Small business owner reviewing EU cookie consent law requirements on a website banner

EU Cookie Consent Law in 2026: What’s Actually Required

Quick answer: EU cookie consent law in 2026 still runs on the ePrivacy Directive plus GDPR — not a new regulation. Your banner needs a real “Reject” option, no pre-ticked boxes, and clear info before any non-essential cookie loads. A proposed update (Articles 88a and 88b) is still in negotiation and isn’t binding yet.

If you run a website that reaches EU visitors, you’ve probably heard “the cookie law is changing” more than once this year. It’s a fair thing to wonder about. Rumors like that cost small business owners real money, because agencies use them to sell rushed rebuilds nobody needs yet.

Here’s the honest version, based on what’s actually in force right now and what’s still just a proposal.

What Law Actually Governs Cookies in the EU Right Now?

Two laws work together here, and people mix them up constantly.

The ePrivacy Directive (2002/58/EC, updated in 2009) is the one that specifically covers cookies. It says any cookie that isn’t strictly necessary for a service you asked for needs your prior consent before it’s set.

The GDPR doesn’t mention cookies by name. However, it defines what valid consent actually looks like — freely given, specific, informed, and unambiguous. So the Directive tells you when you need consent, and GDPR tells you what counts as real consent.

Both apply at the same time. A banner that satisfies one but not the other still isn’t compliant.

Is There a New EU Cookie Law Coming in 2026?

Sort of — but nothing has passed yet. The European Commission formally withdrew the long-stalled ePrivacy Regulation in February 2025, after eight years of Council deadlock. That draft was meant to modernize cookie rules and finally replace the old Directive.

In its place, the Commission published the Digital Omnibus proposal in November 2025. Instead of a separate ePrivacy law, it folds cookie consent directly into the GDPR through two new articles:

  • Article 88a would stop websites from re-prompting users who already refused consent, which is a common annoyance right now.
  • Article 88b would make browser-level consent signals — like Global Privacy Control — legally binding, so a compliant site would have to respect that signal instead of showing a banner at all.

As of mid-2026, this proposal is still in Trilogue negotiations between the Parliament, Council, and Commission. It is not law. Nothing changes for your website today because of it. That said, it’s worth tracking, because once it passes, sites will get a limited window (reportedly around six to twenty-four months, depending on the article) to comply.

What Does a Compliant Cookie Banner Actually Need in 2026?

This is the part that matters for your business today, regardless of what happens with the Digital Omnibus. A compliant banner needs to:

  • Block non-essential cookies until consent is given. Analytics and advertising cookies cannot fire before the user clicks accept.
  • Offer an equally visible “Reject” button. It cannot be hidden behind a “Settings” or “Manage Preferences” link while “Accept” sits front and center.
  • Avoid pre-ticked boxes. Every checkbox for a non-essential category must start unchecked.
  • Explain cookie purposes in plain language. Not just “we use cookies,” but what kind, and why.
  • Let users withdraw consent as easily as they gave it. A permanent, reachable settings link, not a one-time popup.

The European Data Protection Board’s Cookie Banner Taskforce report sets out these exact expectations after reviewing thousands of user complaints across the EU. That report is one of the closest things website owners have to an official checklist, and it’s worth reading directly if you want the source material rather than a summary.

Why Do So Many Cookie Banners Still Get This Wrong?

Because “dark patterns” are still everywhere, and most site owners don’t realize their plugin is generating one by default.

A recent study cited in industry compliance guides found that only about 30.66% of websites had a visible “reject all” button in 2026. That means roughly seven in ten sites are technically out of compliance the moment a regulator looks closely.

The most common mistakes I see on client sites before I touch them:

  1. Reject buried two clicks deep. Accept is one click; Reject requires opening a settings panel first. That’s a classic dark pattern under EDPB guidance.
  2. Analytics scripts loading before consent. Google Analytics or Meta Pixel fires the instant the page loads, regardless of what the banner says.
  3. A cookie policy that hasn’t been updated in years. New ad platforms get added, but the policy still lists tools you stopped using in 2022.

None of these are exotic problems. They’re mostly configuration mistakes in whatever consent plugin got installed once and never revisited.

How Long Does Cookie Consent Last?

Most EU data protection authorities, especially France’s CNIL, treat consent as stale after 12 months. After that, you’re expected to ask again. You also need fresh consent any time you add a new tracking purpose — consent given for analytics doesn’t automatically cover advertising you bolt on later.

If a visitor clears their cookies, your record of their consent disappears too. Legally, that means you have no proof they ever agreed, so the banner needs to reappear.

What Happens If You Get This Wrong?

The penalties aren’t hypothetical. GDPR fines can reach €20 million or 4% of global annual turnover, whichever is higher. And enforcement has been active, not theoretical: France’s CNIL fined Google €325 million and Shein €150 million in September 2025 over cookie consent violations, according to a detailed 2026 practitioner guide from Consenteo.

Most small businesses won’t attract a fine that size. However, national authorities also issue smaller corrective orders that require changes within weeks, and those compound daily if ignored. It’s rarely worth the risk for the cost of fixing a banner properly the first time.

How Do I Fix My Cookie Banner Without Overhauling My Whole Site?

You usually don’t need a full rebuild. Most of the time, this is a targeted fix:

  1. Audit what actually loads before consent using your browser’s network tab.
  2. Reconfigure your consent management plugin so non-essential scripts are genuinely blocked, not just hidden.
  3. Rebuild the banner layout so Reject and Accept carry equal visual weight.
  4. Update your cookie policy to match what’s actually running on the site today.
  5. Set a reminder to refresh consent records every 12 months.

If you’re also updating your privacy policy at the same time — which you should, since the two documents need to match — I’ve written about building a privacy policy page that satisfies Google AdSense reviewers, and the same principles apply to GDPR compliance. You can also generate a starting draft with the free Privacy Policy Generator before customizing it for your specific cookies and vendors.

Frequently Asked Questions

Does the ePrivacy Regulation replace the EU Cookie Directive in 2026? No. The proposed ePrivacy Regulation was withdrawn in February 2025. Cookies are still governed by the original ePrivacy Directive (2002/58/EC) alongside GDPR, and that remains true throughout 2026.

Do I need a cookie banner if my business is based outside the EU? Yes, if you target EU residents or process their personal data. GDPR’s Article 3(2) applies based on who you’re serving, not where your company is registered.

Is “by continuing to browse, you agree to cookies” legal? No. Continued browsing is not valid consent under GDPR or CJEU case law, including the Planet49 ruling. Users must take a clear, affirmative action like clicking “Accept.”

How often do I need to re-collect cookie consent? Most EU regulators, following CNIL guidance, treat consent as expired after 12 months. You should also re-collect consent any time you add a new tracking tool or purpose.

Will browser-level consent signals like Global Privacy Control become mandatory? Not yet. That’s proposed under Article 88b of the Digital Omnibus package, but it’s still in EU Trilogue negotiations as of mid-2026 and isn’t legally binding.

What’s the maximum GDPR fine for cookie consent violations? Up to €20 million or 4% of global annual turnover, whichever is higher. Regulators have issued fines at that scale, including a €325 million penalty against Google in September 2025.

Cookie compliance isn’t glamorous work, but it’s the kind of thing that quietly protects your business while you focus on everything else. If your banner hasn’t been touched since it was installed, that’s usually a sign it’s worth a second look — especially before the Digital Omnibus changes eventually land.

I help small businesses and startups across the EU, US, and UK fix exactly this kind of thing on WordPress and Wix sites, alongside the rest of their build. If you want a second pair of eyes on your setup, message me on WhatsApp and I’ll take a look.

Business owner reviewing her website's cookie banner against the updated UK cookie consent rules

UK Cookie Consent Rules 2026: What Changed

This article explains recent changes to UK law in plain terms and is not a substitute for legal advice. If your business handles sensitive data or faces regulatory scrutiny, consult a qualified data protection professional.

Quick answer: UK cookie consent rules changed significantly in 2026 under the Data (Use and Access) Act. Some low-risk cookies, like basic analytics, no longer require consent, but you must still offer a clear way to object. PECR fines also rose to £17.5 million, matching UK GDPR penalties, so getting your cookie banner right now carries real financial stakes.

If your website hasn’t touched its cookie banner in a year or two, this is worth five minutes of your attention. UK cookie law changed more in the past twelve months than in the previous decade combined.

What Actually Changed, and When

The Data (Use and Access) Act 2025 received Royal Assent in June 2025, and its key cookie-related provisions came into force on 5 February 2026. According to the official legislation on legislation.gov.uk, the Act amended the Privacy and Electronic Communications Regulations (PECR), the law that governs cookies and tracking technologies on UK websites.

The Information Commissioner’s Office then finalized its updated guidance on 29 April 2026, clarifying exactly how businesses should apply these changes in practice. That guidance is what your website needs to comply with today, not the older cookie rules many templates and plugins were built around.

The Three Changes That Actually Matter for Your Website

1. Some Cookies No Longer Require Consent

The Act introduced new exemptions for specific low-risk purposes: basic first-party analytics used solely to improve your website, cookies that preserve your site’s appearance settings, and cookies used for emergency assistance services. If your only non-essential cookies fall into one of these categories, you may not need a full consent banner for them anymore.

However, this exemption comes with a catch. Even under these exemptions, you must still provide a “simple and free” way for visitors to object to the cookie use, and you must clearly explain what the cookie does. Silence or a confusing settings menu doesn’t satisfy that requirement.

2. Penalties Jumped to £17.5 Million

Here’s the number that should genuinely get your attention. Maximum PECR fines rose from £500,000 to £17.5 million, or 4% of global turnover, aligning cookie violations with the same enforcement level as UK GDPR breaches. That’s a 35-fold increase, and it signals the ICO treats cookie compliance as a serious matter now, not a minor technicality.

3. A New Complaints Procedure Requirement

From 19 June 2026, organizations must have a formal, documented complaints procedure for data protection issues, including an audit trail of how complaints get handled. If your privacy policy doesn’t currently mention how someone can raise a data concern with you directly, that’s a gap worth closing.

Does a Simple Business Website Actually Need a Cookie Banner?

Here’s where I’ll give you the direct answer most legal explainers dance around. If your site uses only strictly necessary cookies, things required for basic function like a shopping cart or login session, you likely don’t need a consent banner at all.

However, most small business sites run Google Analytics, embedded social media widgets, or advertising pixels, all of which typically require consent under the updated rules. Before assuming you’re exempt, audit every cookie your site actually sets. WordPress sites in particular often set cookies through plugins you installed months ago and forgot about entirely.

What Should Your Cookie Banner Actually Look Like Now?

The ICO’s guidance is specific here, and it’s worth following exactly. A compliant banner needs an “Accept All” and a “Reject All” option with equal visual prominence. That means no burying “Reject” in a tiny link while “Accept” gets a bold, colorful button, a design pattern the ICO has explicitly flagged as non-compliant.

Pre-ticked boxes for optional cookies also don’t count as valid consent, and neither does “by continuing to browse, you agree to cookies” language. Consent needs an active, clear action from the visitor, not passive acceptance through inaction.

The Nuance Most Small Businesses Miss: This Isn’t Just About the Banner

Here’s my honest take after reviewing enough client sites. Business owners fixate entirely on the cookie banner’s design and completely overlook their privacy policy, which also needs updating to reflect these changes. Your policy should now describe which cookies fall under the new exemptions, how visitors can object to them, and how your new complaints procedure works.

A pretty, technically compliant banner sitting on top of an outdated privacy policy still leaves you exposed. Both pieces need to match the current law, not just the visible banner your visitors interact with.

This kind of compliance work often overlaps with broader site health issues I cover in 10 website mistakes costing small businesses thousands, since outdated legal pages tend to show up alongside other neglected maintenance items.

What Should You Do About This Right Now?

Start by auditing every cookie your site actually sets, most WordPress sites have several plugin-installed cookies owners have never reviewed. Confirm which, if any, fall under the new exemptions, and update your banner to meet the “equal prominence” requirement for accept and reject.

Then update your privacy policy to reflect the DUAA changes and add a documented complaints procedure before the 19 June 2026 deadline, if you haven’t already. If your current developer isn’t confident navigating this, it’s worth confirming they understand current compliance requirements before your next site update. I’ve covered what a technically current WordPress developer should know in more depth in my WordPress developer cost guide, which touches on the broader skill set worth checking for.

Frequently Asked Questions

Do all UK websites need a cookie consent banner in 2026?
No. Sites using only strictly necessary cookies don’t need a banner. Most sites using analytics, advertising, or social media widgets still require consent under the updated PECR rules.

What changed in UK cookie law in 2026?
The Data (Use and Access) Act 2025 introduced new exemptions for low-risk cookies like basic analytics, raised maximum PECR fines to £17.5 million, and added a new complaints procedure requirement from June 2026.

Can I skip consent for Google Analytics on my UK site?
Only in narrow cases where the analytics use falls strictly within the new statistical purposes exemption and no other tracking occurs. Most standard Google Analytics setups still require consent.

What happens if my cookie banner doesn’t meet the new ICO requirements?
You risk enforcement action from the ICO, with maximum penalties now at £17.5 million or 4% of global turnover, though enforcement typically prioritizes serious, repeated, or large-scale violations first.

Do I need to update my privacy policy because of these changes?
Yes. Your privacy policy should reflect the new cookie exemptions, explain how visitors can object to tracking, and describe your complaints handling procedure, required from 19 June 2026.

Is this UK law different from EU cookie rules?
Yes. Since the DUAA amendments, UK cookie law is now a distinct regime from EU GDPR, with its own exemptions and requirements. Sites serving both UK and EU visitors need compliant mechanisms for each separately.

Need Help Reviewing Your Site’s Compliance?

If you’re not sure whether your cookie banner and privacy policy actually meet the updated 2026 requirements, message me on WhatsApp and send me your link. I’ll give you a straight technical read on what needs updating.