This article explains recent changes to UK law in plain terms and is not a substitute for legal advice. If your business handles sensitive data or faces regulatory scrutiny, consult a qualified data protection professional.
Quick answer: UK cookie consent rules changed significantly in 2026 under the Data (Use and Access) Act. Some low-risk cookies, like basic analytics, no longer require consent, but you must still offer a clear way to object. PECR fines also rose to £17.5 million, matching UK GDPR penalties, so getting your cookie banner right now carries real financial stakes.
If your website hasn’t touched its cookie banner in a year or two, this is worth five minutes of your attention. UK cookie law changed more in the past twelve months than in the previous decade combined.
What Actually Changed, and When
The Data (Use and Access) Act 2025 received Royal Assent in June 2025, and its key cookie-related provisions came into force on 5 February 2026. According to the official legislation on legislation.gov.uk, the Act amended the Privacy and Electronic Communications Regulations (PECR), the law that governs cookies and tracking technologies on UK websites.
The Information Commissioner’s Office then finalized its updated guidance on 29 April 2026, clarifying exactly how businesses should apply these changes in practice. That guidance is what your website needs to comply with today, not the older cookie rules many templates and plugins were built around.
The Three Changes That Actually Matter for Your Website
1. Some Cookies No Longer Require Consent
The Act introduced new exemptions for specific low-risk purposes: basic first-party analytics used solely to improve your website, cookies that preserve your site’s appearance settings, and cookies used for emergency assistance services. If your only non-essential cookies fall into one of these categories, you may not need a full consent banner for them anymore.
However, this exemption comes with a catch. Even under these exemptions, you must still provide a “simple and free” way for visitors to object to the cookie use, and you must clearly explain what the cookie does. Silence or a confusing settings menu doesn’t satisfy that requirement.
2. Penalties Jumped to £17.5 Million
Here’s the number that should genuinely get your attention. Maximum PECR fines rose from £500,000 to £17.5 million, or 4% of global turnover, aligning cookie violations with the same enforcement level as UK GDPR breaches. That’s a 35-fold increase, and it signals the ICO treats cookie compliance as a serious matter now, not a minor technicality.
3. A New Complaints Procedure Requirement
From 19 June 2026, organizations must have a formal, documented complaints procedure for data protection issues, including an audit trail of how complaints get handled. If your privacy policy doesn’t currently mention how someone can raise a data concern with you directly, that’s a gap worth closing.
Does a Simple Business Website Actually Need a Cookie Banner?
Here’s where I’ll give you the direct answer most legal explainers dance around. If your site uses only strictly necessary cookies, things required for basic function like a shopping cart or login session, you likely don’t need a consent banner at all.
However, most small business sites run Google Analytics, embedded social media widgets, or advertising pixels, all of which typically require consent under the updated rules. Before assuming you’re exempt, audit every cookie your site actually sets. WordPress sites in particular often set cookies through plugins you installed months ago and forgot about entirely.
What Should Your Cookie Banner Actually Look Like Now?
The ICO’s guidance is specific here, and it’s worth following exactly. A compliant banner needs an “Accept All” and a “Reject All” option with equal visual prominence. That means no burying “Reject” in a tiny link while “Accept” gets a bold, colorful button, a design pattern the ICO has explicitly flagged as non-compliant.
Pre-ticked boxes for optional cookies also don’t count as valid consent, and neither does “by continuing to browse, you agree to cookies” language. Consent needs an active, clear action from the visitor, not passive acceptance through inaction.
The Nuance Most Small Businesses Miss: This Isn’t Just About the Banner
Here’s my honest take after reviewing enough client sites. Business owners fixate entirely on the cookie banner’s design and completely overlook their privacy policy, which also needs updating to reflect these changes. Your policy should now describe which cookies fall under the new exemptions, how visitors can object to them, and how your new complaints procedure works.
A pretty, technically compliant banner sitting on top of an outdated privacy policy still leaves you exposed. Both pieces need to match the current law, not just the visible banner your visitors interact with.
This kind of compliance work often overlaps with broader site health issues I cover in 10 website mistakes costing small businesses thousands, since outdated legal pages tend to show up alongside other neglected maintenance items.
What Should You Do About This Right Now?
Start by auditing every cookie your site actually sets, most WordPress sites have several plugin-installed cookies owners have never reviewed. Confirm which, if any, fall under the new exemptions, and update your banner to meet the “equal prominence” requirement for accept and reject.
Then update your privacy policy to reflect the DUAA changes and add a documented complaints procedure before the 19 June 2026 deadline, if you haven’t already. If your current developer isn’t confident navigating this, it’s worth confirming they understand current compliance requirements before your next site update. I’ve covered what a technically current WordPress developer should know in more depth in my WordPress developer cost guide, which touches on the broader skill set worth checking for.
Frequently Asked Questions
Do all UK websites need a cookie consent banner in 2026?
No. Sites using only strictly necessary cookies don’t need a banner. Most sites using analytics, advertising, or social media widgets still require consent under the updated PECR rules.
What changed in UK cookie law in 2026?
The Data (Use and Access) Act 2025 introduced new exemptions for low-risk cookies like basic analytics, raised maximum PECR fines to £17.5 million, and added a new complaints procedure requirement from June 2026.
Can I skip consent for Google Analytics on my UK site?
Only in narrow cases where the analytics use falls strictly within the new statistical purposes exemption and no other tracking occurs. Most standard Google Analytics setups still require consent.
What happens if my cookie banner doesn’t meet the new ICO requirements?
You risk enforcement action from the ICO, with maximum penalties now at £17.5 million or 4% of global turnover, though enforcement typically prioritizes serious, repeated, or large-scale violations first.
Do I need to update my privacy policy because of these changes?
Yes. Your privacy policy should reflect the new cookie exemptions, explain how visitors can object to tracking, and describe your complaints handling procedure, required from 19 June 2026.
Is this UK law different from EU cookie rules?
Yes. Since the DUAA amendments, UK cookie law is now a distinct regime from EU GDPR, with its own exemptions and requirements. Sites serving both UK and EU visitors need compliant mechanisms for each separately.
Need Help Reviewing Your Site’s Compliance?
If you’re not sure whether your cookie banner and privacy policy actually meet the updated 2026 requirements, message me on WhatsApp and send me your link. I’ll give you a straight technical read on what needs updating.

