If you run an online service accessible from the UK, you need to know about […]
The post UK ICO Cookie Guidance Just Changed: What Your Website Must Do Now appeared first on CookieYes.
If you run an online service accessible from the UK, you need to know about the ICO’s updated cookie guidance. The Information Commissioner’s Office (ICO) published significant revisions to its guidance on storage and access technologies in 2026, and these changes affect how you handle cookie consent, device fingerprinting, and analytics tracking. This article explains exactly what changed, what the law actually requires, and what you should do to stay compliant.
The ICO’s 2026 guidance has been finalized following consultations held in December 2024 and July 2025 on updated cookies guidance and PECR changes under the Data (Use and Access) Act.
The update introduces two new sections: simple means of objecting and using the same storage and access technology for multiple purposes, along with minor clarifications based on stakeholder feedback. The ICO’s updated cookie guidance mainly focuses on clarifying how UK cookie rules under PECR should be interpreted rather than introducing entirely new obligations.
PECR Regulation 6 is the central legal provision. It says that before storing anything on a user’s device (like cookies) or reading what’s already there, you must:
The only exceptions apply when your use falls into one of five specific categories that do not require consent, such as cookies that are strictly necessary for the website to function.
Valid consent under PECRConsent under PECR must meet the UK GDPR Article 4(11) standard. This means it must be freely given, specific, informed, and unambiguous. In practical terms:
The ICO’s 2026 guidance sets out clear expectations for cookie consent mechanisms. A compliant cookie banner needs to present an ‘Accept all’ and a ‘Reject all’ option with equal visual prominence.
Banner with equal prominence to both reject and accept buttons
Opt-in cookie banner example
Automate consent collection, preference management, and audit-ready records with CookieYes.
14-day free trialCancel anytime
Not all cookies require consent. PECR Schedule A1 sets out exceptions where consent is not required. Understanding these correctly is essential because a lot of websites either misapply them or apply them too broadly.
CommunicationThis exception applies to storage and access technologies that are strictly necessary to transmit a communication over an electronic communications network.
The exception only applies where the communication cannot happen without the specific technology being used. Common examples include session cookies used for load balancing between servers. It does not apply to technologies used for additional purposes beyond enabling the communication itself.
Strictly necessaryThe strictly necessary exception covers storage or access that is essential to provide an internet service requested by the user. If the service could technically function without the cookie, it does not qualify.
Examples that qualify:
Examples that do not qualify:
This is one of the most frequently misunderstood exceptions, and the 2026 ICO guidance tightened the conditions significantly.
The statistical purposes exception allows you to collect aggregate data about how visitors use your service, for the purpose of improving that service, without obtaining consent.
| Use of analytics/storage tech | Exempted or consent required? |
| Aggregate website analytics: visits, page views, user journeys, scroll depth, device/browser/OS, referrer URLs, A/B testing, coarse geolocation, load speeds, bounce/exit pages | Exempted |
| Tracking or monitoring individual users: session recordings/logs, ad views/clicks, linking visitor IDs to conversions, profiling by IP/pages visited, cross-site/app tracking | Consent required |
| Online advertising or ad-measurement purposes | Consent required |
But, the exceptions come with strict conditions.
What cookies are on your site?
Scan your website to know for free. No sign up required
Yes. You can use a third-party analytics provider under the statistical purposes exception, provided the provider acts only on your behalf and uses the data solely to help improve your website or service. Do not share analytics data for other purposes, such as advertising or profiling. You must also inform users about the third-party provider and explain how their information is used.
Standard Google Analytics, in its default configuration, may not meet this exception. This is because Google can use the data it collects on your behalf for its own purposes, which goes beyond what the exception permits. In that case, you can use Google Consent Mode with a CMP such as CookieYes to help manage user consent preferences and control when analytics tags are activated.
Consent is still required if the analytics data is used for advertising or cross-site tracking purposes.
This exception allows you to adapt how your service looks or functions based on the user’s own device preferences, without consent. Qualifying examples include detecting whether a user’s operating system has dark mode enabled and displaying your site in dark mode accordingly, remembering which language a user selected on a multilingual website, and adjusting your layout to suit a mobile screen size.
This exception does not cover personalising content based on a user’s browsing history, interests, or demographic profile. Like the statistical purposes exception, you must offer users a simple and free way to object, and you must stop if they do.
Make UK cookie law compliance easier with CookieYesKeeping up with the ICO’s 2026 PECR guidance can quickly become complex, especially when your website uses multiple analytics, advertising, and third-party tracking technologies. A Consent Management Platform (CMP) like CookieYes helps businesses simplify compliance by automating cookie scanning, prior consent blocking, consent logging, and user preference management.
Instead of manually configuring cookie banners and tracking scripts, businesses can use CookieYes to create a consent experience aligned with PECR and UK GDPR requirements.
With CookieYes, you can:
For businesses handling UK website traffic, using a properly configured CMP is one of the most practical ways to reduce PECR compliance risks while improving transparency and user trust.
Stay PECR-ready with automated cookie compliance from CookieYes.
14-day free trialCancel anytime
The ICO have currently issued monetary penalty notices of up to GBP 500,000 for serious PECR breaches. The UK government’s Data (Use and Access) Act and related legislative proposals aim to increase this significantly, potentially aligning PECR fines with UK GDPR fines of up to GBP 17.5 million or 4% of global annual turnover, whichever is higher.
Beyond fines, the ICO can issue enforcement notices requiring you to change your practices, and can handle complaints from users. Individuals can also bring civil claims for damages caused by PECR breaches.
Does UK cookie law apply to small businesses and SMEs?Yes. PECR applies to all organisations, regardless of size, that operate websites or apps accessible to people in the UK and that use cookies or similar technologies.
There is no small business exemption. That said, the ICO’s approach to enforcement tends to focus first on the largest and highest-traffic websites, particularly those whose practices affect the most people. But this does not mean smaller businesses are free to ignore the rules. The ICO does investigate complaints from individuals, and a complaint about a small business’s cookie practices can lead to an enforcement action.
Checklist: UK ICO PECR guidelinesPECR cookie compliance requires ongoing attention as your website changes, as new cookies are added by third-party services, and as the ICO updates its guidance. Here is a practical list of steps to take right now.
What are storage and access technologies under PECR?
Storage and access technologies is the umbrella term PECR uses to cover anything that stores information on a user’s terminal equipment (such as their browser, phone, or laptop) or accesses information that is already stored there. This includes HTTP cookies, local storage, session storage, IndexedDB, device fingerprinting, pixel tracking, and similar mechanisms.
Is cookie consent required in the UK?
Yes. In the UK, cookie consent is generally required for any non-essential cookies or similar tracking technologies. This requirement comes primarily from the Privacy and Electronic Communications Regulations (PECR), which work alongside the UK GDPR.
What are the PECR rules on cookies?
PECR Regulation 6 prohibits storing or accessing information on a user’s device unless you have given them clear and comprehensive information about your purposes and obtained their consent. There are five exceptions: strictly necessary, communication, statistical purposes, appearance, and emergency assistance. For everything outside these exceptions, prior informed consent is required.
What is PECR and how does it relate to UK GDPR?
PECR (Privacy and Electronic Communications Regulations 2003) is the UK law that specifically regulates electronic communications, including the use of cookies, device fingerprinting, and similar tracking technologies on websites and apps accessible from the United Kingdom. UK GDPR, in contrast, is the broader data protection law that governs how organizations collect, use, store, and share personal data.
The two laws work together. PECR applies first at the point where a website stores or accesses information on a user’s device. This means businesses usually need consent under PECR before placing non-essential cookies. Once personal data is collected through those technologies, UK GDPR then governs how that data is processed and protected.
What is the cookie law in the UK?
The main cookie law in the UK is the Privacy and Electronic Communications Regulations (PECR), specifically Regulation 6. PECR works alongside the UK GDPR.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Do I Need a Cookie Policy on My Website: Country-by-Country Guide | 0 | 10.28 | 20-05-2026 |
| 2 | GDPR Best Practices for Businesses: 10 Steps to Stay Compliant in 2026 | 0 | 10.92 | 09-06-2026 |
| 3 | SECURE Data Act: What This Federal Privacy Law Means for Your Business | 0 | 5.52 | 15-05-2026 |
| 4 | GDPR and AI Act: Similarities, Differences, and Overlaps | 0 | 7.94 | 29-04-2026 |
| 5 | Privacy Policy for Google Analytics Users: Free Template and Examples 2026 | 0 | 8.94 | 08-06-2026 |
| 6 | ADA Website Compliance: Guide to WCAG Guidelines and Accessibility Standards | 0 | 13 | 12-05-2026 |
| 7 | Canada’s Biggest Privacy Reform in 25 Years: What Bill C-36 Means for Your Business | 0 | 9.3 | 17-06-2026 |
| 8 | Louisiana Moves Closer to Becoming the 22nd US State With a Privacy Law | 0 | 7 | 26-05-2026 |
| 9 | Cookie Chaos: How to bypass __Host and __Secure cookie prefixes | 0 | 7 | 03-09-2025 |
| 10 | Revealed: The country where most tourists visiting the UK come from | 0 | 5 | 26-08-2025 |