{"id":738,"date":"2022-01-17T09:49:00","date_gmt":"2022-01-17T09:49:00","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=738"},"modified":"2026-03-12T08:19:04","modified_gmt":"2026-03-12T08:19:04","slug":"eprivacy-regulation","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/us\/eprivacy-regulation\/","title":{"rendered":"The EU ePrivacy Regulation: what it is and what to expect"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-what-is-the-eprivacy-regulation\">What is the ePrivacy Regulation?<\/h2>\n\n\n\n<p>The ePrivacy Regulation is a draft European Union (EU) regulation that governs all electronic communications on publicly available services and networks inside the European Union.<\/p>\n\n\n\n<p>The EU's data privacy laws currently consist of the<a href=\"https:\/\/www.cookiebot.com\/en\/gdpr\/\"> General Data Protection Regulation (GDPR)<\/a> and the 2002 &nbsp;ePrivacy Directive, sometimes known as the \u201c<a href=\"https:\/\/www.cookiebot.com\/en\/cookie-law\">cookie law<\/a>\u201d. If passed, the new ePrivacy Regulation would repeal and replace the ePrivacy Directive and bring significant updates by including new technologies in its legal framework.<\/p>\n\n\n\n<p>Its goal is to strengthen data privacy safeguards, extending protections not only to data processed by traditional telecommunications providers, but by all electronic communications services, such as texts, emails, voiceover internet protocol (VoIP), and instant messaging services like WhatsApp and Facebook Messenger.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Timeline of the ePrivacy Regulation<\/h2>\n\n\n\n<p>The ePrivacy Regulation was intended to come into force alongside the GDPR in May 2018. There have, however, been considerable delays since the draft was first published. Key dates include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>January 2017: the<a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:52017PC0010\" target=\"_blank\" rel=\"noreferrer noopener\"> draft text<\/a> of the ePrivacy Regulation was published<\/li>\n\n\n\n<li>October 2017: the European Parliament published a report with<a href=\"https:\/\/www.europarl.europa.eu\/doceo\/document\/A-8-2017-0324_EN.html\" target=\"_blank\" rel=\"noreferrer noopener\"> proposed amendments<\/a><\/li>\n\n\n\n<li>February 2021: the European Council published its<a href=\"https:\/\/data.consilium.europa.eu\/doc\/document\/ST-6087-2021-INIT\/en\/pdf\" target=\"_blank\" rel=\"noreferrer noopener\"> proposed amendments<\/a> and a<a href=\"https:\/\/www.consilium.europa.eu\/en\/press\/press-releases\/2021\/02\/10\/confidentiality-of-electronic-communications-council-agrees-its-position-on-eprivacy-rules\/\" target=\"_blank\" rel=\"noreferrer noopener\"> mandate for negotiations<\/a> with the European Parliament<\/li>\n\n\n\n<li>May 2021: trilogue negotiations officially began, involving the European Commission (EC), European Parliament, and European Council, aiming to reach a consensus on the final text<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_1.svg\" alt=\"The electronic privacy of Individuals inside the EU is the subject and scope of the ePrivacy Regulation 2021.\" class=\"wp-image-14756\" width=\"770px\" height=\"450px\" srcset=\"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_1.svg?v=454f43226b19a475 150w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_1.svg?v=454f43226b19a475 300w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_1.svg?v=454f43226b19a475 768w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_1.svg?v=454f43226b19a475 1024w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_1.svg?v=454f43226b19a475 770w\" sizes=\"(max-width: 770px) 100vw, 770px\" \/><figcaption class=\"wp-element-caption\">The electronic privacy of Individuals inside the EU is the subject and scope of the ePrivacy Regulation 2021.<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What is the <\/strong><strong>status of the ePrivacy Regulation<\/strong><strong>?<\/strong><\/h2>\n\n\n\n<p>As of August 2024, the ePrivacy Regulation is still in trilogue discussions involving the European Parliament, the European Council, and the European Commission. If the draft ePrivacy Regulation is finalized, it will officially become law 20 days after its publication in the EU Official Journal. However, it will only start to apply two years after this date, giving organizations affected by the regulation time to achieve compliance.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_3.svg\" alt=\"The ePrivacy Regulation 2021 faces tough trialogue negotiations in the EU Parliament.\" class=\"wp-image-14760\" width=\"716px\" height=\"auto\" srcset=\"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_3.svg?v=babe4303096a36f1 150w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_3.svg?v=babe4303096a36f1 300w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_3.svg?v=babe4303096a36f1 768w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_3.svg?v=babe4303096a36f1 1024w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_3.svg?v=babe4303096a36f1 770w\" sizes=\"(max-width: 770px) 100vw, 770px\" \/><figcaption class=\"wp-element-caption\">The ePrivacy Regulation 2021 faces tough trialogue negotiations in the EU Parliament.<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-the-difference-between-the-eprivacy-regulation-and-the-eprivacy-directive\">What is the difference between the ePrivacy Regulation and the ePrivacy Directive?<\/h2>\n\n\n\n<p>The ePrivacy Regulation and the ePrivacy Directive are both European legislative frameworks focused on privacy and electronic communications, but they differ primarily in their scope and legal effect, and current status.<\/p>\n\n\n\n<p>The ePrivacy Directive is a legislative act that requires EU member states to implement its provisions into their national laws, such as <a href=\"https:\/\/www.cookiebot.com\/en\/spanish-cookie-laws\/\">Law 34\/2002 in Spain<\/a> and <a href=\"https:\/\/www.cookiebot.com\/en\/danish-cookie-consent-guidelines\/\">Cookiebekendtg\u00f8relsen in Denmark<\/a>. On the other hand, the ePrivacy Regulation, which is intended to replace the Directive, is a regulation that would be directly applicable in all EU member states without the need to implement national legislation.<\/p>\n\n\n\n<p>While both are concerned with the privacy of electronic communications, the ePrivacy Regulation aims to update and expand the rules to align with the GDPR. It covers newer technologies and communication services, like WhatsApp and Zoom, and includes new provisions on marketing communications, cookies, and the confidentiality of communications.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_4.svg\" alt=\"Particular to the electronic communications sector, the ePrivacy Regulation updates the 2002 ePrivacy Directive.\" class=\"wp-image-14759\" width=\"770px\" height=\"513px\" srcset=\"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_4.svg?v=ae5cce36472a964f 150w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_4.svg?v=ae5cce36472a964f 300w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_4.svg?v=ae5cce36472a964f 768w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_4.svg?v=ae5cce36472a964f 1024w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_4.svg?v=ae5cce36472a964f 770w\" sizes=\"(max-width: 770px) 100vw, 770px\" \/><figcaption class=\"wp-element-caption\">Particular to the electronic communications sector, the ePrivacy Regulation updates the 2002 ePrivacy Directive.<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">What is the difference between the ePrivacy Regulation and the GDPR?<\/h2>\n\n\n\n<p>The GDPR protects the personal data of individuals inside the EU, while the ePrivacy Regulation will protect the privacy of electronic communication of individuals and businesses inside the EU.<\/p>\n\n\n\n<p>The ePrivacy Regulation is a lex specialis to the GDPR, which is a lex generalis. This means that it complements the GDPR with rules that apply specifically to the electronic communications sector, which are not explicitly addressed in the GDPR. As lex specialis, the ePrivacy Regulation will override the GDPR in the specific areas that it covers.<\/p>\n\n\n\n<p>The EU ePrivacy Regulation, when it comes into effect, will not replace the GDPR. Rather, these will be two different and complementary laws, deriving from two different rights of the<a href=\"https:\/\/ec.europa.eu\/info\/aid-development-cooperation-fundamental-rights\/your-rights-eu\/eu-charter-fundamental-rights_en\/?uri=CELEX:12012P\/TXT\" target=\"_blank\" rel=\"noreferrer noopener\"> European Charter of Human Rights<\/a>. The GDPR covers the right to protection of personal data, while the ePrivacy Regulation will encompass a person's right to a private life, including confidentiality, in all electronic communications.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Who does the ePrivacy Regulation apply to?<\/h2>\n\n\n\n<p>The ePrivacy Regulation includes an array of electronic communications services beyond traditional telecom companies. It applies to both businesses and individuals involved in electronic communication who:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>handle data related to online communication services<\/li>\n\n\n\n<li>use online tracking tools like<a href=\"https:\/\/www.cookiebot.com\/en\/tracking-cookies\/\"> tracking cookies<\/a> and other<a href=\"https:\/\/www.cookiebot.com\/en\/website-tracking\/\"> website tracking<\/a> technologies<\/li>\n\n\n\n<li>provide directories of end users<\/li>\n\n\n\n<li>engage in electronic direct marketing<\/li>\n<\/ul>\n\n\n\n<p>This includes website owners using cookies, app developers, direct marketers using emails or messages, telecommunications firms, online messaging services, and Internet of Things (IoT) providers, among others.<\/p>\n\n\n\n<p>It has extraterritorial scope like the GDPR, and regulates data pertaining to end users within the EU regardless of where the data collection or processing occurs. This means that entities both inside and outside the EU must comply if they handle data of EU residents.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-who-does-the-eprivacy-regulation-protect\">Who does the ePrivacy Regulation protect?<\/h2>\n\n\n\n<p>Unlike the GDPR and ePrivacy Directive, which protect the personal data of individuals or natural persons, the ePrivacy Regulation aims to protect the fundamental rights and freedoms of \u201clegal persons\u201d with respect to electronic communications services. Legal persons would include not only individuals but any legally registered entity or business.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-the-eprivacy-regulation-s-requirements\">What are the ePrivacy Regulation\u2019s requirements?<\/h2>\n\n\n\n<p>Since the ePrivacy Regulation is still in the negotiation stage, the specific obligations and rules could be subject to change until it is finalized and adopted. However, if the draft is passed without any amendments, the following requirements will apply for all persons and businesses subject to it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-confidentiality-under-the-eprivacy-regulation\">Confidentiality under the ePrivacy Regulation<\/h3>\n\n\n\n<p>Entities that handle electronic communications data must keep them confidential by default. The draft regulation specifically forbids the following actions related to electronic communications data by someone other than the data owner:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>listening<\/li>\n\n\n\n<li>tapping<\/li>\n\n\n\n<li>storing<\/li>\n\n\n\n<li>monitoring<\/li>\n\n\n\n<li>scanning or other kinds of interception<\/li>\n\n\n\n<li>surveillance<\/li>\n\n\n\n<li>processing<\/li>\n<\/ul>\n\n\n\n<p>Art. 6 of the draft regulation permits processing electronic communications data in specific cases, such as for ensuring the transmission of a communication, maintaining or restoring network security, identifying technical issues in the communication's delivery, or if the end user has given explicit consent for a specific purpose.<\/p>\n\n\n\n<p>Electronic communications data under the regulation includes:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>electronic communications content, defined as <em>\u201ccontent exchanged by means of electronic communications services, such as text, voice, videos, images, and sound\u201d<\/em><\/li>\n\n\n\n<li>electronic communications metadata, defined as data processed electronically <em>\u201cfor the purposes of transmitting, distributing or exchanging electronic communications content.\u201d <\/em>including the method of communication, device location, date, time, duration, and type of communication<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-storage-and-erasure-under-the-eprivacy-regulation\">Storage and erasure under the ePrivacy Regulation<\/h3>\n\n\n\n<p>Under Art. 7 of the draft regulation, electronic communications service providers must:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>delete the content or<a href=\"https:\/\/usercentrics.com\/knowledge-hub\/data-anonymization\/\" target=\"_blank\" rel=\"noreferrer noopener\"> anonymize the data<\/a> once the intended recipient receives it<\/li>\n\n\n\n<li>erase the metadata or anonymize it when it\u2019s no longer needed for transmitting the communication<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-cookies-under-the-eprivacy-regulation\">Cookies under the ePrivacy Regulation\u00a0<\/h3>\n\n\n\n<p>Cookies are a widely used technology for collecting, processing, and sharing personal data from end users on the internet today, and the GDPR requires explicit consent from end users before non-essential cookies can be activated.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.cookiebot.com\/en\/cookie-consent\/\">Cookie consent<\/a> remains a core part of the EU ePrivacy Regulation, and cookies and similar website trackers are also covered under the new draft data privacy law. The draft regulation largely retains the current requirement to obtain consent to set or read a cookie unless the cookie is necessary for the provision of the relevant electronic communication services.&nbsp;<\/p>\n\n\n\n<p>Consent has the same meaning, and must meet the same strict conditions as consent under the GDPR.&nbsp;<\/p>\n\n\n\n<p>Under Art. 8 of the draft ePrivacy Regulation, cookies and other tracking technologies are prohibited except when:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>they are necessary for the sole purpose of transmitting the electronic communication<\/li>\n\n\n\n<li>the end user has given their explicit consent<\/li>\n\n\n\n<li>the end user has requested a service that requires them<\/li>\n\n\n\n<li>they are necessary for website analytics, where:\n<ul class=\"wp-block-list\">\n<li>the data collection and analytics is done by the website<\/li>\n\n\n\n<li>if done by a third-party service, this third party complies with the requirements of the GDPR<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p>Recital 21 states that cookies should be used without consent only in <em>\u201csituations that involve no, or only very limited, intrusion of privacy.\u201d <\/em>Examples include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>to keep track of a multi-page form\u2019s inputs<\/li>\n\n\n\n<li>identity verification during online transactions<\/li>\n\n\n\n<li>remembering items placed in a shopping cart<\/li>\n\n\n\n<li>security-related software updates for IoT devices<\/li>\n<\/ul>\n\n\n<div class=\"cta-block cta-block--size-s cta-block--only-buttons cb-ctx--blue\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                    <h2 class=\"cta-block__title no-default-margin like-h4\">\n                        Scan your website for free to find out which cookies and tracking technologies it uses.                    <\/h2>\n                                                                                                                                                                        <\/div>\n                            <div class=\"cta-block__right-column\">\n                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"67c887d3-276c-47e2-876a-9d846e7a0cc0\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"https:\/\/www.cookiebot.com\/en\/cookie-checker\/\" target=\"\">\n<span>Check now<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                        <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n\n\n\n<p>The draft ePrivacy Regulation also deals with<a href=\"https:\/\/www.cookiebot.com\/en\/cookie-walls\/\"> cookie walls<\/a>, a mechanism that some websites use to refuse access without cookie consent. The regulation does not prohibit cookie walls if the user is offered an equivalent experience or access that does not involve giving consent to cookies and trackers.<\/p>\n\n\n\n<p>A new provision in the ePrivacy Regulation aims to reduce consent fatigue that arises when users are inundated with cookie consent requests from each website they visit. The draft ePrivacy Regulation makes it possible for end users to whitelist cookie providers in their browser settings and encourages providers to make it easy for users to amend whitelists and withdraw their consent at any time.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-direct-marketing-communications-under-the-eprivacy-regulation\">Direct marketing communications under the ePrivacy Regulation<\/h3>\n\n\n\n<p>Businesses are not permitted to send marketing messages to individuals through electronic means, such as emails or texts, unless these individuals have explicitly agreed to receive them. This means businesses must obtain the person's specific, explicit consent before sending them marketing materials or communications.<\/p>\n\n\n\n<p>If a business obtains a natural or legal person\u2019s contact details at the time of making a purchase, the business can use this information to send marketing emails or messages about similar products or services they offer. However, they must provide a clear and straightforward way to opt out of these messages, both when they first collect the contact details and every time they send such a marketing message.<\/p>\n\n\n<div class=\"cta-block cta-block--size-s cta-block--only-buttons cb-ctx--blue\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                    <h2 class=\"cta-block__title no-default-margin like-h4\">\n                        Obtain valid consent with the help of a GDPR compliant cookie banner. Sign up for your free Cookiebot CMP trial.                    <\/h2>\n                                                                                                                                                                        <\/div>\n                            <div class=\"cta-block__right-column\">\n                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"9cdfdbc8-b1e8-47be-b444-7101739ead6b\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\">\n<span>Start now<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                        <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-spam-under-the-eprivacy-regulation\">Spam under the ePrivacy Regulation<\/h3>\n\n\n\n<p>Providers of number-based interpersonal communications services \u2014 for example, traditional telephone, SMS, or VoIP \u2014 cannot add natural persons to a publicly available directory without their explicit consent. If the directory has a search function related to data other than end users\u2019 names and numbers, they must also obtain end users\u2019 consent before enabling this search function for their data.<\/p>\n\n\n\n<p>For legal persons listed in a directory, the provider must give them the option to opt out of having their data included. Individuals and businesses should also be able to verify, correct, or delete their data from these directories free of charge.<\/p>\n\n\n\n<p>These providers must also enable end users to block incoming calls from specific numbers or anonymous sources and stop automatic call forwarding from third parties.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-opinion-of-the-european-data-protection-board-on-the-eprivacy-regulation\">Opinion of the European Data Protection Board on the ePrivacy Regulation<\/h2>\n\n\n\n<p>On March 9, 2021, the European Data Protection Board (EDPB)<a href=\"https:\/\/edpb.europa.eu\/our-work-tools\/our-documents\/statements\/statement-032021-eprivacy-regulation_en\/\" target=\"_blank\" rel=\"noreferrer noopener\"> adopted a statement on the ePrivacy Regulation<\/a>, underlining that the coming regulation must under no circumstances lower the level of protection offered by the current ePrivacy Directive, which it would repeal and replace, and must complement the existing<a href=\"https:\/\/www.cookiebot.com\/en\/gdpr\/\"> GDPR<\/a> by providing additional strong guarantees for confidentiality and protection of all electronic communications.<\/p>\n\n\n\n<p>The EDPB emphasized in its statement that:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>some exceptions (in particular Article 6(1)(c), Article 6b(1)(e), Article 6b(1)(f), Article 6c) introduced by the Council seem to allow for very broad types of processing, and recalls the need to narrow down those exceptions to specific and clearly defined purposes<\/li>\n\n\n\n<li>it is necessary to obtain consent that is genuinely freely given, and that this should prevent service providers from using unfair practices, such as \u201ctake it or leave it\u201d solutions like cookie walls, which make access to services and functionality conditional on user consent<\/li>\n\n\n\n<li>there is a need to include an explicit provision in the ePrivacy Regulation against service providers processing information without user consent, and that enables users to accept or refuse profiling<\/li>\n\n\n\n<li>the ePrivacy Regulation should improve the current consent framework with an effective way to obtain consent for websites and mobile applications, by giving back control to the users and addressing the \u201cconsent fatigue\u201d<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" height=\"513\" width=\"770\" src=\"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_2.svg\" alt=\"The draft ePrivacy Regulation 2021 emphasizes user consent as core to electronic data privacy.\" class=\"wp-image-14758\" srcset=\"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_2.svg?v=d70ed9c5379ccf47 150w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_2.svg?v=d70ed9c5379ccf47 300w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_2.svg?v=d70ed9c5379ccf47 768w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_2.svg?v=d70ed9c5379ccf47 1024w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/01\/cb_blog_blody_770x513_eu_eprivacy_202408_2.svg?v=d70ed9c5379ccf47 770w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><figcaption class=\"wp-element-caption\">The draft ePrivacy Regulation 2021 emphasizes user consent as core to electronic data privacy.<\/figcaption><\/figure>\n\n\n\n<p>It is still uncertain what the road ahead looks like for the draft ePrivacy Regulation while trilogue negotiations remain underway.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-enforcement-of-the-eprivacy-regulation-and-penalties\">Enforcement of the ePrivacy Regulation and penalties<\/h2>\n\n\n\n<p>The enforcement of the ePrivacy Regulation aligns closely with the established framework under the GDPR. The same independent supervisory authorities tasked with monitoring GDPR compliance \u2014 the Data Protection Authorities of the EU Member States \u2014 will oversee application of the ePrivacy Regulation. The EDPB will ensure the regulation is uniformly applied across all EU Member States. End users of electronic communication services can seek remedies under the same legal provisions that protect data subjects under the GDPR.<\/p>\n\n\n\n<p>For violations of the EU ePrivacy Regulation, penalties will be tiered based on severity, which is also how the GDPR and a number of other international privacy regulations are set up. Less serious infractions can lead to penalties up to 2 percent of the violator\u2019s annual worldwide turnover or up to EUR 10 million, whichever is greater. More severe violations may result in fines up to 4 percent of annual worldwide turnover or up to EUR 20 million, whichever is greater.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-can-businesses-prepare-for-eprivacy-regulation-compliance\">How can businesses prepare for ePrivacy Regulation compliance?<\/h2>\n\n\n\n<p>Businesses can take steps towards ePrivacy Regulation compliance by implementing several key practices, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>displaying GDPR-compliant<a href=\"https:\/\/www.cookiebot.com\/en\/cookie-banner\/\"> cookie banners<\/a> to inform end users about your website\u2019s cookie usage and to obtain explicit user consent before setting cookies<\/li>\n\n\n\n<li>simplifying the management of user consents and enabling users to easily withdraw consent with a consent management platform (CMP) like<a href=\"https:\/\/www.cookiebot.com\/\"> Cookiebot CMP<\/a><\/li>\n\n\n\n<li>employing<a href=\"https:\/\/www.cookiebot.com\/en\/google-consent-mode\/\"> Google Consent Mode<\/a> alongside<a href=\"https:\/\/www.cookiebot.com\/en\/google-tag-manager\/\"> Google Tag Manager<\/a> to ensure that tags aren\u2019t triggered unless a user has explicitly consented to the collection of their data<\/li>\n\n\n\n<li>keeping your<a href=\"https:\/\/www.cookiebot.com\/en\/cookie-policy\/\"> cookie policy<\/a> and\/or privacy policy updated to reflect your organization\u2019s privacy practices and evolving legal requirements<\/li>\n<\/ul>\n\n\n<div class=\"cta-block cta-block--size-s cta-block--only-buttons cb-ctx--blue\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                    <h2 class=\"cta-block__title no-default-margin like-h4\">\n                        Instantly create your privacy policy with the Cookiebot\u2122 Privacy Policy Generator                    <\/h2>\n                                                                                                                                                                        <\/div>\n                            <div class=\"cta-block__right-column\">\n                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"37c6a4af-6042-420f-92ec-be9051a10b94\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"\/en\/privacy-policy-generator-gdpr\/\" target=\"\">\n<span>Generate now<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                        <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n\n\n\n<p>Although the ePrivacy Regulation is still in negotiations, taking steps towards compliance can help businesses smoothly adapt to new requirements, future-proof marketing operations, and build customer trust.<\/p>\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>What is the ePrivacy Regulation? The ePrivacy Regulation is a draft European Union (EU) regulation that governs all electronic communications on publicly available services and networks inside the European Union. The EU's data privacy laws currently consist of the General Data Protection Regulation (GDPR) and the 2002 &nbsp;ePrivacy Directive, sometimes known as the \u201ccookie law\u201d. [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":14770,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":true,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-738","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":false,"thumbnail_url":"https:\/\/www.cookiebot.com\/us\/wp-content\/uploads\/sites\/8\/2022\/01\/The-EU-ePrivacy-Regulation_1200x630_ffffff.png","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/posts\/738","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/comments?post=738"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/posts\/738\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/media\/14770"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/media?parent=738"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/categories?post=738"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/tags?post=738"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}