LW IT Solutions
« Blog Overview /Data Privacy / European Cookie Rules: The ePrivacy Directive, the...

European Cookie Rules: The ePrivacy Directive, the Withdrawn ePrivacy Regulation and the Digital Omnibus

European Cookie Rules: The ePrivacy Directive, the Withdrawn ePrivacy Regulation and the Digital Omnibus
Contents
  1. What Binds a Site Today
  2. What the Withdrawal Actually Withdrew
  3. What the Digital Omnibus Would Change
  4. The Exemptions, and Why Most Analytics Falls Outside Them
  5. What the Council Cut
  6. What Follows for Today
  7. Questions and answers
  8. Sources

Three things happened to European cookie law in eighteen months. A regulation that had been in preparation since 2017 was withdrawn. A package appeared that would move the consent rules into the GDPR. And in June the Council cut one of that package’s two relevant articles out of its own compromise text.

None of that changed what a website has to do. Sorting the three strands by whether they bind anyone takes one line each, and the sorting is worth doing before the next reorganisation of a consent layer.

Three lanes on one time axis: an unbroken lane for the directive in force since 2002, a lane for the withdrawn regulation that stops in October 2025, and a lane for the Digital Omnibus that runs from November 2025 to today and then forks into dashed possible outcomes
The top lane has no beginning inside the picture and no end. The other two are a proposal that stopped and a proposal that has not arrived.

What Binds a Site Today

Strand Instrument Status Binding?
Applies Directive 2002/58/EC, Article 5(3), through national transposition In force since 2002 Yes
Withdrawn Proposed ePrivacy Regulation Withdrawn, Official Journal C/2025/5423 of 6 October 2025 Never was
Negotiated Digital Omnibus, GDPR Articles 88a and 88b Proposed 19 November 2025, in trilogue Not yet

The consent requirement lives in national law, because a directive is transposed rather than applied directly – in Germany section 25 of the TDDDG, elsewhere under other names and with genuinely different details. That is also why enforcement has always been national and why two supervisory authorities can reach different conclusions about the same banner.

What the Withdrawal Actually Withdrew

The proposal for an ePrivacy Regulation was published in 2017, spent eight years without agreement between the co-legislators, and was dropped. The Commission announced the intention on 11 February 2025, approved it on 16 July 2025, and published it in the Official Journal on 6 October 2025.

What ended was the replacement, not the rule. The regulation would have repealed the 2002 directive on the day it applied; withdrawing it means the directive keeps applying, unchanged and indefinitely. The reading that occasionally appears in vendor material – that ePrivacy has been abandoned – inverts what happened. The reform was abandoned. The law it was meant to reform is the reason cookie banners still exist.

What the Digital Omnibus Would Change

The package proposed on 19 November 2025 takes a different route: instead of replacing the directive it amends it and writes the consent rule into the GDPR as Article 88a. The directive is not repealed. Its Article 5(3) would go on governing storage and access that involves no personal data, while everything touching personal data would be handled by the GDPR alone.

The substance of Article 88a is mostly about the banner. Refusal has to be possible through a single-click button or equivalent means. Once consent has been refused, no new request may be made for the same purpose for six months. Once consent has been given, no further banner may appear for that purpose while it remains valid. None of this abolishes the banner; it constrains how often it may reappear.

The Exemptions, and Why Most Analytics Falls Outside Them

Article 88a(3) lists what may be stored or read without consent: what is necessary to transmit a communication, what is necessary to provide an explicitly requested service, audience measurement, and maintaining or restoring the security of a service.

The audience measurement exemption is the interesting one, and it is written narrowly. It covers aggregated information about the use of an online service, measured by the controller of that service, solely for that controller’s own use. A tool that operates across services, customers or platforms does not fit that description, and no configuration setting inside such a tool makes it fit.

Article 88a(3), applied to an ordinary stack

  basket session cookie          exempt    requested service
  CSRF token                     exempt    security
  language preference            exempt    requested service
  self-hosted analytics,
    own site only, aggregated    exempt?   audience measurement
  GA4                            consent   crosses services
  Meta pixel                     consent   crosses services
  hosted A/B testing             consent   crosses customers

  ? = the wording says solely for its own use, it has not been
      tested, and the reading is not settled

That table is worth building for a real site whatever happens in the trilogue, because the same distinction already decides the question under the directive. The categories are not new; the Omnibus would write them down more explicitly than Article 5(3) ever did.

What the Council Cut

Article 88b was the structural half of the proposal. It would have required a machine-readable consent signal – a preference expressed once in the browser or the operating system and honoured by sites – which is the only mechanism on the table that would have made per-site banners unnecessary rather than merely less frequent.

Reporting on the Council’s compromise text of 18 June 2026 says it removes Article 88b, after lobbying in which the advertising industry and Google were prominent. The Parliament has not settled its position, so nothing about this is decided. It is also worth being precise about what these documents are: compromise texts are negotiating drafts, they are not adopted law, and accounts of what a given version contains do not always agree with each other. The honest summary is that 88b is in trouble and that its fate is open.

What Follows for Today

Rebuilding a consent layer around Article 88a would be building on a draft, and a draft that has already lost one article can lose another. The application date offers no urgency either: 88a is meant to apply six months after the package enters into force, and the package has not entered into force.

Two things are worth doing anyway, because they cost little and pay off under every outcome. The first is the inventory above – which storage operation serves which purpose, and which exemption it would rely on. That question has an answer today under the directive, and having written it down is the difference between answering a supervisory authority in an afternoon and answering it in a month.

The second is the single-click refusal. Whether or not 88a survives, a banner that makes refusal as easy as acceptance is already the settled expectation of most supervisory authorities under existing law, and several have said so in decisions. Building it now is not anticipating a draft; it is complying with the lane that never stopped. What follows here is a description of the state of the texts and not legal advice – but the description alone is enough to show that the pending changes are not a reason to wait.

Questions and answers

Would the Digital Omnibus remove the consent requirement for storage that involves no personal data?

No. Storage and access that involve no personal data would still be governed by Article 5(3) of the directive, which in Germany means section 25 of the TDDDG, as before. Two sets of rules would sit side by side, and every assessment would start with the question of whether a given storage operation involves personal data.

Is self-hosted analytics already exempt from consent today?

That cannot be said across the board. Article 5(3) of the directive provides for only two exemptions: transmitting a communication, and what is strictly necessary to provide a service the user has explicitly requested. Section 25 of the TDDDG takes over exactly these two. A separate exemption for audience measurement only appears in the draft Article 88a, and that is not in force.

Whether analytics counts as strictly necessary is assessed nationally by the supervisory authorities. The French CNIL, for example, sets out conditions under which narrowly configured audience measurement can do without consent; there is no single European line. Being self-hosted is not enough on its own. The deciding factors are purpose and scope: aggregated figures about the site itself, no linking with other services, no passing data on.

The inventory of storage operations helps here too. Recording what the analytics stores, for what purpose and who sees the data makes it possible to answer the responsible authority on this point, and should Article 88a enter into force, that description would only need to be checked once more against its wording.

What would the six-month rule in Article 88a require of a banner in technical terms?

A memory for the refusal. A banner that keeps a refusal only for the current session asks again on the next visit and would not be compatible with the rule. The refusal therefore has to be stored so that it is recognised for six months, and per purpose: according to the wording, the block applies to new requests for the same purpose, not to every request whatsoever.

One limit remains: if someone switches browsers or the stored decision is deleted, the site can no longer recognise the refusal. Since Article 88a is a draft, this belongs in planning, not yet in a rebuild.

Would moving the rule into the GDPR also change which supervisory authority is responsible?

Probably, and it is one of the less noticed consequences. Today the consent rule is enforced through the national transposition law, and in the view of the European Data Protection Board the GDPR’s lead authority procedure, the so-called one-stop shop, does not apply to it. A site with visitors in several countries can therefore end up dealing with several authorities that decide under differently transposed law.

If the rule stood in the GDPR as Article 88a, the GDPR’s enforcement rules would apply to it. Storage operations without personal data would remain under national law. As long as the Omnibus is not in force, nothing about today’s situation changes.

Lukas Wojcik

Lukas Wojcik

Systems architect and technology enthusiast specializing in scalable tracking solutions, GMP Stack (GA4 & GTM), and robust backend architectures. Advocate for clean code and privacy-first design.

Get in Touch

Briefly describe your project or inquiry for a tailored response. This site is protected by reCAPTCHA.

Write a comment

Observations from other implementations, objections and questions are welcome here.

The email address is not published. Required fields are marked with an asterisk.

Articles & categories

CCTV

Follow this category by RSS

Cloud & AI

All 17 articles in this category Follow this category by RSS

Data Privacy

All 20 articles in this category Follow this category by RSS

Digital Analytics

All 58 articles in this category Follow this category by RSS

Digital Marketing

All 38 articles in this category Follow this category by RSS

IT & Networks

All 19 articles in this category Follow this category by RSS

Music Production

All 17 articles in this category Follow this category by RSS

Raspberry PI

All 11 articles in this category Follow this category by RSS

SaaS & Internet Earning

Follow this category by RSS

Smart Home

All 18 articles in this category Follow this category by RSS

Web Development

All 11 articles in this category Follow this category by RSS

WordPress Plugins & Tricks

All 14 articles in this category Follow this category by RSS