EU ePrivacy Directive (2002/58/EC)
Directive 2002/58/EC, concerning the processing of personal data and the protection of privacy in the electronic communications sector (ePrivacy Directive), as amended by Directive 2009/136/EC. It covers confidentiality of communications, cookies and tracking, direct marketing, and the handling of traffic and location data.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (21)
Billing
| Code | Title |
|---|---|
| EPRIV-009 | Itemised Billing Options |
CLI
| Code | Title |
|---|---|
| EPRIV-010 | Calling Line Identification |
Confidentiality
| Code | Title |
|---|---|
| EPRIV-001 | Confidentiality of Communications |
Consent
| Code | Title |
|---|---|
| EPRIV-006 | Withdraw Consent As Easy As Granting |
| EPRIV-021 | Records of Consent |
Cookies
| Code | Title |
|---|---|
| EPRIV-002 | Storage and Access to Information on Terminal Equipment |
| EPRIV-004 | Strictly Necessary Cookie Classification |
| EPRIV-005 | Tracking Pixels and Fingerprinting |
Cross-Border
| Code | Title |
|---|---|
| EPRIV-023 | Cross-Border Marketing Operations |
Directories
| Code | Title |
|---|---|
| EPRIV-011 | Directories of Subscribers |
Implementation and Enforcement
| Code | Title |
|---|---|
| Art. 14 | Human Oversight |
| Art. 14a | Committee procedure |
| Art. 15 | Accuracy, Robustness and Cybersecurity |
| Art. 15a | Implementation and enforcement |
Incident
| Code | Title |
|---|---|
| EPRIV-018 | Personal Data Breach Notification |
Legal
| Code | Title |
|---|---|
| EPRIV-020 | Interplay with GDPR |
Location Data
| Code | Title |
|---|---|
| EPRIV-008 | Location Data Other Than Traffic Data |
Marketing
| Code | Title |
|---|---|
| EPRIV-012 | Unsolicited Communications - Email |
| EPRIV-013 | Unsolicited Communications - SMS |
| EPRIV-014 | Voice Marketing Calls |
| EPRIV-015 | Automated Calling Machines and Faxes |
| EPRIV-016 | Sender Identification and Reply Address |
National Law
| Code | Title |
|---|---|
| EPRIV-019 | National Implementations |
Scope and Definitions
Defines nursing personnel as all categories of persons providing nursing care and services, wherever they work.
| Code | Title |
|---|---|
| 64.2001 | Basis and Purpose |
| 64.2003 | Definitions |
| 64.2004 | Customer Approval Mechanisms |
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| ILO-C149-01 | Article 1 - Definition of nursing personnel covering all categories providing nursing care and services |
Security
| Code | Title |
|---|---|
| EPRIV-017 | Security of Networks and Services |
Security and Confidentiality
| Code | Title |
|---|---|
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| Art. 5(3) | Cookies and similar technologies |
Special Categories
| Code | Title |
|---|---|
| EPRIV-022 | Children and Vulnerable Users |
Subscriber Rights
| Code | Title |
|---|---|
| Art. 10 | Data and Data Governance |
| Art. 11 | Technical Documentation |
| Art. 12 | Record-Keeping |
| Art. 13 | Transparency and Provision of Information to Deployers |
Traffic Data
| Code | Title |
|---|---|
| EPRIV-007 | Traffic Data Processing |
Traffic and Location Data
| Code | Title |
|---|---|
| Art. 6 | Writing |
| Art. 7 | Minimum Standards |
| Art. 8 | Compliance with the Requirements |
| Art. 9 | Risk Management System |
Transparency
| Code | Title |
|---|---|
| EPRIV-003 | Cookie Policy and Transparency |
Your Compliance Coverage
If you comply with EU ePrivacy Directive (2002/58/EC), you already cover:
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
20%
9 controls mapped
Compare →BS 65000:2014 - Guidance on Organizational Resilience
20%
9 controls mapped
Compare →EU AI Act
20%
9 controls mapped
Compare →+ 589 more: EU Digital Markets Act (20%), FTC Health Breach Notification Rule (20%)
See all 592 mapped frameworks ↓Maps to 592 other frameworks
Frequently Asked Questions
What is EU ePrivacy Directive (2002/58/EC)?
EU ePrivacy Directive (2002/58/EC) is a compliance framework from European Union with 21 domains and 45 controls. Directive 2002/58/EC, concerning the processing of personal data and the protection of privacy in the electronic communications sector (ePrivacy Directive), as amended by Directive 2009/136/EC. It covers confidentiality of communications, cookies and tracking, direct marketing, and the handling of traffic and location data. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does EU ePrivacy Directive (2002/58/EC) have?
EU ePrivacy Directive (2002/58/EC) has 45 controls organised across 21 domains. The largest domains are Scope and Definitions (7 controls), Marketing (5 controls), Implementation and Enforcement (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does EU ePrivacy Directive (2002/58/EC) map to?
EU ePrivacy Directive (2002/58/EC) maps to 592 other compliance frameworks. The top mapping partners are CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 (20% coverage), BS 65000:2014 - Guidance on Organizational Resilience (20% coverage), EU AI Act (20% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with EU ePrivacy Directive (2002/58/EC) compliance?
Start your EU ePrivacy Directive (2002/58/EC) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EU ePrivacy Directive (2002/58/EC) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 45 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required