If you run a website that serves UK visitors, the rules around cookies and consent have shifted more in the past twelve months than at any point since the original cookie law arrived in 2011. The Data (Use and Access) Act 2025 has rewritten parts of the Privacy and Electronic Communications Regulations, the Information Commissioner’s Office has finalised fresh guidance on how consent banners must behave, and the maximum penalty for getting it wrong has jumped thirty-five fold. For any UK business owner who last thought about their cookie banner when they first launched their site, this is the year to look again.
This article sets out what has actually changed, which cookies still require consent and which now qualify for a narrower set of exemptions, what a compliant cookie banner looks like in practice, and where the real risk sits for small and medium-sized businesses. Whether you manage your website in-house or work with a digital agency, understanding these rules protects you from regulatory action and, just as importantly, builds the kind of trust that keeps visitors on your site rather than bouncing off it.
Key Takeaways
- UK cookie consent is governed jointly by PECR (which sets out when consent is needed) and UK GDPR (which sets the standard for what counts as valid consent).
- The Data (Use and Access) Act 2025 introduced three new low-risk exemptions from 5 February 2026, covering statistical, appearance and emergency assistance cookies, but analytics and advertising cookies still generally require consent.
- Maximum fines for PECR breaches, including non-compliant cookie banners, rose from £500,000 to £17.5 million or 4% of global turnover from 5 February 2026.
- A compliant cookie banner must give “Reject All” the same visual prominence as “Accept All”, must not use pre-ticked boxes, and must not rely on continued browsing as consent.
- Businesses should treat cookie compliance as an ongoing process, not a one-off task, with regular audits of what tracking technologies are actually running on the site.
- A well-designed, transparent consent experience is also a trust signal that supports conversion, not just a legal box to tick.
Understanding the Legal Framework: PECR and UK GDPR
Cookie consent in the UK sits at the intersection of two pieces of legislation that work together rather than in competition. The Privacy and Electronic Communications Regulations, generally shortened to PECR, is the specific law that governs cookies, device fingerprinting and similar tracking technologies. Regulation 6 of PECR sets out the core rule: an organisation must not store or access information on a user’s device unless it has told the user what the information will be used for and has obtained their consent.
UK GDPR, meanwhile, does not mention cookies directly, but it defines what “consent” actually means. Under Article 4(11), consent must be freely given, specific, informed and unambiguous, and it must involve a clear affirmative action from the user. This is why a cookie banner that relies on a statement like “by continuing to browse this site you agree to our use of cookies” no longer holds up. Silence, inactivity and pre-ticked boxes have never satisfied this standard, and enforcement against these practices has become considerably more consistent over the past year.
For any business operating a UK-facing website, both frameworks apply at once. PECR tells you when you need consent, and UK GDPR tells you what a valid version of that consent looks like. Getting one right without the other still leaves you exposed.
What Changed on 5 February 2026
The Data (Use and Access) Act 2025 received Royal Assent in June 2025, and its provisions relating to PECR came into force on 5 February 2026. This is the most significant reform to UK cookie law since the regulations were first amended back in 2011, and it introduced changes in two directions at once: a small relaxation for certain low-risk technologies, alongside a substantial increase in enforcement powers.

New Exemptions for Low-Risk Cookies
Before this reform, only a narrow “strictly necessary” exception allowed a website to set cookies without consent, generally limited to things like shopping basket functionality or login sessions. The Act added three further categories that no longer require prior consent, provided they are used solely for the stated purpose:
- Statistical purposes cookies used to collect aggregate information about how a website is used, with a genuine view to improving the service.
- Website appearance cookies used to remember a visitor’s viewing preferences, such as language or layout settings.
- Emergency assistance cookies used solely to establish a device user’s location in order to provide emergency help.
These exemptions come with important limits. They only apply where the cookie serves that single purpose and nothing else. An analytics cookie that also feeds into advertising targeting does not qualify, even if statistical reporting is one of its functions. For the statistical and appearance exemptions specifically, businesses must still give users clear information about what the cookie does and provide a simple, free way for them to object. In other words, this is a narrowing of red tape around genuinely low-risk technology, not a general licence to track visitors without consent.
Higher Penalties and Wider Liability
The more consequential change for most businesses is financial. Before 5 February 2026, the maximum fine for a PECR breach was £500,000. From that date, PECR penalties were brought in line with UK GDPR, meaning the maximum is now £17.5 million or 4% of global annual turnover, whichever is higher. A poorly configured cookie banner now carries the same theoretical exposure as a serious data breach.
The reform also introduced an “instigator” concept, which extends responsibility beyond the organisation that directly sets a cookie to any party that causes it to be placed, such as an advertising technology provider embedded on a website. For UK businesses that rely on third-party scripts, tags or widgets, this makes it worth reviewing exactly what those tools are doing on your site, since liability is no longer confined to the most obvious party.
Which Cookies Still Require Consent
For most UK businesses, the practical day-to-day position has not moved as far as the headlines might suggest. The cookies that typically drive marketing and personalisation still require an active, informed opt-in. This includes:
- Analytics cookies used for anything beyond the narrow statistical exemption, particularly where data is shared with third parties or combined with other tracking.
- Advertising and retargeting cookies, including social media pixels, programmatic advertising tags and affiliate tracking scripts.
- Cross-site and cross-device tracking, which has no exemption regardless of how the data is later used.
- Personalisation cookies that go beyond remembering basic display preferences, such as those used to tailor product recommendations or content feeds.
A useful test the ICO itself points to is whether the service would fail in a meaningful way if the cookie were removed. If the honest answer is that the site would simply be “less optimised” or the business would “lose some insight”, that cookie is not strictly necessary and requires consent. Many businesses have historically over-classified tracking tools as essential, and this is one of the most common compliance gaps an audit tends to uncover.
What a Compliant Cookie Banner Looks Like
The ICO’s finalised guidance on storage and access technologies, published in April 2026, is detailed about what does and does not satisfy the consent standard. A compliant banner should include the following elements.

Equal Prominence for Accept and Reject
Users must find it just as easy to reject non-essential cookies as to accept them. In practice, this means a clearly visible “Reject All” option needs to sit at the first layer of the banner, styled with the same visual weight as “Accept All”. Burying the reject option behind a “Manage Settings” link, or styling it as plain text next to a bold, coloured accept button, does not meet this standard and is one of the most frequently cited failures in ICO enforcement activity.
Genuine Affirmative Action
Consent has to come from a positive action the user takes, such as clicking a clearly labelled button. Pre-ticked boxes are not valid, continued scrolling or browsing does not count as consent, and a single toggle covering multiple unrelated purposes, such as analytics and marketing combined, does not provide the specific, granular choice the law requires.
Layered Information
Good practice, and increasingly expected practice, involves a layered structure: a first layer giving a brief, plain-language explanation with accept and reject options, a second layer allowing granular control over individual cookie categories, and a link through to a full cookie policy for anyone who wants complete detail. This approach respects both the casual visitor who just wants to make a quick choice and the more cautious visitor who wants to understand exactly what is being collected.
No Cookie Walls
A cookie wall, where access to a website is conditioned on accepting non-essential cookies, is treated by the ICO as invalid consent, since it is not genuinely freely given. Some limited “pay or consent” models exist in specific circumstances, but they face increasing regulatory scrutiny and are not a safe default approach for most commercial websites.
Accessibility
A cookie banner also needs to work for everyone. That means sufficient colour contrast, full keyboard navigation, and compatibility with screen readers, in line with the same accessibility obligations that apply to the rest of your website under the Equality Act 2010.
Practical Steps for UK Businesses
For most small and medium-sized businesses, bringing a website into line with the current rules does not require a complete rebuild, but it does require a proper review rather than a quick guess. A sensible approach looks like this.
Audit what is actually running on your site: Many businesses are surprised to find tracking scripts, pixels or third-party widgets they had forgotten about, often added years ago for a campaign that has long since ended. A cookie scan will identify every technology in use and what data it collects.
Classify each cookie correctly: Match each one against the strictly necessary exception, the new low-risk exemptions, or the general consent requirement. Where a cookie serves more than one purpose, such as analytics data that also informs advertising, it should be treated as requiring consent.
Rebuild or reconfigure your banner if needed: Check that reject and accept options carry equal visual weight, that no boxes are pre-ticked, and that non-essential cookies are genuinely blocked until consent is given, not simply hidden from view while still running in the background.
Update your privacy and cookie policies: These documents should reflect the current legal basis for each category of cookie, including the new exemptions where they apply, and should be written in plain English rather than dense legal language.
Keep records of consent: Being able to demonstrate when and how a user gave consent, and to show that withdrawal is just as straightforward as giving it, is an expectation the ICO applies during any investigation.
Review third-party tools and partners: Given the expanded “instigator” liability, it is worth understanding exactly what any embedded widget, advertising tag or analytics tool is doing, rather than assuming a supplier’s own compliance covers your obligations as well.
None of this needs to feel purely defensive. A clear, well-designed consent experience signals to visitors that a business takes their privacy seriously, and that kind of transparency tends to support trust and conversion rather than undermine it. If your current website was built before these changes, or before the Equality Act 2010 accessibility requirements were as tightly enforced as they are today, a broader review of your web design and development approach is often the more efficient path than patching individual issues one at a time.
Conclusion
UK cookie law has moved further in the last eighteen months than in the decade before it, and the direction of travel is clear: a small amount of flexibility for genuinely low-risk technology, paired with substantially higher stakes for getting the basics wrong. The core principles have not changed. Consent still needs to be freely given, specific, informed and demonstrated through a clear action, and non-essential cookies still need an honest opt-in rather than a technicality. What has changed is the cost of ignoring those principles, and the level of detail the ICO now expects from a compliant banner.
If you are unsure whether your website’s current cookie set-up would hold up to scrutiny, or if your consent banner has not been reviewed since before February 2026, it is worth having it properly assessed rather than assuming it still does the job. The team at Developers House works with UK businesses on exactly this kind of website review, from cookie and privacy compliance through to the wider design and performance of your site, so do get in touch if you would like a second opinion.
FAQs
Do all UK websites need a cookie banner?
Any website that uses non-essential cookies or similar tracking technologies, such as analytics, advertising or personalisation tools, needs to obtain consent before those cookies are set, which in practice means a compliant banner. Websites that use only strictly necessary cookies, such as those required for a shopping basket to function, are not required to display a consent request for those specific cookies, though good practice is still to explain their use in a cookie policy.
Has the Data (Use and Access) Act removed the need for cookie consent?
No, it introduced three narrow exemptions for low-risk technologies used solely for statistical, website appearance or emergency assistance purposes. Analytics tools that share data with third parties, advertising cookies and cross-site tracking still require consent in the vast majority of cases.
What happens if a business does not comply with the current cookie rules?
Since 5 February 2026, the maximum fine for a PECR breach, including non-compliant cookie practices, is £17.5 million or 4% of global annual turnover, whichever is higher. The ICO also has powers to issue enforcement notices requiring a business to change its practices, separate from any financial penalty.
How often does cookie consent need to be refreshed?
Neither PECR nor UK GDPR sets a fixed time limit, but the ICO has suggested around six months as a sensible general interval, particularly where a user previously declined consent. Consent should also be refreshed sooner if the purposes or categories of cookies in use have changed.
Can a website simply block EU or non-UK visitors instead of dealing with cookie consent?
This does not remove the obligation for UK-facing traffic. Any website accessible to UK users and using cookies is subject to PECR and UK GDPR regardless of where the business itself is based, so geographic blocking only addresses visitors from outside scope, not the UK audience the rules exist to protect.
Is a third-party cookie consent tool required, or can this be built in-house?
There is no legal requirement to use a dedicated consent management platform. What matters is that the outcome meets the standards set out above, including equal prominence for reject and accept, no pre-ticked boxes, and properly blocked non-essential cookies until consent is given. Many small business websites achieve this with a well-configured banner without needing a specialist platform, though larger sites running numerous third-party scripts often find a dedicated tool easier to maintain.