ePrivacy Directive

Directive 2002/58/EC, as amended by Directive 2009/136/EC

Directive on privacy and electronic communications

In force since October 31, 2003

Who it applies to

  • Providers of publicly available electronic communications services
  • Anyone storing information on, or accessing information already stored on, a user's terminal equipment — which covers cookies, pixels, SDKs and local storage

Consumer rights

  • Access / know — not granted
  • Correction — not granted
  • Deletion / erasure — not granted
  • Portability — not granted
  • Opt out of sale / sharing — grantedStop the business selling or sharing your personal data with third parties.
  • Opt out of targeted advertising — grantedStop your data being used to target advertising across sites or services.
  • Opt out of profiling — not granted
  • Limit sensitive data use — not granted
  • Human review of automated decisions — not granted
  • Non-discrimination — not granted
  • Appeal a refusal — not granted
  • Private right of action — not granted

Obligations

Consent model
Opt-in
Universal opt-out signal
Not required
Risk assessments
Not required
Data protection officer
Not required
Records of processing
Not required
Processor contract
Not required
Right to cure
None — enforcement may follow immediately
Data broker registration
Not required

Breach notification

To individuals
Providers notify subscribers where a breach is likely to adversely affect them
To the regulator
Within 24 hours for electronic communications providers, under Regulation 611/2013
What triggers it
A personal data breach affecting subscribers or users of the service

Penalties

Headline
Set by each member state in national transposition — not by the Directive
Private right of action
No — enforcement is by the regulator only
Notes
Because this is a DIRECTIVE rather than a Regulation, it binds member states as to the result and leaves the form to them. Cookie rules therefore differ materially across the EU, and the long-promised ePrivacy Regulation that would have unified them was withdrawn.

Exemptions

Data

  • Storage strictly necessary to provide a service the user explicitly requested
  • Storage for the sole purpose of transmitting a communication

Amendment history

  1. May 25, 2011

    Directive 2009/136/EC — the 'cookie directive'

    Replaced the opt-out standard for terminal-equipment storage with prior informed consent, which is why consent banners exist.

Sources

Timeline

todayePrivacy Directive in forceOctober 31, 2003Directive 2009/136/EC — the 'cookie directive'May 25, 2011