Glossary ePrivacy
ePrivacy
Also known as:
eprivacy-directive, cookie-lawTechPrivacyCompliance
Definition
The EU's 2002 directive on privacy in electronic communications, amended in 2009 to require consent before storing or reading anything on a person's device that is not strictly necessary — the "cookie law" that the banners come from
A directive, not a regulation: each member state enacts it (the UK's is PECR), so the details vary by country while GDPR sits above them all. It is about the device, not the data — which is why a cookieless analytics script is outside it and a preference cookie for the theme is inside the strictly-necessary exemption.
The rule about touching someone's device. GDPR is about the data once you have it; ePrivacy is about whether you may read or write the device at all, and "strictly necessary" is the whole argument.