Glossary · Privacy & regulation
ePrivacy Directive
The ePrivacy Directive (2002/58/EC, amended 2009) is the EU law governing confidentiality of electronic communications, including the cookie-consent rule: storing or reading anything on a user’s device requires prior consent unless it is strictly necessary.
Where the GDPR sets general rules for personal data, the ePrivacy Directive is a more specific, older instrument (first adopted 2002, amended by the 2009 "Cookie Directive" amendment) covering electronic communications: cookies and similar device storage, unsolicited marketing communications, and confidentiality of traffic and location data from telecom and online services. Its cookie provision, Article 5(3), is the actual legal basis for the consent banners seen across the web — not the GDPR itself, which is a common misconception.
The rule is technology-neutral: it covers cookies, local storage, device fingerprinting, and any similar technique used to store or access information on a user’s terminal equipment. An exemption exists for storage that is strictly necessary to provide a service the user requested (a session cookie for a shopping cart, for instance) or for the sole purpose of carrying out the transmission — analytics and advertising cookies do not qualify, which is why they trigger a consent banner.
A long-planned ePrivacy Regulation intended to replace the Directive and align its enforcement with the GDPR has been in negotiation for years without adoption, so the 2002/2009 Directive, as implemented into each member state’s national law, remains the operative rule. Ciphera’s own site uses Pulse, which does not set cookies or fingerprint visitors, so no consent banner is needed under Article 5(3)’s strictly-necessary logic.