In 2022, a journalist purchased location data for $160 that tracked movements at more than 600 Planned Parenthood clinics across the United States over seven days. The records revealed visitor origins, duration of stays, and subsequent destinations. Though the data broker discontinued the product following publication, the underlying market persisted.
Comparable surveillance markets have taken root in Europe. Journalists have accessed billions of commercially available location records originating from Germany and Belgium. These datasets exposed patterns of movement near hospitals, places of worship, union headquarters, government buildings, military installations, European Union offices and NATO facilities. Ordinary advertising applications can harvest information exposing the most intimate aspects of daily existence, pinpoint government workers and threaten institutional security.
These cases highlight a conceptual split embedded in what outsiders often call 'EU privacy law'—a distinction that may appear pedantic to international observers. American legal frameworks typically treat 'privacy' as addressing the entire concern, whereas European law recognizes two separate fundamental rights. Article 7 of the Charter of Fundamental Rights safeguards private life, residence and communications, while Article 8 safeguards personal data.
This separation carries substantial weight: data protection primarily addresses what occurs when personal information undergoes processing, whereas privacy and communications protection also shield the origin point from which information emerges. They establish a threshold preventing entry into that space initially.
The EU structured the ePrivacy framework around this principle. ePrivacy establishes particular rules governing communications confidentiality and device access—including rules for communications, metadata and location information. The General Data Protection Regulation (GDPR), by contrast, chiefly manages personal data access—what entities might accomplish with information after obtaining it. This distinction proves significant, yet becomes obscured when 'privacy' functions as shorthand for data protection.
The law everyone notices in the wrong place
Most individuals encounter ePrivacy through cookie notifications, arguably the least suitable introduction possible. A framework addressing confidentiality appears as a burdensome collection of rules about pop-ups, while the tracking sector points to these notifications—which it helped design—as evidence that the law has collapsed.
Article 5(3), the provision underlying numerous banners, governs when someone may place information on, or retrieve information from, a person's device. Yet its scope extends further: ePrivacy concerns itself with the act of device access itself.
'Terminal equipment' encompasses mobile phones and computers, internet-connected vehicles, television sets, wearable devices, augmented-reality glasses and additional Internet of Things components. The rule addresses fingerprinting, tracking pixels, stored data, device identifiers and operations directing a device to transmit information elsewhere. The underlying logic remains uncomplicated: a device does not become subject to examination merely because one data element cannot independently identify its owner.
ePrivacy additionally protects communications confidentiality and supervises traffic and location information retained by communications companies. It constrains retention periods and reuse, addresses unsolicited communications, and establishes circumstances permitting Member States to limit confidentiality.
The ePrivacy Directive's application has consistently diverged from contemporary digital service usage. Its drafting centered on conventional telephone and communications operators, resulting in numerous online services originally falling outside its protections. Instant messaging and webmail platforms may now qualify for communications confidentiality safeguards, yet coverage hinges on legal classifications invisible to users. Identical messages, location sequences, or device information can receive varying protection contingent on whether an organization qualifies as a telecom provider, messaging platform, or service provider: under such circumstances, does the law genuinely defend the underlying entitlement?
One framework, two surveillance systems
The separation between GDPR and ePrivacy grows increasingly significant when examining surveillance mechanisms. From a commercial angle, tracking frequently commences before GDPR considerations materialize, beginning with device access or communications-related signals: an application might incorporate software that gathers location information, a television might document viewing patterns. These initial access points fuel systems of behavioral analysis, targeted marketing, measurement and commercial exchange.
Though GDPR remains vital once personal information enters that sequence, ePrivacy addresses the antecedent question: Does the provider possess authorization to employ traffic or location information? Can a tracking mechanism access a device, or must a communication stay protected? It does not govern the complete data-broker ecosystem, yet it can restrict certain sources supplying it.
This distinction similarly applies to governmental surveillance. ePrivacy has influenced one of Europe's most protracted surveillance controversies: data retention. Authorities have repeatedly sought to require providers to preserve traffic and location information for subsequent deployment by law-enforcement and intelligence agencies. Article 15 permits restrictions for public purposes, though they remain subject to the Charter, encompassing necessity and proportionality standards under Article 52.
The resulting Court of Justice jurisprudence—spanning Digital Rights Ireland, Tele2 Sverige and Watson, La Quadrature du Net, SpaceNet and, most recently, HADOPI—has grown intricate. Though the Court rejects sweeping and indiscriminate retention of traffic and location information as standard practice, it permits focused retention and certain constrained retention categories.
Information documenting communication partners, timing, duration and location can reconstruct an existence without exposing any message substance. Frequent contact with an oncology clinic might disclose medical status. A telephone present at an abortion facility, mosque, labor organization or public gathering might indicate medical condition, religious conviction, employment circumstances or political engagement.
This explains ePrivacy's importance: metadata can disclose substantial information long before anyone examines message content.
Commercial and governmental surveillance employ distinct authorities and protections. Nevertheless, they increasingly depend on identical systems. In the United States, Immigration and Customs Enforcement and Customs and Border Protection obtained phone-location information gathered through standard applications and marketed by commercial intermediaries. Authorities did not construct independent tracking infrastructure; the advertising sector had already assembled population-scale movement records.
Surveillance software amplifies this convergence. Pegasus-category instruments are manufactured and distributed by private enterprises, subsequently deployed by state bodies targeting journalists, civil-rights advocates, attorneys and political opponents. They penetrate devices, obtain communications and metadata, monitor location, and activate recording devices or cameras. The European Data Protection Supervisor has explicitly linked spyware deployment to the ePrivacy Directive where EU law operates, characterizing the smartphone as a person's "virtual domicile." A commercial sector is commercializing the capacity to breach the devices and communications that ePrivacy intends to safeguard.
ChatControl made the boundary visible
Proposals designated "ChatControl" have rendered this question unusually tangible. Can communications maintain confidentiality when private organizations examine them for governmental objectives? The legal relationship is explicit. Once numerous messaging and webmail platforms entered ePrivacy's confidentiality protections, operations previously evaluated mainly under GDPR now required compliance with Articles 5 and 6 of the ePrivacy Directive, which safeguard communications and traffic information. This meant organizations wanting to maintain voluntary examination could no longer depend solely on a GDPR legal foundation, but also required a particular exception from confidentiality protections.
The EU enacted Regulation 2021/1232 addressing this requirement. It established a temporary exemption permitting organizations, entirely voluntarily and subject to stipulations, to deploy technologies for identifying and reporting child sexual exploitation material and child solicitation, without establishing a legal foundation for examination. As permanent framework discussions continue, the co-legislators have twice extended the exemption with mounting reluctance.
The exemption's necessity proves instructive: A GDPR legal foundation does not grant passage through the ePrivacy barrier; both requirements must be fulfilled.
ChatControl additionally demonstrates blurred distinctions between commercial and governmental surveillance. The platform and technical systems remain commercial, yet the purpose and governmental pressure originate from public bodies. Individuals employ protected communications to interact with legal representatives, healthcare providers, reporters, relatives and assistance organizations, to participate in political activity, disclose violations and request support. Article 52 mandates that any constraints on that space be lawful, essential and balanced. This remains relevant, regardless of the objective's merit.
How the EU made its confidentiality law look obsolete
The ePrivacy Directive genuinely requires updating. It originates from 2002—its most prominent revision occurring in 2009—its language reflects an earlier telecommunications environment; its application remains uneven, encompassing both inadequate enforcement and insufficient coordination, and cookie notifications have transformed into instruments of manipulation rather than authentic decision-making. The EU did pursue replacement.
In 2017, the Commission introduced an ePrivacy Regulation proposal encompassing internet communications, metadata, tracking mechanisms and internet-connected apparatus. However, business associations contended that GDPR sufficed, demanded expanded flexibility for subsequent processing and resisted stricter tracking limitations. Civil-society organizations, consumer advocates and data-protection officials sought enhanced confidentiality and reinforced metadata and device safeguards. Member States held divergent positions regarding scope, implementation, exceptions and data retention. Following prolonged discussions, the Commission abandoned the proposal in 2025.
The Commission occupied a non-neutral position in subsequent developments. It formulated the ChatControl framework and its temporary exemption, is advancing a revised EU data-retention approach, and has now proposed transferring critical device-access rules into the GDPR via the Digital Omnibus.
Business, the Commission and Member States do not constitute a unified bloc. Their objectives frequently diverge: corporations seek expanded latitude for device and communications information deployment in marketing, measurement and machine learning; numerous authorities desire provider data retention for enforcement access; and the Commission aims to demonstrate simplification while strengthening authorized-access mechanisms. The cumulative consequence is momentum to characterize confidentiality as an impediment warranting an exemption, derogation, or more adaptable legal structure.
What changes when device access moves into the GDPR
The Digital Omnibus demonstrated fundamental inadequacy from inception, yet attempted addressing one legitimate concern: individuals experience fatigue from notifications posing identical questions, obscuring rejection options or converting privacy into an ordeal.
Streamlining authorization should not entail eliminating protections.
The Commission's proposal preserves authorization as the baseline for storing or retrieving personal information on a person's device, while broadening exemptions. However, it would partition the identical action between two legal systems. Personal-data access would fall under GDPR, whereas additional information could remain under ePrivacy. Supervision would additionally transition toward GDPR's unified enforcement mechanism, whose effectiveness in holding major technology firms responsible has proven inadequate.
Substantial portions of the business sector advocate for expansion, with certain organizations pursuing device access aligned with all GDPR legal foundations, encompassing legitimate organizational interest.
A commercial motivation in marketing, measurement, protection, operational enhancement, or artificial-intelligence advancement may clarify organizational objectives. However, it does not independently establish whether an organization possesses authorization to access the device initially. A superior response to the so-called cookie fatigue exists. Individuals should communicate privacy preferences—both rejection and authorization—once through web browsers, device operating systems, applications, or comparable user-controlled mechanisms, and platforms should comply with those machine-readable instructions. This would eliminate numerous notifications while preserving the protective boundary.
The EU additionally requires more explicit rules for emerging communications platforms, standardized implementation, and modernized safeguards for metadata, location information and internet-connected apparatus. It requires transparent discussion regarding governmental access. A forthcoming data-retention statute will establish the extent to which authorities can transform ordinary communications records into a perpetual investigative instrument.
The peculiar characteristic of ePrivacy involves its visibility pattern: individuals recognize it when it malfunctions and disregard it when it functions optimally. We observe the notification, yet seldom perceive the limitation on provider location-information deployment, the judicial determinations against sweeping retention, or the requirement for an exemption before private communications can undergo examination.
This obscurity has rendered ePrivacy susceptible to assault. Business interests can reduce it to notifications. Authorities can characterize confidentiality as an impediment to enforcement. The Commission can label the remaining separation between ePrivacy and GDPR as superfluous complexity.
The EU's foundational distinction between privacy and data protection retains significance: internet-connected automobiles, intelligent televisions, smartphones, and perpetually-active communication systems disclose more than previously of our everyday existence. As the distinction between tangible and digital environments narrows, so does the presumption that privacy concerns only information that has been gathered. This explains why a fundamental safeguard involves preventing access in the initial instance.
Source: Tech Policy Press



