What ePrivacy (Cookie Directive) requires
Compliance with the ePrivacy Directive mandates a strict consent-first framework for accessing or storing information on user terminal equipment, directly reflecting Article 5(3) of Directive 2002/58/EC. This node operationalizes such a requirement by enforcing that `require_prior_consent_non_essential` is true for all non-essential cookies and tracking technologies. By default, `default_non_essential_status` must be false, ensuring no data processing occurs without user affirmation. Exceptions are narrowly defined: the system will `allow_strictly_necessary_without_consent` for essential functions and also `exempt_transmission_communication_cookies`. The standard for valid consent, as clarified by Recital 66 of Directive 2009/136/EC and the Court of Justice of the European Union's Planet49 judgment, is high, demanding that a `require_explicit_opt_in_action` be configured. Consequently, the system must `prohibit_pre_ticked_boxes`. In line with EDPB Guidelines 05/2020, passive actions like scrolling do not constitute valid affirmative action. To uphold confidentiality of communications per Article 5(1) and address joint controllership liabilities from the Fashion ID case, it is imperative to `block_third_party_scripts_pre_consent`. User control is paramount, necessitating configurations to `enable_granular_consent_categories` and `require_easy_consent_withdrawal`. All consent events must `log_consent_audit_trail` for demonstrability, with a maximum validity period set at a `cookie_consent_validity_days_max` of 180 days before re-consent is necessary.
Pillar: Data Protection & Privacy · Authority: European Parliament and the Council of the European Union · Version: 1.1.0 · Last updated:
Primary source: https://eur-lex.europa.eu/eli/dir/2002/58/oj
SHA-256 integrity: d307046c21f49c9b7853e4b1e02dc5202ec00dbf22b7e3fe7691bb8c8d5e7588
Primary Citations — 6 traced to source
- Directive 2002/58/EC (ePrivacy Directive), Article 5(3) - Requirement for prior informed consent for storage or access to information stored on a user's terminal equipment.
- Directive 2009/136/EC, Recital 66 - Clarification that consent must be expressed actively and based on clear, comprehensive information.
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/eprivacy-cookie-directive.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/eprivacy-cookie-directive.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/eprivacy-cookie-directive
- Back to registry: Browse all 10,090 compliance nodes