Terminal Equipment Access
Terminal equipment access refers to the placing of information on, or the reading of information from, a user's device, such as a computer, phone, or other connected device, through technologies like cookies. In the EU, laws generally require that a user consent before this kind of access happens, unless the access is strictly necessary to provide a service the user has requested. This concept is central to cookie rules because it focuses on the act of accessing the device itself, not only on any personal data that may result.
In the context of EU cookie and tracking regulation, 'terminal equipment' denotes a user's device connected directly or indirectly to a telecommunications network, for example computers, phones, printers, and similar endpoint devices (see EUR-Lex and general telecommunications definitions of terminal equipment). Under the ePrivacy Directive as implemented in national law, the storing of information, or gaining of access to information already stored, in a user's terminal equipment is generally permitted only with the user's prior, informed consent, subject to a narrow exemption for storage or access that is strictly necessary to provide a service explicitly requested by the user. This obligation attaches to the act of access to the device itself and applies regardless of whether the information involved is personal data; it is technology-neutral and can therefore extend to cookies, pixels, local storage, SDKs, and comparable techniques. Any personal data processing that follows the access is separately governed by the GDPR, so satisfying the ePrivacy consent requirement does not by itself discharge GDPR obligations. Scope note: the evidence provided defines terminal equipment in general telecommunications and technical terms and does not itself detail the ePrivacy consent standard; the precise legal thresholds, exemptions, and enforcement positions vary by jurisdiction (EU member states, the UK, and non-EU regimes) and continue to be shaped by regulatory guidance, so this entry describes the concept rather than a definitive rule for any single country.
Why it matters
Terminal equipment access matters because it defines the trigger point for many EU cookie obligations. Rather than turning solely on whether personal data is processed, the concept focuses on the act of storing information on, or reading information from, a user's device. This means that consent requirements can apply even where no obviously personal data is involved, which is a frequent point of confusion for teams who assume that anonymized or non-identifying data falls outside the rules. Understanding that the obligation attaches to device access itself is often the difference between a compliant and a non-compliant approach in EU jurisdictions.
Because the concept is technology-neutral, it extends beyond cookies to pixels, local storage, software development kits (SDKs), and comparable techniques. Organizations that carefully control their cookie use but overlook these adjacent technologies may still find themselves outside the scope of the relevant consent standard. Treating terminal equipment access as the organizing principle, rather than the word 'cookie,' helps compliance teams identify all the mechanisms that may require attention.
It is important to note that the precise legal thresholds, exemptions, and enforcement positions vary by jurisdiction across EU member states, the UK, and non-EU regimes, and continue to be shaped by regulatory guidance. This entry describes the concept generally rather than stating a definitive rule for any single country, and organizations should confirm the specific requirements applicable to their operations.
Who it's relevant to
Inside Terminal Equipment Access
Common questions
Answers to the questions practitioners most commonly ask about Terminal Equipment Access.