Ch 16.2 - ePrivacy Regulation
The ePrivacy Regulation (proposal)
The Commission's 2017 ePrivacy Regulation proposal would have replaced the ePrivacy Directive and national implementing laws. A Council position described possible rules on territorial scope, consent, marketing and terminal-equipment access. The Commission withdrew the proposal on 6 October 2025. These details are legislative history and are not current legal duties.
| Area | Proposed change |
|---|---|
| Territorial scope | Tied to processing data of users located in the EU (not the sender/collector); 'processing' includes non-personal data |
| Consent | Aligned with the GDPR and extended to legal persons; may be expressed via software technical settings (Art 4(2)) |
| Marketing | Default explicit consent, with a soft opt-in for messages tied to a purchase of the sender's own similar products/services + free, easy chance to object |
| Cookies/tracking | Content and metadata both in scope; use only on consent or in defined cases (e.g. billing, fraud prevention); door open to pseudonymised statistical data |
| Further use | Permits further compatible use subject to a positive compatibility assessment |
Key terms - quick answers
What is “ePrivacy Regulation”?
Proposed Regulation to replace the ePrivacy Directive with uniform, directly-effective EU rules on unsolicited communications, cookies and analytics. Still being negotiated.
What is “Trilogue”?
Negotiation between the EU Council, Parliament and Commission - the procedure also used to enact the GDPR.
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.