Privacy
ePrivacy
Also called ePrivacy Directive, PECR.
ePrivacy is the EU rule on confidentiality of electronic communications, including the requirement to get consent before storing or reading information on a person's device. The UK version is PECR.
How it is measured
The operative text is Article 5(3) of Directive 2002/58/EC. It reaches cookies, local storage, tracking pixels, and scripts that read device data. The only carve-outs are storage needed to send the communication or to deliver a service the user asked for.
To test your site, list every item it stores or reads on first load and match each one to an exemption or to a recorded consent. A replacement regulation was proposed in 2017 and never adopted, so the 2002 directive and each country's law still apply.
Worked example
A Dublin concert-ticketing site passes an internal GDPR review, then a regulator asks about device access. A heat-map tool and an analytics script both write IDs on first load, before any choice. The site's notice cited legitimate interest, which does not satisfy Article 5(3).
The fix moves both scripts behind the consent tool. A fresh visitor now gets two storage items, a session token and a CSRF value, until they accept.
How it differs
ePrivacy governs touching the device. GDPR governs what happens to personal data once you have it. One analytics cookie can trigger both: ePrivacy for writing it, GDPR for the lawful basis, retention, and rights that follow.
Common errors
Relying on legitimate interest to set non-essential cookies. Ignoring local storage and pixels. Assuming a clean GDPR review covers device access. Forgetting the UK runs its own PECR. Waiting for a new regulation before acting.
In practice
Audit device access separately from your data inventory. Open a clean browser, load your top three pages, and list every cookie, storage key, and pixel. Mark each as necessary or consent-needed, then fix the second list.