ConsentPixel – Privacy · Verified

UK Compliance · PECR & ICO

UK Cookie Law 2026: What PECR and the ICO's New Guidance Actually Require

The ICO published finalised guidance on tracking technologies on April 29, 2026 — the most significant update to UK cookie rules since GDPR. The Data Use and Access Act raised PECR fines from £500,000 to £17.5 million. Three new cookie exemptions came into force in February 2026. This is the complete picture of what UK websites must do now — including what changed, what didn't, and where agencies are still getting it wrong.

By the ConsentPixel — Privacy · Verified team July 2026 13 min read For UK website owners and agencies
£17.5M
New maximum PECR fine under the Data Use and Access Act — up from £500,000. In force from February 2026.
Apr 29, 2026
ICO finalised new tracking technology guidance — now explicitly covers pixels, fingerprinting, and scripts
3 new
New PECR cookie exemptions in force from February 2026 — but advertising and analytics still require consent

UK cookie compliance sits at the intersection of two statutes and one regulator. PECR (Privacy and Electronic Communications Regulations 2003) creates the consent requirement for placing cookies. UK GDPR defines what valid consent looks like and applies when those cookies process personal data. Both are enforced by the ICO. The rules are broadly similar to EU GDPR, but the UK's post-Brexit path has produced some differences — including the new PECR exemptions and fine ceiling introduced by the Data Use and Access Act 2025. This article maps the current UK requirements precisely. Not legal advice; consult qualified counsel for specific situations.

PECR and UK GDPR: two laws, one regulator

Understanding the distinction between PECR and UK GDPR matters because they create overlapping but distinct compliance obligations:

PECR Regulation 6 creates the cookie consent obligation itself. It derives from the EU's ePrivacy Directive 2002/58/EC (transposed into UK law before Brexit) and requires that you must not store or access information in the terminal equipment of a user unless you have provided clear and comprehensive information about the purpose and the user has given consent. The "strictly necessary" exemption is narrow — it covers only what is genuinely required to deliver the service the user explicitly requested.

UK GDPR applies when cookies collect or process personal data — which analytics and advertising cookies always do, since they transmit IP addresses, device identifiers, and browsing behaviour. UK GDPR defines the quality and validity of consent: freely given, specific, informed, unambiguous, and documented. In practice, every analytics or advertising cookie deployment has two compliance layers: PECR requires consent before placement, and UK GDPR governs the quality of that consent and the evidence required to demonstrate it.

Both laws are enforced by the ICO, but under different penalty regimes — which the Data Use and Access Act has now substantially aligned.

What the Data Use and Access Act changed

The Data (Use and Access) Act 2025 received Royal Assent on June 19, 2025. Several key provisions relevant to cookie compliance came into force on February 5, 2026. Understanding what changed is essential for any UK website compliance review conducted in 2026.

Feb 5, 2026
In force

PECR fines raised to £17.5 million

Maximum PECR fine increased from £500,000 to £17.5 million or 4% of global annual turnover, whichever is higher — aligning with UK GDPR enforcement levels. Cookie violations now carry the same financial risk as major data protection failures.

Feb 5, 2026
In force

Three new cookie exemptions added to PECR

Statistical purposes, website appearance, and emergency assistance cookies may now be placed without consent under specific conditions. All three carry important limitations and do not cover advertising or marketing tracking of any kind.

Apr 29, 2026
In force

ICO finalised tracking technology guidance

Replaces the old "cookies guidance" with technology-neutral language explicitly covering cookies, tracking pixels, device fingerprinting, web storage, scripts, tags, and link decoration. Includes new sub-chapters on the DUAA exemptions and multiple purpose deployments.

Jun 19, 2026
In force

Formal data protection complaints procedure required

Organisations must have a documented procedure for receiving, processing, and responding to data protection complaints from individuals. An email inbox alone does not satisfy this requirement.

The three new cookie exemptions — and what they don't cover

The three new PECR exemptions that came into force in February 2026 are frequently misunderstood. Understanding their precise scope — and their limitations — is critical before relying on them to remove consent requirements from your site.

✓ New exemption

Statistical purposes

First-party analytics cookies whose sole purpose is collecting information about how a service is used, with a view to making improvements. The exemption requires: the website operator is an ISS provider, the data is used only for statistical purposes, and users are given a simple and free means of objecting. Does not cover data shared with third parties, used for advertising, or fed into targeting.

✓ New exemption

Website appearance

Cookies whose sole purpose is remembering viewing preferences — language, dark mode, layout. Must adapt the service to the user's own device preferences, not to their browsing history or interests. Personalisation based on past behaviour is not covered by this exemption.

✓ New exemption

Emergency assistance

Cookies used to ascertain user location for the sole purpose of providing emergency assistance. Narrow and specific — applies primarily to safety-critical services. Not relevant to most commercial websites.

✗ Not exempt

Google Analytics / third-party analytics

GA4 sends data to Google's servers — this is third-party sharing, not first-party statistical purposes. The statistical exemption requires data to stay with the website operator and be used only for service improvement. GA4 does not qualify. Consent is still required.

✗ Not exempt

Advertising and marketing pixels

Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, Bing UET, and all advertising pixels remain firmly outside the exemptions. Cross-site and cross-device tracking specifically still requires consent — the ICO's finalised guidance is explicit on this point.

✗ Not exempt — yet

Analytics that feed advertising

The statistical exemption applies only where cookies are used "solely" for statistical purposes. If your analytics tool feeds data into advertising targeting, A/B testing audiences, or conversion tracking, it cannot rely on the exemption. Mixed-purpose deployments require consent.

The analytics exemption does not cover Google Analytics

The ICO's finalised guidance is clear: the statistical purposes exemption applies to first-party analytics where data stays with the website operator and is used solely for service improvement. Google Analytics sends data to Google's servers for Google's own use. Multiple DPAs across Europe have found GA4 non-compliant on this basis. UK websites that implement GA4 under the new statistical exemption are exposed to ICO enforcement — consent is still required for GA4 in the UK. Not legal advice.

ICO's April 2026 guidance: what's new

The ICO's finalised guidance on storage and access technologies, published April 29, 2026, introduced several important clarifications and expansions:

Technology-neutral language. The guidance explicitly drops "cookies" as the primary frame and addresses "storage and access technologies" — a broader category covering cookies, tracking pixels, device fingerprinting, web storage (HTML5 local storage, IndexedDB), scripts, tags, and link decoration. All of these fall within PECR Regulation 6's scope.

Multiple purposes must be separated. If a technology serves both an exempt purpose and a non-exempt purpose, you cannot collapse them into a single deployment and call it exempt. Either separate the technologies — deploying one for the exempt purpose and obtaining consent for the non-exempt one — or obtain consent for everything. This directly affects analytics tools that dual-purpose as advertising measurement.

"Simple means of objecting" clarified. For the two exemptions that require a means of objecting (statistical and website appearance), the ICO clarified what "simple and free means of objecting" means: it must be accessible, not buried in a privacy policy, presented in plain language, and not require users to navigate complex settings menus. A preference centre linked from every page footer meets this standard.

Pre-enabling is explicitly forbidden. The guidance explicitly forbids "pre-enabling" non-exempt tracking technologies or relying on silence and inactivity as agreement. This re-confirms what has always been required under PECR but makes the ICO's enforcement position explicit.

Pixels, fingerprinting, scripts: the expanded scope

One of the most practically significant elements of the April 2026 ICO guidance is the explicit confirmation that PECR Regulation 6 applies to technologies beyond HTTP cookies. The ICO has aligned with the EU EDPB's position (from EDPB Guidelines 2/2023) that any technology that stores or accesses information on a user's terminal device requires consent if non-essential:

  • Tracking pixels in web pages — any 1x1 pixel or transparent image that triggers a request to a third-party server on page load. When a visitor's browser fetches the pixel, it transmits the IP address, user agent, referral URL, and any identifiers in the request. This constitutes "access to" the terminal device's outgoing communications, requiring prior consent if the pixel is non-essential.
  • Device fingerprinting — collecting combinations of browser and device characteristics to identify individual users without cookies. Explicitly within scope — if your analytics or advertising tools use fingerprinting to identify returning visitors, consent is required regardless of whether any cookie is set.
  • Scripts and tags — JavaScript tags loaded from third-party servers (Google Tag Manager tags, Meta Pixel base code, LinkedIn Insight Tag) that access and transmit information about the user's session. All require consent before loading if they serve non-essential purposes.
  • Link decoration — URL parameters appended to links that track individual users across sessions or sites. Where these identifiers are used to track individual user journeys (as opposed to aggregate campaign tracking), they may fall within scope.
TechnologyConsent required?Applicable rule
Google Analytics 4 (GA4)Yes — third-party data sharingStatistical exemption does not apply; third-party server transmission requires consent
Meta Pixel / Facebook PixelYesAdvertising pixel — no exemption; fires before consent = PECR violation
TikTok PixelYesAdvertising pixel — same as Meta Pixel
LinkedIn Insight TagYesAdvertising pixel — cross-site tracking requires consent
Microsoft Bing UET + ClarityYesBoth transmit to Microsoft's advertising infrastructure; Clarity does not respect Do Not Track
Hotjar / session replayYesNon-essential tracking technology; captures keystroke and interaction data
Device fingerprintingYesExplicitly within PECR and ICO guidance scope
Shopping cart cookiesNo — exemptStrictly necessary for service requested by user
Login / session cookiesNo — exemptStrictly necessary for service requested by user
Cookie consent state cookieNo — exemptNecessary to remember the user's consent choice
First-party analytics (sole purpose, no third-party sharing)No — new DUAA exemptionStatistical purposes exemption — must provide objection mechanism

UK GDPR Article 4(11) defines consent identically to EU GDPR: freely given, specific, informed, and unambiguous. The specific requirements the ICO enforces:

  • Accept and Reject must have equal visual prominence on the first layer. The ICO's finalised guidance is explicit: a prominent Accept button with a small "Manage preferences" link is non-compliant. Both options must be immediately visible and equally easy to use.
  • No pre-ticked boxes. Planet49 (CJEU 2019) established this as non-compliant throughout the UK's EU membership, and the UK carried this standard forward post-Brexit. Pre-ticked optional cookie categories remain non-compliant.
  • No implied consent. "By continuing to use this site, you agree to cookies" is not valid consent. The visitor must actively click something.
  • Consent must precede placement. The cookie — or tracking pixel, or script — must not fire while the banner is loading or before the visitor has made a choice. Prior consent is required.
  • Consent records with timestamps. If the ICO investigates, you need to be able to demonstrate that a specific user consented on a specific date, what banner version they saw, and what they chose. Storing a cookie called "consent=accepted" with a date is not sufficient — you need a timestamped log with the banner version, choices offered, and the user's selection.

ICO enforcement: what it actually looks like

The ICO's actual enforcement record on cookies has been dominated by public reprimands and compliance letters rather than large fines — but the DUAA's fine increase changes the risk calculus significantly.

In November 2023, the ICO wrote to 53 of the top 100 UK websites warning them their banners did not comply. In January 2025, it extended this campaign to the top 1,000 UK websites. The ICO's enforcement strategy has been coordinated and public — making the reprimand itself a reputational risk alongside the legal one.

The practical steps the ICO uses to assess compliance: visiting the website with a fresh browser session and watching the network tab. If third-party requests to Google Analytics, Meta, or similar domains appear before any consent interaction — the site fails. This is the identical test plaintiff firms run to generate CIPA demand letters in the US. In the UK, it generates an ICO letter. The test is the same; the consequence is different.

UK website compliance checklist

UK PECR + UK GDPR Cookie Compliance Checklist

For website owners and agencies · updated for DUAA February 2026 and ICO guidance April 2026 · not legal advice

Audit — what's actually firing?

Network tab test. Open site in a clean browser with no cookies. Filter network requests for google-analytics.com, facebook.com/tr, analytics.tiktok.com, snap.licdn.com, and any other known tracking domains. If any fire before you've interacted with a consent banner — non-compliant.
Cookie inventory. List every cookie your site sets, categorised as strictly necessary, statistical (first-party only), or non-essential. For each non-essential cookie, confirm it is blocked until consent is granted.
Check whether analytics tools share data with third parties. If using GA4, Clarity, or any analytics that transmits to a third-party server, they cannot rely on the DUAA statistical exemption. Consent is required.

Consent banner

Accept and Reject are equally prominent on the first layer. Both buttons must be visible without clicking "Manage preferences." Equal prominence in size, colour weight, and position.
No pre-ticked optional categories. All non-essential categories must default to off. Users must actively tick or toggle them on.
Cookie categories are granular and clearly described. At minimum: strictly necessary, analytics/performance, and marketing/advertising as separate categories with plain-language explanations.
Named tools disclosed in the banner. The banner (not just the linked privacy policy) should identify the key tracking tools in use — Google Analytics, Meta Pixel — and explain what they do.

Technical enforcement

CMP blocks all non-essential scripts before consent. The consent management platform must prevent scripts from executing — not just display a banner while they load in the background.
Returning visitor consent restores on load. For returning visitors who previously consented, the CMP must restore and communicate that consent state before any scripts fire.
Withdrawal is accessible. A preference centre accessible from every page (not just the footer privacy policy) where users can change or withdraw consent at any time.

Records and accountability

Timestamped consent logs are stored. Every consent event logged with: timestamp, banner version shown, categories accepted/declined, session identifier. Exportable for ICO audit.
Formal complaints procedure in place. Required from June 19, 2026 under the DUAA. Documented process, assigned responsibilities, audit trail.
CMP configuration snapshots retained periodically. If the ICO investigates a past period, you need evidence of what your consent configuration looked like at that time.

The bottom line

UK cookie compliance in 2026 is more demanding than it was 12 months ago — not because the fundamental requirements changed, but because the financial stakes did. Maximum PECR fines rising from £500,000 to £17.5 million under the Data Use and Access Act changes the calculus for any business weighing compliance costs against enforcement risk. The ICO's April 2026 finalised guidance makes the scope explicit: it's not just HTTP cookies, it's pixels, fingerprinting, scripts, and link decoration — every non-essential technology that stores or accesses information on a visitor's device. The three new DUAA exemptions are real but narrow: they don't cover Google Analytics, Meta Pixel, or any tool that shares data with third parties or serves advertising purposes. What they do cover is first-party, sole-purpose statistical analytics — which most UK website analytics stacks are not. For UK website owners and the agencies managing them, the compliance action required is the same as it has always been: block all non-essential scripts before consent, present Accept and Reject with equal prominence, log every consent choice with a timestamp, and make withdrawal as easy as consent. The fact that this is now enforced under a £17.5M ceiling rather than a £500K ceiling is reason to treat it as a current operational priority. This is informational, not legal advice; consult qualified counsel for specific situations.

See if your UK site passes the ICO's network tab test

ConsentPixel — Privacy · Verified scans any website and shows exactly which tracking technologies fire before consent. Free, no card required.

Scan my site free

Frequently asked questions

Does UK cookie law still apply after Brexit?

Yes. The UK retained the EU's cookie requirements in its own law through PECR (Privacy and Electronic Communications Regulations 2003) and UK GDPR (the retained EU GDPR, incorporated via the European Union (Withdrawal) Act 2018 and the Data Protection Act 2018). The ICO enforces both. The Data Use and Access Act 2025 updated PECR — adding new exemptions and raising the fine ceiling — but the fundamental consent requirement for non-essential cookies remained.

Does Google Analytics need consent in the UK?

Yes. Despite the new DUAA statistical purposes exemption, Google Analytics 4 requires consent in the UK. The statistical exemption requires that data is used solely for statistical purposes and does not leave the website operator's control. GA4 sends data to Google's servers for Google's own purposes. Multiple DPAs across Europe have found GA4 non-compliant on this basis, and the ICO's guidance is consistent with this interpretation. GA4 must be blocked until consent is obtained. Not legal advice.

What does the ICO actually do when it finds cookie non-compliance?

The ICO's primary enforcement mechanism for cookie compliance has been public reprimands and compliance letters — it wrote to 53 of the top 100 UK websites in November 2023 and extended the campaign to the top 1,000 UK websites in January 2025. Formal monetary penalties are reserved for the most serious cases. However, the DUAA's increase of the maximum PECR fine to £17.5 million changes the enforcement landscape significantly. The ICO has stated that fines will be reserved for serious infringements — but with the raised ceiling, the financial risk of being found in serious breach has increased 35-fold. Not legal advice.

Is a cookie banner enough to comply with PECR?

Not on its own. A compliant banner is necessary but not sufficient. The banner must be backed by technical enforcement — the CMP must actually block non-essential scripts before consent is given, not just display a notice while they load in the background. The ICO's test is the network tab test: if third-party tracking requests appear before any consent interaction in a fresh browser session, the site is non-compliant regardless of whether a banner is present. Not legal advice.

ConsentPixel — Privacy · Verified
We build GDPR, PECR and CIPA-first consent enforcement for websites and the agencies that manage them. This article is informational and not legal advice. UK law is evolving rapidly — verify against current ICO guidance. Consult qualified counsel for specific situations.
Scroll to Top