Home

Donate
Perspective

Europe’s Cookie Law Is Really a Law About Surveillance

Itxaso Domínguez de Olazábal, Chiara Casati / Sep 10, 2026

Photo by: Lino Mirgeler/picture-alliance/dpa/AP Images

Republish

In 2022, a reporter paid $160 for a week’s worth of location data linked to visits to over 600 Planned Parenthood clinics in the United States. The dataset showed where groups of visitors had come from, how long they stayed, and where they went next. The broker withdrew the product after the story was published. However, the market behind it remained.

Europe has seen a similar market emerge. Journalists have obtained billions of commercially traded location records from Germany and Belgium. The data exposed movements around hospitals, religious sites, trade union offices, government ministries, military sites, EU institutions and NATO buildings. Information gathered through ordinary apps for advertising can reveal intimate details of people’s lives, identify public officials and create security risks for entire institutions.

These examples illustrate a distinction at the heart of what people usually call ‘EU privacy law’ that may seem unnecessarily fussy to readers elsewhere. In the United States, ‘privacy’ often covers the whole problem, while EU law recognizes two distinct fundamental rights. Article 7 of the Charter of Fundamental Rights of the Union protects private life, the home and communications, while Article 8 protects personal data.

The distinction is quite important: whereas data protection largely governs what happens when personal data are processed, privacy and communications confidentiality also protect the space from which information is obtained. They put a boundary on entering that space in the first place.

The EU built the ePrivacy framework around that question. ePrivacy adds specific rules for the confidentiality of communications and access to information stored on, or generated by, people’s devices, including rules covering communications, metadata, and location. While the General Data Protection Regulation (GDPR) primarily governs access to personal data — what organizations might do with data once they have processed it. This distinction matters, and it disappears when ‘privacy’ becomes a casual synonym for data protection.

The law everyone notices in the wrong place

Most people meet ePrivacy through a cookie banner, and this may be the worst possible introduction. A framework about confidentiality looks like a tedious set of rules about pop-ups, while the tracking industry points to the pop-ups it helped create as proof that the law has failed.

Article 5(3), the provision behind many banners, controls when an actor may store information on, or obtain information from, a person’s terminal equipment. But it goes beyond that: ePrivacy is concerned with the act of accessing the device itself.

“Terminal equipment” includes phones and laptops, connected cars, televisions, wearables, smart glasses and other parts of the Internet of Things. The rule covers fingerprinting, tracking pixels, local storage, operating-system identifiers and instructions that make a device send information elsewhere. The principle is straightforward: a device does not become open to inspection simply because one fragment of information cannot identify its user on its own.

ePrivacy also protects communications confidentiality and regulates the traffic and location data held by communications providers. It limits retention and reuse, covers unsolicited communications, and sets the conditions under which Member States may restrict confidentiality.

The ePrivacy Directive’s scope has never matched the way people use digital services. It was written around traditional telephone and communications providers, meaning that many online services originally were excluded from its protection. Messaging and webmail services can now fall under communications confidentiality rules, but coverage still depends on legal classifications that users cannot see. The same message, location trail, or device data can receive different protection depending on whether the company is labeled a telecom provider, messaging service, or platform: under these conditions, is the law still protecting the underlying right?

One framework, two surveillance systems

The distinction between GDPR and ePrivacy becomes even more important when we look at surveillance. From one side,commercial surveillance commonly starts before the GDPR question even arises, with access to a device or a communications-related signal: for example, an app includes a software kit that collects location, a television records viewing habits. These small acts of access feed systems of profiling, advertising, measurement and sale.

While the GDPR remains essential once personal data enter that chain, ePrivacy asks the question that comes first: Is the provider allowed to use traffic or location data? Can a tracker read from a device, or must a communication remain confidential? It does not regulate the entire data-broker market, but it can close some of the taps that supply it.

The same distinction matters in terms of state surveillance. ePrivacy has shaped one of Europe’s longest surveillance disputes: data retention. Governments have repeatedly wanted providers to keep traffic and location data for later use by police and security bodies. Article 15 allows restrictions for public objectives, but they remain subject to the Charter, including the necessity and proportionality requirements in Article 52.

The resulting Court of Justice case law — from Digital Rights Ireland, Tele2 Sverige and Watson, La Quadrature du Net, SpaceNet and, more recently, HADOPI — has become complicated. While the Court rejects general and indiscriminate retention of traffic and location data as the default, it allows targeted retention and some limited forms of general retention.

A record of who contacted whom, when, for how long and from where can reconstruct a life without revealing the content of a single message. Repeated calls to an oncology department may disclose a diagnosis. A phone present at an abortion clinic, mosque, union office or demonstration may reveal health, religion, employment relations or political activity.

This is why ePrivacy matters: the metadata can be revealing long before anyone even reads the message.

Commercial and state surveillance involve different powers and safeguards. Still, they increasingly use the same infrastructure. In the United States, ICE and Customs and Border Protection bought access to phone-location data gathered through ordinary apps and sold by brokers. The authorities did not need to build their own tracking system; the advertising industry had already collected people’s movements at scale.

Spyware makes the overlap even clearer. Pegasus-type tools are developed and sold by private companies, then used by public authorities against journalists, activists, lawyers and opposition figures. They can enter a phone, access communications and metadata, follow location, and activate microphones or cameras. The European Data Protection Supervisor has explicitly connected spyware deployment to the ePrivacy Directive where EU law applies, and described the phone as a person’s “virtual domicile.” A commercial market is selling the capacity to enter the devices and communications that ePrivacy is meant to protect.

ChatControl made the boundary visible

The proposals commonly called “ChatControl” have made this question unusually concrete. Can communications remain confidential when private providers scan them for a public-policy

purpose? The legal link is direct. Once many messaging and webmail services came within the scope of the ePrivacy’s confidentiality rules, practices that had previously been assessed mainly under the GDPR now also had to comply with Articles 5 and 6 of the ePrivacy Directive, which protect communications and traffic data. That meant providers wishing to continue voluntary scanning could no longer rely on a GDPR legal basis alone, but also on a specific exception from confidentiality rules.

The EU adopted Regulation 2021/1232 for that purpose. It created a temporary derogation that allowed providers, on a purely voluntary basis and subject to conditions, to use technologies to detect and report child sexual abuse material and the solicitation of children, without providing a legal basis for scanning. While negotiations on a permanent framework continue, the co-legislators have twice renewed the derogation with increasing reluctance.

The need for a derogation is important: A GDPR legal basis does not give you a free pass through the ePrivacy door, both layers must be satisfied.

ChatControl also shows the blurred lines between private and public surveillance. The service and technical infrastructure are private, but the objective and legal pressure come from public authorities. People use confidential communications to speak with lawyers, doctors, journalists, family members and support organizations, to organize politically, report wrongdoing and seek help. Article 52 requires any restrictions to that space to be lawful, necessary and proportionate. This matters, even if the objective to pursue is worthy

How the EU made its confidentiality law look obsolete

The ePrivacy Directive is indeed outdated. It dates from 2002 — with its best-known amendment in 2009 — its terminology reflects an earlier telecoms market; its enforcement is inconsistent, both in terms of insufficiencies and lack of harmonization, and cookie banners have become a tool for manipulation rather than meaningful choice. But the EU did try to replace it.

In 2017, the Commission proposed an ePrivacy Regulation covering internet-based communications, metadata, tracking technologies and connected devices. However, industry groups argued that the GDPR was sufficient, demanded greater flexibility for further processing and opposed stronger limits on tracking. Civil society, consumer organizations and data protection authorities wanted stronger confidentiality and better protection for metadata and devices. Member States disagreed over scope, enforcement, exceptions and data retention. After years of negotiations, the Commission withdrew the proposal in 2025.

The Commission is not a neutral observer in what followed. It proposed the ChatControl framework and its temporary derogation, is working towards a new EU approach to data retention, and has now proposed moving important terminal-equipment rules into the GDPR through the Digital Omnibus.

Industry, the Commission and Member States do not form a single alliance. Their interests often conflict: companies want more room to use device and communications-related data for advertising, analytics and AI; many governments want providers to retain data for law-enforcement access; and the Commission wants to show simplification while expanding lawful-access tools. The net result is pressure to treat confidentiality as friction requiring an exception, derogation, or more flexible legal regime.

What changes when device access moves into the GDPR

The Digital Omnibus was completely inadequate from the outset, but tried to address one real problem: people are tired of banners that repeat the same question, hide the refusal button or turn privacy into an endurance test.

But simplifying the consent should not mean simplifying the rights away.

The Commission’s proposal keeps consent as the general rule for storing or accessing personal data on a person’s device, while widening exceptions. But it would split the same act between two regimes. Access to personal data would fall under the GDPR, while other information could remain under ePrivacy. Oversight would also shift towards the GDPR’s one-stop-shop system, whose record in holding large technology companies accountable has been poor.

Much of industry is pressing for more, with some companies seeking to access devices aligned with all GDPR legal bases, including legitimate interest.

A business interest in advertising, analytics, security, service improvement, or AI development may explain what a company wants to do with information. But it does not, by itself, answer whether the company is allowed to enter the device in the first place. There is a better response to the so-called cookie fatigue. People should be able to express privacy choices — both refusal and consent — once through browsers, operating systems, apps, or other user-side tools, and services should have to respect those machine-readable signals. This would remove many banners without getting rid of the boundary.

The EU also needs clearer rules for new communications services, consistent enforcement, and updated protection for metadata, location and connected devices. It needs an honest debate about state access too. A future data-retention law will determine how far governments can turn the records of ordinary communications into a standing investigative resource.

The strange thing about ePrivacy is that people tend to notice it when it is ineffective and to overlook it when it matters most. We see the banner, but rarely the rule limiting a provider’s use of location data, the judgments against indiscriminate retention, or the need for a derogation before private messages can be scanned.

This invisibility has made ePrivacy easy to attack. Industry can reduce it to cookies. Governments can describe confidentiality as an obstacle to investigations. The Commission can call the remaining division between ePrivacy and the GDPR unnecessary complexity.

The EU’s ad hoc distinction between privacy and data protection remains valuable: connected cars, smart televisions, phones, and always-on communication devices expose more than ever our everyday lives. As the boundary between the physical world and the digital world thins, so does the idea that privacy is only about data collected. That’s why a crucial protection is stopping someone from accessing it in the very first place.

Support Tech Policy Press
If you've found our work helpful, consider supporting us.

Authors

Itxaso Domínguez de Olazábal
Itxaso Domínguez de Olazábal, PhD, is an expert in data protection and privacy, with a focus on commercial surveillance and the multidimensional virtual harms caused by online tracking. She also specialises in online freedom of expression, examining the role of security forces in content governance....
Chiara Casati
Chiara Casati works on communication and press relations at European Digital Rights (EDRi), shaping public narratives and political engagement on digital rights across Europe.

Topics

Related

Perspective
Digital Omnibus Proposal Could Finally End Europe’s Cookie Banner ProblemJuly 14, 2026
Analysis
Why the EU’s GDPR ‘Simplification’ Reforms Could Unravel Hard-Won ProtectionsMay 12, 2025