Skip to content

Cookie Regulations 2027 Complete UK & EU Guide

The full 2026/27 picture. What the UK's DUAA reforms changed, where EU rules diverge, the dates ahead, and exactly what to do. The annual flagship guide.

By Cookie Control Content TeamReviewed by Cookie Control Product TeamLast reviewed: 15 Sept 20268 min read

Cookie Regulations 2027: The Complete UK & EU Guide on an off-white and mint cover with an editorial illustration.

Planning for cookie rules in 2027 means accounting for divergence: the UK loosened consent requirements for low-risk cookies while raising maximum fines to £17.5 million or 4% of annual global turnover. The EU retains a consent baseline for non-exempt storage, with national differences. A site serving both can use regional variants or a suitably strict global baseline — this guide covers both.

Parallel UK and EU tracks separate the draft’s February and April 2026 milestones from guidance, consent-or-pay and reform watch items.

The 2026–27 planning map separates milestones from watch items. Use the rules that apply to your markets; regional variants are one implementation option.

The UK and EU have long had important differences in national cookie rules. The 2026 UK reforms widen that divergence, and 2027 will be the first full calendar year after those changes. The UK traded looser rules for far bigger fines; the EU held its stricter line while arguing about reform. This guide — updated through the year, with each claim dated — covers what changed, what applies where, what is coming, and precisely what to do about it.

The UK regime in 2027, in one section

The legal frame is UK GDPR and PECR, as amended by the Data (Use and Access) Act 2025, whose main provisions commenced on 5 February 2026. Three changes define the new posture. First, conditional exemptions: PECR regulation 6 now exempts statistical purposes, appearance and functionality preferences, and emergency-assistance location storage or access — each with its own conditions. Statistics and appearance/functionality require clear information and a free, simple opt-out; emergency assistance has a separate narrow purpose and necessity test. Second, penalties: the PECR maximum rose from £500,000 to up to £17.5 million or 4% of annual global turnover, whichever is higher — the same ceiling as the UK GDPR. Third, guidance: the ICO finalised its storage and access technologies guidance on 29 April 2026, setting out how it reads the amended rules, including a chapter on online advertising. The practical translation: a UK site can now lawfully run qualifying statistical analytics without a consent prompt — if it meets the conditions — while the fixed sterling limb of the maximum fine has risen thirty-five-fold, from £500,000 to £17.5 million. Loosened does not mean relaxed.

In Cookie Control terms, a category that qualifies for one of the exemptions is switched on before the visitor interacts, as a consent exception — and the product is explicit that this should only be done where the category genuinely falls within a recognised exemption such as statistical purposes or appearance and functionality. For a TCF implementation, assess the purpose and vendor signals separately; a UK consent-exception setting is not permission to bypass TCF requirements. The framework supports consent and, for some purposes, legitimate interests. Confirm the options supported by your Cookie Control TCF configuration before enabling an exception.

The EU regime in 2027: continuity, with arguments

The EU's cookie rules remain the ePrivacy Directive's consent requirement implemented per member state, alongside the EU GDPR (upper-tier fines up to €20 million or 4% of worldwide annual turnover, whichever is higher). National ePrivacy penalties are not a single EU-wide GDPR fine. Analytics cookies still require consent in most member states; there is no EU-wide equivalent of the UK's statistical exemption, though a few national regulators — France's CNIL notably — allow narrow audience-measurement carve-outs under strict conditions. Two live debates matter for planning. Consent-or-pay — the model where visitors choose between consenting to tracking or paying — has drawn EDPB scrutiny and regulator attention across markets, and any publisher considering it should treat the compliance position as unsettled and jurisdiction-specific.

UK and EU comparison covering statistics, preference storage, penalty frameworks, regulators and regional planning. Strictly necessary preferences can be exempt; national ePrivacy penalties differ from EU GDPR penalties.

A UK/EU planning comparison, including national exceptions. The EU GDPR maximum is not a uniform penalty for national ePrivacy infringements.

The EU is not one regime: country notes

The ePrivacy Directive is implemented nationally, and the differences matter for a site with real traffic in a given market.

  • France. The CNIL allows a narrow audience-measurement exemption for analytics that is first-party, produces only aggregated statistics and is not combined with other processing — conditions strict enough that most Google Analytics configurations do not qualify. It has taken enforcement action on reject parity and on tags firing before consent.
  • Germany. Storage and access are governed by section 25 of the TDDDG, which mirrors the Directive: consent, with a strictly-necessary exemption. The regulators’ joint guidance reads the exemption narrowly, and analytics needs consent.
  • Italy. The Garante’s cookie guidelines rule out scrolling as consent, treat cookie walls as generally unlawful, and expect a visitor who refused not to be asked again for at least six months unless the circumstances change.
  • Spain. The AEPD’s cookie guidance requires a reject option on the first layer with the same prominence as accept, and the regulator enforces it. Netherlands. Dutch law allows analytics cookies without consent where they are configured in a privacy-friendly way and have little or no impact on the visitor’s privacy — the closest EU analogue to the UK’s new exemption, and narrower.
  • Ireland. The DPC’s guidance follows the Directive closely: consent for anything non-essential, no pre-ticked boxes, and a specific expectation that consent is refreshed periodically.

The pattern: the EU baseline is consent for analytics, with narrow national exceptions, including those discussed for France and the Netherlands, conditional on configuration. A geolocation variant per market is only worth building where you have the traffic to justify it; for most sites the EU baseline is one posture.

What this means for a multi-market site

The divergence makes geolocation-aware consent useful where you want to apply different regional rules. A suitably strict global consent baseline remains an alternative. A UK-only posture applied globally under-asks EU visitors (a breach in the EU); an EU posture applied globally over-asks UK visitors (legal, but it can forgo measurement available under a qualifying UK exemption). The working pattern: a strict baseline configuration, a UK variant using the exemptions you qualify for, and per-market variants where you operate at scale. Our geolocation guide covers the mechanics — including the guard-rails that stop a looser mode leaking onto visitors whose law demands more.

The guard-rail is the important part. Cookie Control Premium uses geolocation to upgrade automatically to a stricter mode where a visitor’s location requires it, even when a looser mode is set as the default, and implied consent cannot be selected for a European geolocation at all. This is a safeguard, not a substitute for testing the actual regional settings, categories and tag behaviour for UK and EU visitors.

Records: what you must be able to show

Both regimes rest on accountability, and for cookies that means the consent record. Cookie Control’s consent logging stores exactly six data points for every consent and every withdrawal. It is enabled in the user area once the data processing agreement has been accepted. If you change your privacy policy date, earlier consent is treated as out of date and visitors are asked again, which is the right behaviour and worth timing deliberately.

A note on US traffic: GPC, CCPA and Do Not Track

Most UK and EU sites have some American traffic, and the relevant signal there is Global Privacy Control, a browser setting that expresses an opt-out under California’s CCPA and several other state laws. Cookie Control honours GPC in its CCPA mode, with every category defaulting off. It does not apply GPC in UK or EU modes, where the law works on opt-in consent rather than a US-style opt-out — UK and EU visitors still have their own objection rights, handled through the banner, not the browser signal. It does not support the older Do Not Track header, whose working group the W3C disbanded in 2019. If you serve US visitors at any scale, a CCPA-mode variant selected by geolocation is the clean answer.

The calendar: dates to plan around

  • Now in force: the DUAA exemptions and the raised PECR ceiling (since 5 February 2026); the ICO's storage and access guidance (April 2026).
  • Guidance watch: the ICO’s final storage and access guidance already includes online advertising. Monitor changes to that guidance and to its consent-or-pay position; do not treat an unconfirmed future guidance date as a deadline.
  • Accessibility: EN 301 549, the standard behind public-sector accessibility duties, has a revision in progress; public bodies and their suppliers should track it alongside WCAG 2.2 (our accessibility guide covers what banners owe today).
  • EU procedure: Regulation (EU) 2025/2518 on cross-border GDPR enforcement applies from 2 April 2027, with transitional rules for investigations and dispute-resolution cases. It affects multinationals’ regulator experience rather than the day-to-day design of a cookie banner.
  • US and beyond: additional state privacy laws continue coming into force through 2026–27 — relevant to UK/EU sites mainly through CCPA-style modes and GPC handling for American traffic.

A worked example: a UK retailer serving the EU

Make the split concrete. Picture a Manchester retailer: 60% UK traffic, 25% EU, the usual stack (GA4, Meta Pixel, embedded video, a review widget). For this example, a regional setup has three layers. UK visitors: first-party analytics assessed against the statistical exemption and, if the configuration qualifies, running from first page view with disclosure and a one-click opt-out; Meta Pixel and the review widget behind marketing consent as ever. EU visitors: the geolocation variant serves a consent baseline for non-exempt storage — analytics included in this example — because the UK exemption stopped at Dover. Everyone: the same records, the same withdrawal route, the same declaration generated from the same scans. At minimum, this example needs a regional variant, a documented exemption assessment and tests of the resulting tag behaviour. Total legal difference: the whole reform.

The same three layers, as a diagram.

Location-aware configuration routes UK and EU visitors to different assessed settings, with shared records, withdrawal and review routines.

One possible regional setup: a documented UK variant, an appropriate EU baseline, and shared records and withdrawal controls. Test the actual settings and tags.

How to document an exemption assessment

The UK exemptions only pay if you can show your working.

  1. What exactly is stored or read, by which tool, and for what purpose? Name the cookies or storage keys.
  2. Which exemption is claimed — statistical, appearance and functionality, or emergency assistance — and why the purpose fits it?
  3. For statistics, is processing solely for improving your service, including any provider acting on your behalf? Does the tool use the data for its own purposes, and if so, how have you switched that off?
  4. For statistics and appearance/functionality, where are the clear information and simple, free means of objecting? Screenshot both. For emergency assistance, document its separate necessity and location-purpose conditions.
  5. Who assessed this, when, and when will it be reviewed?

In Cookie Control, the category is then enabled before interaction as a consent exception. Keep the assessment with your records of processing; it is the first thing a regulator would ask for.

The quarterly refresh routine

This routine works for keeping up to date with compliance regulations.

  • Re-run the scan and diff it against the last one. Anything new is uncategorised until someone categorises it.
  • Check the ICO’s cookies and storage pages for new or updated guidance, and the EDPB for opinions touching consent.
  • Check the EU legislative tracker for any adopted text on ePrivacy reform or digital simplification. Proposals do not change your obligations; adopted texts do.
  • Re-read your own banner as a visitor: reject parity, copy, withdrawal route. Fix what has drifted.
  • Confirm the consent log is still being written and that you can retrieve it.
  • Re-verify every dated claim on your cookie policy page.

Quarterly checklist: scan, check guidance, track adopted changes, test the banner, retrieve consent records and recheck dated claims.

The existing quarterly routine, made visual: scan, check guidance, track adopted changes, test the banner, retrieve records and refresh dated claims.

Glossary

  • PECR — the Privacy and Electronic Communications Regulations 2003, the UK law on storing or accessing information on a device. Regulation 6 is the cookie rule.
  • DUAA — the Data (Use and Access) Act 2025, which amended PECR and the UK GDPR; main provisions in force from 5 February 2026.
  • Strictly necessary — storage without which a service the visitor explicitly requested would not work. Never needs consent.
  • Consent exception — a Cookie Control setting that enables a category before the visitor interacts, for use only where a recognised exemption applies.
  • Consent Mode — Google’s signalling system that tells its tags what the visitor agreed to. Signals, not blocking.
  • TCF — the IAB Europe Transparency and Consent Framework, used in programmatic advertising. Its purpose and vendor signals can support consent or, where permitted, legitimate interests.
  • GPC — Global Privacy Control, a browser signal expressing a US opt-out. Honoured by Cookie Control in CCPA mode only.
  • Consent-or-pay — offering visitors a choice between consenting to tracking or paying for access. Contested in the EU; the ICO has set out a position for the UK.
  • Geolocation variant — a banner configuration selected by the visitor’s location, so different markets get different postures.
  • Consent log — the record of each consent and withdrawal. In Cookie Control, six data points per decision.

What is suggested by December 2027

  • A scan-generated declaration that matched the site all year, because scheduled scans kept it true.
  • A UK posture that claims exactly the exemptions it documented — no more, no fewer — and an EU posture that never inherited them.
  • A consent log you exported at least once, so you know the export works before anyone asks.
  • A banner that passed its own dark-pattern read-through each quarter: reject parity, plain copy, working withdrawal.
  • A diary that caught the year's regulatory movement because the quarterly watch-list check actually ran.

The divergence turns a few features from nice-to-have into the job itself. Whatever you use, check for:

  • Geolocation variants with a stricter-mode safety net, with tests confirming that visitors receive the intended regional rules.
  • Scheduled scans that notify you when the site changes — schedules that run for a year at a time — because the declaration has to stay true between audits, not just on launch day.
  • Consent logging that records enough to prove a decision, and that you have actually retrieved at least once.
  • Accessibility you can cite: Cookie Control from version 9 is built to WCAG 2.2 level AA.
  • Certification where it matters: Cookie Control is certified by Google and registered with IAB Europe for the Transparency and Consent Framework; confirm the current registrations and supported versions before publishing.
  • No cookie walls. Check that access and consent choices meet the freely-given standard.
  • Languages for the markets you actually serve — Cookie Control ships with more than thirty.

The 2027 action list

  1. Audit against the new UK map: scan, then sort into strictly necessary / exempt-with-conditions / needs-consent. The exemption categories only pay if you document meeting their conditions.
  2. Implement the conditions where you claim them: the specific exemption’s conditions, including disclosure and a simple opt-out for statistics and appearance/functionality, wired through your consent platform.
  3. Split your postures: UK variant with your qualifying exemptions; EU variant on a consent baseline for non-exempt storage; geolocation deciding, with stricter-mode auto-upgrade as the safety net.
  4. Re-verify your banner against the enforcement-tested failures: reject parity, no non-exempt storage before consent, honest categories, easy withdrawal, records kept.
  5. Diarise the watch items: quarterly check on ICO advertising guidance, EU proposal texts, EN 301 549, and re-read this page, which tracks them.

Frequently asked questions

Sources

  1. Data (Use and Access) Act 2025
  2. PECR regulation 6 (as amended)
  3. ICO — storage and access technologies guidance (April 2026)
  4. EU ePrivacy Directive + EU GDPR Article 83
  5. EDPB Opinion 08/2024 on consent-or-pay (large online platforms)