{"id":445,"date":"2024-02-15T00:00:00","date_gmt":"2024-02-14T23:00:00","guid":{"rendered":"https:\/\/stage.usercentrics.com\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/"},"modified":"2025-04-04T10:57:14","modified_gmt":"2025-04-04T08:57:14","slug":"eprivacy-everything-you-need-to-know-about-it","status":"publish","type":"knowledge","link":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/","title":{"rendered":"The ePrivacy Directive, ePrivacy Regulation and GDPR: what do they mean for your business?"},"content":{"rendered":"<p>The European Union (EU) has some of the world\u2019s most stringent data privacy laws, the <a href=\"https:\/\/usercentrics-pipeline.psapp.dev\/knowledge-hub\/the-eu-general-data-protection-regulation\/\">General Data Protection Regulation (GDPR)<\/a> and ePrivacy Directive, which are already in effect. But the proposed ePrivacy Regulation is set to bring some changes to data protection and cookie consent, and it will broaden the scope of organizations that will be impacted.<\/p>\n<p>Let\u2019s take a look at ePrivacy requirements and what the changes mean for data protection.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-1-what-is-eprivacy\">1. What is ePrivacy?<\/h2>\n\n\n<p>ePrivacy encompasses both the <a href=\"https:\/\/www.edps.europa.eu\/data-protection\/our-work\/subjects\/eprivacy-directive_en\" target=\"_blank\" rel=\"noopener\">ePrivacy Directive<\/a> (Directive 2002\/58\/EC) and the proposed <a href=\"https:\/\/usercentrics-pipeline.psapp.dev\/knowledge-hub\/the-new-eprivacy-regulation\/\">ePrivacy Regulation<\/a>, which aim to ensure privacy and protection in electronic communications within the EU. It is designed to complement the GDPR.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-2-what-is-the-eprivacy-directive\">2. What is the ePrivacy Directive?<\/h2>\n\n\n<p>The EU ePrivacy Directive (known as the &#8220;cookie law&#8221;) was enacted in 2002 and updated in 2009. It specifically addresses privacy issues in electronic communication. It mandates the confidentiality of communication over public networks, requires user consent for cookies, sets guidelines for the security of electronic communication services, and regulates direct marketing practices. Cookie consent banners became more prominent after the ePrivacy Directive\u2019s enactment, as they are a practical way to collect explicit consent from users.<\/p>\n<p>This directive requires incorporation into national laws of EU member states, leading to variations in enforcement across the Union.<\/p>\n<p>In November 2023, the European Data Protection Board (EDPB) issued new guidelines that widened the scope of technologies covered under the directive.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-3-what-are-the-proposed-changes-to-the-eprivacy-directive\">3. What are the proposed changes to the ePrivacy Directive?<\/h2>\n\n\n\n<p>Article 5(3) of the ePrivacy Directive provides that before a company or website can store information on or get information from a user\u2019s device (like a computer or smartphone), they must obtain prior consent from the user.<\/p>\n\n\n\n<p>Under the <a href=\"https:\/\/edpb.europa.eu\/our-work-tools\/documents\/public-consultations\/2023\/guidelines-22023-technical-scope-art-53-eprivacy_en\" target=\"_blank\" rel=\"noopener\">Guidelines 2\/2023<\/a> on the Technical Scope of Article 5(3) of ePrivacy Directive, the EDPB expands the directive&#8217;s application for storing or accessing information on a user&#8217;s device. The EDPB adopts a wide reading of what constitutes terminal equipment and the nature of information, suggesting that many digital tracking methods will require prior opt-in consent unless they are necessary for delivering a requested service.<\/p>\n\n\n\n<p>The guidelines specifically address the use of several modern tracking technologies, which have become prevalent in digital marketing and online tracking.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">URL and pixel tracking<\/h4>\n\n\n\n<p>Tracking pixels are tiny images embedded in websites or emails, linking to a server. When an email containing a tracking pixel is opened or a webpage with a tracking pixel is visited, it allows the server to record the action and capture details such as the time the email was opened, the IP address of the recipient, and the type of device used. URL tracking links to websites help identify where visitors come from.<\/p>\n\n\n<div class=\"uc-notice\">\n    <div class=\"uc-notice__icon\">\n        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M10.8177 17.0093H12.8177V11.0093H10.8177V17.0093ZM11.8177 9.00928C12.1011 9.00928 12.3386 8.91344 12.5302 8.72178C12.7219 8.53011 12.8177 8.29261 12.8177 8.00928C12.8177 7.72594 12.7219 7.48844 12.5302 7.29678C12.3386 7.10511 12.1011 7.00928 11.8177 7.00928C11.5344 7.00928 11.2969 7.10511 11.1052 7.29678C10.9136 7.48844 10.8177 7.72594 10.8177 8.00928C10.8177 8.29261 10.9136 8.53011 11.1052 8.72178C11.2969 8.91344 11.5344 9.00928 11.8177 9.00928ZM11.8177 22.0093C10.4344 22.0093 9.13442 21.7468 7.91775 21.2218C6.70108 20.6968 5.64275 19.9843 4.74275 19.0843C3.84275 18.1843 3.13025 17.1259 2.60525 15.9093C2.08025 14.6926 1.81775 13.3926 1.81775 12.0093C1.81775 10.6259 2.08025 9.32594 2.60525 8.10928C3.13025 6.89261 3.84275 5.83428 4.74275 4.93428C5.64275 4.03428 6.70108 3.32178 7.91775 2.79678C9.13442 2.27178 10.4344 2.00928 11.8177 2.00928C13.2011 2.00928 14.5011 2.27178 15.7177 2.79678C16.9344 3.32178 17.9928 4.03428 18.8927 4.93428C19.7927 5.83428 20.5052 6.89261 21.0302 8.10928C21.5552 9.32594 21.8177 10.6259 21.8177 12.0093C21.8177 13.3926 21.5552 14.6926 21.0302 15.9093C20.5052 17.1259 19.7927 18.1843 18.8927 19.0843C17.9928 19.9843 16.9344 20.6968 15.7177 21.2218C14.5011 21.7468 13.2011 22.0093 11.8177 22.0093Z\" fill=\"black\"\/>\n<\/svg>\n    <\/div>\n    <div class=\"uc-notice__content\">\n                <p>Read about <a href=\"https:\/\/usercentrics-pipeline.psapp.dev\/guides\/social-media-email-marketing-compliance\/email-marketing-privacy-policy\/\">email marketing privacy policy<\/a> now.<\/p>\n            <\/div>\n<\/div>\n\n\n\n\n\n<h4 class=\"wp-block-heading\">Local processing<\/h4>\n\n\n\n<p>Sometimes, websites use APIs to access information stored on a user\u2019s device, such as location data. If processed information is made available over the network, it is considered gaining access to stored information under these guidelines.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Tracking based on IP only<\/h4>\n\n\n\n<p>Some technologies rely only on the collection of the IP address for the tracking of users. If the IP Address originates from the terminal equipment of the user, Article 5(3) of the ePrivacy Directive would apply.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Internet of Things (IoT) reporting<\/h4>\n\n\n\n<p>Under the guidelines, you will require user consent for data collection and processing by devices connected directly or indirectly to the internet. This applies to smart devices like fridges or fitness trackers, whether they send data directly or through another device like a smartphone.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Unique Identifier<\/h4>\n\n\n\n<p>Unique Identifiers are special codes that are attached to a user\u2019s online data to signify that it belongs to the user. It often comes from persistent personal data, or personal information that doesn&#8217;t change much over time, such as email addresses, usernames or account IDs, or date of birth. They&#8217;re used to recognize users across different websites or apps. When a website tells a user\u2019s browser to send this data, it&#8217;s accessing information on the device and invokes Article 5(3).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-4-do-all-cookies-require-consent-under-the-eprivacy-directive\">4. Do all cookies require consent under the ePrivacy Directive?<\/h2>\n\n\n<p>No, under the ePrivacy Directive, cookies that are &#8220;strictly necessary&#8221; for the delivery of a service explicitly requested by the user do not require consent. These cookies are essential for the basic functioning of the website or to provide the service the user has directly requested. Examples include:<\/p>\n<ul>\n<li>cookies that are used to maintain the state of a user&#8217;s activities on a website during a browsing session, such as maintaining logged-in status<\/li>\n<li>cookies used to support security features and to help identify and prevent security risks<\/li>\n<li>cookies that remember information entered by the user, such as username, language, or region, to provide a more personalized experience<\/li>\n<\/ul>\n<p>While these cookies are exempt from the consent requirement, you are still expected to inform users about the use of such cookies, often through a<a href=\"https:\/\/usercentrics-pipeline.psapp.dev\/knowledge-hub\/what-is-a-privacy-policy-and-why-do-you-need-one\/\"> privacy policy<\/a> or cookie policy.<\/p>\n\n<div id=\"uc-cta_69fda948c74fa\" class=\"uc-cta uc-cta--button uc-cta--primary uc-ctx--blue\">\n    <div class=\"uc-cta__inner container\">\n        <div class=\"uc-cta__content\">\n                                        <div class=\"uc-cta__heading no-default-margin\">Set up your privacy policy and cookie policy in under 30 minutes<\/div>\n                                                                                <\/div>\n                            <div class=\"uc-cta__section\">\n                                        <a id=\"3a1398e5-3950-46da-8f05-5e110600f96c\" class=\"uc-button uc-button-size-m uc-button-contained  no-default-link-decoration\" href=\"https:\/\/usercentrics-pipeline.psapp.dev\/policy-generator\/\" target=\"\"><span>Generate policy<\/span><\/a>                                    <\/div>\n            <\/div>\n<\/div>\n    <script type=\"module\">\n        new Uc_Cta(document.getElementById(\"uc-cta_69fda948c74fa\"));\n    <\/script>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-5-what-is-the-new-eprivacy-regulation\">5. What is the new ePrivacy Regulation?<\/h2>\n\n\n<p>The ePrivacy Regulation is a proposed legal framework by the EU intended to update and replace the existing ePrivacy Directive. The primary focus of the ePrivacy Regulation is to enhance privacy protections in electronic communications, extending beyond traditional telecommunications providers to include new communication services like instant messaging applications, VoIP services, and email. It includes text, images, speech, videos, and metadata.<\/p>\n<p>Unlike directives, which require transposition into national laws, regulations are directly applicable, meaning they enforce uniformity across the EU upon taking effect. The ePrivacy Regulation is designed to align closely with the GDPR, ensuring a coherent and unified approach to data protection and privacy across the EU.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-6-who-does-eprivacy-regulation-apply-to\">6. Who does ePrivacy Regulation apply to?<\/h2>\n\n\n<p>The ePrivacy Regulation aims to extend privacy protections to a wider range of electronic communications beyond traditional telecom operators. It will apply to any business that processes data in connection with any form of online communication service, uses online tracking technologies, or engages in electronic direct marketing, encompassing both natural and legal persons involved in electronic communication.<\/p>\n<p>Examples of who the regulation applies to are:<\/p>\n<ul>\n<li>website owners<\/li>\n<li>owners of apps that have electronic communication as a component<\/li>\n<li>natural or legal persons sending direct marketing communications<\/li>\n<li>telecommunications companies<\/li>\n<li>messaging service providers (WhatsApp, Facebook and Skype)<\/li>\n<li>internet access providers, (ex. a store or caf\u00e9 providing open Wi-Fi access)<\/li>\n<\/ul>\n<p>The regulation will also apply to machine-to-machine communications (Internet of Things).<br \/>\nLike the GDPR, the territorial scope of the regulation extends outside the EU. It will apply to data from end-users located in the EU, even if the data collecting and\/or processing take place outside the EU or by providers outside the EU.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-7-what-actions-does-the-eprivacy-regulation-prohibit\">7. What actions does the ePrivacy Regulation prohibit?<\/h2>\n\n\n<p>The ePrivacy Regulation sets forth several specific prohibitions to protect users&#8217; privacy rights:<\/p>\n<ul>\n<li>any interception, storage, monitoring, scanning, or otherwise surveilling of electronic communications data by anyone other than the end users (unless expressly permitted by the regulation)<\/li>\n<li>use of tracking technologies for non-technical purposes without obtaining explicit consent<\/li>\n<li>gaining access to information stored on a user&#8217;s terminal equipment without their consent<\/li>\n<li>sending unsolicited electronic communications or spam, covering unsolicited emails, text messages, and automated calling systems<\/li>\n<li>processing metadata derived from electronic communications (such as location data, call times, and recipient information) without user consent or another legal basis<\/li>\n<\/ul>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-8-what-will-be-new-with-the-eprivacy-regulation\">8. What will be new with the ePrivacy Regulation?<\/h2>\n\n\n\n<p>The ePrivacy Regulation isn\u2019t implemented yet and is subject to change before it is passed as a binding regulation. Key areas of focus in the proposed ePrivacy Regulation include:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-electronic-communications\">Electronic communications<\/h4>\n\n\n\n<p>It expands the scope of the current directive to encompass modern forms of communication, including messaging services on social media platforms (WhatsApp, Facebook Messenger) and VoIP providers, aiming for a comprehensive coverage of digital communication methods.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-cookie-walls\">Cookie walls<\/h4>\n\n\n\n<p>A cookie wall is a mechanism by which websites refuse access to users unless the user consents to cookies. The proposed ePrivacy Regulation does not prohibit cookie walls outright and allows them under certain conditions. Specifically, a website can ask users to consent to cookies if it also offers a similar option that doesn&#8217;t require cookie consent. The key is providing users with a clear choice, ensuring they have an alternative means to access services without being forced to accept cookies.<\/p>\n\n\n<div id=\"uc-cta_69fda948c9e97\" class=\"uc-cta uc-cta--button uc-cta--size-7 uc-cta--primary uc-ctx--blue\">\n    <div class=\"uc-cta__inner container\">\n        <div class=\"uc-cta__content\">\n                                        <div class=\"uc-cta__heading no-default-margin\">Check if your website meets key privacy standards<\/div>\n                                        <div class=\"uc-cta__description\">\n                    <p>Quickly check if your site meets legal privacy standards and ad platform rules. Help protect your ad campaigns and revenue by scanning your website with our free cookie checker.<\/p>\n                <\/div>\n                                                                    <\/div>\n                            <div class=\"uc-cta__section\">\n                                        <a id=\"6b52a3b3-a2f8-4142-b09b-e9f0a66be623\" class=\"uc-button uc-button-size-m uc-button-contained  no-default-link-decoration\" href=\"\/cookie-checker\/\" target=\"\"><span>Check your website<\/span><\/a>                                    <\/div>\n            <\/div>\n<\/div>\n    <script type=\"module\">\n        new Uc_Cta(document.getElementById(\"uc-cta_69fda948c9e97\"));\n    <\/script>\n\n\n<h4>Confidentiality<\/h4>\n<p>Providers of any electronic communication service, like Gmail, Skype, Facebook Messenger and WhatsApp, will be required to provide higher data safety standards to make sure communications data is kept confidential. They will be required to secure all communications data through the best available techniques.<\/p>\n<h4>Metadata<\/h4>\n<p>The regulation also protects electronic communications metadata. Examples of metadata include:<\/p>\n<ul>\n<li>time and date of the communication<\/li>\n<li>how long the communication lasted<\/li>\n<li>where the sender and receiver of the communication were located at the time of the communication<\/li>\n<li>whether the communication was a voice call, video call, text message, email, etc.<\/li>\n<li>information about the devices used for the communication, including device types and identifiers<\/li>\n<li>details regarding the network used for the communication, such as Wi-Fi or cellular network identifiers and signal strength.<\/li>\n<\/ul>\n<p>Interception of metadata can only happen in accordance with the regulation.<\/p>\n<h4>Directive vs. Regulation<\/h4>\n<p>There is a significant difference between EU directives, like the EU cookie law from 2002, and regulations, like the proposed ePrivacy Regulation. While a directive needs to be implemented by different countries on a national level, a regulation becomes legally binding in the EU countries immediately.<\/p>\n<p>Directives are implemented with slight differences across country borders, while regulations have the exact same content in all EU countries. That the ePrivacy laws will now be a regulation shows the EU\u2019s continuing dedication to thorough data protection across the EU.<\/p>\n<h4>Unsolicited marketing<\/h4>\n<p>Marketers will not be able to send emails, text or any other form of communication without prior permission from users, which will lead to a reduction in spam.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-9-how-does-the-eprivacy-regulation-compare-to-the-gdpr\">9. How does the ePrivacy Regulation compare to the GDPR?<\/h2>\n\n\n<p>The GDPR and ePrivacy Regulation share several similarities:<\/p>\n<ul>\n<li>They share the same high fines for non-compliance<\/li>\n<li>Both aim to align data privacy laws across the EU<\/li>\n<li>Both apply to the processing of data of individuals residing in EU territory, whether or not the processors themselves are located within the EU<\/li>\n<li>Both are EU regulations<\/li>\n<\/ul>\n<p>There are, however, some major differences between the two regulations, which are outlined in the table below.<\/p>\n<table>\n<tbody>\n<tr>\n<th><\/th>\n<th>GDPR<\/th>\n<th>ePrivacy Regulation<\/th>\n<\/tr>\n<tr>\n<td><em>Scope<\/em><\/td>\n<td>Applies to the processing of EU residents\u2019 personal data, irrespective of the technology used.<\/td>\n<td>Focused on the processing of personal data and metadata in electronic communications.<\/td>\n<\/tr>\n<tr>\n<td><em>Definition<\/em><\/td>\n<td>\u201cPersonal data\u201d means any data that can be used to identify someone.<\/td>\n<td>\u201cElectronic communications\u201d means any data that is communicated electronically, whether or not it can be used to identify someone.<\/td>\n<\/tr>\n<tr>\n<td><em>Reach<\/em><\/td>\n<td>Since \u201cpersonal data\u201d is not as wide of a definition as \u201celectronic communications\u201d, the GDPR has a smaller reach than the ePrivacy Regulation.<\/td>\n<td>\u201cElectronic communications\u201d is a wider definition than \u201cpersonal data\u201d and therefore makes the ePrivacy Regulation far-reaching.<\/td>\n<\/tr>\n<tr>\n<td><em>Purpose<\/em><\/td>\n<td>To protect the personal data of individuals within the EU, providing them with greater control over their personal information and ensuring that their data is processed securely and transparently by organizations.<\/td>\n<td>To ensure privacy and confidentiality in electronic communications across the EU, specifically regulating tracking technologies, electronic marketing, and the security of users&#8217; communications data.<\/td>\n<\/tr>\n<tr>\n<td><em>Type of data<\/em><\/td>\n<td>Covers any personal data, whether it is electronic or in hard copy format.<\/td>\n<td>Covers only \u201celectronic\u201d communications data, not hard copy data.<\/td>\n<\/tr>\n<tr>\n<td><em>Lex Specialis<\/em><\/td>\n<td>GDPR is the less specific law when it comes to electronic communications. Because of this, the ePrivacy Regulation takes precedence over the GDPR in electronic communications cases.<\/td>\n<td>The ePrivacy Regulation is lex specialis \u2014 the more specific law compared to the GDPR \u2014 when it comes to electronic communications. Because of this, it takes precedence over the GDPR in electronic communications cases.<\/td>\n<\/tr>\n<tr>\n<td><em>Who is given responsibilities<\/em><\/td>\n<td>Anyone who is the controller or processor of personal data. Data controllers are those who decide why and how personal data should be processed. Data processors are the ones doing the actual data processing for the controller. As an example, if a restaurant has a payroll company pay the restaurant employees, then the restaurant is the data controller and the payroll company is the processor of the employees&#8217; personal data.<\/td>\n<td>Anyone processing content of electronic communications, including website owners, owners of communication apps, anyone engaging in direct marketing, telecommunications companies, messaging service providers (WhatsApp, Facebook, Skype), internet access providers.<\/td>\n<\/tr>\n<tr>\n<td><em>Who is given rights and protections<\/em><\/td>\n<td>Provides protection only to natural persons, or people.<\/td>\n<td>Provides protections for both natural and legal persons, that means people as well as organizations, companies and businesses.<\/td>\n<\/tr>\n<tr>\n<td><em>Coming into effect<\/em><\/td>\n<td>Came into effect on 25th May 2018<\/td>\n<td>Still in the approval stage with EU legislators. It was expected to come into effect in 2023 but has been delayed.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-10-when-will-the-eprivacy-regulation-come-into-force\">10. When will the ePrivacy Regulation come into force?<\/h2>\n\n\n<p>The ePrivacy Regulation was initially intended to come into effect alongside the GDPR on May 25, 2018, but it has not yet been adopted. The EU Council published a draft, finalized on February 10, 2021, which is now in negotiations between the Council and European Parliament. If the draft is approved, it will pass into law in all 27 EU member states.<\/p>\n<p>Once the draft is approved, there will be a two-year period before the regulation will be enforced. This gives you time to make the necessary changes and become compliant if your organization is impacted.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-11-why-and-how-should-companies-prepare-for-the-eprivacy-regulation\">11. Why and how should companies prepare for the ePrivacy Regulation?<\/h2>\n\n\n<h4>Fines<\/h4>\n<p><a href=\"https:\/\/usercentrics-pipeline.psapp.dev\/knowledge-hub\/what-is-the-maximum-fine-related-to-gdpr-violations\/\">GDPR penalties<\/a> are substantial, and the same fines will apply to non-compliance with the ePrivacy Regulation: up to \u20ac20 million or 4% of yearly global revenue for the preceding financial year, whichever is higher.<\/p>\n<p>When the ePrivacy Regulation becomes effective it will immediately apply to electronic communications processors across the EU, and companies should make sure to be compliant before that time.<\/p>\n<h4>Preparing for the ePrivacy Regulation<\/h4>\n<p>The ePrivacy Regulation will not replace the GDPR; rather the two regulations are meant to coexist and complement each other. It is not the case that the ePrivacy Regulation will totally change privacy rules so that GDPR-compliant companies have to start over again. The ePrivacy Regulation will only expand EU privacy laws. Even after it becomes effective, companies will be required to comply with both the GDPR and the ePrivacy Regulation or risk being fined.<\/p>\n<p>Furthermore, consent will likely be more heavily relied upon as a legal basis for data processing after the ePrivacy Regulation comes into effect, and the ePrivacy Regulation uses the GDPR definition of consent. Having a GDPR-compliant method of obtaining consent in place already is a great way to prepare for the ePrivacy Regulation.<\/p>\n<p>Usercentrics keeps track of regulatory developments to make sure that our product is up to date with the latest standards. Companies can use our <a href=\"https:\/\/usercentrics-pipeline.psapp.dev\/website-consent-management\/\" target=\"_blank\" rel=\"noopener\">consent management platform (CMP)<\/a> to enable <a href=\"https:\/\/usercentrics-pipeline.psapp.dev\/gdpr\/\" target=\"_blank\" rel=\"noopener\">GDPR compliance<\/a> and ePrivacy compliance and prepare for future data privacy laws such as the ePrivacy Regulation.<\/p>\n<p><strong>Further information:<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/iabeurope.eu\/wp-content\/uploads\/2019\/10\/31.10.2018-IABEU-ePR_Position_Paper.pdf\" target=\"_blank\" rel=\"noopener\">January 2017: Draft text of the ePrivacy Regulation was published<\/a><\/li>\n<li><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CONSIL:ST_11995_2017_INIT&amp;from=EN&amp;mkt_tok=eyJpIjoiWWpBMk1EUTJZV015TlRBeCIsInQiOiJPZHFPUnF4ZngyK1RtNlhoMjhvREl5NTlmc0VlTVNJUlhnRGl2R3lJZURCd3A4UmZHMDVPXC8zQzlqXC94bFQwTFpLZkI2a1NDYlpoVEZRVFNuUH\" target=\"_blank\" rel=\"noopener\">September 2017: European Council published proposed amendments<\/a><\/li>\n<li><a href=\"https:\/\/www.consilium.europa.eu\/en\/press\/press-releases\/2021\/02\/10\/confidentiality-of-electronic-communications-council-agrees-its-position-on-eprivacy-rules\/\" target=\"_blank\" rel=\"noopener\">February 2021: European Council published mandate for negotiations with the European Parliament<\/a><\/li>\n<\/ul>\n<p>Usercentrics GmbH does not provide legal advice. The contents of the above article are not to be understood as legally binding. The article constitutes the opinion of Usercentrics.<\/p>\n\n<div id=\"uc-cta_69fda948ca42a\" class=\"uc-cta uc-cta--button uc-cta--primary uc-ctx--blue\">\n    <div class=\"uc-cta__inner container\">\n        <div class=\"uc-cta__content\">\n                                        <div class=\"uc-cta__heading no-default-margin\">Is your website GDPR- and ePrivacy-compliant?<\/div>\n                                        <div class=\"uc-cta__description\">\n                    <p>Find out with a data privacy audit<\/p>\n                <\/div>\n                                                                    <\/div>\n                            <div class=\"uc-cta__section\">\n                                        <a id=\"81d35ecb-22e7-4888-9da0-511ae34f7868\" class=\"uc-button uc-button-size-m uc-button-contained  no-default-link-decoration\" href=\"https:\/\/usercentrics-pipeline.psapp.dev\/data-privacy-audit\/\" target=\"\"><span>Check compliance<\/span><\/a>                                    <\/div>\n            <\/div>\n<\/div>\n    <script type=\"module\">\n        new Uc_Cta(document.getElementById(\"uc-cta_69fda948ca42a\"));\n    <\/script>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The ePrivacy Directive, ePrivacy Regulation and General Data Protection Regulation (GDPR) all impact data privacy for European Union users and entities doing business with them. But what are they, and how do they affect you? We give you an overview of ePrivacy, cookies and data protection in the EU.<\/p>\n","protected":false},"featured_media":8876,"template":"","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"tags":[],"magazine_issue":[],"magazine_tag":[],"resource_tag":[16,13],"class_list":["post-445","knowledge","type-knowledge","status-publish","has-post-thumbnail","hentry","resource_tag-privacy-policy","resource_tag-regulations"],"acf":[],"yoast_head":"<title>Everything you need to know about ePrivacy<\/title>\n<meta name=\"description\" content=\"Discover how the ePrivacy Directive impacts your business &amp; stay updated on the upcoming ePrivacy Regulation. Get the insights you need for ePrivacy compliance.\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Everything you need to know about ePrivacy\" \/>\n<meta property=\"og:description\" content=\"Discover how the ePrivacy Directive impacts your business &amp; stay updated on the upcoming ePrivacy Regulation. Get the insights you need for ePrivacy compliance.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/\" \/>\n<meta property=\"og:site_name\" content=\"Usercentrics - US\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/usercentrics\" \/>\n<meta property=\"article:modified_time\" content=\"2025-04-04T08:57:14+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/usercentrics-pipeline.psapp.dev\/wp-content\/uploads\/2018\/10\/uc_some_post_1200x630_eprivacy_directive.png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Everything You Need To Know About ePrivacy | Usercentrics\" \/>\n<meta name=\"twitter:description\" content=\"What exactly is ePrivacy and how does it affect your business? In this article we want to give you an overview over the new EU regulation.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/usercentrics-pipeline.psapp.dev\/wp-content\/uploads\/2020\/01\/Consent-under-GDPR-and-ePrivacy-header-scaled.jpg\" \/>\n<meta name=\"twitter:site\" content=\"@usercentrics\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/\",\"url\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/\",\"name\":\"Everything you need to know about ePrivacy\",\"isPartOf\":{\"@id\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2024\/03\/Comprehensive-GDPR-compliance-checklist-for-U.S.-companies-1.jpg\",\"datePublished\":\"2024-02-14T23:00:00+00:00\",\"dateModified\":\"2025-04-04T08:57:14+00:00\",\"description\":\"Discover how the ePrivacy Directive impacts your business & stay updated on the upcoming ePrivacy Regulation. Get the insights you need for ePrivacy compliance.\",\"breadcrumb\":{\"@id\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/\"}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/#primaryimage\",\"url\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2024\/03\/Comprehensive-GDPR-compliance-checklist-for-U.S.-companies-1.jpg\",\"contentUrl\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2024\/03\/Comprehensive-GDPR-compliance-checklist-for-U.S.-companies-1.jpg\",\"width\":1000,\"height\":1000,\"copyrightNotice\":\"\u00a9 Copyright 2026 Usercentrics GmbH\",\"creator\":{\"@type\":\"Organization\",\"name\":\"Usercentrics GmbH\"},\"creditText\":\"Image: Usercentrics GmbH\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Resources\",\"item\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/resources\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog\",\"item\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"The ePrivacy Directive, ePrivacy Regulation and GDPR: what do they mean for your business?\",\"item\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/#website\",\"url\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/\",\"name\":\"Usercentrics - US\",\"description\":\"Consent Management Platform (CMP) Usercentrics\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/usercentrics-pipeline.psapp.dev\/us\/?s={search_term_string}\"}}],\"inLanguage\":\"en-US\"}]}<\/script>","yoast_head_json":{"title":"Everything you need to know about ePrivacy","description":"Discover how the ePrivacy Directive impacts your business & stay updated on the upcoming ePrivacy Regulation. Get the insights you need for ePrivacy compliance.","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"Everything you need to know about ePrivacy","og_description":"Discover how the ePrivacy Directive impacts your business & stay updated on the upcoming ePrivacy Regulation. Get the insights you need for ePrivacy compliance.","og_url":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/","og_site_name":"Usercentrics - US","article_publisher":"https:\/\/www.facebook.com\/usercentrics","article_modified_time":"2025-04-04T08:57:14+00:00","og_image":[{"url":"https:\/\/usercentrics-pipeline.psapp.dev\/wp-content\/uploads\/2018\/10\/uc_some_post_1200x630_eprivacy_directive.png","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_title":"Everything You Need To Know About ePrivacy | Usercentrics","twitter_description":"What exactly is ePrivacy and how does it affect your business? In this article we want to give you an overview over the new EU regulation.","twitter_image":"https:\/\/usercentrics-pipeline.psapp.dev\/wp-content\/uploads\/2020\/01\/Consent-under-GDPR-and-ePrivacy-header-scaled.jpg","twitter_site":"@usercentrics","twitter_misc":{"Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/","url":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/","name":"Everything you need to know about ePrivacy","isPartOf":{"@id":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/#website"},"primaryImageOfPage":{"@id":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/#primaryimage"},"image":{"@id":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/#primaryimage"},"thumbnailUrl":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2024\/03\/Comprehensive-GDPR-compliance-checklist-for-U.S.-companies-1.jpg","datePublished":"2024-02-14T23:00:00+00:00","dateModified":"2025-04-04T08:57:14+00:00","description":"Discover how the ePrivacy Directive impacts your business & stay updated on the upcoming ePrivacy Regulation. Get the insights you need for ePrivacy compliance.","breadcrumb":{"@id":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/"}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/#primaryimage","url":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2024\/03\/Comprehensive-GDPR-compliance-checklist-for-U.S.-companies-1.jpg","contentUrl":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2024\/03\/Comprehensive-GDPR-compliance-checklist-for-U.S.-companies-1.jpg","width":1000,"height":1000,"copyrightNotice":"\u00a9 Copyright 2026 Usercentrics GmbH","creator":{"@type":"Organization","name":"Usercentrics GmbH"},"creditText":"Image: Usercentrics GmbH"},{"@type":"BreadcrumbList","@id":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/resources\/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/"},{"@type":"ListItem","position":3,"name":"The ePrivacy Directive, ePrivacy Regulation and GDPR: what do they mean for your business?","item":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/knowledge-hub\/eprivacy-everything-you-need-to-know-about-it\/"}]},{"@type":"WebSite","@id":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/#website","url":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/","name":"Usercentrics - US","description":"Consent Management Platform (CMP) Usercentrics","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/?s={search_term_string}"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-json\/wp\/v2\/knowledge\/445","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-json\/wp\/v2\/knowledge"}],"about":[{"href":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-json\/wp\/v2\/types\/knowledge"}],"version-history":[{"count":0,"href":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-json\/wp\/v2\/knowledge\/445\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-json\/wp\/v2\/media\/8876"}],"wp:attachment":[{"href":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-json\/wp\/v2\/media?parent=445"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-json\/wp\/v2\/tags?post=445"},{"taxonomy":"magazine_issue","embeddable":true,"href":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-json\/wp\/v2\/magazine_issue?post=445"},{"taxonomy":"magazine_tag","embeddable":true,"href":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-json\/wp\/v2\/magazine_tag?post=445"},{"taxonomy":"resource_tag","embeddable":true,"href":"https:\/\/usercentrics-pipeline.psapp.dev\/us\/wp-json\/wp\/v2\/resource_tag?post=445"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}