Key Takeaways
- The European Commission formally withdrew the ePrivacy Regulation proposal on October 6, 2025, after eight years of stalled negotiations. It is not delayed. It no longer exists as a pending law.
- The ePrivacy Directive (2002/58/EC), the law the Regulation was meant to replace, remains the sole governing framework for cookies, tracking, and electronic-communications privacy across the EU, with no successor in force or in progress.
- Because it's a Directive rather than a Regulation, each EU member state implements it through its own national law, which is why cookie-consent specifics still vary somewhat country to country, something a single Regulation was originally meant to standardize.
- Any content still describing the ePrivacy Regulation as "expected to pass," "in trilogue," or "coming into force" in 2026 or any future year is working from outdated information. There is no active EU-level effort to revive it as a standalone Regulation.
- Cookie-consent rules aren't standing still, though: the EU's November 2025 Digital Omnibus package proposes folding them directly into GDPR via new Articles 88a and 88b, including a rule banning re-prompting a visitor who refused consent for at least six months.
- Nothing about day-to-day GDPR and cookie-consent compliance changes because of the withdrawal. The rules that already applied under the Directive and GDPR continue to apply exactly as they did before.
The EU's long-anticipated ePrivacy Regulation, meant to replace the 2002 ePrivacy Directive with a single, directly-applicable EU-wide law on cookies and electronic communications, was formally withdrawn by the European Commission on October 6, 2025. It isn't stalled again or pushed to a later year: the proposal no longer exists, and the Commission has given no indication it plans to introduce a replacement. Below: what actually happened, why it collapsed after eight years of negotiation, and what governs cookie consent and electronic-communications privacy in the EU now that it's gone.
Secure Privacy is a cookie and consent management platform built for the law that's actually in force, generating ePrivacy Directive- and GDPR-compliant consent banners across every EU member state's own national implementation, not a single hoped-for future standard.
| Category | ePrivacy Directive (in force) | ePrivacy Regulation (withdrawn) | Digital Omnibus Articles 88a/88b (proposed) |
|---|---|---|---|
| Status | Currently governs, via national implementation | Withdrawn Oct 6, 2025; no longer exists | Proposed Nov 2025; under negotiation, not yet adopted |
| Legal form | Directive (each member state implements separately) | Would have been a Regulation (direct EU-wide effect) | Amendment to GDPR itself, not a standalone law |
| Applies uniformly across the EU? | No, varies by national implementation | Would have, if adopted | Yes, once adopted, as part of GDPR |
| Enforced by | A mix of telecoms regulators and data protection authorities, depending on member state | N/A, never adopted | Consolidated under GDPR's data protection authorities |
| Re-consent after refusal | No EU-wide minimum wait period specified | N/A | Minimum 6 months before re-prompting for the same purpose |
What Happened to the ePrivacy Regulation?
The European Commission proposed the ePrivacy Regulation in January 2017, intending it to replace the ePrivacy Directive with a single directly-applicable law across all EU member states, the same legal mechanism GDPR uses. It never got there. The proposal spent years cycling through Council rejections and successive EU presidencies attempting new drafts, with no version ever securing enough member-state agreement to proceed to final negotiation.
The Commission's own 2025 Work Programme, published February 11, 2025, announced its intent to withdraw the proposal, citing an "absence of foreseeable agreement" among member states after years of deadlock. The Commission formally approved the withdrawal on July 16, 2025, and it took effect with publication in the EU's Official Journal on October 6, 2025. The European Parliament's own Legislative Observatory now lists the procedure's status as simply "lapsed or withdrawn." There is no draft currently under negotiation, and no announced timeline for a replacement effort.
This is worth stating clearly because so much existing content, on this site and elsewhere, still frames the Regulation as a matter of "when," not "if." Any source citing a specific expected passage year, a draft number, or a projected grace period for the ePrivacy Regulation is describing a proposal that the EU itself has already closed the book on.
What Actually Governs Cookies and Tracking in the EU Now?
The ePrivacy Directive (2002/58/EC, as amended by 2009/136/EC) remains the operative law, exactly as it has been since before the Regulation was ever proposed. Because it's a Directive rather than a Regulation, it doesn't apply directly; each EU member state transposes it into its own national law, which is why the specific mechanics of cookie consent (exact banner wording requirements, enforcement posture, penalty amounts) still differ somewhat from one member state to another, Germany's TTDSG and the UK's post-Brexit PECR being two commonly cited examples of that variation in practice.
GDPR sits alongside the Directive rather than replacing it: the Directive governs the narrower question of when consent is required to access or store information on a user's device (cookies, local storage, tracking pixels), while GDPR governs what happens to any personal data collected once that access has occurred. A compliant cookie banner still has to satisfy both frameworks together, exactly as it did before the Regulation proposal existed at all: valid consent under the Directive's national implementation, and a lawful basis and proper handling of whatever data that consent unlocks under GDPR.
Why Did the ePrivacy Regulation Fail to Pass?
The core, recurring sticking point across every failed draft was disagreement among member states over how far the Regulation should restrict metadata analysis, tracking-based advertising, and the balance between user consent and legitimate business use of communications data. Successive Council presidencies each attempted a compromise text, and each one drew enough objections from a different bloc of member states that no version ever cleared the threshold needed to move to trilogue negotiations with Parliament and the Commission on stable footing. Eight years of that pattern, without a version ever converging toward consensus, is what the Commission's own "absence of foreseeable agreement" language in its withdrawal notice was describing.
Is a New Version of the ePrivacy Regulation Coming?
Not as a standalone Regulation, but cookie-consent rules are being rebuilt somewhere else. In November 2025, the European Commission published its Digital Omnibus package, which folds cookie-consent obligations directly into GDPR itself through two new provisions rather than reviving a separate ePrivacy law: Article 88a restructures how consent for accessing a device (cookies, local storage, fingerprinting) works, and Article 88b makes browser-level consent signals legally binding on the businesses receiving them. Both are still proposals under negotiation, not adopted law, with Article 88a taking effect six months after formal adoption and Article 88b's browser-signal requirement following within 24 months.
The most operationally significant piece is Article 88a's six-month re-request rule: once a visitor refuses consent for a purpose, a business can't re-prompt for that same purpose for at least six months. Most cookie banners today re-surface on every visit or after a short interval, which would be a violation the moment this provision takes effect. Enforcement also consolidates under GDPR's data protection authorities, replacing the current patchwork where some EU member states enforce cookie rules through telecoms regulators instead. A dedicated breakdown of exactly what Article 88a and 88b require covers the compliance mechanics in full; the short version here is that this is a real, live development, not a revival of the withdrawn Regulation under a new name, and not something to wait out.
Compliance itself doesn't get simpler or harder because of this news; it stays exactly what it already was. A consent platform that already handles the Directive's national variations across EU member states, rather than assuming a single EU-wide standard was about to arrive, was never depending on the Regulation passing in the first place. Secure Privacy's banners are built against the Directive's actual national implementations and GDPR today, not a future law that no longer exists.
FAQ
Is the ePrivacy Regulation still coming?
No. The European Commission formally withdrew the proposal, effective October 6, 2025, after eight years without member-state agreement. No replacement has been announced.
What replaced the ePrivacy Regulation?
Nothing. The ePrivacy Directive (2002/58/EC), the law already in force before the Regulation was ever proposed, remains the governing framework, alongside GDPR.
What's the difference between the ePrivacy Directive and the ePrivacy Regulation?
The Directive is already in force and is implemented differently by each EU member state through national law. The Regulation would have applied directly and uniformly across the entire EU without national implementation, the same way GDPR does, but it was withdrawn before ever being adopted.
Does the ePrivacy Directive's withdrawal-adjacent news change how cookie banners need to work?
No. Nothing about actual cookie-consent or GDPR compliance obligations changed. The rules already in force under the Directive's national implementations and GDPR continue to apply exactly as before.
Is anything replacing the withdrawn ePrivacy Regulation?
Not as a standalone Regulation. The EU's November 2025 Digital Omnibus package proposes moving cookie-consent rules directly into GDPR through new Articles 88a and 88b instead, including a rule barring re-prompting a visitor who refused consent for at least six months. It's still a proposal under negotiation, not adopted law.
Why did the ePrivacy Regulation take so long and ultimately fail?
Member states repeatedly disagreed over how strictly to regulate metadata analysis and tracking-based advertising versus legitimate business use of communications data. No compromise draft across eight years and multiple Council presidencies secured enough support to proceed to final negotiations.




