Ch 16.2 - ePrivacy Regulation

The ePrivacy Regulation (proposal)

The Commission's 2017 ePrivacy Regulation proposal would have replaced the ePrivacy Directive and national implementing laws. A Council position described possible rules on territorial scope, consent, marketing and terminal-equipment access. The Commission withdrew the proposal on 6 October 2025. These details are legislative history and are not current legal duties.

Proposed ePrivacy Regulation changes (Feb 2022 position)
AreaProposed change
Territorial scopeTied to processing data of users located in the EU (not the sender/collector); 'processing' includes non-personal data
ConsentAligned with the GDPR and extended to legal persons; may be expressed via software technical settings (Art 4(2))
MarketingDefault explicit consent, with a soft opt-in for messages tied to a purchase of the sender's own similar products/services + free, easy chance to object
Cookies/trackingContent and metadata both in scope; use only on consent or in defined cases (e.g. billing, fraud prevention); door open to pseudonymised statistical data
Further usePermits further compatible use subject to a positive compatibility assessment

Key terms - quick answers

What is “ePrivacy Regulation”?
Proposed Regulation to replace the ePrivacy Directive with uniform, directly-effective EU rules on unsolicited communications, cookies and analytics. Still being negotiated.
What is “Trilogue”?
Negotiation between the EU Council, Parliament and Commission - the procedure also used to enact the GDPR.

Sources and study method

This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.