EU ePrivacy Directive (2002/58/EC)
Evidence request list. 15 controls, 13 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
ePrivacy - Implementation, Enforcement and Final (Articles 14-21)
Article 14 governs technical features and standardisation: in implementing the Directive, Member States shall ensure (subject to Article 14(2)-(3)) that no mandatory requirements for specific technical features are imposed on terminal equipment or other electronic communications equipment which could impede the placing of equipment on the market and the free circulation of such equipment in and between Member States. Where the implementation of provisions of the Directive requires the introduction of technical features in electronic communications networks, Member States shall inform the Commission per Directive 98/34/EC.
- Internal note on the entity's reliance on Article 14 free-circulation principle
Article 14a sets the committee procedure (the Communications Committee assists the Commission). Article 15a (added by Directive 2009/136/EC) requires Member States to lay down the rules on penalties applicable to infringements of the national provisions adopted under the Directive, to take all measures necessary to ensure that they are implemented, including granting national competent authorities the power to order the cessation of infringements, even where the infringement consists of failure to comply with the requirements laid down in this Directive for measures to be taken by the authority itself.
- Awareness of the applicable national-law ePrivacy penalty regime in each Member State the entity operates in (these are distinct from the GDPR penalty regime and may run in parallel)
- Compliance plan that only addresses GDPR penalties and ignores parallel ePrivacy national-law penalty exposure
Article 15(1) allows Member States to adopt legislative measures to restrict the scope of the rights and obligations provided for in Articles 5, 6, 8(1)-(4), and 9, when such restriction constitutes a necessary, appropriate and proportionate measure within a democratic society to safeguard national security (i.e. State security), defence, public security, the prevention, investigation, detection and prosecution of criminal offences or unauthorised use of the electronic communication system. Article 15(2) requires the cooperation of providers in the investigation of breaches of confidentiality. Article 15(3) provides for the application of Directive 95/46/EC (now the GDPR) more generally.
- Internal procedure to receive and respond to Article 15(1) Member State data-retention or lawful-interception orders
- Cooperation records with competent authorities
- Cooperation procedures that do not check proportionality / necessity of the Article 15(1) order
Article 16 sets transitional arrangements: Article 12 (directories of subscribers) shall not apply to directory editions already produced or placed on the market in printed or off-line electronic form before the national provisions adopted pursuant to this Directive enter into force. Article 17 (Transposition) required Member States to transpose by 31 October 2003 and to notify the Commission of the texts adopted.
Article 18 requires the Commission to submit to the European Parliament and the Council, not later than three years after the date referred to in Article 17(1), a report on the application of this Directive (such reports continue periodically). Article 19 repeals Directive 97/66/EC with effect from the Article 17(1) date. Article 20 provides that the Directive entered into force on 31 July 2002. Article 21 addresses the Directive to the Member States.
The European Commission has WITHDRAWN the proposed ePrivacy Regulation in February 2025 as part of its 2025 work-programme prioritisation. Negotiations on the proposal (COM(2017) 10 final and successor texts) had been stalled in Council for years; the Commission cited the entry into force of related instruments (the GDPR + AI Act + Data Act + DSA + DMA) as already covering significant ground that the proposed Regulation had targeted. The 2002/58/EC Directive remains the in-force ePrivacy instrument until a new proposal is adopted. Some Member States and consumer-protection groups have called for reintroduction; as of corpus retrieval, the Commission has not done so.
- Internal note that the 2002/58/EC Directive continues to apply and that any new ePrivacy Regulation will require fresh tracking + transition planning when proposed
- Compliance plan assuming the ePrivacy Regulation will replace 2002/58/EC in the near term (the proposal is withdrawn)
ePrivacy - Scope and Definitions (Articles 1-3)
Article 1 sets the subject matter: the Directive harmonises Member State provisions to ensure an equivalent level of protection of fundamental rights and freedoms (in particular the right to privacy and confidentiality) in respect of the processing of personal data in the electronic communications sector, and to ensure the free movement of such data + electronic communications equipment and services in the Union. Article 2 supplies definitions, expressly referencing GDPR Article 4 for personal data + consent. Article 3 sets the scope: the Directive applies to the processing of personal data in connection with the provision of publicly available electronic communications services in public communications networks in the Union, including public communications networks supporting data collection and identification devices.
- Internal scope analysis confirming whether the entity is a provider of publicly available electronic communications services + whether the GDPR (as lex generalis) is supplemented by Article 5(3) and Article 13
- Treating the ePrivacy Directive as superseded by the GDPR (it is lex specialis and continues to apply)
ePrivacy - Security and Confidentiality (Articles 4-5)
Article 4(1) requires the provider of a publicly available electronic communications service to take appropriate technical and organisational measures to safeguard the security of its services, in conjunction with the network provider where necessary, with the level of security appropriate to the risk. Article 4(1a) requires that those measures include at least: ensuring access to personal data only by authorised personnel for legally authorised purposes; protection against accidental or unlawful destruction, accidental loss or alteration, unauthorised storage, processing or access or disclosure; and a security policy. Article 4(2) requires the provider to inform subscribers of any particular risk of a breach of the security of the network. Article 4(3) requires the provider to notify the competent national authority of a personal data breach without undue delay, and to notify the subscr
- Article 4(1a) appropriate technical and organisational measures aligned with the GDPR Art.32 baseline
- Article 4(3) breach-notification procedure to national authority + affected subscriber
- Article 4(2) risk-notification procedure for particular network-security risks
- No breach-notification procedure aligned with both Article 4(3) (ePrivacy authority) and GDPR Article 33 (data-protection authority)
- No documented security policy per Article 4(1a)
Article 5(1) requires Member States to ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, including the prohibition of listening, tapping, storage or other kinds of interception or surveillance of communications, except when legally authorised in accordance with Article 15(1). Article 5(2) allows the recording of communications and traffic data for the purposes of providing evidence of a commercial transaction. Article 5(3) imposes the famous prior-consent rule: the storing of information or the gaining of access to information already stored, in the terminal equipment of a subscriber or user, is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information in accordance
- Consent-management platform (CMP) implementing the Article 5(3) prior-consent rule for non-essential cookies + tracking technologies
- Strictly-necessary exception assessment for each cookie / similar technology
- Clear and comprehensive information to subscribers per Article 5(3) (information notice + purposes)
- Records of consent retention + withdrawal mechanism
- Setting non-essential cookies / tracking pixels before consent is captured (most common Article 5(3) breach)
- Reliance on the strictly-necessary exception for analytics / marketing cookies (the exception is narrow)
- Pre-ticked consent boxes (consent not freely given - aligned with GDPR Art.7 + EDPB Guidelines 5/2020)
ePrivacy - Traffic, Billing, CLI, Location and Directories (Articles 6-12)
Article 10 sets exceptions to Articles 8 + 9 for legally authorised purposes (emergency services, tracing nuisance/malicious calls). Article 11 enables subscribers to stop automatic call forwarding free of charge. Article 12 requires that subscribers are informed, free of charge and before they are included in a directory, of the purposes of the directory + any further usage possibilities (incl. search functions), and that they are given the opportunity to determine whether their personal data are included in a directory and to verify, correct or withdraw their data. Reverse-look-up via additional categories of subscriber data shall be subject to subscriber consent.
- Article 12 directory information notice + opt-in/out + access/rectify/withdraw mechanism
- Subscriber controls to stop automatic call forwarding
- Directory inclusion without Article 12 information + opt-in/out
- No subscriber control to stop automatic call forwarding
Article 6(1) requires traffic data relating to subscribers and users processed and stored by the provider of a public communications network or a publicly available electronic communications service to be erased or made anonymous when no longer needed for the purpose of the transmission of a communication. Article 6(2) permits processing for billing and interconnection-payment purposes only until the end of the period during which the bill may lawfully be challenged or payment pursued. Article 6(3) permits processing for marketing electronic communications services / value-added services only with the prior consent of the subscriber / user (revocable at any time). Article 6(5) restricts access to authorised personnel.
- Traffic-data retention schedule aligned with Article 6 (operational + billing + marketing-consent-based)
- Traffic-data access controls (authorised personnel only, audit logging)
- Retention of traffic data beyond the Article 6(1)-(2) windows without a marketing consent under Article 6(3)
- Traffic data used for marketing without prior subscriber consent
Article 7 requires subscribers to have the right to receive non-itemised bills, and Member States to apply national provisions in order to reconcile the rights of subscribers receiving itemised bills with the right to privacy of calling users and called subscribers, for example by ensuring that sufficient alternative privacy-enhancing methods of communications or payments are available.
- Provider option allowing subscriber to receive non-itemised bills + balancing privacy of called subscribers
- Default itemised billing without subscriber option for non-itemised
Article 8 governs the presentation and restriction of calling-line identification (CLI) and connected-line identification (COLI): subscribers must have the possibility, on a per-line or per-call basis, to prevent the presentation of CLI / COLI; called subscribers must have the possibility to reject incoming calls where CLI has been suppressed; called subscribers must have the possibility to eliminate the presentation of the COLI of the connected line; subscribers must have free of charge means to prevent and refuse cost-trace / nuisance calls.
- Subscriber-facing CLI/COLI controls available per-line and per-call free of charge
- CLI / COLI controls not freely available or not granular
Article 9(1) requires that location data other than traffic data (precise position data e.g. cellular triangulation, GNSS, Wi-Fi positioning) relating to users / subscribers may only be processed when they are made anonymous, or with the consent of the users / subscribers to the extent and for the duration necessary for the provision of a value-added service. Article 9(2) requires the provider to inform users / subscribers, prior to obtaining their consent, of the type of location data which will be processed, of the purposes and duration of the processing, and whether the data will be transmitted to third parties. Article 9(2) further provides that users / subscribers shall be given the possibility to withdraw consent at any time and to temporarily refuse the processing for each connection or transmission.
- Article 9(2) location-data information notice + opt-in consent + per-connection-refusal mechanism
- Withdrawal-of-consent and anonymisation procedures for value-added services
- Processing of precise location data without Article 9 consent
- No per-connection refusal mechanism for location-based value-added services
ePrivacy - Unsolicited Communications (Article 13)
Article 13(1) prohibits the use of automated calling and communication systems without human intervention (automated calling machines), facsimile machines (fax) or electronic mail (email, SMS) for the purposes of direct marketing without the prior consent of the subscriber or user, save for the soft-opt-in in Article 13(2). Article 13(2) permits a natural or legal person to use electronic contact details for direct marketing of its own similar products / services provided that customers clearly and distinctly are given the opportunity to object, free of charge and in an easy manner, both at the time of collection and on each subsequent message. Article 13(4) prohibits the practice of sending email for direct marketing purposes disguising or concealing the identity of the sender on whose behalf the communication is made, or in contravention of Article 6 of Directive 2000/31/EC, or without
- Article 13 consent records for all marketing channels (email/SMS/automated voice/fax)
- Article 13(2) soft-opt-in records (own similar products + clear opt-out at collection + on each message)
- Sender identification + valid address per Article 13(4)
- Marketing-to-legal-persons policy aligned with the Member State Article 13(5) approach
- Marketing email without prior consent or Article 13(2) soft-opt-in
- Concealed sender identity (Article 13(4) breach)
- No clearly-marked opt-out mechanism on every marketing message
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.