EuroComply
Sign up

ePrivacy Directive

The ePrivacy Directive governs electronic communications privacy, covering cookies, email marketing, and confidentiality of communications. Its replacement (ePrivacy Regulation) is pending but the Directive remains law. Maximum administrative fine: Per member state (GDPR rates of โ‚ฌ20M/4% apply where violation also breaches GDPR).

Free EU Compliance Checker

What does ePrivacy require and when does it apply?

ePrivacy applies to Telecommunications and Digital Services organisations across all EU member states. The key deadline is In force โ€” update expected 2025-2026. Non-compliance carries a maximum penalty of Per member state (GDPR rates of โ‚ฌ20M/4% apply where violation also breaches GDPR). Core obligations include obtain consent for cookies and tracking and honour opt-out for direct marketing.

  • Obtain consent for cookies and tracking
  • Honour opt-out for direct marketing
  • Protect confidentiality of communications
  • Notify breaches to authorities
  • Implement privacy by default
DeadlineIn force โ€” update expected 2025-2026
Max finePer member state (GDPR rates of โ‚ฌ20M/4% apply where violation also breaches GDPR)
Primary sectorsTelecommunications, Digital Services, E-commerce
TL;DR

ePrivacy: Per member state (GDPR rates of โ‚ฌ20M/4% apply where violation also breaches GDPR) max fine

ePrivacy applies to Telecommunications and Digital Services organisations in all EU member states. Key deadline: In force โ€” update expected 2025-2026.

Source: Official Journal of the European Union โ€” ePrivacy Directive

Deadline

In force โ€” update expected 2025-2026

Max Fine

Per member state (GDPR rates of โ‚ฌ20M/4% apply where violation also breaches GDPR)

Sectors Affected

Telecommunications, Digital Services, E-commerce

Per member state (GDPR rates of โ‚ฌ20M/4% apply where violation also breaches GDPR)maximum fine

The highest penalty for non-compliance with ePrivacy in the EU.

EU Official Journal

Key regulatory facts: ePrivacy Directive
Official nameDirective 2002/58/EC of the European Parliament and of the Council concerning the processing of personal data and the protection of privacy in the electronic communications sector (as amended by Directive 2009/136/EC)
Reg. No.2002/58/EC
CELEX32002L0058
Typedirective
In force2002-07-31
Applies from2003-10-31
Transposition2003-10-31
Max finePenalties set by national law. Cookie/consent violations may also trigger GDPR Article 83 penalties via the personal-data overlap.
Authorities
National DPAs (in most member states) (member-state)
National communications regulators (in some member states) (member-state)
Source2002/58/EC โ€” EUR-Lex Official Journal

How do I comply with ePrivacy?

  • Obtain consent for cookies and tracking
  • Honour opt-out for direct marketing
  • Protect confidentiality of communications
  • Notify breaches to authorities
  • Implement privacy by default

Does ePrivacy apply to your business?

Find out in 2 minutes with our free regulation checker.

Check now โ€” free

Next step โ€” classify

Classify your AI systems

Use the free regulation checker to find out exactly which ePrivacy obligations apply to your business in 2 minutes.

Classify your AI systems

Check Your Compliance Obligations

Find out which ePrivacy obligations apply to your organisation in under 2 minutes.

Check Your EU Compliance

For informational purposes only. This is not legal advice โ€” consult qualified legal counsel.

Last verified: ยท Source: EUR-Lex 32002L0058 ยท Editorial policy