ePrivacy Directive (Directive 2002/58/EC)
The EU's confidentiality-of-communications law — the legal root of every cookie banner — published in the Official Journal on 31 July 2002 (OJ L 201, 31.7.2002, p. 37) and materially rewritten by Directive 2009/136/EC (the "Cookie Directive"). This folder reproduces the consolidated text 02002L0058-20091219. It is lex specialis to the GDPR for electronic communications: where it applies, its rules displace the GDPR's lawful-basis analysis, while "consent" takes the GDPR meaning.
Being a directive, it acts through national implementations that differ meaningfully — PECR in the UK, Prawo komunikacji elektronicznej in Poland, and so on. Per-country entries in the TODO carry the national instruments; this folder is the common root they transpose.
Applicability to EdTech
- Article 5(3) is the operative rule for cookies, SDKs and device storage: "the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information" (Art. 5(3)) — with the strictly-necessary and transmission exemptions in the same paragraph. It is technology-neutral: localStorage, device fingerprinting, telemetry reads from a headset or portal all count. Note the consent-or-necessity analysis is per purpose, not per cookie.
- It protects legal persons too (Art. 1(2)) — schools as subscribers, not only individual users.
- Marketing email/SMS to teachers and parents: prior consent, or the soft opt-in for existing customers of a product/service, with an opt-out in every message (Art. 13). B2B nuances are national-law choices under Art. 13(5).
- Traffic and location data rules (Art. 6, Art. 9) bind providers of electronic communications services/networks — mostly relevant where a product embeds communications functionality rather than merely uses connectivity.
Contents
| Document | Covers |
|---|---|
| SCOPE-AND-DEFINITIONS.md | Arts. 1–3 — scope and definitions |
| SECURITY-AND-CONFIDENTIALITY.md | Arts. 4–5 — security/breach notification, confidentiality, the Art. 5(3) cookie rule |
| TRAFFIC-AND-LOCATION-DATA.md | Arts. 6, 9 — traffic data, location data |
| UNSOLICITED-COMMUNICATIONS.md | Art. 13 — direct-marketing opt-in and soft opt-in |
Scope note: itemised billing through directories (Arts. 7–8, 10–12), the Art. 15 restrictions/data-retention hook and the remedies/committee machinery can be added with the same tooling when needed. The proposed ePrivacy Regulation that would have replaced this Directive was withdrawn by the Commission in 2025 — the Directive remains the law; re-verify status when this matters.
Key obligations at a glance
- Consent before storing or accessing information on terminal equipment, unless strictly necessary for a service the user requested or for transmission (Art. 5(3)).
- Confidentiality of communications and related traffic data — no listening, tapping, storage or surveillance without consent or legal authority (Art. 5(1)).
- Service providers: appropriate security measures, subscriber risk information, and personal-data-breach notification to the competent authority and, for likely-adverse breaches, the subscriber (Art. 4).
- Direct marketing by automated means only with prior consent, save the soft opt-in (Art. 13(1)–(2)).
Enforcement
National — each Member State's implementation designates the enforcer (data-protection authority or communications regulator; in the UK, the ICO under PECR). There is no EU-level fine regime; national penalties and GDPR-style enforcement apply through the transpositions.
Related
- EU GDPR — general regime; ePrivacy is lex specialis and borrows its consent standard
- Per-country transpositions are tracked in the TODO Tier 3 entries (Poland, Romania, Portugal, …)
Sources
- EUR-Lex — Directive 2002/58/EC (ePrivacy), consolidated text 02002L0058-20091219
- EDPB — Guidelines 2/2023 on the technical scope of Art. 5(3) of the ePrivacy Directive
Meta
Article text in the content documents is reproduced verbatim from the EUR-Lex consolidated text (CELEX 02002L0058-20091219) and built/re-verified mechanically by tools/eur-lex/build_eu_eprivacy.py (verify mode; do not hand-edit). The four corrigenda postdating the consolidation touch only the CS/SK, BG and LV versions (checked via Cellar RDF, 2026-09-06), so the consolidated EN text is current. Anchors: official ELI ids plus derived paragraph/point anchors from printed labels. The statement about the withdrawn ePrivacy Regulation proposal is a status note, not extracted text — re-verify via the Commission's work programme when it matters.