ePrivacy Directive
Directive 2002/58/EC, as amended by Directive 2009/136/ECDirective on privacy and electronic communications
In force since October 31, 2003
Who it applies to
- Providers of publicly available electronic communications services
- Anyone storing information on, or accessing information already stored on, a user's terminal equipment — which covers cookies, pixels, SDKs and local storage
Consumer rights
- Access / know — not granted
- Correction — not granted
- Deletion / erasure — not granted
- Portability — not granted
- Opt out of sale / sharing — grantedStop the business selling or sharing your personal data with third parties.
- Opt out of targeted advertising — grantedStop your data being used to target advertising across sites or services.
- Opt out of profiling — not granted
- Limit sensitive data use — not granted
- Human review of automated decisions — not granted
- Non-discrimination — not granted
- Appeal a refusal — not granted
- Private right of action — not granted
Obligations
- Consent model
- Opt-in
- Universal opt-out signal
- Not required
- Risk assessments
- Not required
- Data protection officer
- Not required
- Records of processing
- Not required
- Processor contract
- Not required
- Right to cure
- None — enforcement may follow immediately
- Data broker registration
- Not required
Breach notification
- To individuals
- Providers notify subscribers where a breach is likely to adversely affect them
- To the regulator
- Within 24 hours for electronic communications providers, under Regulation 611/2013
- What triggers it
- A personal data breach affecting subscribers or users of the service
Penalties
- Headline
- Set by each member state in national transposition — not by the Directive
- Private right of action
- No — enforcement is by the regulator only
- Notes
- Because this is a DIRECTIVE rather than a Regulation, it binds member states as to the result and leaves the form to them. Cookie rules therefore differ materially across the EU, and the long-promised ePrivacy Regulation that would have unified them was withdrawn.
Exemptions
Data
- Storage strictly necessary to provide a service the user explicitly requested
- Storage for the sole purpose of transmitting a communication
Amendment history
May 25, 2011
Directive 2009/136/EC — the 'cookie directive'
Replaced the opt-out standard for terminal-equipment storage with prior informed consent, which is why consent banners exist.
Sources
- PrimaryRegulationDirective 2002/58/EC — consolidated text