Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: Laws and Regulations

Article 5(3) ePrivacy Directive

Also known as: Article 5(3) ePD, ePrivacy Directive Article 5(3), Art. 5(3) ePrivacy Directive
Simply put

Article 5(3) is the provision of the EU's ePrivacy Directive that generally requires organisations to obtain a user's consent before storing information on, or gaining access to information already stored on, their device, for example when placing cookies. It is the main legal basis in the EU for cookie consent requirements, and it applies to a range of tracking technologies beyond traditional cookies. In most cases consent is required unless a limited exemption applies, such as for strictly necessary functions.

Formal definition

Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive) governs the storing of information, or the gaining of access to information already stored, in the terminal equipment of a user, permitting such operations only where the user has given consent after being provided with clear and comprehensive information, subject to exemptions for operations strictly necessary to transmit a communication or to provide a service explicitly requested by the user. Because it is a Directive, its effect depends on national transposition, so the precise wording, enforcement, and consent standard may vary between EU/EEA member states; where the operation involves personal data, the GDPR additionally governs the subsequent processing and supplies the applicable definition and standard of consent. In its Guidelines 2/2023 on the technical scope of Article 5(3) (adopted November 2023), the EDPB clarified that the provision applies broadly to technical solutions beyond cookies, potentially including pixels, local storage, SDKs, and similar tracking methods, with the stated aim of protecting the user's private sphere. This entry summarises scope only and does not resolve contested questions of national implementation or specific exemption boundaries, which turn on facts and applicable national law.

Why it matters

Article 5(3) of the ePrivacy Directive is the foundational legal provision behind cookie consent requirements across the EU and EEA. For any organisation operating websites or apps that reach users in Europe, it is the rule that generally determines whether consent must be obtained before cookies or similar technologies are placed on, or read from, a user's device. Understanding it is essential because it operates as the trigger for consent obligations, while the GDPR governs the separate question of how any resulting personal data may be processed. Treating the two regimes as interchangeable is a common source of compliance error.

The practical reach of Article 5(3) has expanded well beyond traditional browser cookies. In its Guidelines 2/2023 on the technical scope of Article 5(3), adopted in November 2023, the EDPB clarified that the provision can apply to a broad range of technical solutions, potentially including pixels, local storage, SDKs, and similar tracking methods, where information is stored on or accessed from a user's terminal equipment. The EDPB framed this broad reading around the provision's underlying aim of protecting the user's private sphere. For compliance teams, this means that consent analysis cannot be limited to a cookie banner; it must consider the full set of technologies deployed on a site or app.

Because the ePrivacy Directive is a directive rather than a regulation, its effect depends on transposition into national law. As a result, the precise wording, the standard of consent, the scope of exemptions, and enforcement practice may vary between member states. Organisations operating across multiple EU/EEA jurisdictions should therefore treat Article 5(3) as a common foundation rather than a single uniform rule, and should confirm the applicable national implementation for each market.

Who it's relevant to

Privacy officers and data protection professionals
Article 5(3) is the starting point for determining when consent is required before deploying tracking technologies in the EU/EEA. DPOs and privacy teams should use it to map which cookies and similar technologies require consent versus which may qualify for the strictly necessary exemptions, while confirming the applicable national implementation for each relevant member state.
Legal counsel and compliance teams
Counsel advising on EU operations must distinguish the Article 5(3) consent trigger from the GDPR's rules on subsequent processing, since the two regimes are governed separately. Because the provision is a directive dependent on national transposition, legal teams should assess how it has been implemented and enforced in each jurisdiction rather than assuming a single uniform standard.
Web developers and engineering teams
The EDPB's Guidelines 2/2023 clarified that Article 5(3) can extend beyond cookies to technical solutions such as pixels, local storage, and SDKs where information is stored on or accessed from a user's device. Developers should therefore inventory all such technologies deployed on a site or app, not only browser cookies, when supporting consent implementation.
Marketing and analytics compliance teams
Analytics and advertising technologies generally fall outside the strictly necessary exemptions, so their deployment typically requires prior consent under Article 5(3) as implemented in EU/EEA member states. Marketing teams should ensure tags and trackers are gated by valid consent and remain aware that requirements may differ across jurisdictions.

Inside Article 5(3) ePrivacy Directive

Storage of and access to information
Article 5(3) governs both the placing of information on a user's terminal equipment (such as writing a cookie) and the gaining of access to information already stored there. This dual scope is technology-neutral and captures more than traditional cookies.
Technology-neutral scope
Although commonly associated with cookies, the provision applies to any technique that stores or reads information on a device, including tracking pixels, local storage, software development kits (SDKs), and device fingerprinting, where those techniques involve storing or accessing information on terminal equipment.
Prior informed consent requirement
As a general rule, storing or accessing information on a user's device requires the user's prior consent, provided with clear and comprehensive information. The consent standard is generally read in light of the GDPR definition, meaning consent must typically be freely given, specific, informed, and unambiguous.
Strictly necessary exemption
Consent is generally not required where storage or access is carried out for the sole purpose of transmitting a communication, or where it is strictly necessary to provide a service explicitly requested by the user. This is typically interpreted narrowly and does not usually cover analytics or advertising.
Relationship to the GDPR
Article 5(3) addresses the act of storing or accessing information on the device, while any subsequent processing of personal data resulting from that access is separately governed by the GDPR. Satisfying one regime does not automatically satisfy the other.
National implementation
As part of a directive, Article 5(3) takes legal effect through the national laws that transpose it in each EU member state. Details, enforcement positions, and supervisory authority guidance can therefore vary between jurisdictions.

Common questions

Answers to the questions practitioners most commonly ask about Article 5(3) ePrivacy Directive.

Does complying with Article 5(3) of the ePrivacy Directive mean I have also satisfied my GDPR obligations?
No. Article 5(3) governs a distinct legal question from the GDPR: it addresses the storing of information on, or gaining access to information already stored in, a user's terminal equipment. The GDPR separately governs any processing of personal data that follows once information has been placed or read. In most EU jurisdictions these are treated as two separate compliance layers, so consent or an exemption relied upon under Article 5(3) does not automatically provide a lawful basis under the GDPR, and vice versa. You generally need to consider both regimes, and this entry does not address the full scope of GDPR lawful bases.
Does Article 5(3) only apply to cookies?
No. Although it is often described as the 'cookie law,' Article 5(3) is drafted in technology-neutral terms and covers the storing of, or access to, information on a user's device regardless of the specific technique. This is generally understood to include technologies such as pixels, local storage, software development kits (SDKs), and device fingerprinting, not only HTTP cookies. The determining factor is whether information is stored on or read from the terminal equipment, not the label given to the technology. Precise application to any given technique can depend on the facts and on national implementation.
Which cookies or similar technologies fall within the Article 5(3) exemption from consent?
Article 5(3) contains exemptions that are generally understood to cover storage or access that is strictly necessary for a service explicitly requested by the user, or solely for the purpose of carrying out the transmission of a communication. Cookies commonly treated as falling within this scope include those strictly necessary for functions the user has asked for. Analytics, advertising, and many functional cookies typically fall outside the exemption and generally require prior consent in EU jurisdictions. Whether a particular cookie is 'strictly necessary' can be contested and may depend on national guidance, so a case-by-case assessment is usually needed.
What standard of consent does Article 5(3) require when consent is the applicable basis?
Where Article 5(3) requires consent, it is generally interpreted by reference to the consent standard in the GDPR, meaning consent that is freely given, specific, informed, and unambiguous and expressed through a clear affirmative action. As a result, pre-ticked boxes, reliance on continued browsing as implied consent, and cookie walls are widely considered non-compliant in the EU, though positions can vary between authorities. Consent is also generally expected to be obtained before non-exempt storage or access takes place. Requirements differ under other frameworks, such as certain US state laws that rely on opt-out mechanisms rather than prior opt-in.
How does Article 5(3) interact with national law when implementing a consent solution?
Article 5(3) is part of a Directive, which means it takes effect through each EU member state's national implementing legislation rather than applying directly and uniformly. This can produce differences in wording, in how exemptions are interpreted, and in supervisory and enforcement practice across jurisdictions. When implementing a consent solution, you should generally check the specific national transposition and any guidance from the relevant data protection or telecommunications authority for each market you operate in. This entry describes the Directive at a general level and does not substitute for reviewing applicable national law.
Can a consent management platform (CMP) ensure my Article 5(3) compliance?
A CMP can support compliance by helping to present information, obtain and record consent, and control when non-exempt technologies fire, but no tool guarantees compliance by itself. Configuration decisions, such as which cookies are categorized as strictly necessary, whether tags are genuinely blocked before consent, and how choices are worded, still require legal and factual judgment. Frameworks such as the IAB Transparency and Consent Framework may assist with signaling but do not remove the underlying obligations. Effective use generally combines a properly configured tool with documented, jurisdiction-specific assessments.

Common misconceptions

Article 5(3) only applies to cookies.
The provision is technology-neutral and applies to any storing of or access to information on a user's terminal equipment. Similar technologies such as pixels, local storage, SDKs, and fingerprinting can fall within its scope even though they are not literally cookies.
Complying with Article 5(3) means you have also satisfied the GDPR.
Article 5(3) concerns the act of storing or accessing information on the device. Any resulting processing of personal data is separately governed by the GDPR, and consent or a lawful basis under one regime does not automatically cover the other.
Any cookie a website considers useful can rely on the strictly necessary exemption.
The exemption is generally interpreted narrowly, applying to transmission of a communication or services strictly necessary for a service the user explicitly requested. Analytics and advertising technologies typically fall outside it and generally require prior consent.

Best practices

Inventory all technologies that store or access information on user devices, including cookies, pixels, local storage, SDKs, and fingerprinting, since Article 5(3) may apply regardless of the specific technique.
Obtain prior consent before non-exempt storage or access, ensuring the consent meets the standard generally applied under the GDPR (freely given, specific, informed, and unambiguous through a clear affirmative action).
Apply the strictly necessary exemption cautiously and document why each technology qualifies, treating analytics and advertising as generally requiring consent unless specific national guidance indicates otherwise.
Assess GDPR obligations separately from Article 5(3), since any processing of personal data that follows storage or access needs its own lawful basis and compliance analysis.
Check the national implementation and supervisory authority guidance in each relevant EU member state, because transposition details and enforcement positions can differ between jurisdictions.
Treat consent management tools and platforms as support for compliance rather than a guarantee of it, and retain legal judgment over how the provision applies to your specific facts.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.