Definition
The ePrivacy Directive (2002/58/EC), also known as the Cookie Directive, is a European Union regulation that specifically governs electronic communications privacy. It operates alongside the GDPR but addresses distinct areas: cookies and similar tracking technologies, unsolicited marketing communications, confidentiality of communications, and location data. In the UK, the directive is implemented through the Privacy and Electronic Communications Regulations (PECR). While the GDPR provides the general data protection framework, the ePrivacy Directive provides the specific rules for how electronic communications channels must handle user privacy, creating a layered compliance requirement where both regulations apply simultaneously.
The directive's scope extends well beyond web cookies to include tracking pixels embedded in emails, read receipts, and any technology that accesses or stores information on a user's device. For email marketers, this means that deploying a tracking pixel to determine whether a recipient has opened an email requires prior informed consent unless a legitimate interest exemption applies, which is narrowly interpreted. The regulation also prohibits the use of electronic mail for direct marketing purposes without prior consent, subject to the limited soft opt-in exemption for existing customers marketing similar products or services, creating a substantially more restrictive framework than the CAN-SPAM Act in the United States.
Best Practices
Obtain explicit prior consent before deploying any tracking technology, including email open pixels, read receipts, or location tracking mechanisms in mobile email clients. The consent must be freely given, specific, informed, and unambiguous, meeting both ePrivacy Directive and GDPR standards. Pre-ticked boxes or implied consent through inaction do not satisfy the requirement.
Distinguish clearly between the soft opt-in exemption for marketing emails to existing customers and the strict consent requirement for non-customer recipients. The soft opt-in only applies when marketing similar products or services, was offered during the sale or negotiation process, and the recipient is given a clear opportunity to opt out during every subsequent communication.
Maintain auditable consent records for every subscriber, documenting exactly what they consented to, when, and how. This includes storing the specific wording of your consent notice, the method of collection, and timestamped proof of opt-in. Regulators expect organisations to demonstrate compliance proactively rather than reactively.
Implement cookie consent management platforms that categorise tracking technologies by purpose and obtain granular consent for each category. Strictly necessary technologies (such as those required for core functionality) are exempt, but any technology used for analytics, marketing, or personalisation requires active consent with clear disclosure of what data is collected and how it is used.
Conduct regular compliance audits of all email marketing practices against both ePrivacy and GDPR requirements, reviewing consent mechanisms, privacy notices, data retention periods, and third-party data processor agreements. Non-compliance can result in penalties of up to the greater of €10 million (or £500,000 under PECR) or 2% of global annual turnover, and in severe cases, additional GDPR fines of up to €20 million or 4% of global annual turnover.
Related Glossary Terms
Anonymized Data
Anonymized data is email subscriber or interaction data that has been stripped of personally identifiable information so individuals cannot be re-identified.
Consent Banner
A consent banner is an on-site notice that informs visitors about data collection and allows them to agree to or manage email marketing preferences.
Consent Expiry (Email Marketing)
Consent expiry is the time period after which a subscriber's permission to send marketing emails legally expires and must be re-obtained, varying by jurisdiction and consent type.
Data Retention Schedule (Email Marketing)
A data retention schedule defines how long subscriber personal data is stored after unsubscribing or becoming inactive, ensuring compliance with GDPR, CCPA, and similar privacy laws.
Email Consent Withdrawal
Email consent withdrawal is the process by which a subscriber revokes their permission to receive marketing emails, requiring immediate processing and suppression from future sends.
Email Data Anonymization
Email data anonymization removes or irreversibly transforms personally identifiable information (PII) from subscriber data so it can no longer be linked to an individual, enabling safe analytical use after a subscriber leaves.
Frequently Asked Questions
The ePrivacy Directive is a lex specialis that supplements GDPR, providing specific rules for electronic communications. GDPR covers general data protection principles, while the ePrivacy Directive specifically regulates cookies, tracking pixels, marketing communications, and confidentiality of communications. When both apply, the ePrivacy Directive takes precedence for its specific areas, and organisations must comply with both simultaneously.
Deploying a tracking pixel in an email requires prior informed consent unless a legitimate interest exemption applies, which is interpreted very narrowly. The pixel must be disclosed, and recipients must be informed about what data the pixel collects (such as open time, device information, IP address, and location). Consent must be obtained before the pixel fires, typically through a cookie consent banner or by confirmation during email sign-up.
Marketing emails to individual subscribers require prior consent under PECR, except when the soft opt-in applies: the sender obtained the recipient's contact details during a sale or negotiation for a similar product or service, and the recipient is given a clear opportunity to opt out during every communication. Corporate subscribers have slightly different rules, where a corporate soft opt-in may apply for business-to-business marketing.
Read receipts that use tracking pixels or any technology that accesses the recipient's device require consent under the ePrivacy Directive. Location tracking in email, such as using IP geolocation to determine a recipient's physical location, similarly requires informed consent. Both practices must be clearly disclosed, and the data collected must be proportionate and relevant to the stated purpose.
Under PECR in the UK, enforcement is carried out by the Information Commissioner's Office (ICO) with maximum fines of £500,000 per violation. However, where the same processing also breaches GDPR, fines can reach up to €20 million or 4% of annual global turnover. Enforcement actions have included fines against major brands for sending marketing emails without valid consent and failing to provide clear opt-out mechanisms.