Skip to main content
Category: Laws and Regulations

ePrivacy Regulation

Also known as: Proposed ePrivacy Regulation, ePR, Regulation on Privacy and Electronic Communications
Simply put

The ePrivacy Regulation was a proposed European Union law intended to update and eventually replace the older ePrivacy Directive, setting rules for privacy in electronic communications, including how cookies and similar tracking technologies may be used. It was designed to work alongside the GDPR, applying specifically to the confidentiality of communications and to information stored on or accessed from a user's device. The proposal was never adopted, and the European Commission withdrew it, so as things stand there is no ePrivacy Regulation in force.

Formal definition

The ePrivacy Regulation refers to the European Commission's 2017 legislative proposal (procedure 2017/0003(COD)) concerning the respect for private life and the protection of personal data in electronic communications, intended to repeal and modernize Directive 2002/58/EC (the ePrivacy Directive) and to align it with Regulation (EU) 2016/679 (GDPR). As a proposed regulation rather than a directive, it would have been directly applicable across Member States without national transposition, aiming to harmonize rules on the confidentiality of electronic communications and on the storing of, or gaining access to, information on a user's terminal equipment, the legal basis governing cookies, pixels, SDKs, local storage, and similar technologies, independent of whether personal data is processed. It intended to preserve the GDPR standard of consent for non-exempt technologies while carving out limited exemptions. The proposal underwent prolonged negotiation in the Council and Parliament but was never adopted; the Commission subsequently withdrew it, meaning there is currently no ePrivacy Regulation draft active in the EU legislative process. In the interim, the ePrivacy Directive (as implemented in national law, such as the UK's PECR) continues to govern cookie consent, read together with the GDPR/UK GDPR. Practitioners should treat any specific substantive provisions of the withdrawn proposal as non-binding and monitor whether the Commission introduces a replacement instrument.

Why it matters

The ePrivacy Regulation matters primarily as an illustration of a long-anticipated reform that ultimately did not materialize. For nearly a decade, privacy professionals and industry groups treated the proposal as the likely successor to the ePrivacy Directive, expecting it to modernize and harmonize the rules governing cookies and similar tracking technologies across the EU. Compliance strategies, vendor roadmaps, and consent management approaches were frequently discussed with an eye toward the anticipated regulation. Because it was drafted as a regulation rather than a directive, it would have been directly applicable across Member States without national transposition, potentially reducing the fragmentation that arises from divergent national implementations of the current Directive.

The practical significance today is the opposite of what was long expected: the proposal was never adopted, and the European Commission withdrew it. This means there is currently no ePrivacy Regulation in force and no active draft in the EU legislative process. Practitioners who built expectations around specific provisions of the 2017 proposal should treat those provisions as non-binding, since they never became law. The rules governing cookie consent in the EU therefore continue to rest on the existing ePrivacy Directive, as implemented in national law (such as the UK's PECR), read together with the GDPR or UK GDPR.

The withdrawal leaves the regulatory landscape substantially unchanged from the status quo that preceded the proposal, which carries its own implications. The harmonization and modernization the proposal sought to deliver did not occur, so differences in national implementations of the Directive persist. Organizations should monitor whether the Commission introduces any replacement instrument, but should not plan compliance around the withdrawn text.

Who it's relevant to

Privacy officers and data protection professionals
Those tracking the EU regulatory horizon should understand that the ePrivacy Regulation is no longer a live file and that the withdrawn proposal's provisions are non-binding. Compliance planning for cookies and electronic communications should continue to be based on the ePrivacy Directive as implemented nationally, read together with the GDPR, rather than on the anticipated regulation.
Legal counsel and compliance teams
Counsel advising on cookie consent and electronic communications privacy should avoid citing substantive provisions of the withdrawn 2017 proposal as if they were forthcoming law. Advice should rest on the currently applicable framework, while monitoring whether the Commission proposes any replacement instrument in the future.
Web developers and technical implementers
Because the rules governing access to and storage of information on a user's device continue to derive from the existing Directive rather than the withdrawn proposal, technical approaches to cookies, pixels, SDKs, and local storage should be built against the current legal framework and its national implementations, not against anticipated regulation text.
Marketing and advertising compliance teams
Teams relying on tracking technologies for advertising and analytics should recognize that the harmonized, modernized rules the proposal promised did not take effect. National differences in how the Directive is implemented persist, so cross-border campaigns may still face divergent consent requirements across EU Member States.

Inside ePrivacy Regulation

Proposed successor to the ePrivacy Directive
The ePrivacy Regulation was conceived as an EU instrument intended to replace the existing ePrivacy Directive (2002/58/EC, as amended) and to modernise the rules governing electronic communications and the confidentiality of terminal equipment. As a regulation rather than a directive, it would have applied directly across EU Member States without requiring national transposition, aiming to reduce the fragmentation that currently exists between national implementations of the Directive.
Withdrawn 2017 proposal
The most recent legislative draft originated from a European Commission proposal published in January 2017 (procedure 2017/0003(COD)). After prolonged negotiation without agreement among the EU institutions, the Commission formally withdrew that proposal on 6 October 2025. As a result, there is currently no ePrivacy Regulation draft in the EU legislative process, and the ePrivacy Directive and its national implementations remain the operative ePrivacy framework.
Intended relationship with the GDPR
The ePrivacy Regulation was designed to sit alongside the GDPR as lex specialis for electronic communications and for the placing of and access to information on a user's device, while the GDPR would continue to govern the broader processing of personal data. The two regimes were intended to be complementary rather than interchangeable, meaning compliance with one would not automatically satisfy the other.
Scope covering cookies and similar technologies
The proposal addressed not only cookies but also equivalent tracking technologies such as pixels, local storage, software development kits (SDKs), and device fingerprinting, reflecting the principle that these fall within the same consent framework as cookies even though they are not literally cookies. The precise treatment of exemptions and consent requirements evolved across successive negotiating texts and was never finalised.
Consent and confidentiality principles
Consistent with the ePrivacy Directive, the draft retained the general principle that prior consent is required for the placing of and access to information on a user's terminal equipment, subject to exemptions for strictly necessary purposes. Because the instrument was never adopted, the exact contours of these consent rules and their exemptions remained subject to negotiation and never took legal effect.

Common questions

Answers to the questions practitioners most commonly ask about ePrivacy Regulation.

Is the ePrivacy Regulation currently in force and replacing the ePrivacy Directive?
No. There is no ePrivacy Regulation in force. The instrument currently governing the placing of and access to information on users' devices in the EU remains the ePrivacy Directive, as transposed into national law by each member state. The proposal for an ePrivacy Regulation did not complete the EU legislative process, and you should not plan compliance on the assumption that a Regulation has replaced or will imminently replace the Directive. Always verify the current status of any ePrivacy instrument against up-to-date official sources before relying on it.
Does the ePrivacy Regulation, once adopted, mean the GDPR no longer applies to cookies?
No, and this reflects a common misunderstanding of how the two regimes interact. Even where a dedicated ePrivacy instrument governs the placing of and access to information on a device, the GDPR continues to govern any processing of personal data that follows from that access. The two regimes are complementary rather than mutually exclusive: an ePrivacy rule addresses whether you may store or read information on a user's device, while the GDPR addresses how any resulting personal data may be processed. Satisfying one does not automatically satisfy the other.
Which legal instrument should we base our cookie consent implementation on right now?
In most EU jurisdictions, your cookie and similar-technology practices should currently be built around the ePrivacy Directive as implemented in the relevant national law, read together with the GDPR for any processing of personal data. Because national transpositions differ and data protection authority guidance evolves, you should confirm the specific requirements and any guidance in each jurisdiction where you operate rather than assuming a single harmonised EU standard applies.
How should we monitor for changes if a new ePrivacy instrument is proposed in the future?
Track the status through official EU sources such as EUR-Lex and the Official Journal, and follow guidance from the relevant data protection authorities, rather than relying on secondary summaries that may lag behind the legislative process. Because the scope, consent standards, and treatment of technologies such as pixels, local storage, SDKs, and fingerprinting could differ from the current Directive-based framework, treat any future instrument as a distinct compliance exercise once its final text and applicability date are confirmed. Avoid building implementations around draft provisions that may change or may not be adopted.
Do the technical tools we already use, such as a CMP, need to change based on ePrivacy developments?
Consent management platforms, consent logging, and signal-handling mechanisms such as Global Privacy Control support compliance with current obligations but do not by themselves guarantee it, and their configuration reflects the legal standards in force. Since the operative framework in the EU currently rests on the ePrivacy Directive and the GDPR, you should configure and document your tools against those requirements today. Reassess your tooling only when and if a new instrument is confirmed and its requirements are known, and continue to apply legal judgment rather than relying on any tool as a substitute.
Should our consent approach differ between the EU, the UK, and US states while there is no ePrivacy Regulation?
Yes. Cookie consent obligations vary by jurisdiction regardless of the status of any ePrivacy instrument. In most EU jurisdictions and in the UK, non-essential cookies generally require prior consent meeting the standard of freely given, specific, informed, and unambiguous through a clear affirmative action, while several US state privacy frameworks such as the CCPA and CPRA in California often rely on an opt-out model. You should map obligations separately for each region where you operate and confirm the current national rules and authority guidance, as these differ and continue to evolve.

Common misconceptions

The ePrivacy Regulation is currently in force or about to become law across the EU.
No ePrivacy Regulation has been adopted. The 2017 proposal (procedure 2017/0003(COD)) was formally withdrawn by the European Commission on 6 October 2025, so there is no draft presently moving through the EU legislative process. The ePrivacy Directive and its national implementations remain the applicable ePrivacy framework.
The ePrivacy Regulation would replace the GDPR for cookies and tracking.
The proposal was designed to complement, not replace, the GDPR. It was intended to govern the confidentiality of communications and access to terminal equipment as a specialised regime, while the GDPR would continue to govern the processing of personal data. Compliance with one would not have automatically satisfied the other.
Because the Regulation was never adopted, there are currently no EU rules on cookies.
The ePrivacy Directive (2002/58/EC, as amended) and the national laws implementing it continue to apply, together with the GDPR where personal data is processed. Practitioners must comply with the existing framework rather than assuming a legal gap.

Best practices

Base current compliance decisions on the ePrivacy Directive as implemented in the relevant Member State's national law, together with the GDPR, rather than on the withdrawn Regulation proposal.
Treat cookies and similar technologies such as pixels, local storage, SDKs, and fingerprinting as subject to the same consent principles, and assess each for whether it qualifies as strictly necessary or requires prior consent under applicable national law.
Do not rely on any expected harmonisation from the ePrivacy Regulation, and be aware that national implementations of the existing Directive continue to differ across the EU, so verify requirements for each jurisdiction in which you operate.
Distinguish the ePrivacy layer (placing and accessing information on a device) from the GDPR layer (processing personal data) in your consent design and documentation, since satisfying one does not automatically satisfy the other.
Monitor official EU sources such as EUR-Lex and data protection authority guidance for any future legislative developments, since the withdrawal of the 2017 proposal does not preclude a new instrument being proposed later.
Seek qualified legal advice for jurisdiction-specific questions, as tools and templates support compliance but do not replace legal judgment about how the current framework applies to your specific processing.