Vai al contenuto principale
Torna al wiki
Privacy & Compliance

What Is ePrivacy?

Ultimo aggiornamento il 3 agosto 2026

ePrivacy is the body of EU law governing electronic communications and access to a user's device, the source of the cookie banner and one of the most frequently confused pairings in European data law, since it is a distinct legal instrument from the GDPR that happens to interact constantly with it. The current ePrivacy Directive, in force since 2002 and amended in 2009, requires consent before storing or reading anything on a user's device that isn't strictly necessary for a service the user requested. That single requirement is the entire legal basis for the consent banner every European website now carries.

The rule GDPR doesn't cover

The GDPR governs what happens to personal data once collected. ePrivacy governs something narrower and earlier: the act of accessing a user's device at all, regardless of whether what gets accessed later counts as personal data. This is why a purely anonymous analytics cookie, holding no personal identifiers whatsoever, still needs ePrivacy consent: the rule protects the device, not the data derived from it. The exemption that matters most in practice is "strictly necessary": a session cookie that keeps a shopping cart working is exempt, because the service cannot function without it; an analytics or advertising cookie is not, because the service functions perfectly well without measuring or monetizing the visit. Our web cookie entry maps that distinction in more detail.

Why the fragmentation persists

A long-planned ePrivacy Regulation was meant to replace the current directive, harmonizing enforcement across member states the way the GDPR did for data protection, but repeated legislative delays have left it stalled, so ePrivacy remains implemented as national law, transposed with local variation into each member state's legal code. The practical consequence is genuine fragmentation: consent mechanics, enforcement intensity, and even which cookie categories require explicit versus implied consent differ somewhat between France, Germany, and the rest of the EU, which is why a single EU-wide "compliant" cookie banner is more aspiration than reality.

What it means for verification tools

A security or verification widget that avoids setting cookies or persistent identifiers sidesteps the ePrivacy consent requirement entirely, rather than merely justifying it under an exemption: there is simply nothing on the device to require consent for. That is the design CaptchaFox follows: verifying sessions through transient signal processing instead of a stored identifier, which keeps the widget out of the consent banner altogether and out of the audit that inventories every cookie a site's third-party components set. For a compliance team, a verification layer with nothing to disclose is one line item a cookie audit never has to argue about.

Informazioni su CaptchaFox

CaptchaFox è una soluzione conforme al GDPR con sede in Germania che protegge siti web e applicazioni da abusi automatizzati, come bot e spam. Il suo approccio distintivo e multilivello utilizza segnali di rischio e sfide crittografiche per facilitare un processo di verifica robusto. CaptchaFox consente ai clienti di essere operativi in pochi minuti, non richiede gestione continua e offre alle aziende una protezione duratura.

Per saperne di più su CaptchaFox, contattaci o inizia a integrare la nostra soluzione con una prova gratuita.

Termini correlati

What Is Legitimate Interest (GDPR)?

Legitimate interest is a GDPR lawful basis that allows processing personal data without consent, provided a documented balancing test favors the business.

Continua a leggere
What Is PII (Personally Identifiable Information)?

PII is any information that can identify a specific person, directly or in combination, from names and emails to IP addresses and device identifiers.

Continua a leggere
What Is Privacy by Design?

Privacy by design is the principle that data protection must be built into systems from the first architecture decision, not added on afterwards.

Continua a leggere
What Is Schrems II?

Schrems II is the 2020 EU court ruling that invalidated the Privacy Shield, reshaping how personal data may be transferred from the EU to the United States.

Continua a leggere

Combatti i bot e proteggi i dati dei tuoi utenti.

Non dare ai truffatori e agli spammer alcuna possibilità e proteggi il tuo sito web con CaptchaFox oggi.

CaptchaFox protegge i siti web su desktop e dispositivi mobili