Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector
- Document
- 31 July 2002
- Event
- 25 November 2009
- Retrieved
- 16 September 2026
The workload
Getting cookie consent right is often treated as a GDPR task, but the specific requirement to ask before storing or reading non-essential data on a visitor's device comes from a different law. A site operator's workload is to identify which cookies or local storage are strictly necessary to a service the user requested, which do not need consent, and which are not, which do, then build a consent mechanism that actually withholds those cookies until consent is given rather than merely displaying a banner over them.
What the documents show
Verified: the original ePrivacy Directive, 2002/58/EC, set out at Article 5(3), initially conditioned cookie-style storage and access on giving the user clear and comprehensive information and the right to refuse it, an opt-out model. Verified: the amending Directive 2009/136/EC, done at Strasbourg on 25 November 2009, replaced that paragraph with a requirement that storage or access is allowed only if the user has given consent, after being given the same clear information, an opt-in model, while preserving the exceptions for storage or access strictly necessary to deliver a requested service. Verified: the 2009 amending directive required Member States to transpose it by 25 May 2011, which is why today's opt-in consent standard dates from that transposition period rather than from 2002. Neither document is a GDPR provision; the GDPR separately governs the personal-data processing that may follow once cookies are read, but the consent-to-store rule itself sits in this directive.
The operating cost
Neither directive states a compliance fee; the cost is implementation labour for a consent-management layer that defaults to off for non-essential storage, plus periodic review as cookies and tags change. A vendor's own claim that its analytics tool is cookieless or GDPR-compliant is a vendor's marketing statement, not a regulator's or court's finding, and this entry does not treat any such claim as a compliance determination on that vendor's behalf.
The stop condition
Editorially: the consent obligation does not expire, but the practical trigger to re-check it is any change to what a site stores or reads on a device, a new analytics tag, a new advertising pixel, a new session-recording tool, since each is a separate storage-or-access event the Article 5(3) test applies to.
- Which specific cookies or storage calls on the site are strictly necessary to a requested service, and which are not?
- Does the consent tool actually block non-essential storage before consent, or does it only hide a banner while cookies load anyway?
- Has any vendor's no-consent-needed or cookieless claim been checked against the directive's own text rather than accepted from the vendor's page?
The rule is older than the GDPR and asks a narrower question: was consent obtained before storage or access, not only whether data is later processed lawfully.
Sources & reading trail
The original Article 5(3) text, conditioning cookie-style storage and access on information plus a right to refuse, the opt-out model later replaced.
Source published: 31 July 2002 · Retrieved: 16 September 2026
Replaces Article 5(3) with a consent (opt-in) requirement and sets the Member State transposition deadline of 25 May 2011 at its own Article 4.
Source published: 25 November 2009 · Retrieved: 16 September 2026
Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.