Skip to main content
Category: Consent Principles

Terminal Equipment Access

Also known as: Access to Terminal Equipment, Storing and Accessing Information on Terminal Equipment
Simply put

Terminal equipment access refers to the placing of information on, or the reading of information from, a user's device, such as a computer, phone, or other connected device, through technologies like cookies. In the EU, laws generally require that a user consent before this kind of access happens, unless the access is strictly necessary to provide a service the user has requested. This concept is central to cookie rules because it focuses on the act of accessing the device itself, not only on any personal data that may result.

Formal definition

In the context of EU cookie and tracking regulation, 'terminal equipment' denotes a user's device connected directly or indirectly to a telecommunications network, for example computers, phones, printers, and similar endpoint devices (see EUR-Lex and general telecommunications definitions of terminal equipment). Under the ePrivacy Directive as implemented in national law, the storing of information, or gaining of access to information already stored, in a user's terminal equipment is generally permitted only with the user's prior, informed consent, subject to a narrow exemption for storage or access that is strictly necessary to provide a service explicitly requested by the user. This obligation attaches to the act of access to the device itself and applies regardless of whether the information involved is personal data; it is technology-neutral and can therefore extend to cookies, pixels, local storage, SDKs, and comparable techniques. Any personal data processing that follows the access is separately governed by the GDPR, so satisfying the ePrivacy consent requirement does not by itself discharge GDPR obligations. Scope note: the evidence provided defines terminal equipment in general telecommunications and technical terms and does not itself detail the ePrivacy consent standard; the precise legal thresholds, exemptions, and enforcement positions vary by jurisdiction (EU member states, the UK, and non-EU regimes) and continue to be shaped by regulatory guidance, so this entry describes the concept rather than a definitive rule for any single country.

Why it matters

Terminal equipment access matters because it defines the trigger point for many EU cookie obligations. Rather than turning solely on whether personal data is processed, the concept focuses on the act of storing information on, or reading information from, a user's device. This means that consent requirements can apply even where no obviously personal data is involved, which is a frequent point of confusion for teams who assume that anonymized or non-identifying data falls outside the rules. Understanding that the obligation attaches to device access itself is often the difference between a compliant and a non-compliant approach in EU jurisdictions.

Because the concept is technology-neutral, it extends beyond cookies to pixels, local storage, software development kits (SDKs), and comparable techniques. Organizations that carefully control their cookie use but overlook these adjacent technologies may still find themselves outside the scope of the relevant consent standard. Treating terminal equipment access as the organizing principle, rather than the word 'cookie,' helps compliance teams identify all the mechanisms that may require attention.

It is important to note that the precise legal thresholds, exemptions, and enforcement positions vary by jurisdiction across EU member states, the UK, and non-EU regimes, and continue to be shaped by regulatory guidance. This entry describes the concept generally rather than stating a definitive rule for any single country, and organizations should confirm the specific requirements applicable to their operations.

Who it's relevant to

Privacy and Data Protection Officers
This concept helps privacy officers map where consent obligations are triggered, since the requirement generally attaches to device access rather than only to personal data processing. It underscores the need to inventory not just cookies but also pixels, local storage, SDKs, and similar technologies that may fall within the same rules in EU jurisdictions.
Legal Counsel and Compliance Teams
Legal teams rely on this distinction to assess when the ePrivacy consent standard applies versus when GDPR obligations arise, recognizing that the two are separate and that meeting one does not automatically satisfy the other. Because thresholds, exemptions, and enforcement positions vary across EU member states, the UK, and other regimes, counsel should confirm the specific rules for each relevant jurisdiction.
Web Developers and Engineers
Developers implementing tracking technologies need to understand that the obligation is technology-neutral and can extend to local storage, SDKs, and pixels, not only traditional cookies. This informs how consent gating is built so that device access does not occur before valid consent is obtained, except where an access is strictly necessary for a service the user has requested.
Marketing Compliance Teams
Marketing teams often deploy advertising and analytics technologies that involve storing or reading information on a user's device. Understanding terminal equipment access clarifies why these deployments may require prior consent in EU jurisdictions, independent of whether the data collected is considered personal data.

Inside Terminal Equipment Access

Storing or accessing information on terminal equipment
The core act governed by the ePrivacy Directive (Article 5(3) and its national implementations): the placing of information on, or the gaining of access to information already stored in, a user's or subscriber's terminal equipment, such as a computer, smartphone, or other connected device. This is the trigger for consent obligations, independent of whether the information involved is personal data.
Technology-neutral scope
The rules apply not only to HTTP cookies but to any technology that stores or reads information on a device, including pixels, local storage, software development kits (SDKs) in mobile apps, and device fingerprinting techniques. The literal presence of a cookie is not required for the obligation to arise.
Consent requirement and its exemptions
In most EU jurisdictions, prior consent is generally required before storing or accessing information on terminal equipment. Two commonly cited exemptions apply: where access is carried out for the sole purpose of transmitting a communication over an electronic communications network, or where it is strictly necessary to provide a service explicitly requested by the user.
Relationship to the GDPR
The ePrivacy Directive governs the storage and access step, while the GDPR governs any subsequent processing of personal data that results. These are separate legal bases and obligations; satisfying one does not automatically satisfy the other. Consent obtained for device access does not, on its own, cover all downstream data processing purposes.
Terminal equipment as protected sphere
The concept treats the user's device as a protected sphere warranting particular protection, so that both the placing of information and the reading of information already present fall within scope, regardless of the sensitivity of the specific data involved.

Common questions

Answers to the questions practitioners most commonly ask about Terminal Equipment Access.

Does obtaining GDPR consent for data processing also cover the storing of or access to information on a user's device?
No, these are governed by separate legal regimes and should not be conflated. The rules on accessing or storing information on a user's terminal equipment derive from the ePrivacy Directive and its national implementations, which require consent (subject to limited exemptions) for the act of placing or reading information on the device itself. The GDPR then governs any processing of personal data that follows. Consent obtained for one does not automatically satisfy the other, and in practice organizations typically need to address both bases. The exact interaction varies by national implementation and evolving guidance from data protection authorities.
Do the rules on terminal equipment access only apply to cookies?
No. Although the rules are often discussed in the context of cookies, they generally apply to any storing of information, or gaining of access to information already stored, on a user's terminal equipment. This can include technologies such as pixels, local storage, software development kits (SDKs), and device fingerprinting, even though these are not literally cookies. Where such techniques store or access information on the device, they typically fall within the same consent framework in most EU jurisdictions. Whether a specific technique is caught can depend on how it operates, so a technical assessment is usually needed.
Which technologies on our website should we assess for terminal equipment access obligations?
As a starting point, organizations generally review any technology that reads from or writes to the user's device. This commonly includes first- and third-party cookies, local and session storage, tracking pixels, embedded SDKs, and identifiers used for fingerprinting. A technical audit or scan can help identify these, but the results should be reviewed against the legal test for storing or accessing information on the device. Because tools may not detect every technique, and classification can be fact-specific, legal and technical judgment is typically required to determine which items trigger consent obligations.
How do we determine whether a given technology is exempt from consent for terminal equipment access?
In most EU jurisdictions, exemptions are narrow and generally cover access or storage that is strictly necessary for a service explicitly requested by the user, or solely for carrying out the transmission of a communication. Cookies or similar technologies used for analytics, advertising, or non-essential functionality typically fall outside these exemptions and require prior consent. The assessment turns on the specific purpose and necessity of each technology rather than its label, so each item should be evaluated individually. National guidance on the scope of these exemptions varies and continues to evolve.
When must consent for terminal equipment access be collected relative to when the technology fires?
Where consent is required, it generally must be obtained before the information is stored on or accessed from the user's device. This typically means non-exempt cookies, pixels, and similar technologies should be blocked from firing until the user has given a clear affirmative action. In most EU jurisdictions, pre-ticked boxes, implied consent from continued browsing, and cookie walls are widely considered non-compliant approaches to obtaining this consent. Implementation usually involves a consent management platform configured to prevent non-essential technologies from executing before valid consent is captured, though a CMP supports rather than guarantees compliance.
What records should we keep to demonstrate valid consent for terminal equipment access?
Organizations subject to EU rules generally maintain records sufficient to demonstrate that valid consent was obtained, which may include information such as what the user was shown, the choices made, and when consent was recorded. Consent management platforms often provide logging features to support this, but the specific record-keeping expectations can depend on national implementations and data protection authority guidance. Requirements also differ under other frameworks, such as certain US state privacy laws that rely on opt-out rather than opt-in, so record-keeping practices should be scoped to the applicable jurisdictions. This entry does not prescribe a fixed retention period or format, which should be determined based on legal advice.

Common misconceptions

The rules only apply to cookies.
The obligation is technology-neutral in most EU jurisdictions. Storing or accessing information via pixels, local storage, mobile SDKs, or fingerprinting techniques falls within the same rules even though these are not literally cookies.
Terminal equipment access rules only bite when personal data is involved.
The ePrivacy trigger concerns the act of storing or accessing information on a device, and applies irrespective of whether that information constitutes personal data. Separately, the GDPR applies where personal data is processed. The two regimes operate in parallel.
If you have a lawful basis under the GDPR, you do not separately need consent to access the device.
In most EU jurisdictions, the storage or access step generally requires consent under the ePrivacy rules unless an exemption applies, and this is distinct from the legal basis needed for any subsequent GDPR processing. Practitioners typically need to address both steps.

Best practices

Map every technology that stores or accesses information on user devices, including cookies, pixels, local storage, SDKs, and any fingerprinting techniques, rather than focusing on cookies alone.
Assess each storage or access operation against the ePrivacy consent requirement first, and separately assess any resulting personal data processing under the GDPR, treating them as distinct compliance steps.
Where you intend to rely on an exemption, document why the operation is either solely for transmitting a communication or strictly necessary for a service the user has explicitly requested, and apply the exemption narrowly.
Do not assume consent for device access covers downstream processing purposes; identify and record a separate GDPR basis for each such purpose.
Confirm the geographic and legal scope of your obligations, since terminal equipment access rules derive from national implementations of the ePrivacy Directive within the EU and may differ in the UK, US states, and other regimes.
Keep configurations and records under review, as regulatory guidance and enforcement positions on device access and non-cookie technologies continue to evolve.