All Blog Posts

After the EU ePrivacy Regulation: Data Privacy Evolution in the EU and the Legacy of the ePrivacy Directive

Close
Read time
9 mins
Updated
Jul 20, 2026
Share
  • The EU ePrivacy Regulation was formally withdrawn by the European Commission in 2025 and will not become law.
  • The Commission announced the withdrawal in its February 2025 Work Programme, citing a lack of agreement between the European Parliament and Council and calling the eight-year-old proposal outdated.
  • Withdrawal was formally approved in July 2025 and published in the EU Official Journal in October 2025.
  • The 2002 ePrivacy Directive remains in force, governed through each EU member state's own national transposition of it.
  • Cookie consent and electronic communications privacy across the EU continue to sit under the ePrivacy Directive and the GDPR, with no confirmed EU-wide successor regulation currently in development.

The ePrivacy Regulation was proposed to replace the ePrivacy Directive with a single, consistent framework across the EU, one that would have expanded data protection, cookie consent rules, and the range of organizations covered. But the data privacy landscape has shifted considerably since the proposal was first introduced, and as of February 2025, the European Commission has withdrawn it without naming a replacement.

That leaves the Directive as the operative law, and it's worth understanding what it covers, how it got here, and what still applies to your website's use of cookies today.

What Was the ePrivacy Regulation?

The ePrivacy Regulation was a draft European Union (EU) regulation that would have governed all electronic communications on publicly available services and networks inside the European Union.

The EU's data privacy laws had consisted of the General Data Protection Regulation (GDPR) and the 2002 ePrivacy Directive, sometimes known as the “cookie law”. If passed, ePrivacy Regulation would have repealed and replaced the ePrivacy Directive and brought significant updates by including new technologies in its legal framework.

Its goal was to strengthen data privacy safeguards, extending protections not only to data processed by traditional telecommunications providers, but by all electronic communications services, such as texts, emails, voiceover internet protocol (VoIP), and instant messaging services like WhatsApp and Facebook Messenger.

History of the ePrivacy Regulation

The ePrivacy Regulation was intended to come into force alongside the GDPR in May 2018. There have, however, been considerable delays since the draft was first published. Key dates include:

  • January 2017: Draft text of the ePrivacy Regulation was published.
  • October 2017: European Parliament published a report with proposed amendments.
  • February 2021: European Council published its proposed amendments and a mandate for negotiations with the European Parliament.
  • May 2021: Trilogue negotiations officially began, involving the European Commission (EC), European Parliament, and European Council, aiming to reach a consensus on the final text.
  • February 2025: The European Commission formally withdrew the ePrivacy Regulation proposal in its 2025 Work Programme, citing lack of consensus among co-legislators and the proposal being outdated relative to newer legislation (DSA, DMA). No replacement has been proposed.

What Is the Status of the ePrivacy Regulation?

The European Commission officially withdrew the ePrivacy Regulation on February 11, 2025, citing a lack of consensus among legislators and stating that the proposal had become outdated in light of newer legislation, including the Digital Services Act and Digital Markets Act. No replacement has been proposed. The ePrivacy Directive's guidelines remain in place, interpreted and implemented separately by each EU member state.

What Is the Difference Between the ePrivacy Regulation and the ePrivacy Directive?

The ePrivacy Regulation and the ePrivacy Directive were both European legislative frameworks focused on privacy and electronic communications, but they differed primarily in their scope, legal effect, and current status.

The ePrivacy Directive is a legislative act that requires EU member states to implement its provisions into their national laws, such as Law 34/2002 in Spain and Cookiebekendtgørelsen in Denmark. The ePrivacy Regulation, which was intended to replace the Directive, would have been a regulation directly applicable in all EU member states, without the need for national implementing legislation.

While both were concerned with the privacy of electronic communications, the ePrivacy Regulation aimed to update and expand the rules to align with the GDPR. It would have covered newer technologies and communication services, like WhatsApp and Zoom, and would have included new provisions on marketing communications, cookies, and the confidentiality of communications.

How Do the GDPR and ePrivacy Directive Compare?

While the GDPR and the ePrivacy Directive overlap in certain ways and share common goals, each was created to address different challenges and needs. Here's how they overlap and diverge.

Key Similarities Between the GDPR and ePrivacy Directive

  • Regulatory body: Both laws were drafted and passed by the European Parliament and Council.
  • Goals: Both laws are meant to align data privacy regulations across the EU.
  • Applicability: Both laws apply to and protect EU residents and outline responsibilities for organizations handling their data.
  • Personal data: Both laws apply to the collection, processing, and storage of individuals' personal data, though the ePrivacy Directive applies to more types of data.
  • Extraterritoriality: Both laws apply to organizations inside and outside the EU if they process the personal data of EU residents.
  • Platforms: Both laws include digital platforms and communications, though the ePrivacy Directive is specific to electronic communications.
  • Penalties: Both laws carry high fines and other potential penalties for noncompliance.

Key Differences Between the GDPR and ePrivacy Directive

  • Scope and reach: The GDPR's scope is narrower, covering only personal data. The ePrivacy Directive's reach includes both personal and non-personal data within electronic communications. The GDPR is also a regulation applicable across the EU directly, while the ePrivacy Directive's guidelines must be individually legislated by each EU member state.
  • Definitions: The GDPR defines "personal data" as any data that can identify an individual. The ePrivacy Directive focuses on "electronic communications," covering both identifying and non-identifying data.
  • Purpose: The GDPR aims to give individuals control over their personal data and how organizations process it. The ePrivacy Directive focuses on privacy and confidentiality in electronic communications, regulating areas like tracking technologies and digital marketing.
  • Types of data: The GDPR covers personal data in both electronic and hard copy formats. The ePrivacy Directive applies only to electronic communications data.
  • Applicability: The GDPR applies to any organization that collects or uses the personal data of EU residents, including both data controllers and data processors. The ePrivacy Directive applies to a wider range of entities involved in electronic communications, including businesses, third parties using tracking technologies, and service providers.
  • Rights and protections: The GDPR grants rights and protections to natural persons (individuals). The ePrivacy Directive extends these rights to both natural and legal persons (organizations).

In cases of conflict, the ePrivacy Directive takes precedence over the GDPR due to its more specific focus on electronic communications.

Meet cookie consent requirements under the ePD, GDPR, and other global regulations. Try Cookiebot™ CMP free for 14 days.

Who Would Have Had to Comply With the ePrivacy Regulation?

The ePrivacy Regulation would have applied to both natural and legal persons involved in sending electronic communications, and would have impacted any organization that processed data relating to online communication services, used online tracking technologies, or engaged in electronic direct marketing.

This would have included:

  • Machine-to-machine communication providers (Internet of Things)
  • Website owners
  • App owners that use electronic communication
  • Companies that send direct marketing communications
  • Telecommunications companies
  • Messaging service providers (e.g. WhatsApp, Facebook)
  • Internet access providers (e.g. a café providing open Wi-Fi)

Who Does the ePrivacy Directive Apply To?

The ePrivacy Directive (ePD) applies to a wide range of organizations that either provide electronic communications services or process the personal data of EU residents. These include:

  • Website operators that use cookies or other tracking technologies to collect information about site visitors and customers.
  • Businesses that process personal data, including those engaged in digital marketing, tracking via cookies, or otherwise using digital means to collect personal data via websites or other digital services.
  • Third parties using tracking technologies on websites or apps to track user behaviors or activities, such as social media platforms, advertisers, or analytics providers.
  • Electronic communications services providers that enable electronic communications and collection of personal data, such as internet service providers (ISP), telephone service providers, or public communications networks.

The ePrivacy Directive states that cookies that are strictly necessary (also known as "essential") for providing a service specifically requested by the user do not require consent. These cookies, which enable a website's basic functioning or deliver the requested service, may be used for the following purposes:

  • Maintaining user session state: Including activities like preserving a user's login status or the contents of a shopping cart during browsing.
  • Supporting security features: Aiding in the identification and prevention of security risks.
  • Remembering user input: Storing information like username, language, or region to personalize the user experience.

Although exempt from consent requirements, you must still inform visitors about the use of these cookies, usually through a cookie policy and/or privacy policy. Use of non-essential cookies does require consent, commonly obtained via a consent management platform.

What Updates Have Been Made to the ePrivacy Directive?

Article 5(3) of the ePrivacy Directive states that companies or websites must obtain prior consent from users before they can store information on, or retrieve information from, a user's device (such as a computer or smartphone).

Under Guidelines 2/2023 on the Technical Scope of Article 5(3), the European Data Protection Board (EDPB) expanded the application of the ePrivacy Directive for storing or accessing information on a user's device. The EDPB adopted a broad interpretation of what constitutes terminal equipment — like smartphones or personal computers — and the nature of information involved, suggesting that many digital tracking methods now require prior consent unless they're necessary for delivering a requested service.

The guidelines specifically address several modern tracking technologies that have become common in digital marketing and online tracking:

  • URL and pixel tracking: Tracking pixels are tiny images embedded in websites or emails, linked to a server. When an email containing a tracking pixel is opened, or a web page with a tracking pixel is visited, the server can record the action and capture details such as the time the email was opened, the IP address of the recipient, and the type of device used. URL tracking links help identify where site visitors come from.
  • Local processing: Websites sometimes use APIs to access information stored on a user's device, such as location data. If that processed information is made available over the network, it's considered gaining access to stored information under ePD guidelines.
  • Tracking based on IP address only: Some technologies rely solely on collecting a user's IP address for tracking. If the IP address originates from the user's terminal equipment, Article 5(3) applies.
  • Internet of Things (IoT) reporting: Under ePD guidelines, companies need user consent for data collection and processing by devices connected directly or indirectly to the internet — smart devices like fridges or fitness trackers, whether they send data directly or through another device like a smartphone.
  • Unique identifiers: Unique identifiers (UIDs) are codes attached to a user's online data to signify ownership. They often come from persistent personal data — information that doesn't change much over time, such as an email address, username, account ID, or date of birth. UIDs are used to recognize users across different websites or apps. When a website tells a browser to send this data, it's accessing information on the device, invoking Article 5(3).

What Is the Future of EU Privacy Regulation and the ePrivacy Directive?

The ePrivacy Directive and the GDPR are aging in light of the rapidly changing technology landscape, other legislation, and shifting consumer expectations. The Directive's last update, in 2009, predates TikTok and widespread iPhone use.

Additional laws, including the Digital Services Act, the Digital Markets Act, and the AI Act, have since been implemented to address data privacy from specific angles, and these laws intersect with existing regulations like the GDPR. The European Court of Justice also continues to guide enforcement.

Transparency and obtaining valid consent remain essential for regulatory compliance in Europe and around the world, as well as for building customer trust. Cookiebot CMP helps businesses support privacy compliance, and features like automated updates help maintain it without heavy manual intervention. Keep your customers informed, provide real consent choice, and demonstrate your respect for their data privacy.

Frequently asked questions

The EU ePrivacy Regulation is a proposed regulation intended to update and replace the 2002 ePrivacy Directive. It aims to enhance privacy protections for electronic communications across all publicly available networks and services within the EU.

While the GDPR focuses on protecting personal data of EU residents, the ePrivacy Regulation specifically targets the privacy of electronic communications for natural and legal persons. It is designed as a lex specialis to the GDPR, meaning it provides specific rules for the electronic communications sector that override the more general protections under the GDPR where applicable.

The draft ePrivacy Regulation applies to a wide range of entities, including traditional telecom companies, internet service providers, and businesses that handle data related to electronic communication services. This encompasses those using online tracking tools, providing directories of end users, or engaging in electronic direct marketing.

As of August 2024, the ePrivacy Regulation is still in the trilogue negotiations between the European Commission, European Parliament, and European Council. Once finalized, it will officially become law 20 days after its publication in the EU Official Journal and will start to apply two years after this date, allowing time for organizations to comply.