UK GDPR & PECR Cookie Rules Explained in Plain English
What PECR and the UK GDPR actually require for cookies in 2026, what the Data (Use and Access) Act changed, and what to do about it — in plain English.
Two laws govern cookies in the UK. PECR requires consent before you store or read anything non-exempt on a visitor's device. The UK GDPR governs what you do with any personal data collected afterwards. Both were updated by the Data (Use and Access) Act 2025, with the main changes in force since 5 February 2026.
Two laws, two jobs: PECR governs storage or access on the device; UK GDPR applies where personal data is processed.
Most explanations of UK cookie law fail at the first step: they talk about "GDPR cookie consent" as if one law covered everything. There are two laws, they regulate different moments, and almost every practical question — do I need a banner, can I run analytics without consent, what can I be fined — turns on which law you are actually dealing with. This guide is the plain-English version of the rulebook we have been implementing in Cookie Control since 2012.
Which law does what?
PECR — the Privacy and Electronic Communications Regulations — is the law about the device. Regulation 6 says you may not store information on someone's equipment, or read information already stored there, unless they have consented or an exemption applies. Note what that covers: not just cookies but localStorage, pixels, device fingerprinting, SDK storage — any storage or access. And note what it does not require: the information does not have to be personal data. PECR applies even if the cookie contains nothing about an identifiable person.
The UK GDPR is the law about personal data. If what a cookie collects can identify someone — directly or combined with other data — then everything you do with it after collection needs a lawful basis, transparency, and all the other obligations of data protection law.
The practical consequence: for non-exempt cookies, PECR decides whether you can set them at all, and the answer is consent. The UK GDPR then defines what valid consent looks like — freely given, specific, informed and unambiguous, and governs the data trail afterwards. You cannot use legitimate interests to skip the PECR consent requirement; that shortcut does not exist, however often it appears in banner footers.
What did the Data (Use and Access) Act 2025 change?
The DUAA is the first substantial rewrite of the UK's cookie rules since 2011, and its main provisions commenced on 5 February 2026. Two changes matter for cookies.
First, new exemptions. PECR regulation 6 now exempts, subject to their own conditions, statistical purposes (aggregated information used solely to improve the service), appearance and functionality preferences (a chosen language, a display setting), and emergency-assistance location storage or access. The conditions are the substance: statistics and appearance/functionality require clear information and a free, simple way to object. The emergency exception instead has its own narrow purpose and necessity conditions: locating a person who requests help or otherwise indicates that emergency assistance is needed. Miss the applicable conditions and the exemption does not apply.
Second, new penalties. The maximum fine under PECR rose on the same date from £500,000 to the UK GDPR level — up to £17.5 million or 4% of annual global turnover, whichever is higher. The exemptions made the rules looser; the fines made getting them wrong much more expensive. That trade is the story of the reform.
Before and since 5 February 2026: consent scope, statistics, preferences, penalties and the conditions for statistics and appearance. Emergency assistance has separate conditions.
What has never needed consent?
PECR has always exempted storage that is strictly necessary for a service the visitor explicitly asked for. It is a narrow list: session cookies that keep someone logged in, a shopping basket, load balancing, security measures such as detecting repeated failed logins, and the cookie that records someone's own consent choice. "Strictly necessary" means necessary for the service the user requested, not necessary for your business model. An advertising cookie is never strictly necessary in PECR's sense, however essential the revenue.
PECR also has a separate communication exception, covering storage solely necessary to transmit a communication, such as relevant load-balancing cookies. The three buckets below are practical action groups, not the number of legal exceptions.
The edge cases people argue about?
- A/B testing cookies. Not strictly necessary — the visitor did not ask to be in an experiment. Consent, unless you can document that a first-party statistical exemption genuinely applies to how you use them.
- Chat widgets. The cookie that keeps a conversation open is necessary once the visitor has opened the chat. The ones the widget sets on page load, before anyone has clicked, are not.
- Load balancing and CDN cookies. Exempt where their actual purpose is necessary to transmit or provide the requested service; the CDN label alone is not enough.
- Fraud and security cookies. Exempt where genuinely necessary to protect the requested service. This is the reason security_storage is the one Consent Mode signal Cookie Control leaves granted by default.
- The consent cookie itself. Necessary, and exempt: it is the record of the choice the visitor just made.
- Web fonts and CDNs that read no identifiers. Outside PECR regulation 6 unless they store or read something on the device — but check, because some do.
The rule of thumb: if you have to explain why the visitor needed it, they probably did not.
What still needs consent?
Everything outside the strictly-necessary list and the new conditional exemptions. In practice, the big categories are advertising and marketing cookies of every kind, social media embeds and their tracking, and any analytics that shares data with the tool's provider for that provider's own purposes. The new statistical exemption is about improving your own service: a provider may assist on your behalf, but using your visitors' data for its own ends takes you outside it. Cross-site tracking of any description remains firmly in consent territory.
The embeds are the ones people forget. A standard video embed, a map, a social feed, a chat widget, a review carousel — each loads a third party’s code into your page, and they may store or access information before the visitor has done anything, depending on their configuration. Our first-party versus third-party explainer covers why that matters; the short version is that an embed is a tracker until you have checked that it is not.
What does valid consent look like?
The UK GDPR standard, applied to banners: no pre-ticked boxes, no consent by scrolling or continued browsing, rejecting must be as easy as accepting, and non-exempt cookies must not be set before the choice is made. People must also be able to change their mind as easily as they consented, which is why Cookie Control keeps a persistent icon or link available to reopen preferences, and why the consent choice itself is stored in a first-party cookie so it is remembered without re-prompting.
The supplied Cookie Control panel shows accept and reject, optional categories switched off, and Save and close. Reopening preferences and pre-consent script behaviour require separate live tests.
What the ICO looks for in a banner
When the regulator has written to organisations about their banners, the same handful of points come up, and they map directly onto the consent standard.
- Rejecting is as easy as accepting: a "Reject all" of equal prominence, on the same layer, not buried in settings.
- Nothing non-exempt before the choice. Tags that set non-exempt storage on page load and ask afterwards are a common failure to test for.
- No pre-ticked boxes, and no design that nudges — colour, size or placement that makes accepting the path of least resistance.
- Clear information before the choice: what is set, by whom, for what.
- A working withdrawal route, as easy to find as the original banner.
- Honest categories. A "necessary" bucket that contains analytics is a misclassification to check for.
None of this is exotic. It is what a banner built to the standard does by default, and what a banner tuned for acceptance rate does not.
Proving it: what a consent record contains
Accountability under the UK GDPR means being able to show that consent was given, when, and for what. Cookie Control’s consent logging stores exactly six data points for every consent and every withdrawal: a 36-character identifier unique to that browser, the categories chosen, the date and time, an anonymised IP address, the user agent, and the URL the decision was made on. These are the consent-record fields described here; logging is switched on in the user area once the data processing agreement has been accepted.
Two consequences are worth planning for. First, if you change your privacy policy date, Cookie Control treats earlier consent as out of date and asks visitors again — the right behaviour, but expect a temporary dip in consented traffic when you do it. Second, Cookie Control lets a category be marked as relying on legitimate interests, and it is honest about what that means: no consent record is created, because none was sought. The documentation also warns that legitimate interests is unlikely to be the right basis for most analytics, advertising or third-party software. Use it for what it was designed for, not as a route around the banner.
Who enforces this, and what actually happens?
The ICO enforces both laws, and it finalised guidance on storage and access technologies on 29 April 2026 setting out how it reads the amended rules. The regulator has long described its cookie work as proportionate, and its public banner reviews have started with the UK's most-visited sites. But the ceiling is now the same as for any serious data protection breach, and the reputational cost of being the example is real regardless of the fine. The pragmatic reading: the regulator has been given both a carrot and a much bigger stick, and sites that ignore both are the ones taking the risk.
The ICO has also set out a position on "consent or pay" models — access in exchange for consent to tracking, or a fee. It has not ruled them out, but it expects the consent side of the choice to meet the freely-given standard, and the position is still developing. If you are considering one, take advice before you build it.
Sorting what you find: the three buckets
Every cookie, pixel and script your scan turns up goes into one of three buckets, and the bucket decides what you owe. Strictly necessary: no consent, but explain it in your policy. Exempt with conditions: no consent request if the specific exemption’s conditions are met — including clear information and a simple, free way to object for statistics and appearance/functionality — with a written note of why it qualifies. Needs consent: nothing fires until the visitor says yes, and no is as easy as yes. The action list that follows is just this sort, done properly.
Three practical action groups: essential storage, conditional exceptions and storage requiring consent. The communication and strictly-necessary exceptions sit within the first group.
What should you actually do?
- Find out what your site sets. Run a scan — you cannot categorise what you have not found.
- Sort every cookie into three buckets: strictly necessary, exempt under the new conditional exemptions, or needs consent.
- For anything in the exempt bucket, implement that exemption’s conditions; for statistics and appearance/functionality, this includes clear information and a simple opt-out. An exemption without its conditions is just a breach with better paperwork.
- For everything needing consent, configure your banner so nothing fires before the choice, and rejecting is as easy as accepting.
- Write down your reasoning. The accountability principle means being able to show your working, and it is also what turns a regulator conversation into a short one.
Where to go next: if you are still deciding whether you need a banner at all, start with do you need a banner. If you run Google tags, Consent Mode v2 is the piece that sits between the banner and Google’s products. And for the year ahead on both sides of the Channel, the 2027 guide is the annual picture.
Frequently asked questions
Sources
- PECR regulation 6 (as amended)
- Data (Use and Access) Act 2025
- ICO guidance on storage and access technologies (April 2026)
- cookiecontrol.com/updates — Changes in 2025 to UK GDPR (September 2025)