ePrivacy Regulation
The ePrivacy Regulation was a proposed European Union law intended to update and eventually replace the older ePrivacy Directive, setting rules for privacy in electronic communications, including how cookies and similar tracking technologies may be used. It was designed to work alongside the GDPR, applying specifically to the confidentiality of communications and to information stored on or accessed from a user's device. The proposal was never adopted, and the European Commission withdrew it, so as things stand there is no ePrivacy Regulation in force.
The ePrivacy Regulation refers to the European Commission's 2017 legislative proposal (procedure 2017/0003(COD)) concerning the respect for private life and the protection of personal data in electronic communications, intended to repeal and modernize Directive 2002/58/EC (the ePrivacy Directive) and to align it with Regulation (EU) 2016/679 (GDPR). As a proposed regulation rather than a directive, it would have been directly applicable across Member States without national transposition, aiming to harmonize rules on the confidentiality of electronic communications and on the storing of, or gaining access to, information on a user's terminal equipment, the legal basis governing cookies, pixels, SDKs, local storage, and similar technologies, independent of whether personal data is processed. It intended to preserve the GDPR standard of consent for non-exempt technologies while carving out limited exemptions. The proposal underwent prolonged negotiation in the Council and Parliament but was never adopted; the Commission subsequently withdrew it, meaning there is currently no ePrivacy Regulation draft active in the EU legislative process. In the interim, the ePrivacy Directive (as implemented in national law, such as the UK's PECR) continues to govern cookie consent, read together with the GDPR/UK GDPR. Practitioners should treat any specific substantive provisions of the withdrawn proposal as non-binding and monitor whether the Commission introduces a replacement instrument.
Why it matters
The ePrivacy Regulation matters primarily as an illustration of a long-anticipated reform that ultimately did not materialize. For nearly a decade, privacy professionals and industry groups treated the proposal as the likely successor to the ePrivacy Directive, expecting it to modernize and harmonize the rules governing cookies and similar tracking technologies across the EU. Compliance strategies, vendor roadmaps, and consent management approaches were frequently discussed with an eye toward the anticipated regulation. Because it was drafted as a regulation rather than a directive, it would have been directly applicable across Member States without national transposition, potentially reducing the fragmentation that arises from divergent national implementations of the current Directive.
The practical significance today is the opposite of what was long expected: the proposal was never adopted, and the European Commission withdrew it. This means there is currently no ePrivacy Regulation in force and no active draft in the EU legislative process. Practitioners who built expectations around specific provisions of the 2017 proposal should treat those provisions as non-binding, since they never became law. The rules governing cookie consent in the EU therefore continue to rest on the existing ePrivacy Directive, as implemented in national law (such as the UK's PECR), read together with the GDPR or UK GDPR.
The withdrawal leaves the regulatory landscape substantially unchanged from the status quo that preceded the proposal, which carries its own implications. The harmonization and modernization the proposal sought to deliver did not occur, so differences in national implementations of the Directive persist. Organizations should monitor whether the Commission introduces any replacement instrument, but should not plan compliance around the withdrawn text.
Who it's relevant to
Inside ePrivacy Regulation
Common questions
Answers to the questions practitioners most commonly ask about ePrivacy Regulation.