Sector-Specific Law
Directive on privacy and electronic communications (ePrivacy Directive)
European Union · July 31, 2002 (as amended from May 25, 2011); applied through national implementing laws
The legal basis for cookie banners, and a genuinely separate regime from the GDPR that businesses routinely fold into it by mistake. Art. 5(3) requires prior informed consent before storing information on, or gaining access to information already stored on, a user's terminal equipment, exempting only what is strictly necessary to provide a service the user requested — and it is technology-neutral, so local storage, pixels, SDK identifiers, and device fingerprinting are all in scope, not just HTTP cookies. Two consequences follow. First, legitimate interest is not available here: consent under Art. 5(3) means GDPR-standard consent, and pre-ticked boxes do not qualify (Planet49, C-673/17). Second, because it is a DIRECTIVE, the operative text is 27 national implementing laws with real variation in enforcement posture and in the treatment of analytics cookies, and it is enforced in several member states by a telecoms or consumer regulator rather than the data protection authority. Art. 13 separately governs unsolicited direct marketing by email, SMS, and automated calling. The long-pending ePrivacy Regulation intended to replace this Directive was withdrawn rather than adopted; the Directive remains in force.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.