A single biscuit displayed on a gallery plinth behind a velvet rope under a spotlight
SEO

The Cookie Law in 2026: What UK Websites Actually Need to Do

If your website serves people in the UK, the cookie rules in 2026 come from two places: PECR, the Privacy and Electronic Communications Regulations, and the UK GDPR, which defines what counts as consent. In practice you must ask before setting any cookie that is not strictly necessary, make rejecting as easy as accepting, explain in plain words what each type of cookie does, and let people change their mind later. Strictly necessary cookies, such as a shopping basket or a login session, are exempt. Everything else, including analytics, needs a genuine yes first. The authoritative rulebook is the ICO’s cookies guidance, not any blog post, ours included.

What we said in 2011, and what has changed since

This post started life in December 2011 as a short announcement of the then-new EU cookie law, the e-Privacy Directive. The original advice was simple: install a WordPress plugin called Choc Chip EU Cookie, point it at your terms and conditions page, and the job was done. Our own banner at the time read “We use cookies. By browsing this site you agree to the use of cookies”, with a single Accept button and no way to say no.

Fifteen years on, almost every part of that has aged out:

  • The legal basis moved. The UK left the EU, but the cookie rules did not leave the UK. They now sit in PECR, with the consent standard supplied by the UK GDPR. Regulation 6 of PECR, the same regulation the 2011 post quoted, still covers storing or reading information on a visitor’s device.
  • Implied consent died. “Keep browsing and we will take that as a yes” was tolerated by the ICO in the early years while everyone adjusted. Its current guidance is unambiguous: consent means a clear, positive choice made before non-essential cookies are set.
  • A notice bar is no longer the job. The Choc Chip plugin displayed a message; it did not stop anything loading. In 2026 the mechanism matters more than the message. Non-essential cookies have to stay off until someone opts in.
  • The tooling changed too. We built everything on WordPress back then, in the years when our founder Mo Rafi was teaching WordPress at Google Campus London. Today we build fast static Astro sites, which has a pleasant side effect for this topic: a static site sets almost no cookies until you deliberately add something that does.

The rules in plain English

Two sets of rules do the work, and they interlock.

PECR says you must not store information on someone’s device, or read information from it, without consent, unless doing so is strictly necessary for a service the person has asked for. Note the wording: it covers the technique, not just files literally named cookies. Local storage, tracking pixels and fingerprinting scripts all fall under the same rule.

UK GDPR defines what that consent must look like: freely given, specific, informed and unambiguous, given by a clear positive action. Pre-ticked boxes fail. Silence fails. Scrolling past the banner fails.

Strictly necessary is narrower than most site owners hope. It means necessary for the thing the visitor asked to do: keeping a basket together through checkout, keeping someone logged in, security and fraud prevention, remembering the cookie choice itself. It does not mean necessary for your marketing. Analytics, personalisation and advertising cookies all sit on the consent side of the line.

None of this is legal advice, and the detail matters, so treat the ICO’s cookies guidance at ico.org.uk as the live rulebook. UK data law is still being reformed, and when official guidance and blog posts disagree, the guidance wins.

Cookie or technologyConsent needed?Why
Login and session cookiesNoStrictly necessary for the service the visitor requested
Shopping basket and checkoutNoSame exemption
Security and fraud preventionNoSame exemption
Remembering the visitor’s cookie choiceNoYou are allowed to remember that someone said no
Analytics (GA4 and similar)YesUseful to you is not the same as essential to the visitor
Preference cookies (language, display settings)Usually yesExempt only when genuinely needed to deliver what was asked for
Advertising and retargetingYesNon-essential by definition
Third-party embeds (video players, maps, social widgets)Yes, if they set cookiesYou are responsible for what loads through your pages

If your site only uses the top half of that table, you may not need a consent banner at all: a clear cookies section in your privacy page can be enough. The banner obligation starts the moment anything from the bottom half appears.

What an honest banner looks like

The ICO has been openly critical of banners designed to harvest consent rather than ask for it. A fair banner passes this checklist:

  • Nothing non-essential loads before the visitor chooses. Test this rather than assuming it.
  • Reject is as easy as accept: same screen, same prominence, same number of clicks.
  • Plain wording that says what the cookies are for, not “to enhance your experience”.
  • No pre-ticked boxes, and no consent bundled into “by using this site you agree”.
  • A way to change or withdraw the choice later that is easy to find.
  • A cookie policy that lists what you actually set, kept up to date.

If your current banner fails the second point, fix that first. A giant coloured Accept button next to a grey “manage preferences” maze is exactly the pattern the regulator keeps calling out.

The analytics trade-off nobody should dodge

Ask honestly and some visitors will say no. That means GA4 will report fewer users than actually visited your site. The smaller number is not broken; the old number was inflated by people who were never given a choice. Some practical ways to live with it:

  • Use Google’s consent mode properly. It adjusts how Google tags behave based on the visitor’s choice and estimates some of what can no longer be measured directly. Whether modelled data is good enough for your decisions is a judgement call, not a legal question.
  • Lean on data that does not come from your visitors’ browsers. Google Search Console reports your search performance without setting a single cookie on your site. Our guide to checking your Google rankings shows how to read it, and the DIY SEO guide covers how far you can get with free data alone.
  • Remember that most SEO work never touches visitor cookies. Rank tracking, site audits and keyword research all happen from outside your site. We keep a round-up in best free SEO tools, and the wider SEO tools hub compares the paid platforms we use on client work.
  • Be sceptical of “no consent needed” analytics claims. Some cookieless analytics products genuinely avoid PECR’s consent requirement; others just claim to. Judge the claim against the ICO’s guidance, not the vendor’s marketing page.

One more 2026 wrinkle: AI assistants do not accept cookies and never see your banner. Whether ChatGPT recommends your business depends on your content and the sources that cite you, not on your consent rate, so a stricter banner costs you nothing on that front.

A workflow to get compliant this week

  1. Audit what actually loads. Open your site in a clean private window with developer tools open (the Application or Storage tab) and note every cookie set before you click anything. A cookie scanner does the same job at scale.
  2. Delete what you do not need. Old plugins, abandoned tracking scripts and forgotten embeds are the usual culprits. Fewer cookies means a simpler banner, or none.
  3. Classify what remains as strictly necessary or non-essential, using the table above.
  4. Install a consent tool that blocks first and only fires tags after consent. A tool that merely displays a message repeats our 2011 mistake.
  5. Wire your tags to consent. In practice that means consent mode for Google tags, or consent-based triggers in your tag manager.
  6. Test as a stranger. Fresh private window: confirm nothing non-essential is set before you choose, click reject and confirm it stays that way, then accept and confirm the tags appear.
  7. Write it down and recheck. Update the cookie policy, then repeat the audit whenever you add a plugin, embed or script, because that is when new cookies sneak in.

Where the real rules live

We are an SEO and web design agency in London, not a law firm, and this post is practical guidance, not legal advice. The authoritative source for UK cookie rules is the Information Commissioner’s Office: ico.org.uk carries the current cookies guidance, written for site owners rather than lawyers, and it is updated when the law moves. If your situation is sensitive, for example health data, children’s services or finance, pay a privacy specialist rather than betting on a blog post, including this one.

What we can help with is the practical side: building sites that need fewer cookies in the first place, wiring consent tools so they actually block, and keeping your visibility measurable when analytics data thins out.

Book a Free Consultation

Frequently asked questions

No. The requirement is consent for non-essential cookies, not a banner for its own sake. A site that sets only strictly necessary cookies, or none at all, does not need one. Plenty of small brochure sites fall into that category, especially static builds with no analytics or embeds.

Is “by continuing to browse you agree to cookies” still acceptable?

No. That wording was everywhere in the early 2010s, and our own 2011 banner said almost exactly that. The ICO tolerated implied consent for a period, but current guidance requires a clear positive action before non-essential cookies are set, so implied consent banners fail on both wording and mechanics.

Under current ICO guidance, yes. Analytics helps you, but it is not strictly necessary for the visitor to receive the service they asked for, however anonymous the reports feel. UK data law has been under reform, so if you are hoping this position softens, watch the ICO’s guidance rather than the rumour mill.

Who is responsible for cookies set by embedded content?

You are responsible for what loads through your pages. An embedded video player, map or social widget that sets cookies needs consent like anything else on your site. Good consent tools can hold these embeds back until the visitor agrees, showing a placeholder in the meantime.

No. PECR remained UK law after Brexit, and the EU GDPR’s consent standard carried over into the UK GDPR. The labels changed; the obligation to ask first did not.

Can we just copy the banner a big brand uses?

Better than nothing, worse than checking. Large sites are regularly criticised for consent design that nudges people towards accepting, so a famous logo is no guarantee of compliance. The ICO’s guidance is short enough to read directly; copy that instead.

Excellent

Based on 60 reviews

Google

Showing our 12 most recent Google reviews, newest first. No filtering by rating. Read all 60 on Google.