rights reserved.