Guides

Cookie banners and UK law in 2026: what PECR, UK GDPR and the ICO actually require

UK cookie rules come from PECR, with UK GDPR setting the consent standard and the Data (Use and Access) Act 2025 adding new exemptions. What a compliant banner needs, how to check yours and what fixing it costs.

By the WE-DEV teamUpdated 8 min read
A stack of three chocolate chip cookies on a white marble surface scattered with chocolate chips

In the UK you need a cookie banner whenever your website stores or reads anything on a visitor’s device that is not strictly necessary, which in practice means most advertising pixels, social media embeds and remarketing tags, and many analytics set-ups. The rule comes from the Privacy and Electronic Communications Regulations (PECR), and the consent itself must meet the UK GDPR standard: freely given, specific, informed and given by a clear positive action. The ICO expects non-essential tags to stay blocked until someone agrees, “Reject all” to be as easy as “Accept all”, no pre-ticked boxes, and an easy way to change your mind later. The Data (Use and Access) Act 2025 relaxed the rules for some low-risk cookies, such as basic first-party analytics, but most business sites running ads or marketing tags still need a proper consent banner.

Below is what that means for a normal UK business website: which cookies need consent, what changed in 2025, what a compliant banner looks like, how to check yours in ten minutes, and what fixing it costs. It is general information, not legal advice.

Where the rules come from

  • PECR, regulation 6, says you must not store or access information on a user’s device unless you give clear information and get consent, unless an exemption applies. It is technology-neutral: cookies, local storage, tracking pixels, device fingerprinting and SDKs in apps are all covered.
  • UK GDPR defines what valid consent looks like, and applies separately to any personal data you collect through those technologies.
  • The Data (Use and Access) Act 2025 amends PECR, adding new consent exemptions and raising the maximum fines. Its provisions have been brought into force in stages since it received Royal Assent in June 2025.

The Information Commissioner’s Office (ICO) enforces all three. Cookie compliance has been an active enforcement area: the ICO has written to operators of many of the UK’s most visited websites about their banners, and in 2025 said it was reviewing the top 1,000 UK websites. Smaller sites are less likely to be first in line, but complaints from visitors and competitors do reach the ICO, and the fixes are cheap.

TypeExamplesConsent needed?
Strictly necessaryShopping basket, login session, CSRF and fraud protection, load balancing, storing the consent choiceNo
SecurityBot detection, protecting a login formNo (strictly necessary, and now an explicit exemption)
Basic analytics for your own sitePage views and visits used only to improve your site, not shared for the provider’s own purposesPossibly not, under the DUAA exemption, if you give clear information and an easy opt-out
PreferencesRemembering language, region or text size chosen by the userPossibly not, under the DUAA functionality exemption, with information and opt-out
Advertising and remarketingMeta Pixel, Google Ads, LinkedIn Insight Tag, TikTok PixelYes
Social and video embedsYouTube, Instagram, X embeds and share buttons that set tracking cookiesYes, unless loaded only on click or in a privacy-enhanced mode
Third-party analytics with data sharingAnalytics linked to ad platforms or used for the provider’s own purposesYes

Two traps catch people. First, “first-party” does not mean exempt: a first-party cookie used for advertising still needs consent. Second, being useful to your business does not make something strictly necessary. The test is whether it is essential to the service the user has asked for.

What the Data (Use and Access) Act 2025 changed

The Act is the first significant change to UK cookie rules in years, and it moves the UK away from the EU on this point. The main changes:

  • New exemptions from consent for certain low-risk purposes: collecting statistical information to improve your own website or service, adapting how the site looks or works to the user’s preferences, security and fraud prevention, and locating someone in an emergency. The analytics and preference exemptions only apply if users get clear information and a simple, free way to object.
  • Much higher fines. PECR penalties now align with UK GDPR: up to £17.5 million or 4 % of global annual turnover, whichever is higher. Previously the cap was £500,000.

What it does not change: advertising, remarketing and cross-site tracking still need opt-in consent. So does analytics where the data is shared with a third party that uses it for its own purposes, such as linking it to advertising profiles. Whether your specific analytics set-up fits the exemption depends on how the tool is configured, so check the ICO’s current guidance on storage and access technologies before switching consent off. If you also have EU visitors in volume, remember the EU rules have not relaxed in the same way.

What this means in practice

  • A brochure site with privacy-focused, first-party analytics and no ad tags may no longer need an opt-in banner, but still needs clear information and an opt-out link.
  • A site running Google Ads conversion tracking, Meta Pixel or remarketing still needs a full consent banner. That is most businesses that pay for online advertising.
  • An online shop almost always uses marketing tags somewhere, so assume you need a banner.
  1. Non-essential tags are blocked until consent. Nothing that needs consent should load on the first page view. This is the most common failure we find, and the one the ICO has focused on.
  2. “Accept all” and “Reject all” on the first layer, with equal prominence. Same size, same style, same number of clicks. A big green Accept beside a grey “Manage settings” link is the classic non-compliant pattern.
  3. Plain-English explanation of each category and who sets it, with a link to a cookie policy listing the actual cookies.
  4. No pre-ticked boxes for non-essential categories.
  5. No consent by scrolling or “by continuing to browse you accept”. Consent needs a clear action.
  6. Easy to change your mind, for example a “Cookie settings” link in the footer on every page. Withdrawing should be as easy as agreeing.
  7. Consent is recorded (what was chosen, when, and against which version of the banner), so you can show it later.
  8. Accessible. Usable by keyboard and screen reader, readable contrast, focus moved to the banner sensibly. A banner that traps keyboard users is an accessibility barrier as well as a consent problem; see our guide to website accessibility and UK law.

Cookie walls and “consent or pay”

Blocking the whole site until someone accepts cookies is unlikely to give valid consent, because it is not freely given. The ICO has published guidance on “consent or pay” models used by some publishers, with strict conditions around fairness and the price of the alternative. For an ordinary business website, don’t use a cookie wall.

If you use Google Analytics or Google Ads with UK or EEA visitors, Google requires consent signals to be passed through Consent Mode (version 2). Your banner should integrate with it so Google tags respect the visitor’s choice. There are two set-ups:

  • Basic mode: Google tags do not load at all until the visitor consents. Simplest to defend.
  • Advanced mode: tags load before consent but send cookieless “pings” that Google uses for modelling. More data for your reports, but harder to square with PECR unless you are confident an exemption applies. Get advice before choosing it.

Consent Mode does not replace a compliant banner; it is how Google’s tags receive the answer. The same goes for server-side tagging: moving tags to your own server does not remove the need for consent if the purpose still requires it.

Common mistakes we find on UK sites

  • Analytics and ad tags hard-coded into the theme, so they fire regardless of the banner.
  • Tags added to Google Tag Manager without consent triggers, typically by a marketing agency after the site launched.
  • A banner that records a choice but blocks nothing.
  • Cookie policies that list cookies from a plugin removed two years ago, and miss the five added since.
  • YouTube videos and Google Maps setting cookies on page load. Use privacy-enhanced YouTube embeds or click-to-load placeholders for both.
  • Chat widgets and heatmap tools loading before consent. They are usually not strictly necessary.
OptionTypical costGood forWatch out for
Free WordPress consent pluginFree to around £50 a yearSmall sites with a few tagsOften needs manual tag blocking; check it really blocks
Hosted consent platform (CMP)Roughly £5–£50+ a month, priced by pages or trafficSites with many tags, multiple domains, EU trafficHeavy scripts can hurt speed; auto-scanners miss things
Custom lightweight bannerA few developer hoursSites we build where performance mattersNeeds a developer to update categories

Whichever you choose, a heavy consent script can slow the page, and a banner that pushes content down causes layout shift. Overlay the banner rather than inserting it above the content, load the script early but efficiently, and check the effect on your Core Web Vitals.

Check your own site in ten minutes

  1. Open your site in a private browser window.
  2. Before clicking anything, open developer tools (F12) and look at the Application tab for cookies and local storage, and the Network tab for requests to analytics and ad domains. Anything marketing-related at this point is loading before consent.
  3. Click “Reject all”, reload, and check again. Nothing non-essential should appear.
  4. Accept, then check the expected tags now load. If they don’t, your consent set-up is also costing you data.
  5. Find the link to reopen cookie settings. It should be on every page.
  6. Try the banner with the keyboard only: Tab, Enter, Escape.
  7. Compare what you found with your cookie policy and update it.

Repeat this whenever you add a plugin, a tracking tag, a chat widget or an embedded video. It belongs in the yearly review of any sensible WordPress maintenance plan.

What fixing it costs

On a typical WordPress site, a consent audit and fix takes us between two and six hours: list everything the site sets, put a compliant banner in place, move tags behind consent (including in Tag Manager), wire up Google Consent Mode and rewrite the cookie policy. At our WordPress rate of £50/h + VAT that is £100 to £300 before VAT. If you are combining it with other jobs, a 10-hour bank costs £500 − 5 % = £475 + VAT £95 = £570, and the unused hours never expire. You can book hours online.

On every site we build, consent is set up from day one: a light, accessible banner, tags that wait for consent, Consent Mode where needed and a cookie policy that matches reality. See our web development service for new builds and cybersecurity services for wider data protection work. Our team is based in St Albans and works with businesses across the UK. The ICO’s guidance remains the authoritative source; we are happy to check how your site behaves against it.

Frequently asked questions

Do I need a cookie banner if I only use Google Analytics?

Probably, unless your set-up fits the analytics exemption added by the Data (Use and Access) Act 2025. That exemption covers statistics used only to improve your own site, with clear information and an easy opt-out. Google Analytics linked to Google Ads or Google Signals is unlikely to fit. Check the ICO's current guidance for your configuration.

Does my cookie banner need a 'Reject all' button?

The ICO expects rejecting non-essential cookies to be as easy as accepting them. In practice that means a 'Reject all' option on the first layer of the banner with the same prominence as 'Accept all'.

Which cookies don't need consent in the UK?

Strictly necessary cookies (basket, login, security, storing the consent choice) never need consent. Since the Data (Use and Access) Act 2025, some analytics and preference cookies can also be exempt if you give clear information and a simple way to object. Advertising and cross-site tracking always need consent.

What are the penalties for getting cookies wrong?

The ICO can issue reprimands, enforcement notices and fines. The Data (Use and Access) Act 2025 raised the maximum PECR fine from £500,000 to UK GDPR levels: up to £17.5 million or 4 % of global annual turnover, whichever is higher.

Is a cookie policy enough without a banner?

No. If you use cookies or tags that need consent, you must get that consent before they are set. A policy explains what you use; it does not replace consent.

Do UK cookie rules apply to my EU visitors?

If you target customers in the EU, the EU ePrivacy rules and GDPR can also apply, and they have not been relaxed in the way the UK's have. Sites with significant EU traffic often keep an opt-in banner for analytics to satisfy both.

WE-DEVUK software and web development agency. We build websites, custom software, mobile apps and online shops, and write these guides from the projects we run every week.

Photo: Danny Kahn via Unsplash

Read next

Tell us what the business needs.

A developer replies within one working day. Fixed price or hourly, your choice — and the code is yours.