Cookie Directive
Officially ePrivacy Directive, Storage of and Access to Information on Terminal Equipment
Also known as ePrivacy Directive, Cookie Law.
Directive 2002/58/EC, Art. 5(3)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since .
A device storage and tracking consent rule binding public and private bodies.
As of .
What it requires
- Obtain the user's or subscriber's consent, after giving them clear and comprehensive information about the purposes of the processing, before storing information on their device or accessing information already stored there (cookies, local storage, device fingerprinting, or any comparable technique), whether or not that information is personal data.
- You do not need consent for storage or access that is strictly technical for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or strictly necessary for an information-society service the user explicitly requested.
If you get it wrong
Criminal exposureNo
Criminal exposure note
Article 15a(1) requires Member States to lay down penalties 'including criminal sanctions where appropriate' for an infringement of any provision adopted under this Directive, but the Directive itself does not make a breach a criminal offence; whether an Article 5(3) infringement is prosecuted as a crime is entirely a matter for each Member State's own transposing law.
Who enforces it
Enforcement body
Each Member State's own competent national authority and, where relevant, other national bodies designated under Article 15a(2) to (4). The Directive states no equivalent to Article 13(6)'s private-suit clause for Article 5.
Settledness
Planet49 settled whether a pre-ticked checkbox can be valid consent and whether the personal-data character of the stored information matters; it did not address every technique this Article now reaches (device fingerprinting, server-side tracking without local storage).
- As of
- Case link
- https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0673
- Case citation
- C-673/17
What it reaches
Obligation class
Consent, Disclosure
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 5(3), as rewritten by Directive 2009/136/EC, requires that storing information, or gaining access to information already stored, in a subscriber's or user's terminal equipment is allowed only where the subscriber or user has given consent after being provided clear and comprehensive information about the purposes of the processing, with an exemption for storage or access that is strictly technical to carry a communication or strictly necessary for an information-society service the user explicitly requested.
The Court of Justice held in Planet49 (C-673/17) that a pre-ticked consent checkbox the user must deselect to refuse does not satisfy this Article, that the rule applies whether or not the stored or accessed information is personal data, and that the information a service provider must give before consent includes the duration cookies will operate and whether third parties can access them.
When LexLint raises it
tracks_devices
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.