ePrivacy and the GDPR: Where They Overlap and Where They Don't
Many European Union agency operators and marketing managers maintain an oversimplified, and ultimately hazardous, view of the digital regulatory landscape. While the General Data Protection Regulation is universally recognized as the primary standard for data privacy, the ePrivacy Directive is frequently relegated to "that cookie thing"—an afterthought addressed by installing a generic website banner.
Conflating these two legal frameworks or treating them as a single compliance exercise is a critical operational error. They are distinct legal instruments with separate scopes, different enforcement mechanisms, and unique compliance triggers. Understanding the boundaries between the ePrivacy Directive and the GDPR is essential for any digital agency operating in the European Economic Area. Compliance under one framework does not guarantee compliance under the other, and a tracking setup that is technically compliant under the GDPR may still directly violate the ePrivacy Directive, exposing organizations to significant regulatory penalties.
This guide untangles these overlapping legal regimes, providing a clear roadmap to navigate their intersection so you know exactly which law governs which activity.
1. Two Laws, Two Different Scopes
To build a robust compliance strategy, operators must first separate the fundamental scopes of the GDPR and the ePrivacy Directive.
The General Data Protection Regulation (Regulation (EU) 2016/679) is a directly applicable regulation that governs the processing of "personal data"—defined as any information relating to an identified or identifiable natural person. Its reach is horizontal and technology-neutral, applying to any form of processing, whether online or offline, and regardless of the technical infrastructure involved.
Conversely, the ePrivacy Directive (Directive 2002/58/EC) is a sectoral piece of legislation specifically designed to protect the confidentiality of electronic communications and govern access to or storage of information on users' terminal equipment, such as browsers, personal computers, and smartphones.
In legal terminology, the relationship between these two frameworks is defined by the doctrine of lex specialis. The ePrivacy Directive operates as the lex specialis (the specific law), while the GDPR acts as the lex generalis (the general law). This means that where the ePrivacy Directive establishes specific rules governing electronic communications or terminal equipment access, its provisions take absolute precedence over the more general rules of the GDPR. However, for any processing aspect not specifically covered by the ePrivacy Directive, the GDPR continues to apply as normal.
2. Where Each Law Applies Independently
The operational separation of ePrivacy vs GDPR obligations is best illustrated by looking at practical scenarios where only one of the frameworks applies. Understanding this separation proves why compliance teams must evaluate them independently.
When ePrivacy Applies, but the GDPR Does Not
Crucially, the ePrivacy Directive applies regardless of whether the data stored or accessed constitutes "personal data" under the GDPR. Purely technical, non-identifying identifiers stored in local browser memory are governed by the ePrivacy Directive, even if they fall completely outside the scope of the GDPR.
Consider a website cookie used strictly to store a user’s preferred interface language, text size, or custom UI theme. This cookie does not assign a unique tracking ID, does not log an IP address, and does not record any behavioral attributes that could be used to profile or identify the visitor. Because this cookie accesses and stores information on the user’s terminal equipment, the technical act of dropping it immediately triggers the ePrivacy Directive. However, because the information stored does not relate to an identified or identifiable natural person, the GDPR’s personal data processing provisions do not apply. If this preference cookie is deemed non-essential, the operator must still obtain ePrivacy-compliant consent to drop the cookie, despite the total absence of personal data.
When the GDPR Applies, but ePrivacy Does Not
Consider an agency that performs server-side analytics by analyzing raw server logs generated directly on its hosting server. These server logs typically contain IP addresses, which are legally classified as personal data under the GDPR. However, if this process happens entirely on the first-party server without writing any cookie, reading local browser storage, executing device fingerprinting, or utilizing URL tracking parameters on the client side, the ePrivacy Directive is not triggered.
Because no terminal equipment was accessed or utilized for storage, the ePrivacy Directive is irrelevant. However, because personal data (IP addresses) is being processed, the GDPR applies in its entirety. The agency must identify a valid GDPR lawful basis for this server-side processing, even though no cookie consent banner is legally required.
3. Cookie Consent: Navigating the Overlap
The most common compliance failure for agencies and marketers occurs in the "overlap zone"—specifically, website tracking and cookie consent. Setting and utilizing a marketing cookie requires a sequential, "dual-track" legal analysis because both laws apply to different stages of the tracking lifecycle.
The technical act of dropping a tracking cookie, loading a marketing pixel, or reading local browser storage constitutes accessing the user's terminal equipment. This act is strictly regulated by Article 5(3) of the ePrivacy Directive, which mandates prior user consent. However, the ePrivacy Directive itself does not define what constitutes valid consent. Instead, it references the GDPR’s rigorous consent standard. Therefore, to drop the cookie lawfully, the operator must obtain consent that is freely given, specific, informed, and unambiguous, demonstrated through a clear affirmative action. This means that scripts must not execute, and tracking pixels must not fire, before the visitor clicks "Accept".
Once the cookie has been dropped and begins collecting data, the ePrivacy Directive's primary role in that specific operation concludes. The subsequent processing, storage, and sharing of the personal data collected by that cookie are governed strictly by the GDPR. This subsequent processing requires its own independent GDPR Article 6 lawful basis.
This dual-track relationship has profound practical implications. Many marketers erroneously attempt to rely on "legitimate interest" under the GDPR to justify website tracking and profiling. While legitimate interest might theoretically be argued for certain backend data-processing activities, it can never bypass the initial ePrivacy requirement. Because the cookie cannot be set in the first place without ePrivacy-compliant consent, the entire downstream data processing chain collapses if prior consent is not obtained.
4. The Strict Boundary of the "Strictly Necessary" Exemption
The ePrivacy Directive provides a narrow exemption to the prior consent rule. This exemption allows organizations to store or access information on a user's device without prior consent in only two highly specific circumstances: when the storage is carried out solely for the purpose of transmitting a communication over an electronic network, or when it is strictly necessary to provide an information society service explicitly requested by the subscriber or user.
Typical examples of strictly necessary cookies include shopping cart cookies that remember items during a browsing session, authentication tokens that keep a user securely logged in, and user-centric security cookies designed to detect authentication abuses. Under the ePrivacy Directive, these can be set without asking for permission.
However, the intersection with the GDPR remains critical here. Even when a cookie is exempt from consent under the ePrivacy Directive because it is strictly necessary, the personal data it processes is still subject to the GDPR. The operator must establish a valid GDPR legal basis for processing that personal data. For instance, while a shopping cart cookie is exempt from a consent banner under ePrivacy, the subsequent processing of that cart data is usually justified under GDPR Article 6(1)(b) (contractual necessity) because processing the data is required to fulfill the user's purchase request.
It is vital to note that analytics cookies, advertising trackers, and cross-site behavioral profiling tools do not meet the threshold of being strictly necessary for a service explicitly requested by the user, and therefore always require prior ePrivacy consent.
5. Email Marketing: The Transposition Problem
Beyond website tracking, the interplay between the ePrivacy Directive GDPR rules shapes the framework for direct electronic marketing. Article 13 of the ePrivacy Directive governs unsolicited electronic commercial communications, including email, SMS, and automated messaging.
The baseline rule under ePrivacy is clear: sending direct marketing emails to individuals requires prior, explicit opt-in consent. However, Article 13(2) of the Directive provides a vital exception known as the "soft opt-in". This exception allows organizations to send direct marketing communications without prior explicit consent only if specific, cumulative conditions are met: the sender obtained the electronic contact details directly from the customer in the context of a sale, the marketing relates only to the sender’s own similar products or services, and the customer is given a clear and distinct opportunity to object (opt-out) at the time of collection and in every subsequent message. A November 2025 judgment from the Court of Justice of the European Union (Case C-654/23) clarified that offering a free user account can amount to a "sale" for the purposes of this soft opt-in exemption.
However, recent rulings from the CJEU have explicitly warned that this exemption applies only to the direct transmission of the marketing email. Surrounding data operations—such as compiling user purchase histories, building targeted behavioral profiles, or sharing data with third parties—remain strictly governed by the GDPR and require an independent Article 6 legal basis. For a deeper dive into choosing the correct legal framework for these backend processing activities, operators should refer to our guide on legitimate interest vs consent.
Compounding this complexity is the fact that because ePrivacy is a Directive (rather than a directly applicable Regulation), its implementation varies widely among EU member states. Organizations operating across multiple EU jurisdictions must carefully adapt their subscription flows to satisfy local discrepancies:
- Germany: The national transposition via the Act Against Unfair Competition (UWG) enforces highly restrictive rules, consistently maintaining that a double opt-in mechanism is the only legally defensible proof of consent.
- France: The CNIL enforces strict boundaries, requiring separate and distinct consent checkboxes for separate processing operations, and heavily monitors the reuse of transactional data.
- United Kingdom: The UK continues to apply its own transposition of the ePrivacy Directive via the Privacy and Electronic Communications Regulations (PECR), which retains the soft opt-in mechanism but is enforced independently by the Information Commissioner's Office.
6. The Missing ePrivacy Regulation
For nearly a decade, compliance officers eagerly anticipated the arrival of the ePrivacy Regulation, which was designed to replace the aging 2002 Directive. As a Regulation, it would have applied directly in all 27 member states, eliminating the fragmented patchwork of national transpositions and unifying cookie and direct marketing enforcement across the continent.
However, the ePrivacy Regulation never arrived. Following years of political deadlock and shifting technological landscapes, the European Commission officially withdrew the ePrivacy Regulation proposal in February 2025. The Commission acknowledged that the draft had become outdated in light of newer frameworks, such as the Digital Services Act.
Practically, this withdrawal means that the fragmented model of the 2002 ePrivacy Directive remains the governing framework indefinitely. EU agencies must continue to navigate 27 distinct national laws rather than relying on a singular European rulebook. While some consolidation has occurred through recent digital reform packages, the core requirements governing cookie consent and direct marketing consent remain completely untouched and heavily fragmented across the European Union.
Conclusion
Treating data protection as a monolithic exercise governed entirely by the GDPR creates massive operational vulnerabilities. The ePrivacy Directive is an equally powerful legal instrument that demands independent consideration whenever your agency interacts with a user's terminal equipment or sends electronic communications. By understanding where the ePrivacy Directive takes precedence and where the GDPR dictates the rules, you can architect marketing and tracking stacks that are genuinely compliant.
To bridge the technical gap between strict ePrivacy consent interfaces and downstream data processing, Custodia’s Consent Management Platform (CMP) handles both the initial ePrivacy consent-gathering and downstream Google Consent Mode v2 signaling in one unified integration. For technical implementation guidance, review our Consent Mode v2 walkthrough. To understand how these frameworks fit into your broader liability, refer to our GDPR compliance guide for agencies.
Identify hidden compliance gaps in your current marketing stack and ensure your cookie banners and email campaigns satisfy both legal regimes by taking our free assessment.
Find out your GDPR score
Take our free 12-minute assessment to see where your agency stands.
Take free assessment