The EU ePrivacy Directive (Cookie Law) Explained

Summary
The EU cookie-consent rule comes from the ePrivacy Directive, at Article 5(3): a website must get consent before it stores or reads information on a visitor’s device, unless strictly necessary for a service the visitor asked for, or only to carry a transmission. So analytics and marketing cookies need consent first, while a login or cart cookie does not.
The nickname “cookie law” is slightly misleading. Article 5(3) covers any storing of or access to information on a device. EU regulators (EDPB guidelines, October 2024) read it as covering tracking pixels and URL tracking as well as cookies.
The sections below cover what Article 5(3) requires, how it fits with the GDPR when it comes to cookies, and what is changing under the Digital Omnibus. The last section covers how to comply and verify.
What Article 5(3) requires
Two things. Before a site places or reads anything on a visitor’s device, it needs the visitor’s consent, and that consent has to meet the GDPR’s standard: freely given, specific, informed, and unambiguous. The consent has to come first, before the cookie or tag acts.

There is one exception. Storage or access that is “strictly necessary” for a service the visitor explicitly requested does not need consent. A cookie that keeps a shopping cart or a login session is strictly necessary. An analytics or advertising cookie is not, so it needs consent.
ePrivacy or GDPR: which governs cookies?
Both, in sequence. The ePrivacy Directive decides whether you may place a cookie or fire a tag at all, and it says you need consent first. The GDPR then governs any personal data that tag goes on to process, including what counts as valid consent and what your basis is. When they overlap, the specific rule, ePrivacy, sets the consent-before-access requirement, and the GDPR fills in the standard for that consent.
What is changing: the Digital Omnibus
The rules are set to move, though not yet. The long-stalled ePrivacy Regulation, which was meant to replace the Directive, was formally withdrawn in 2025 (notice published 6 October 2025). The Directive still applies. Separately, the Commission proposed the EU Digital Omnibus on 19 November 2025. It would move the cookie-consent rule, where personal data is involved, into a new GDPR Article 88a, and add a GDPR Article 88b on machine-readable browser choices.
As of September 2026 it is still a proposal and has not been adopted, so none of it is in force. Today’s rule remains Article 5(3): consent before access.
How to comply and verify
Compliance under the current rule comes down to behavior: nothing non-essential stores or reads on the device before the visitor consents, and a refusal is honored. That is testable. DataTrue loads your site in a real browser, in each consent state, and records what is set and sent before consent, so you can confirm that only strictly necessary cookies and tags act ahead of a choice, and that everything else waits. If the Digital Omnibus becomes law, the prominence-of-reject and honor-the-signal requirements it proposes are the same kind of behavior a test can verify.
This law is part of our EU website tracking compliance hub.
Questions
What is the ePrivacy Directive?
It is the EU law behind cookie-consent banners. Article 5(3) requires a website to get consent before storing or reading information on a visitor’s device, unless it is strictly necessary for a service the visitor asked for. EU regulators read it as covering tracking pixels and URL tracking as well as cookies, and it works alongside the GDPR.
Do all cookies need consent?
No. Cookies that are strictly necessary for a service the visitor requested, such as a login session or shopping cart, do not need consent. Analytics and advertising cookies are not strictly necessary, so they need consent before they are set.
Is the ePrivacy Regulation in force?
No. The proposed ePrivacy Regulation was formally withdrawn in 2025 (notice published 6 October 2025). The current rule is still the ePrivacy Directive. A separate proposal, the Digital Omnibus, proposed on 19 November 2025, would move the cookie rule into the GDPR where personal data is involved. As of September 2026 it is still a proposal and has not been adopted.
What is the difference between ePrivacy and GDPR for cookies?
The ePrivacy Directive decides whether you may set a cookie or fire a tag at all, requiring consent first. The GDPR governs the personal data that follows and defines what valid consent looks like. Cookies engage both, in that order.
See what your tags do in every consent state
DataTrue loads your real pages as a visitor who accepts, rejects, or sends an opt-out signal, and reads what each tag sends. A tag that ignores the visitor’s choice shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
