Ch 3.6.4 - ePrivacy Regulation

Reform of the ePrivacy Directive - ePrivacy Regulation

The Commission proposed an ePrivacy Regulation on 10 January 2017 to replace the ePrivacy Directive. The draft included wider electronic-communications coverage, revised terminal-equipment rules and GDPR-style fine tiers. The Commission withdrew the proposal on 6 October 2025. Those draft provisions did not become law, and the ePrivacy Directive remains in force.

After a 2015 study and a 2016 consultation, the Commission released the draft ePrivacy Regulation on 10 January 2017. Being a regulation, it would be directly applicable and provide a single set of rules. Parliament's LIBE committee tabled over 800 amendments; the Council settled its position in February 2021.

  • Wider application: all electronic communications providers - messaging, email, voice, not just telecoms
  • Confidentiality: no listening, tapping, intercepting, scanning or storing without consent, save narrow public-interest exceptions
  • Consent for content and metadata: must be anonymised or deleted without consent, unless needed e.g. for billing
  • Revised cookie rules: no consent for non-intrusive cookies (shopping cart, login, visitor counting); fewer consent pop-ups
  • Anti-spam: ban on unsolicited communications without consent, with a soft opt-in for similar products; marketing callers must show their number or a prefix
  • Enforcement by national DPAs
Proposed ePrivacy Regulation fines (two-tier)
Breach typeMaximum fine
Notice/consent, default settings, public directories, unsolicited communications€10 million or 2% of worldwide annual turnover
Confidentiality of communications, permitted processing, time limits for erasure€20 million or 4% of worldwide annual turnover
Status

The planned regulation did not complete the legislative process. The Commission withdrew the proposal on 6 October 2025. Treat the details on this page as legislative history, not current duties.

Key terms - quick answers

What is “ePrivacy Regulation”?
Proposed directly applicable regulation to replace the ePrivacy Directive and align with the GDPR.
What is “Metadata”?
Data about a communication (time, location, duration, sites visited) that must be anonymised or deleted without consent.
What is “OTT services”?
Over-the-top services such as messaging, email and voice apps, brought into scope alongside traditional telecoms.

Sources and study method

This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.