ePrivacy Regulation
Definition
ePrivacy Regulation
The ePrivacy Regulation was a proposed European Union law to replace the 2002 ePrivacy Directive and sit beside the General Data Protection Regulation. The proposal was withdrawn, so the older directive and its national implementations still govern the field.
The proposal appeared in January 2017 and was meant to arrive with the GDPR in 2018.
It did not — member states could not agree, technology moved, and the file sat unresolved for the better part of a decade.
The Commission eventually closed it — a rare outcome for a flagship digital proposal, and one that leaves a twenty-year-old directive doing the work.
Key takeaways
- The ePrivacy Regulation was a proposal that never became law.
- The Commission withdrew it, with the withdrawal announced in the Official Journal in October 2025.
- Directive 2002/58/EC and its national transpositions remain in force.
- Consent for cookies and similar technologies still comes from the directive, not a regulation.
How it works
The rules in force are directive based, which means they reach you through national law rather than uniformly. That fragmentation was the main argument for a regulation, and it survives the proposal’s failure.
The cookie rule sits in Article 5(3).
Storing information or gaining access to information stored in a subscriber’s terminal equipment is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information and offered the right to refuse.
Security is handled in Article 4. A provider of a publicly available electronic communications service must take appropriate technical and organisational measures to safeguard the security of its services.
Those two articles do different jobs. One controls access to a device and the other controls the security of a service, so a contract addressing only one of them leaves a gap.
| Topic | Governing instrument today |
|---|---|
| Cookies and terminal equipment access | Directive 2002/58/EC as transposed nationally |
| Communications confidentiality | The same directive, plus national implementations |
| Personal data generally | The General Data Protection Regulation |
| Direct marketing by electronic mail | National transpositions, which differ materially |
| The proposed harmonised regime | Withdrawn, with no replacement proposal |
The withdrawal itself is documented. The Commission approved it at its meeting on 16 July 2025, and the announcement appeared in the Official Journal on 6 October 2025.
The stated reason was blunt — agreement was not foreseeable, and the proposal had become outdated against later legislation.
Examples
For outsourcing buyers the consequence is mostly about what your contracts and policies cite. Each case here turned on wording that looked harmless until it was tested.
A Dublin marketing agency built its consent platform around draft regulation language. The platform works, but the compliance memo behind it references an instrument that no longer exists.
A contact centre provider offering outbound campaigns across Europe discovers the rules differ by country. Direct marketing consent is transposed nationally, so one pan-European script is not compliant everywhere.
A software vendor’s cookie banner claims regulation compliance in its trust centre. The claim is meaningless, and a buyer’s diligence team will treat it as a signal about everything else in the document.
A telecommunications operator outsources network monitoring. Confidentiality of communications obligations apply to the operator, and the monitoring contract has to reflect that rather than assume the GDPR covers it.
Related terms
European privacy instruments are easy to confuse, particularly when one of them was never adopted. Each term below is close enough to be mistaken for this one in conversation.
- General Data Protection Regulation (GDPR): the regulation that did pass and still governs personal data.
- GDPR outsourcing: the processor contract rules that apply to your providers.
- TCPA compliance: the United States telephone consumer rules covering similar marketing ground.
- CCPA outsourcing: the Californian regime with its own tracking provisions.
- ISO 27701: the privacy certification providers offer during diligence.
- Business process outsourcing (BPO): the delivery model behind most outbound campaigns.
- Compliance outsourcing: contracting the compliance function rather than the campaign.
FAQ
Is the ePrivacy Regulation in force?
No. It was a proposal, it was never adopted, and the Commission withdrew it with the announcement published in October 2025.
What governs cookies now?
Directive 2002/58/EC as implemented in each member state, read alongside the GDPR’s consent standard. National rules differ in detail.
Does the withdrawal loosen the rules?
No. It leaves the existing directive in place, which means fragmentation continues rather than obligations disappearing.
Why did the proposal fail?
Co-legislators could not reach agreement over several years, and the Commission concluded the text had become outdated against newer legislation.
Will there be a replacement?
None has been proposed. Aspects of the subject matter are being handled through other digital files instead.
What should our contracts cite?
The directive as transposed in the relevant member state, plus the GDPR.
Begin at Outsource Accelerator and work outward from the providers who publish their controls.







Independent




