Skip to content

Evidence request lists

EU ePrivacy Directive (2002/58/EC)

Evidence request list. 15 controls, 13 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

ePrivacy - Implementation, Enforcement and Final (Articles 14-21)

ePD-Art.14
Technical features and standardisation (Article 14)

Article 14 governs technical features and standardisation: in implementing the Directive, Member States shall ensure (subject to Article 14(2)-(3)) that no mandatory requirements for specific technical features are imposed on terminal equipment or other electronic communications equipment which could impede the placing of equipment on the market and the free circulation of such equipment in and between Member States. Where the implementation of provisions of the Directive requires the introduction of technical features in electronic communications networks, Member States shall inform the Commission per Directive 98/34/EC.

Artefacts an auditor will ask for
  • Internal note on the entity's reliance on Article 14 free-circulation principle
ePD-Art.14a_15a
Committee procedure and implementation/enforcement (Articles 14a and 15a)

Article 14a sets the committee procedure (the Communications Committee assists the Commission). Article 15a (added by Directive 2009/136/EC) requires Member States to lay down the rules on penalties applicable to infringements of the national provisions adopted under the Directive, to take all measures necessary to ensure that they are implemented, including granting national competent authorities the power to order the cessation of infringements, even where the infringement consists of failure to comply with the requirements laid down in this Directive for measures to be taken by the authority itself.

Artefacts an auditor will ask for
  • Awareness of the applicable national-law ePrivacy penalty regime in each Member State the entity operates in (these are distinct from the GDPR penalty regime and may run in parallel)
Where this commonly fails
  • Compliance plan that only addresses GDPR penalties and ignores parallel ePrivacy national-law penalty exposure
ePD-Art.15
Application of Directive 95/46/EC provisions and Article 15(1) Member-State restrictions (Article 15)

Article 15(1) allows Member States to adopt legislative measures to restrict the scope of the rights and obligations provided for in Articles 5, 6, 8(1)-(4), and 9, when such restriction constitutes a necessary, appropriate and proportionate measure within a democratic society to safeguard national security (i.e. State security), defence, public security, the prevention, investigation, detection and prosecution of criminal offences or unauthorised use of the electronic communication system. Article 15(2) requires the cooperation of providers in the investigation of breaches of confidentiality. Article 15(3) provides for the application of Directive 95/46/EC (now the GDPR) more generally.

Artefacts an auditor will ask for
  • Internal procedure to receive and respond to Article 15(1) Member State data-retention or lawful-interception orders
  • Cooperation records with competent authorities
Where this commonly fails
  • Cooperation procedures that do not check proportionality / necessity of the Article 15(1) order
ePD-Art.16_17
Transitional arrangements and transposition (Articles 16-17)

Article 16 sets transitional arrangements: Article 12 (directories of subscribers) shall not apply to directory editions already produced or placed on the market in printed or off-line electronic form before the national provisions adopted pursuant to this Directive enter into force. Article 17 (Transposition) required Member States to transpose by 31 October 2003 and to notify the Commission of the texts adopted.

ePD-Art.18_19_20_21
Review, repeal, entry into force and addressees (Articles 18-21)

Article 18 requires the Commission to submit to the European Parliament and the Council, not later than three years after the date referred to in Article 17(1), a report on the application of this Directive (such reports continue periodically). Article 19 repeals Directive 97/66/EC with effect from the Article 17(1) date. Article 20 provides that the Directive entered into force on 31 July 2002. Article 21 addresses the Directive to the Member States.

ePD-Status.eRegWithdrawn
Status: proposed ePrivacy Regulation withdrawn (February 2025)

The European Commission has WITHDRAWN the proposed ePrivacy Regulation in February 2025 as part of its 2025 work-programme prioritisation. Negotiations on the proposal (COM(2017) 10 final and successor texts) had been stalled in Council for years; the Commission cited the entry into force of related instruments (the GDPR + AI Act + Data Act + DSA + DMA) as already covering significant ground that the proposed Regulation had targeted. The 2002/58/EC Directive remains the in-force ePrivacy instrument until a new proposal is adopted. Some Member States and consumer-protection groups have called for reintroduction; as of corpus retrieval, the Commission has not done so.

Artefacts an auditor will ask for
  • Internal note that the 2002/58/EC Directive continues to apply and that any new ePrivacy Regulation will require fresh tracking + transition planning when proposed
Where this commonly fails
  • Compliance plan assuming the ePrivacy Regulation will replace 2002/58/EC in the near term (the proposal is withdrawn)

ePrivacy - Scope and Definitions (Articles 1-3)

ePD-Art.1_2_3
Scope, definitions and services concerned (Articles 1-3)

Article 1 sets the subject matter: the Directive harmonises Member State provisions to ensure an equivalent level of protection of fundamental rights and freedoms (in particular the right to privacy and confidentiality) in respect of the processing of personal data in the electronic communications sector, and to ensure the free movement of such data + electronic communications equipment and services in the Union. Article 2 supplies definitions, expressly referencing GDPR Article 4 for personal data + consent. Article 3 sets the scope: the Directive applies to the processing of personal data in connection with the provision of publicly available electronic communications services in public communications networks in the Union, including public communications networks supporting data collection and identification devices.

Artefacts an auditor will ask for
  • Internal scope analysis confirming whether the entity is a provider of publicly available electronic communications services + whether the GDPR (as lex generalis) is supplemented by Article 5(3) and Article 13
Where this commonly fails
  • Treating the ePrivacy Directive as superseded by the GDPR (it is lex specialis and continues to apply)

ePrivacy - Security and Confidentiality (Articles 4-5)

ePD-Art.4
Security of services and personal-data-breach notification (Article 4)

Article 4(1) requires the provider of a publicly available electronic communications service to take appropriate technical and organisational measures to safeguard the security of its services, in conjunction with the network provider where necessary, with the level of security appropriate to the risk. Article 4(1a) requires that those measures include at least: ensuring access to personal data only by authorised personnel for legally authorised purposes; protection against accidental or unlawful destruction, accidental loss or alteration, unauthorised storage, processing or access or disclosure; and a security policy. Article 4(2) requires the provider to inform subscribers of any particular risk of a breach of the security of the network. Article 4(3) requires the provider to notify the competent national authority of a personal data breach without undue delay, and to notify the subscr

Artefacts an auditor will ask for
  • Article 4(1a) appropriate technical and organisational measures aligned with the GDPR Art.32 baseline
  • Article 4(3) breach-notification procedure to national authority + affected subscriber
  • Article 4(2) risk-notification procedure for particular network-security risks
Where this commonly fails
  • No breach-notification procedure aligned with both Article 4(3) (ePrivacy authority) and GDPR Article 33 (data-protection authority)
  • No documented security policy per Article 4(1a)
ePD-Art.5
Confidentiality of communications including the Article 5(3) cookie consent rule

Article 5(1) requires Member States to ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, including the prohibition of listening, tapping, storage or other kinds of interception or surveillance of communications, except when legally authorised in accordance with Article 15(1). Article 5(2) allows the recording of communications and traffic data for the purposes of providing evidence of a commercial transaction. Article 5(3) imposes the famous prior-consent rule: the storing of information or the gaining of access to information already stored, in the terminal equipment of a subscriber or user, is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information in accordance

Artefacts an auditor will ask for
  • Consent-management platform (CMP) implementing the Article 5(3) prior-consent rule for non-essential cookies + tracking technologies
  • Strictly-necessary exception assessment for each cookie / similar technology
  • Clear and comprehensive information to subscribers per Article 5(3) (information notice + purposes)
  • Records of consent retention + withdrawal mechanism
Where this commonly fails
  • Setting non-essential cookies / tracking pixels before consent is captured (most common Article 5(3) breach)
  • Reliance on the strictly-necessary exception for analytics / marketing cookies (the exception is narrow)
  • Pre-ticked consent boxes (consent not freely given - aligned with GDPR Art.7 + EDPB Guidelines 5/2020)

ePrivacy - Traffic, Billing, CLI, Location and Directories (Articles 6-12)

ePD-Art.10_11_12
Exceptions, automatic call forwarding and directories of subscribers (Articles 10-12)

Article 10 sets exceptions to Articles 8 + 9 for legally authorised purposes (emergency services, tracing nuisance/malicious calls). Article 11 enables subscribers to stop automatic call forwarding free of charge. Article 12 requires that subscribers are informed, free of charge and before they are included in a directory, of the purposes of the directory + any further usage possibilities (incl. search functions), and that they are given the opportunity to determine whether their personal data are included in a directory and to verify, correct or withdraw their data. Reverse-look-up via additional categories of subscriber data shall be subject to subscriber consent.

Artefacts an auditor will ask for
  • Article 12 directory information notice + opt-in/out + access/rectify/withdraw mechanism
  • Subscriber controls to stop automatic call forwarding
Where this commonly fails
  • Directory inclusion without Article 12 information + opt-in/out
  • No subscriber control to stop automatic call forwarding
ePD-Art.6
Traffic data (Article 6)

Article 6(1) requires traffic data relating to subscribers and users processed and stored by the provider of a public communications network or a publicly available electronic communications service to be erased or made anonymous when no longer needed for the purpose of the transmission of a communication. Article 6(2) permits processing for billing and interconnection-payment purposes only until the end of the period during which the bill may lawfully be challenged or payment pursued. Article 6(3) permits processing for marketing electronic communications services / value-added services only with the prior consent of the subscriber / user (revocable at any time). Article 6(5) restricts access to authorised personnel.

Artefacts an auditor will ask for
  • Traffic-data retention schedule aligned with Article 6 (operational + billing + marketing-consent-based)
  • Traffic-data access controls (authorised personnel only, audit logging)
Where this commonly fails
  • Retention of traffic data beyond the Article 6(1)-(2) windows without a marketing consent under Article 6(3)
  • Traffic data used for marketing without prior subscriber consent
ePD-Art.7
Itemised billing (Article 7)

Article 7 requires subscribers to have the right to receive non-itemised bills, and Member States to apply national provisions in order to reconcile the rights of subscribers receiving itemised bills with the right to privacy of calling users and called subscribers, for example by ensuring that sufficient alternative privacy-enhancing methods of communications or payments are available.

Artefacts an auditor will ask for
  • Provider option allowing subscriber to receive non-itemised bills + balancing privacy of called subscribers
Where this commonly fails
  • Default itemised billing without subscriber option for non-itemised
ePD-Art.8
Calling-line and connected-line identification (Article 8)

Article 8 governs the presentation and restriction of calling-line identification (CLI) and connected-line identification (COLI): subscribers must have the possibility, on a per-line or per-call basis, to prevent the presentation of CLI / COLI; called subscribers must have the possibility to reject incoming calls where CLI has been suppressed; called subscribers must have the possibility to eliminate the presentation of the COLI of the connected line; subscribers must have free of charge means to prevent and refuse cost-trace / nuisance calls.

Artefacts an auditor will ask for
  • Subscriber-facing CLI/COLI controls available per-line and per-call free of charge
Where this commonly fails
  • CLI / COLI controls not freely available or not granular
ePD-Art.9
Location data other than traffic data (Article 9)

Article 9(1) requires that location data other than traffic data (precise position data e.g. cellular triangulation, GNSS, Wi-Fi positioning) relating to users / subscribers may only be processed when they are made anonymous, or with the consent of the users / subscribers to the extent and for the duration necessary for the provision of a value-added service. Article 9(2) requires the provider to inform users / subscribers, prior to obtaining their consent, of the type of location data which will be processed, of the purposes and duration of the processing, and whether the data will be transmitted to third parties. Article 9(2) further provides that users / subscribers shall be given the possibility to withdraw consent at any time and to temporarily refuse the processing for each connection or transmission.

Artefacts an auditor will ask for
  • Article 9(2) location-data information notice + opt-in consent + per-connection-refusal mechanism
  • Withdrawal-of-consent and anonymisation procedures for value-added services
Where this commonly fails
  • Processing of precise location data without Article 9 consent
  • No per-connection refusal mechanism for location-based value-added services

ePrivacy - Unsolicited Communications (Article 13)

ePD-Art.13
Unsolicited communications (Article 13)

Article 13(1) prohibits the use of automated calling and communication systems without human intervention (automated calling machines), facsimile machines (fax) or electronic mail (email, SMS) for the purposes of direct marketing without the prior consent of the subscriber or user, save for the soft-opt-in in Article 13(2). Article 13(2) permits a natural or legal person to use electronic contact details for direct marketing of its own similar products / services provided that customers clearly and distinctly are given the opportunity to object, free of charge and in an easy manner, both at the time of collection and on each subsequent message. Article 13(4) prohibits the practice of sending email for direct marketing purposes disguising or concealing the identity of the sender on whose behalf the communication is made, or in contravention of Article 6 of Directive 2000/31/EC, or without

Artefacts an auditor will ask for
  • Article 13 consent records for all marketing channels (email/SMS/automated voice/fax)
  • Article 13(2) soft-opt-in records (own similar products + clear opt-out at collection + on each message)
  • Sender identification + valid address per Article 13(4)
  • Marketing-to-legal-persons policy aligned with the Member State Article 13(5) approach
Where this commonly fails
  • Marketing email without prior consent or Article 13(2) soft-opt-in
  • Concealed sender identity (Article 13(4) breach)
  • No clearly-marked opt-out mechanism on every marketing message
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.