ePrivacy Directive

European UnionPrivacy2002
ByDecipherU Editorial

The ePrivacy Directive governs cybersecurity and privacy in electronic communications within the EU. It covers confidentiality of communications, cookies and tracking technologies, unsolicited marketing, and traffic data retention. Often called the 'Cookie Law,' it requires user consent before storing cookies or similar technologies on user devices.

Quick Reference

EnactedJuly 12, 2002
Last AmendedDirective 2009/136/EC (2009); ePrivacy Regulation proposal still pending
Enforcement BodyNational data protection authorities and telecommunications regulators
PenaltiesDetermined by member state transposition; typically aligned with GDPR penalties where member states have updated laws
Applicable ToElectronic communications service providers and website operators in the EU

Key Requirements

Article 5(3)

Storing or accessing information on a user's device (including cookies) requires prior informed consent, except for strictly necessary cookies

Article 4(2)

Providers of electronic communications services must notify subscribers of personal data breaches that are likely to adversely affect their privacy

Article 13

Unsolicited electronic communications for direct marketing are only permitted with prior consent of the subscriber (opt-in)

How Does ePrivacy Directive Affect Cybersecurity Careers?

Cybersecurity professionals implementing cookie consent and tracking controls work directly with ePrivacy requirements. Security engineers at telecommunications companies must address the directive's confidentiality and breach notification mandates. Web application security roles involve ensuring compliant consent management implementations.

Cybersecurity Roles That Work With ePrivacy Directive

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of ePrivacy Directive at the official source: https://eur-lex.europa.eu/eli/dir/2002/58/oj

Frequently Asked Questions

The ePrivacy Directive governs cybersecurity and privacy in electronic communications within the EU. It covers confidentiality of communications, cookies and tracking technologies, unsolicited marketing, and traffic data retention. Often called the 'Cookie Law,' it requires user consent before storing cookies or similar technologies on user devices.

Cybersecurity professionals implementing cookie consent and tracking controls work directly with ePrivacy requirements. Security engineers at telecommunications companies must address the directive's confidentiality and breach notification mandates. Web application security roles involve ensuring compliant consent management implementations.

Determined by member state transposition; typically aligned with GDPR penalties where member states have updated laws

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?