Legal and compliance
What is ePrivacy Directive?
The rules governing cookies, similar tracking technologies and electronic marketing, implemented in the UK as PECR and across the EU as national ePrivacy laws. It sits alongside GDPR and is the reason cookie consent is required even for data GDPR might otherwise permit.
Also called: cookie law · PECR
What it covers beyond cookies
- Marketing email and SMS, and when consent is needed for each
- The soft opt-in for existing customers, which is narrower than most assume
- Any storage or access on a user’s device — including local storage and device fingerprinting
- Unsolicited marketing calls
Why it catches people out
It applies to storage on a device regardless of whether the data is personal. A cookie holding an anonymous identifier still needs consent, which is why "it is anonymised" is not the defence people expect it to be.
The soft opt-in, precisely
You may email existing customers about similar products without prior consent, provided you collected the address during a sale or negotiation and offered an opt-out every time. It does not cover people who only downloaded something or entered a competition.
Where this is covered in depth
A definition can only go so far. Core Web Vitals, and the order that actually reduces them covers this properly — 3 minutes, free, no email required.
Who wrote this
Anas Bin Masud builds e-commerce sites and does technical SEO for businesses in the UK, Canada and Pakistan. These definitions come from client work rather than from a content brief — where an entry describes a mistake, it is usually one found on a real site. More about how I work.