Regulation
Directive 2002/58/EC (as amended by Directive 2009/136/EC)

ePrivacy Directive

Directive, European Union
Effective: July 12, 2002 100 platforms tracked 6152 provisions indexed Enforced by: National Data Protection Authorities, National Telecom Regulators Last reviewed May 9, 2026

Overview

The ePrivacy Directive governs the processing of personal data and the protection of privacy in the electronic communications sector. Article 5(3) is particularly significant: it requires prior informed consent before storing or accessing information on a user's terminal equipment (cookies, tracking technologies, local storage), with narrow exceptions for storage strictly necessary to provide a service explicitly requested by the user. The Directive complements the GDPR and applies specifically to electronic communications, covering cookies, direct marketing, traffic data, and location data. A proposed ePrivacy Regulation intended to replace it has been under negotiation since 2017.

Penalties

Set by national implementing legislation. Varies by EU member state.

Key Articles & Sections

Platforms We Track Subject to ePrivacy Directive

Recent Changes Related to ePrivacy Directive

ConductAtlas maps governance language to potentially relevant regulatory frameworks. Regulatory applicability and enforceability may vary by jurisdiction, enforcement context, and individual circumstances. This page is informational and does not constitute legal advice. Methodology

Provisions Governed by ePrivacy Directive (6152 across 100 platforms)

Product development uses de-identified information 23andMe
Medium
Eligible users invited to participate in 23andMe Research 23andMe
Medium
Research participation is voluntary with IRB consent 23andMe
Medium
Consent required for sensitive personal information in some states Activision
Medium
No privacy expectation in UGC or communications Activision
Medium
Frequency capping cookies used after opt-out Activision
Medium
Collection of date of birth and interests Activision
Medium
Other users' personal information deemed Activision confidential Activision
Medium
Japan marketing and profiling use of personal information Activision
Medium
Collection of third party account information on linking Activision
Medium
Public sharing features carry no privacy expectation Activision
Medium
Information obtained from third party sources Activision
Medium
Social Media data used for personalization and marketing Activision
Medium
Adobe Processes Data For Legal Compliance And Fraud Detection Adobe
Medium
Adobe Collects Identity And Contact Information At Registration Adobe
Medium
Adobe Collects Accessibility And Disability Information Adobe
Medium
Adobe Infers Data From Third Party Sources Adobe
Medium
Session Replay Partners Recreate User Web And App Sessions Adobe
Medium
Adobe Will Not Publicly Display Content Under Analytics License Adobe
Medium
Social Sign On Shares Profile Data With Adobe Adobe
Medium
Business Must Ensure Business User Compliance with Sensitive Data Prohibition Adobe
Medium
License to Adobe to Operate Services on User Behalf Adobe
Medium
Adobe Will Not Use Content License to Market Adobe Adobe
Medium
Adobe Collects Data From Data Brokers For Fraud Prevention Adobe
Medium
Adobe Collects Payment And Billing Information Adobe
Medium
Adobe Collects Customer Support Call Recordings Adobe
Medium
Content Analytics on Cloud Content Subject to Opt-Out Adobe
Medium
License for Content Analytics to Improve Services Adobe
Medium
Human Review of Cloud Content in Limited Circumstances Adobe
Medium
Adobe Collects Visitor Name And Biometrics At Physical Offices Adobe
Medium

Showing 30 of 6152 provisions. View all →

Related Regulations

Official Source

View official regulation text →

Stay ahead of the changes

Watch this before it changes again

Follow unlimited companies, monitor the clauses that matter across every platform, and get the full institutional analysis on what each change obligates you to do.

Frequently Asked Questions

What does ePrivacy Directive require?

Which platforms does ePrivacy Directive apply to?

ConductAtlas tracks ePrivacy Directive-relevant provisions across 100 platforms. Each platform's specific provisions are classified by severity and mapped to ePrivacy Directive requirements.

How does ConductAtlas monitor ePrivacy Directive compliance?

ConductAtlas captures policy documents daily, classifies provisions by regulatory framework, and flags changes that affect ePrivacy Directive obligations. Every change is archived with cryptographic verification.