What Is ePrivacy?
ePrivacy is the body of EU law governing electronic communications and access to a user's device, the source of the cookie banner and one of the most frequently confused pairings in European data law, since it is a distinct legal instrument from the GDPR that happens to interact constantly with it. The current ePrivacy Directive, in force since 2002 and amended in 2009, requires consent before storing or reading anything on a user's device that isn't strictly necessary for a service the user requested. That single requirement is the entire legal basis for the consent banner every European website now carries.
The rule GDPR doesn't cover
The GDPR governs what happens to personal data once collected. ePrivacy governs something narrower and earlier: the act of accessing a user's device at all, regardless of whether what gets accessed later counts as personal data. This is why a purely anonymous analytics cookie, holding no personal identifiers whatsoever, still needs ePrivacy consent: the rule protects the device, not the data derived from it. The exemption that matters most in practice is "strictly necessary": a session cookie that keeps a shopping cart working is exempt, because the service cannot function without it; an analytics or advertising cookie is not, because the service functions perfectly well without measuring or monetizing the visit. Our web cookie entry maps that distinction in more detail.
Why the fragmentation persists
A long-planned ePrivacy Regulation was meant to replace the current directive, harmonizing enforcement across member states the way the GDPR did for data protection, but repeated legislative delays have left it stalled, so ePrivacy remains implemented as national law, transposed with local variation into each member state's legal code. The practical consequence is genuine fragmentation: consent mechanics, enforcement intensity, and even which cookie categories require explicit versus implied consent differ somewhat between France, Germany, and the rest of the EU, which is why a single EU-wide "compliant" cookie banner is more aspiration than reality.
What it means for verification tools
A security or verification widget that avoids setting cookies or persistent identifiers sidesteps the ePrivacy consent requirement entirely, rather than merely justifying it under an exemption: there is simply nothing on the device to require consent for. That is the design CaptchaFox follows: verifying sessions through transient signal processing instead of a stored identifier, which keeps the widget out of the consent banner altogether and out of the audit that inventories every cookie a site's third-party components set. For a compliance team, a verification layer with nothing to disclose is one line item a cookie audit never has to argue about.
About CaptchaFox
CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.
To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.