A journalist in 2022 purchased location data for $160 that tracked visits to over 600 Planned Parenthood clinics across the United States. The records revealed visitor origins, duration of stays, and subsequent movements. Though the broker halted sales after publication, the underlying market persisted.
Similar trading in location records has surfaced in Europe. Journalists have accessed billions of commercially traded location records originating from Germany and Belgium. These datasets exposed movements near hospitals, religious buildings, trade union headquarters, government offices, military installations, EU facilities and NATO sites. Ordinary advertising-related apps can expose sensitive personal information, pinpoint public officials, and pose institutional security threats.
These cases highlight a distinction fundamental to EU law that may appear pedantic elsewhere. In the United States, 'privacy' encompasses the entire issue, whereas EU law recognizes two separate fundamental rights. Article 7 of the Charter of Fundamental Rights safeguards private life, home and communications, while Article 8 protects personal data.
The distinction carries weight: data protection governs what occurs when personal data undergo processing, whereas privacy and communications confidentiality also shield the space from which information originates. They establish a barrier against entering that space initially. The EU constructed the ePrivacy framework around this principle. ePrivacy establishes specific rules for communications confidentiality and access to information stored on or generated by devices, encompassing communications, metadata and location. The General Data Protection Regulation (GDPR) primarily addresses access to personal data—what organizations may do with data after processing. This distinction proves significant, yet it vanishes when 'privacy' becomes shorthand for data protection.
The law everyone notices in the wrong place
Most encounter ePrivacy through cookie banners, possibly the worst possible introduction. A framework addressing confidentiality appears as tedious rules about pop-ups, while the tracking sector points to the banners it created as evidence the law has failed. Article 5(3), the provision underlying many banners, governs when an actor may store or retrieve information from a person's terminal equipment. Yet it extends further: ePrivacy concerns the act of accessing the device itself.
"Terminal equipment" encompasses phones and laptops, connected cars, televisions, wearables, smart glasses and other Internet of Things devices. The rule covers fingerprinting, tracking pixels, local storage, operating-system identifiers and instructions directing a device to transmit information elsewhere. The underlying principle is straightforward: a device does not become subject to inspection merely because one data fragment cannot independently identify its user. ePrivacy additionally protects communications confidentiality and regulates traffic and location data held by communications providers. It restricts retention and reuse, addresses unsolicited communications, and establishes conditions under which Member States may limit confidentiality.
The ePrivacy Directive's scope has never aligned with how people engage with digital services. It was drafted around traditional telephone and communications providers, leaving many online services originally outside its protection. Messaging and webmail services may now fall within communications confidentiality rules, yet coverage depends on legal classifications invisible to users. The identical message, location history or device data receives different protection depending on whether the company qualifies as a telecom provider, messaging service or platform: under such conditions, does the law still safeguard the underlying right?
One framework, two surveillance systems
The distinction between GDPR and ePrivacy becomes crucial when examining surveillance. Commercial surveillance frequently begins before GDPR considerations arise, with access to a device or communications-related signal: an app may include a software kit collecting location data, or a television may record viewing patterns. These initial access points feed into systems of profiling, advertising, measurement and sale.
While GDPR remains essential once personal data enter that chain, ePrivacy poses the preceding question: May the provider use traffic or location data? Can a tracker access a device, or must a communication stay confidential? It does not govern the entire data-broker market, but it can restrict some sources supplying it.
The distinction similarly applies to state surveillance. ePrivacy has shaped one of Europe's most prolonged surveillance disputes: data retention. Governments have repeatedly sought to require providers to preserve traffic and location data for subsequent use by law enforcement and security agencies. Article 15 permits restrictions for public objectives, yet they remain subject to the Charter, including necessity and proportionality requirements in Article 52.
The resulting Court of Justice case law—from Digital Rights Ireland, Tele2 Sverige and Watson, La Quadrature du Net, SpaceNet and, more recently, HADOPI—has grown intricate. While the Court rejects general and indiscriminate retention of traffic and location data as standard practice, it permits targeted retention and certain limited forms of general retention.
A record documenting who contacted whom, when, for how long and from where can reconstruct a life without exposing the content of any single message. Repeated calls to an oncology department may disclose a diagnosis. A phone present at an abortion clinic, mosque, union office or demonstration may reveal health, religion, employment relations or political activity.
This is why ePrivacy matters: the metadata can be revealing long before anyone even reads the message.
Commercial and state surveillance operate through different powers and safeguards. Yet they increasingly rely on identical infrastructure. In the United States, ICE and Customs and Border Protection purchased access to phone-location data collected through ordinary apps and distributed by brokers. The authorities did not construct their own tracking system; the advertising industry had already gathered people's movements at scale.
Spyware renders the overlap even starker. Pegasus-type tools are developed and sold by private companies, then deployed by public authorities against journalists, activists, lawyers and opposition figures. They can penetrate a phone, access communications and metadata, monitor location, and activate microphones or cameras. The European Data Protection Supervisor has explicitly linked spyware deployment to the ePrivacy Directive where EU law applies, and characterized the phone as a person's "virtual domicile." A commercial market is selling the capacity to enter the devices and communications that ePrivacy is meant to protect.
ChatControl made the boundary visible
Proposals commonly referred to as "ChatControl" have rendered this question unusually tangible. Can communications stay confidential when private providers scan them for a public-policy objective? The legal connection is direct. Once many messaging and webmail services fell within ePrivacy's confidentiality rules, practices previously assessed mainly under GDPR now also had to comply with Articles 5 and 6 of the ePrivacy Directive, which protect communications and traffic data. This meant providers wishing to continue voluntary scanning could no longer depend on a GDPR legal basis alone, but also required a specific exception from confidentiality rules.
The EU adopted Regulation 2021/1232 for this purpose. It created a temporary derogation permitting providers, on a purely voluntary basis and subject to conditions, to employ technologies detecting and reporting child sexual abuse material and the solicitation of children, without establishing a legal basis for scanning. While negotiations on a permanent framework continue, the co-legislators have twice renewed the derogation with increasing reluctance.
The need for a derogation is significant: a GDPR legal basis does not grant passage through the ePrivacy door; both layers must be satisfied. ChatControl also demonstrates the blurred distinction between private and public surveillance. The service and technical infrastructure are private, but the objective and legal pressure originate from public authorities. People use confidential communications to speak with lawyers, doctors, journalists, family members and support organizations, to organize politically, report wrongdoing and seek help. Article 52 requires any restrictions to that space to be lawful, necessary and proportionate. This matters, even if the objective pursued is worthy.
How the EU made its confidentiality law look obsolete
The ePrivacy Directive is indeed outdated. It originates from 2002—with its most prominent amendment in 2009—its language reflects an earlier telecoms market; its enforcement is inconsistent, both in terms of insufficiencies and lack of harmonization, and cookie banners have become a tool for manipulation rather than meaningful choice. However, the EU did attempt to replace it.
In 2017, the Commission proposed an ePrivacy Regulation addressing internet-based communications, metadata, tracking technologies and connected devices. However, industry groups contended that GDPR was adequate, demanded greater flexibility for further processing and opposed stronger limits on tracking. Civil society, consumer organizations and data protection authorities sought stronger confidentiality and improved protection for metadata and devices. Member States disagreed over scope, enforcement, exceptions and data retention. Following years of negotiations, the Commission withdrew the proposal in 2025.
The Commission is not a neutral observer in what followed. It proposed the ChatControl framework and its temporary derogation, is developing a new EU approach to data retention, and has now proposed moving important terminal-equipment rules into the GDPR through the Digital Omnibus. Industry, the Commission and Member States do not constitute a single alliance. Their interests frequently diverge: companies seek more room to use device and communications-related data for advertising, analytics and AI; many governments want providers to retain data for law-enforcement access; and the Commission wants to show simplification while expanding lawful-access tools. The net result is pressure to treat confidentiality as friction requiring an exception, derogation or more flexible legal regime.
What changes when device access moves into the GDPR
The Digital Omnibus was fundamentally inadequate from the start, yet attempted to address one genuine problem: people are exhausted by banners that repeat the same question, conceal the refusal button or transform privacy into an endurance test. However, simplifying the consent should not entail simplifying the rights away.
The Commission's proposal maintains consent as the general rule for storing or accessing personal data on a person's device, while broadening exceptions. Yet it would divide the same act between two regimes. Access to personal data would fall under GDPR, while other information could remain under ePrivacy. Oversight would also shift towards the GDPR's one-stop-shop system, whose record in holding large technology companies accountable has been weak. Much of industry is pushing for more, with some companies seeking to access devices aligned with all GDPR legal bases, including legitimate interest.
A business interest in advertising, analytics, security, service improvement or AI development may explain what a company wants to do with information. However, it does not, by itself, answer whether the company is allowed to enter the device in the first place. There is a better response to the so-called cookie fatigue. People should be able to express privacy choices—both refusal and consent—once through browsers, operating systems, apps or other user-side tools, and services should have to respect those machine-readable signals. This would eliminate many banners without removing the boundary.
The EU also needs clearer rules for new communications services, consistent enforcement, and updated protection for metadata, location and connected devices. It needs an honest debate about state access too. A future data-retention law will determine how far governments can turn the records of ordinary communications into a standing investigative resource.
The peculiar aspect of ePrivacy is that people tend to notice it when it is ineffective and to overlook it when it matters most. We see the banner, but rarely the rule limiting a provider's use of location data, the judgments against indiscriminate retention, or the need for a derogation before private messages can be scanned. This invisibility has made ePrivacy easy to attack. Industry can reduce it to cookies. Governments can describe confidentiality as an obstacle to investigations. The Commission can call the remaining division between ePrivacy and GDPR unnecessary complexity.
The EU's ad hoc distinction between privacy and data protection remains valuable: connected cars, smart televisions, phones and always-on communication devices expose more than ever our everyday lives. As the boundary between the physical world and the digital world thins, so does the idea that privacy is only about data collected. That's why a crucial protection is stopping someone from accessing it in the very first place.
Source: EDRi (European Digital Rights)



