Back to Blog
Compliance

ePrivacy Directive (Cookie Law) vs. GDPR: A CMP Perspective

Rachel Torres, Privacy CounselDecember 3, 202514 min read
ePrivacyGDPRCookiesLegal

TLDR: ePrivacy says "no cookies without consent." GDPR says "consent must be freely given, specific, informed, unambiguous." You need both. Most sites only think about GDPR and miss the ePrivacy requirement entirely.

Read full summary Understanding the interplay between the ePrivacy Directive (Article 5(3)) and GDPR is essential for compliant consent management. ePrivacy governs when you can place cookies; GDPR governs how valid that consent must be. A CMP must satisfy both simultaneously. *Summary by Claude AI*
## The Law Most Companies Forget Everyone knows about GDPR. It's the regulation with the €20 million fines, the 4% of revenue penalties, the headlines about Meta and Amazon paying billions. Fewer people know about the ePrivacy Directive. But here's the thing: the ePrivacy Directive is what actually requires consent for cookies. Not GDPR. GDPR just defines what valid consent looks like. Article 5(3) of the ePrivacy Directive states: you cannot store information on (or access information from) a user's device without their prior consent. Full stop. That's cookies. That's local storage. That's fingerprinting. That's anything that touches the user's device for purposes beyond what they explicitly requested. GDPR comes in second. Once ePrivacy requires consent, GDPR defines how that consent must be obtained: freely given, specific, informed, unambiguous. No pre-ticked boxes. No dark patterns. No cookie walls. Most companies build their consent flows thinking only about GDPR. Then a regulator points out they've been violating ePrivacy since the beginning—setting cookies before consent is given, treating "strictly necessary" too broadly, or missing the "prior" part of "prior consent." ### The Two Laws, Explained **Focus:** The GDPR is a comprehensive regulation governing the processing of **personal data**. It applies to any information relating to an identified or identifiable natural person. Its core principles include lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability. **Key Relevance to CMPs:** * **Lawful Basis (Article 6):** GDPR mandates a lawful basis for all processing of personal data. Consent (Article 7) is one such basis, and it's particularly stringent for non-essential data processing like marketing analytics or personalization. * **Data Subject Rights:** GDPR grants individuals extensive rights over their data, including the right to access, rectify, erase ("right to be forgotten"), restrict processing, data portability, and object to processing. A CMP must facilitate the exercise of these rights, especially consent withdrawal. * **Accountability:** Organizations must be able to *demonstrate* compliance, including proof of valid consent. CMPs are vital for recording and managing these consent records. ### ePrivacy Directive: The Communication Enabler (and Cookie Guardian) **Focus:** The ePrivacy Directive specifically addresses the confidentiality of electronic communications and the use of tracking technologies, such as **cookies** and similar technologies (e.g., local storage, pixels, fingerprinting). It's often referred to as a "lex specialis" (specific law) to the GDPR, meaning it takes precedence for its specific scope. **Key Relevance to CMPs:** * **Prior Consent for Cookies (Article 5(3)):** This is the directive's most famous clause. It states that storing information or gaining access to information already stored on a user's terminal equipment (like cookies) is **only allowed if the user has given prior, informed consent.** * **Exceptions:** Consent is generally not required for cookies that are "strictly necessary" for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user (e.g., shopping cart, login session). * **Transparency:** Users must be provided with clear and comprehensive information about the purposes of the processing before consent is obtained. ### The Interplay: Why Your CMP Needs Both A modern CMP must satisfy both GDPR and ePrivacy requirements simultaneously: 1. **ePrivacy First:** Before *any* non-essential cookie or tracking technology is placed on a user's device, the ePrivacy Directive requires **prior, informed consent**. Your CMP's banner is the first line of defense here, obtaining this initial permission. 2. **GDPR's High Bar for Consent:** Once ePrivacy's "prior consent" is obtained, the GDPR steps in to define *what constitutes valid consent*. This means the consent collected by your CMP must meet GDPR's Article 7 criteria: freely given, specific, informed, and unambiguous. Implicit consent (like scrolling) is generally invalid. 3. **Personal Data Processing:** If the cookies/trackers collect **personal data** (which most analytics and marketing cookies do), then GDPR's requirements for a lawful basis (often consent), data minimization, transparency, and data subject rights all come into play. Your CMP assists in managing this entire lifecycle. **Example:** * **ePrivacy:** Prohibits setting a marketing cookie without prior consent. * **GDPR:** Requires that the consent for that marketing cookie be explicit (e.g., an opt-in click), specific (for marketing), and easily withdrawable. ### Looking ahead to the ePrivacy Regulation The long-discussed ePrivacy Regulation has stalled for years, but most Member States already enforce the directive with national guidance (CNIL, ICO, BfDI) that expects explicit opt-in for non-essential cookies. Even without a new regulation, supervisory authorities are aligned on one thing: banners must present a real choice with equal prominence for acceptance and rejection. ## Bottom line for CMP teams A compliant CMP doesn't choose between the ePrivacy Directive and the GDPR; it has to satisfy both. Treat ePrivacy as the gatekeeper—no non-essential cookies before a clear opt-in—and let GDPR set the quality bar for consent granularity, withdrawal, and record keeping. Keep parity between what your banner promises, how your SDK behaves, and how you log consent events. That alignment keeps regulators satisfied and users confident that their choices genuinely matter.

Frequently Asked Questions

What is the main difference between the ePrivacy Directive and GDPR?
The ePrivacy Directive focuses specifically on the confidentiality of electronic communications and tracking technologies like cookies, while GDPR is a broader regulation covering all processing of personal data.
Which EU law requires "prior consent" for cookies?
The ePrivacy Directive (Article 5(3)) explicitly requires prior, informed consent before storing or accessing information on a user\s device, such as cookies.
How do CMPs ensure compliance with both ePrivacy and GDPR?
CMPs first obtain ePrivacy\s prior consent for non-essential cookies and then ensure that this consent meets GDPR\s stringent conditions (freely given, specific, informed, unambiguous) for any personal data processed by those cookies.
R

Rachel Torres, Privacy Counsel

Contributing writer at GetCookies, specializing in privacy compliance, consent management, and digital marketing optimization.

Ready to Simplify Cookie Consent?

GetCookies makes GDPR, CCPA, and global privacy compliance effortless. Get started today.