Terminal Equipment Storage
Terminal equipment storage refers to the placing of information onto, or reading of information from, a device that a person uses to connect to a network, such as a computer, smartphone, or tablet. Cookies are the most familiar example, but the concept also covers other technologies that write to or read from a user's device. In the UK, rules on this activity fall under the Privacy and Electronic Communications Regulations (PECR).
In the context of UK ePrivacy law, 'terminal equipment' is the device belonging to a subscriber or user, and PECR applies to any technology that stores information on, or gains access to information stored on, that terminal equipment. This scope is technology-neutral: it captures cookies as well as similar techniques such as pixels, local storage, software development kits (SDKs), and device fingerprinting, so long as they involve storage on or access to the device. The rules generally require prior, informed consent for such storage or access, subject to exemptions (for example, activity strictly necessary to provide a service the user has requested); the concepts of 'terminal equipment' and 'subscriber or user' derive from the underlying ePrivacy framework, and equivalent provisions exist under the EU ePrivacy Directive as implemented in individual Member States. Note that the term 'terminal equipment' also has an unrelated general telecommunications and engineering meaning (for example Data Terminal Equipment); this entry addresses only its use in the storage-and-access context. The consent obligation for placing or accessing information sits under ePrivacy rules, while any subsequent processing of personal data is separately governed by the GDPR (or UK GDPR).
Why it matters
Terminal equipment storage sits at the heart of cookie and tracking compliance because it defines the trigger point for legal obligations. In the UK, PECR applies whenever a technology stores information on, or accesses information stored on, a subscriber's or user's terminal equipment. This means the rules attach to the act of writing to or reading from the device itself, independently of whether personal data is later processed. Understanding this scope helps organisations identify which of their web and app activities fall within ePrivacy consent requirements in the first place.
The concept matters most because it is deliberately technology-neutral. Focusing only on cookies risks overlooking pixels, local storage, SDKs, and device fingerprinting, which can all involve storage on or access to a device and therefore generally attract the same consent obligations. Teams that scope compliance narrowly around the word 'cookie' may leave equivalent tracking techniques unaddressed, creating gaps between what they disclose to users and what actually happens on the device.
A further reason for care is the layered legal analysis. The consent obligation for placing or accessing information sits under ePrivacy rules such as PECR, while any subsequent processing of personal data is separately governed by the UK GDPR (or the GDPR in EU Member States). Treating the two regimes as a single step can lead organisations to assume that satisfying one automatically satisfies the other, which is not the case. Because enforcement positions and regulator guidance in this area continue to evolve, professionals should treat the boundaries of specific exemptions as fact-dependent rather than settled.
Who it's relevant to
Inside Terminal Equipment Storage
Common questions
Answers to the questions practitioners most commonly ask about Terminal Equipment Storage.