Law / European Union

Cookie Directive

Officially ePrivacy Directive, Storage of and Access to Information on Terminal Equipment

Also known as ePrivacy Directive, Cookie Law.

Directive 2002/58/EC, Art. 5(3)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since .

A device storage and tracking consent rule binding public and private bodies.

As of .

What it requires

  • Obtain the user's or subscriber's consent, after giving them clear and comprehensive information about the purposes of the processing, before storing information on their device or accessing information already stored there (cookies, local storage, device fingerprinting, or any comparable technique), whether or not that information is personal data.
  • You do not need consent for storage or access that is strictly technical for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or strictly necessary for an information-society service the user explicitly requested.

If you get it wrong

Criminal exposureNo

Criminal exposure note

Article 15a(1) requires Member States to lay down penalties 'including criminal sanctions where appropriate' for an infringement of any provision adopted under this Directive, but the Directive itself does not make a breach a criminal offence; whether an Article 5(3) infringement is prosecuted as a crime is entirely a matter for each Member State's own transposing law.

Who enforces it

Enforcement body

Each Member State's own competent national authority and, where relevant, other national bodies designated under Article 15a(2) to (4). The Directive states no equivalent to Article 13(6)'s private-suit clause for Article 5.

Settledness

Planet49 settled whether a pre-ticked checkbox can be valid consent and whether the personal-data character of the stored information matters; it did not address every technique this Article now reaches (device fingerprinting, server-side tracking without local storage).

As of
Case link
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0673
Case citation
C-673/17

What it reaches

Obligation class

Consent, Disclosure

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 5(3), as rewritten by Directive 2009/136/EC, requires that storing information, or gaining access to information already stored, in a subscriber's or user's terminal equipment is allowed only where the subscriber or user has given consent after being provided clear and comprehensive information about the purposes of the processing, with an exemption for storage or access that is strictly technical to carry a communication or strictly necessary for an information-society service the user explicitly requested.

The Court of Justice held in Planet49 (C-673/17) that a pre-ticked consent checkbox the user must deselect to refuse does not satisfy this Article, that the rule applies whether or not the stored or accessed information is personal data, and that the information a service provider must give before consent includes the duration cookies will operate and whether third parties can access them.

When LexLint raises it

  • tracks_devices

Read the law

Official Journal text, EUR-Lex, consolidated version of Directive 2002/58/EC as amended by Directive 2009/136/EC

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app