Article 5(3) ePrivacy Directive
Article 5(3) is the provision of the EU's ePrivacy Directive that generally requires organisations to obtain a user's consent before storing information on, or gaining access to information already stored on, their device, for example when placing cookies. It is the main legal basis in the EU for cookie consent requirements, and it applies to a range of tracking technologies beyond traditional cookies. In most cases consent is required unless a limited exemption applies, such as for strictly necessary functions.
Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive) governs the storing of information, or the gaining of access to information already stored, in the terminal equipment of a user, permitting such operations only where the user has given consent after being provided with clear and comprehensive information, subject to exemptions for operations strictly necessary to transmit a communication or to provide a service explicitly requested by the user. Because it is a Directive, its effect depends on national transposition, so the precise wording, enforcement, and consent standard may vary between EU/EEA member states; where the operation involves personal data, the GDPR additionally governs the subsequent processing and supplies the applicable definition and standard of consent. In its Guidelines 2/2023 on the technical scope of Article 5(3) (adopted November 2023), the EDPB clarified that the provision applies broadly to technical solutions beyond cookies, potentially including pixels, local storage, SDKs, and similar tracking methods, with the stated aim of protecting the user's private sphere. This entry summarises scope only and does not resolve contested questions of national implementation or specific exemption boundaries, which turn on facts and applicable national law.
Why it matters
Article 5(3) of the ePrivacy Directive is the foundational legal provision behind cookie consent requirements across the EU and EEA. For any organisation operating websites or apps that reach users in Europe, it is the rule that generally determines whether consent must be obtained before cookies or similar technologies are placed on, or read from, a user's device. Understanding it is essential because it operates as the trigger for consent obligations, while the GDPR governs the separate question of how any resulting personal data may be processed. Treating the two regimes as interchangeable is a common source of compliance error.
The practical reach of Article 5(3) has expanded well beyond traditional browser cookies. In its Guidelines 2/2023 on the technical scope of Article 5(3), adopted in November 2023, the EDPB clarified that the provision can apply to a broad range of technical solutions, potentially including pixels, local storage, SDKs, and similar tracking methods, where information is stored on or accessed from a user's terminal equipment. The EDPB framed this broad reading around the provision's underlying aim of protecting the user's private sphere. For compliance teams, this means that consent analysis cannot be limited to a cookie banner; it must consider the full set of technologies deployed on a site or app.
Because the ePrivacy Directive is a directive rather than a regulation, its effect depends on transposition into national law. As a result, the precise wording, the standard of consent, the scope of exemptions, and enforcement practice may vary between member states. Organisations operating across multiple EU/EEA jurisdictions should therefore treat Article 5(3) as a common foundation rather than a single uniform rule, and should confirm the applicable national implementation for each market.
Who it's relevant to
Inside Article 5(3) ePrivacy Directive
Common questions
Answers to the questions practitioners most commonly ask about Article 5(3) ePrivacy Directive.
