Skip to content
Privacy and law

What is ePrivacy Directive?

The ePrivacy Directive, often called the cookie law, is the EU rule that requires consent before storing information on, or reading information from, a visitor's device. It applies to the act of device storage itself, so it catches cookies, local storage and device fingerprinting regardless of whether the data collected is personal.

Explanatory, not legal advice. Implementations differ by member state and your obligations depend on your circumstances.

This is the most common confusion in the whole area. The banner requirement comes from ePrivacy, not the GDPR.

The distinction is precise and it matters:

Triggered byConsent needed for
ePrivacyStoring or reading data on a deviceAny non-essential storage, personal or not
GDPRProcessing personal dataDepends on the lawful basis chosen

So a cookie holding a random number that identifies nobody still needs consent under ePrivacy, because the storage is what is regulated. And conversely, analytics that stores nothing on the device never triggers this rule at all — which is the whole legal argument behind cookieless analytics.

The strictly necessary exemption

Consent is not required for storage that is strictly necessary to deliver a service the user explicitly requested — a session token for a logged-in area, a shopping-cart identifier, a load-balancer cookie.

Analytics has consistently not qualified. Regulators have been clear that measuring your audience is necessary for you, not for the visitor, however useful it is.

Directive, not regulation

Because it is a directive, each member state implements it in its own law, and the details differ. The UK’s version is PECR. A long-promised ePrivacy Regulation, which would apply uniformly, has been in negotiation for years without being adopted — so national variation remains the reality to plan around.

Questions

Frequently asked.

Cookies, install and pricing, answered. Still stuck? Ask us anything .

01 Can sonex show revenue next to my traffic?

Yes. Connect Stripe or Polar with a read-only key and sonex reads revenue straight from your payment provider, per website. Revenue then appears as a focusable series on the Overview chart and as its own report, beside the traffic that earned it. No tracked event is needed for it to work.

02 Does sonex use cookies?

No. sonex sets no cookies and needs no consent banner. It counts visits without cookies, fingerprinting, or any personal data, so it is GDPR, PECR and CCPA-ready by default.

03 How do I install sonex?

Add one script tag to your site's <head> with your website id. It is a single lightweight tracker — no build step and no SDK required.

04 Is sonex a Google Analytics alternative?

Yes. sonex gives you the reports that matter — visitors, pages, referrers, funnels, revenue and a world map — without surveilling your audience or drowning you in configuration.

05 How is sonex priced?

By monthly tracked events. Free covers 2k events, Pro is $20/mo for 200k events, and Business is $200/mo for 2M events with team seats.

See what your traffic actually earns.

Revenue beside the visitors that produced it. No cookies, no credit card, no consent banner.

Get started