The requirement to obtain consent before setting cookies isn't found in the GDPR — it's older, and comes from a different law: the ePrivacy Directive, formally Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in electronic communications. It was adopted on 12 July 2002, at a time when cookies were mainly used for login sessions and basic personalisation — cross-site tracking was technically possible, but not yet a mass phenomenon.
In its original form, Article 5(3) of the Directive required little more than informing users about cookies and giving them a way to object — an opt-out model. Doing nothing counted as implicit consent. In practice, that often meant a small notice buried somewhere on the page that almost no one read, with cookies already set before anyone had even noticed the notice.
That changed with Directive 2009/136/EC of 25 November 2009, which rewrote Article 5(3) from the ground up — commonly known as the "Cookie Directive," even though formally it's only an amendment to the original ePrivacy Directive. The opt-out model became a genuine consent requirement: cookies that aren't strictly necessary to provide a service the user explicitly requested may only be set after the user has given informed consent — not after the fact, not silently.
The reason for this tightening lay in the rapid growth of the online advertising market during the 2000s: tracking cookies became the foundation of entire business models, and user profiles were built from data flowing together across ten, twenty, a hundred different websites — usually without the people concerned even knowing. European lawmakers responded by reversing the burden: it was no longer the user who had to object, but the website that had to obtain consent.
It's important to understand that the ePrivacy Directive is a directive, not directly applicable EU law like a regulation. Directives set a goal that each member state must transpose into its own national law — and that transposition is exactly where the real trouble lay for years. The deadline for transposition was 25 May 2011, yet many member states — Germany among them — adopted the new consent requirement only reluctantly, or in a form that stayed close to the old opt-out logic. How Germany eventually resolved this is the subject of its own post in this series.
To this day, the ePrivacy Directive remains the actual legal basis for cookie consent itself — not the GDPR, which only became applicable in 2018 and governs a different, if closely related, matter: the handling of personal data in general. The two laws interlock, and exactly how they do so is the topic of the next post.
A planned successor, the ePrivacy Regulation, was originally meant to replace the directive and take effect as directly applicable law requiring no national transposition. It has been under negotiation between the EU institutions for years and has not yet been adopted — until it is, the 2002/2009 directive remains the governing basis.
For website operators, this history is worth understanding because it shows that cookie consent didn't emerge as a reaction to a single scandal, but as a gradual response to a practice that had grown over years. The 2009 rule wasn't a surprise — it was the logical continuation of an idea already set out in 2002: access to someone else's device is not a neutral technical act, but an intervention that requires justification.
