RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The archive · 200 retrospective records ↗

The archive / Compliance & obligations

Compliance & obligations / From the archive · 25 November 2009 event · prepared 16 September 2026

The ePrivacy Directive, not GDPR, set the cookie consent rule

A 2009 amendment to the ePrivacy Directive replaced an opt-out cookie rule with a consent requirement, predating and sitting alongside the GDPR.

eur-lex.europa.euprimary record

Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector

Document
31 July 2002
Event
25 November 2009
Retrieved
16 September 2026
No visual was published with this record, so its primary document stands in its place.

The workload

Getting cookie consent right is often treated as a GDPR task, but the specific requirement to ask before storing or reading non-essential data on a visitor's device comes from a different law. A site operator's workload is to identify which cookies or local storage are strictly necessary to a service the user requested, which do not need consent, and which are not, which do, then build a consent mechanism that actually withholds those cookies until consent is given rather than merely displaying a banner over them.

What the documents show

Verified: the original ePrivacy Directive, 2002/58/EC, set out at Article 5(3), initially conditioned cookie-style storage and access on giving the user clear and comprehensive information and the right to refuse it, an opt-out model. Verified: the amending Directive 2009/136/EC, done at Strasbourg on 25 November 2009, replaced that paragraph with a requirement that storage or access is allowed only if the user has given consent, after being given the same clear information, an opt-in model, while preserving the exceptions for storage or access strictly necessary to deliver a requested service. Verified: the 2009 amending directive required Member States to transpose it by 25 May 2011, which is why today's opt-in consent standard dates from that transposition period rather than from 2002. Neither document is a GDPR provision; the GDPR separately governs the personal-data processing that may follow once cookies are read, but the consent-to-store rule itself sits in this directive.

The operating cost

Neither directive states a compliance fee; the cost is implementation labour for a consent-management layer that defaults to off for non-essential storage, plus periodic review as cookies and tags change. A vendor's own claim that its analytics tool is cookieless or GDPR-compliant is a vendor's marketing statement, not a regulator's or court's finding, and this entry does not treat any such claim as a compliance determination on that vendor's behalf.

The stop condition

Editorially: the consent obligation does not expire, but the practical trigger to re-check it is any change to what a site stores or reads on a device, a new analytics tag, a new advertising pixel, a new session-recording tool, since each is a separate storage-or-access event the Article 5(3) test applies to.

  • Which specific cookies or storage calls on the site are strictly necessary to a requested service, and which are not?
  • Does the consent tool actually block non-essential storage before consent, or does it only hide a banner while cookies load anyway?
  • Has any vendor's no-consent-needed or cookieless claim been checked against the directive's own text rather than accepted from the vendor's page?

The rule is older than the GDPR and asks a narrower question: was consent obtained before storage or access, not only whether data is later processed lawfully.

Sources & reading trail

Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector ↗

The original Article 5(3) text, conditioning cookie-style storage and access on information plus a right to refuse, the opt-out model later replaced.

Source published: 31 July 2002 · Retrieved: 16 September 2026

Directive 2009/136/EC amending Directive 2002/22/EC, Directive 2002/58/EC and Regulation (EC) No 2006/2004 ↗

Replaces Article 5(3) with a consent (opt-in) requirement and sets the Member State transposition deadline of 25 May 2011 at its own Article 4.

Source published: 25 November 2009 · Retrieved: 16 September 2026

Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.