Article content
In briefShow moreShow lessThe guidance covered more than traditional cookies.
- The guidance covered more than traditional cookies.
- Pixels, links, local processing, IP-only tracking, IoT reporting and unique identifiers may, depending on the technical facts, involve access to or storage on terminal equipment.
- It addressed the provision’s technical scope, not a GDPR amendment or a final rule on consent mechanics and exemptions.
The EDPB’s approach focused on what a technology does rather than on its commercial label or implementation format. The central question is whether a service accesses information on terminal equipment or stores information there. That makes the analysis relevant even where a solution does not use a conventional cookie.
URL-based tracking methods and pixels formed part of the technical assessment. A link or image address can be used to transmit identifiers or other information between a terminal and a service. The practical operation of the system, rather than its description in product material, determines whether Article 5(3) may be engaged.
The guidance also addressed local processing and methods based on IP addresses. Processing information locally, or using an IP address instead of writing a device identifier, does not automatically take a technique outside Article 5(3). Organisations must examine how information is obtained, stored and used.
Connected devices and IoT reporting raised similar issues. Communications from an IoT device may involve the same access or storage questions as browser tracking when information is retrieved from or placed on the equipment. Unique device or user identifiers therefore require a factual assessment of their technical role and context.
The document concerned the technical scope of the ePrivacy provision. It did not create a new general consent rule, amend the GDPR or finally determine every exemption. Consent mechanics and exemptions still require separate analysis under the applicable rules and national practice.
For Norwegian organisations, this was not a Norwegian legal amendment. The guidance interpreted an EU directive whose cookie rules are implemented nationally. Businesses should verify the corresponding Norwegian electronic-communications rules and the final guideline version before treating particular details as settled.
Technical review should therefore cover browser requests, identifiers in URL parameters and information processed locally by scripts or apps. Teams should record the signal that activates each operation, whether third-party code loads before a choice, and whether rejection stops later access. This connects legal analysis to observable network traffic.
Sources
European Data Protection Board: “EDPB provides clarity on tracking techniques,” 15 November 2023.
European Data Protection Board: “Guidelines 2/2023 on Article 5(3) ePrivacy,” 14 November 2023.
For discussion
Have we mapped every technical operation that accesses or stores information on user equipment?

