The ePrivacy Directive and cookie consent

The law that requires a cookie banner is not the GDPR. It is the ePrivacy Directive, in force since 2002 and amended in 2009 to require consent before anything is stored on or read from a visitor’s device. The GDPR then supplies the standard that consent has to meet. Because it is a directive rather than a regulation, each member state implements it in its own law, so the detail differs across the EU.

  • European Union, since 2002
  • Storage and access, not personal data
  • Implemented per country

From €10 a month. No credit card, no per-visitor billing.

What the ePrivacy Directive asks for

Article 5(3) is the operative provision, and it is shorter than the amount written about it.

  • Consent before storing or accessing anything on a device
  • Clear and comprehensive information about the purpose
  • An exemption for carrying out a transmission
  • An exemption for what is strictly necessary for a requested service
  • Consent meeting the GDPR standard, since 2018

This page explains what the law asks for and what our software does about it. It is not legal advice, and it cannot tell you whether your organisation is compliant, because that depends on everything else you process.

What Consent Studio does about it

  • Gates storage, not just tracking

    A tag you add in the tag manager waits by default, and a script already in your markup is held once you mark it, whether it writes to the device or reads from it. Storage and access is the actual scope of the rule. Tools that reason about personal data instead let through a whole category of local storage that is caught.

    • Cookies and local storage
    • Before first write
    • Every tag
  • Applies the right national default

    Implementations differ, and the defaults follow the visitor rather than your head office. A site trading across the EU does not have to run one configuration per member state.

    • By visitor region
    • One configuration
    • Multilingual
  • Evidences it to the GDPR standard

    Since 2018 the consent ePrivacy asks for is GDPR consent, which brings the accountability duty with it. Each choice is stored with a timestamp against the wording that was shown.

    • Timestamped
    • Versioned wording
    • Exportable

What people get wrong about ePrivacy

  1. Assuming no personal data means no consent

    The rule bites on storage and access on terminal equipment, not on personal data. A cookie holding a random string that identifies nobody still needs consent, and this is the reasoning error that puts most sites in breach while their team believes the opposite.

  2. Waiting for the ePrivacy Regulation

    A regulation to replace the directive has been in draft for years and was withdrawn from the Commission work programme. Teams that deferred work on the basis that the rules were about to change have now been deferring for most of a decade.

  3. Treating the EU as one implementation

    It is a directive, so twenty-seven national laws implement it and the details differ, from what counts as strictly necessary to how national authorities treat analytics. There is no single European answer to quote at a regulator.

Essential

€10/month

For a single site that has to be compliant, and stay that way.

  • Unlimited pages and displays
  • 200,000 consent actions a month
  • The full stack, not a starter tier
Try Essential for FreeNo credit card required. 7 day free trial.
  • Professional

    €36/month

    For growing teams that run on data, and the agencies serving them.

    Try Professional for Free
  • Enterprise

    From €250/month

    For a volume, or an obligation, a standard plan cannot answer.

    Explore Enterprise
  • Agencies & Resellers

    Buy at a partner rate and resell client sites at your own price.

    Discover Partner Programme
  • Public Sector

    Government, healthcare and education run on Enterprise.

    See Enterprise

Running under rules like these, in more than one country


  • Philips, the Dutch electronics group, using Consent Studio for cookie consent
  • Erasmus Universiteit Rotterdam, managing cookie consent with Consent Studio
  • America Today, a fashion retailer using Consent Studio across its webshop
  • Van Vulpen, an infrastructure contractor using Consent Studio for cookie consent
  • EuroParcs, a European holiday park operator running Consent Studio on its booking sites
  • Optica, a Dutch opticians chain using Consent Studio for consent management
  • Jeans Centre, a Dutch fashion retailer using Consent Studio for cookie consent
  • Mondiaen, a Tilburg primary school foundation, running Consent Studio across its school websites
  • Fiterman Pharma, a pharmaceutical company using Consent Studio for cookie consent
  • Eddie Rockets, a hospitality group managing cookie consent with Consent Studio
  • Veneta, a kitchen retailer using Consent Studio for consent management
  • MS Mode, a fashion retailer running Consent Studio across its European webshops
  • Dynamis
  • SB Supply
  • The Chosen

Other rules that may apply to you

Common ePrivacy questions

Is it the GDPR or ePrivacy that requires a cookie banner?

ePrivacy. Article 5(3) of the directive has required consent before storing or accessing information on a device since the 2009 amendment, which is six years before the GDPR was adopted. What the GDPR added in 2018 was the standard that consent must meet.

Does ePrivacy apply to cookies that hold no personal data?

Yes. The rule is about storing or accessing information on terminal equipment, and it does not ask whether that information identifies anybody. This is the most consequential difference from the GDPR and the one teams most often get backwards.

Which cookies are strictly necessary?

Those needed to deliver the service the visitor explicitly requested, such as a session identifier, a shopping basket or a load balancer. Analytics, advertising and personalisation are not, however useful they are to you, and national authorities have been consistent about that.

What happened to the ePrivacy Regulation?

It spent years in draft and was ultimately withdrawn from the Commission work programme, so the 2002 directive as amended in 2009 remains the instrument in force. Planning on the basis that it is about to be replaced has not been a good bet for some time.

Does Consent Studio make us compliant?

No single tool can, and any vendor saying otherwise is selling you something. Consent Studio handles the part a consent platform can handle: asking properly, holding every tag to the answer, keeping the record, and telling you when the site changes. What you process elsewhere is yours.

Where is our consent data stored?

In Amsterdam, on infrastructure owned and operated by Scaleway, a French company. Ownership matters more than location here: Scaleway is independently French rather than a European subsidiary of a US parent, so neither they nor we fall under the US CLOUD Act. Consent Studio itself is built and owned in the Netherlands.

Get Started with the Full Consent Stack

Everything you need in one bundle. Consent Studio provides you with a consent banner, scanner and client-side tag manager that guarantees no data ever gets transferred overseas.

Read the documentation

Our help center walks through every integration, plugin and template step by step, with screenshots. It is written and kept current by the people who build Consent Studio.

Which privacy policy?

We publish two, and they cover different audiences. Pick the one that describes you.