A startup pitch says “GDPR equals cookie law.” Which correction should privacy counsel give?
Select an answer to reveal the explanation.
Short Explanation
Calling GDPR “the cookie law” is like calling traffic code “the parking-meter statute.” GDPR is the big personal-data rulebook; ePrivacy is the specialist chapter for cookies, terminal equipment, and electronic communications. They talk to each other on a website, but they are not the same instrument.
Full Explanation
Regulation (EU) 2016/679 establishes general principles and obligations for processing personal data. Specific rules on confidentiality of communications and storage of or access to information in terminal equipment (commonly engaged by cookies) arise primarily from the ePrivacy Directive framework, which operates alongside the GDPR. Equating GDPR with a standalone cookie statute misstates both instruments. US CAN-SPAM and NIS 2 are not the correct primary substitutes for that analysis.