Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. ePrivacy Directive, Cookies & Consent Platforms (CMPs)
Courses Guides Blog Resources News
Français English Nederlands
Fiche 24/54 Part 3 — Lawfulness & Key Actors Advanced Reviewed 2026-08-23

ePrivacy Directive, Cookies & Consent Platforms (CMPs)

The ePrivacy Directive (Directive 2002/58/EC) specifically governs cookies and terminal trackers. The rule is absolute: any cookie that is not strictly essential requires prior GDPR-grade opt-in conse

Open in interactive reader
⚖️ ePrivacy Directive Lex Specialis 📋 CJEU Planet49 & Belgian DPA IAB Ruling

ePrivacy Directive, Cookies & CMPs

⚡ In 30 seconds

Under Article 5(3) of Directive 2002/58/EC (ePrivacy), storing information or gaining access to information stored in terminal equipment (cookies, localStorage, SDKs, fingerprinting) is prohibited without the user's prior consent, unless strictly necessary to provide a service explicitly requested by the subscriber.

Cookie Category ePrivacy Exemption Status Mandatory Implementation Standard
Strictly Necessary Exempt from consent: Shopping cart, login session tokens, load balancing, CSRF protection. May deploy on page load; must still be disclosed in the cookie policy.
Audience Analytics Consent required: (Strict exemptions exist under French CNIL for purely anonymous first-party analytics). Blocked prior to opt-in; no third-party cross-site data sharing.
Targeted Advertising Consent mandatory: Retargeting pixels, programmatic bidding trackers, ad cookies. Hard block before user click; equal 'Reject All' prominence.
⚡ Key Takeaways
  • ePrivacy acts as lex specialis over GDPR: consent standards derive from GDPR Art. 4(11) & 7.
  • Dark patterns (hiding the reject button, deceptive color contrasting) are systematically sanctioned.
  • Belgian DPA landmark decision on IAB Europe TCF: TC Strings and consent signals are personal data.
⚠️ Common Pitfall

Firing Google Analytics or Meta Pixel tags on DOMContentLoaded while the cookie banner is still pending user interaction.

🛠️ In Practice

Configure your Consent Management Platform (CMP) with Google Consent Mode v2 or ContentSquare opt-out controls before tag firing.

⚖️ Official Sources: Art. 5(3) Directive 2002/58/EC · CJEU C-673/17 Planet49 · Belgian DPA Decision 21/2022 (IAB Europe) ✓ Legal review: 23 August 2026

✓ Key takeaways

  • Strictly essential functional cookies (cart, security authentication) are exempt from consent.
  • Analytics, advertising, and social media trackers require prior affirmative consent (opt-in).
  • Refusing cookies must be as easy as accepting them (e.g. equal 'Reject all' button on banner layer 1).

⚠ Common pitfall: Conflating cookie technical expiration (e.g. 1 year) with consent validity duration (typically 6 months under DPA standards).

→ Actionable practice: Deploy a CMP that strictly halts all tracking scripts from executing until the user explicitly clicks 'Accept'.

← Consent Regime & Validity Standards (Art. 4.11 & 7) Controller Obligations & Joint Controllership (Art. 24 & 26) →