Definition
The ePrivacy Directive (2002/58/EC), also known as the Cookie Directive, is a European Union regulation that specifically governs electronic communications privacy. It operates alongside the GDPR but addresses distinct areas: cookies and similar tracking technologies, unsolicited marketing communications, confidentiality of communications, and location data. In the UK, the directive is implemented through the Privacy and Electronic Communications Regulations (PECR). While the GDPR provides the general data protection framework, the ePrivacy Directive provides the specific rules for how electronic communications channels must handle user privacy, creating a layered compliance requirement where both regulations apply simultaneously.
The directive's scope extends well beyond web cookies to include tracking pixels embedded in emails, read receipts, and any technology that accesses or stores information on a user's device. For email marketers, this means that deploying a tracking pixel to determine whether a recipient has opened an email requires prior informed consent unless a legitimate interest exemption applies, which is narrowly interpreted. The regulation also prohibits the use of electronic mail for direct marketing purposes without prior consent, subject to the limited soft opt-in exemption for existing customers marketing similar products or services, creating a substantially more restrictive framework than the CAN-SPAM Act in the United States.
Best Practices
Obtain explicit prior consent before deploying any tracking technology, including email open pixels, read receipts, or location tracking mechanisms in mobile email clients. The consent must be freely given, specific, informed, and unambiguous, meeting both ePrivacy Directive and GDPR standards. Pre-ticked boxes or implied consent through inaction do not satisfy the requirement.
Distinguish clearly between the soft opt-in exemption for marketing emails to existing customers and the strict consent requirement for non-customer recipients. The soft opt-in only applies when marketing similar products or services, was offered during the sale or negotiation process, and the recipient is given a clear opportunity to opt out during every subsequent communication.
Maintain auditable consent records for every subscriber, documenting exactly what they consented to, when, and how. This includes storing the specific wording of your consent notice, the method of collection, and timestamped proof of opt-in. Regulators expect organisations to demonstrate compliance proactively rather than reactively.
Implement cookie consent management platforms that categorise tracking technologies by purpose and obtain granular consent for each category. Strictly necessary technologies (such as those required for core functionality) are exempt, but any technology used for analytics, marketing, or personalisation requires active consent with clear disclosure of what data is collected and how it is used.
Conduct regular compliance audits of all email marketing practices against both ePrivacy and GDPR requirements, reviewing consent mechanisms, privacy notices, data retention periods, and third-party data processor agreements. Non-compliance can result in penalties of up to the greater of €10 million (or £500,000 under PECR) or 2% of global annual turnover, and in severe cases, additional GDPR fines of up to €20 million or 4% of global annual turnover.
Related Glossary Terms
Email Hyper-Personalisation
Hyper-personalisation in email beyond merge tags using AI-driven content, behavioural data streams, predictive recommendations, and dynamic content blocks.
Email List Rental
Email list rental and purchase risks under CAN-SPAM and GDPR, including spam trap exposure, deliverability damage, and ethical building alternatives.
Email Spam Trigger
Words, phrases, and email characteristics that increase the likelihood of an email being filtered as spam by modern classification systems.
Frequently Asked Questions
The ePrivacy Directive is a lex specialis that supplements GDPR, providing specific rules for electronic communications. GDPR covers general data protection principles, while the ePrivacy Directive specifically regulates cookies, tracking pixels, marketing communications, and confidentiality of communications. When both apply, the ePrivacy Directive takes precedence for its specific areas, and organisations must comply with both simultaneously.
Deploying a tracking pixel in an email requires prior informed consent unless a legitimate interest exemption applies, which is interpreted very narrowly. The pixel must be disclosed, and recipients must be informed about what data the pixel collects (such as open time, device information, IP address, and location). Consent must be obtained before the pixel fires, typically through a cookie consent banner or by confirmation during email sign-up.
Marketing emails to individual subscribers require prior consent under PECR, except when the soft opt-in applies: the sender obtained the recipient's contact details during a sale or negotiation for a similar product or service, and the recipient is given a clear opportunity to opt out during every communication. Corporate subscribers have slightly different rules, where a corporate soft opt-in may apply for business-to-business marketing.
Read receipts that use tracking pixels or any technology that accesses the recipient's device require consent under the ePrivacy Directive. Location tracking in email, such as using IP geolocation to determine a recipient's physical location, similarly requires informed consent. Both practices must be clearly disclosed, and the data collected must be proportionate and relevant to the stated purpose.
Under PECR in the UK, enforcement is carried out by the Information Commissioner's Office (ICO) with maximum fines of £500,000 per violation. However, where the same processing also breaches GDPR, fines can reach up to €20 million or 4% of annual global turnover. Enforcement actions have included fines against major brands for sending marketing emails without valid consent and failing to provide clear opt-out mechanisms.