UK GDPR and PECR: Cookie and Tracking Rules After the DUAA

Summary
UK website tracking is governed by the UK GDPR, for personal data, and the Privacy and Electronic Communications Regulations (PECR), the UK’s cookie rule. The Data (Use and Access) Act lets some analytics cookies run without prior consent under a narrow “statistical purposes” exception, and raised the maximum PECR fine to £17.5 million or 4 percent of worldwide annual turnover.
For years, UK and EU cookie rules were effectively identical. The Data (Use and Access) Act, effective 5 February 2026, is the first major post-Brexit split, and it changes the calculation for one specific kind of cookie.
The sections below cover what the UK GDPR and PECR require, what the DUAA changed for analytics cookies, and the bigger fines. The last section shows how to verify your UK setup.
What the UK GDPR and PECR require
PECR is the UK’s version of the EU cookie rule. It requires consent before a site stores or reads information on a visitor’s device, unless it is strictly necessary. The UK GDPR then governs the personal data any tag processes and sets the standard for valid consent: freely given, specific, informed, and unambiguous. Together they produce the same baseline the EU has, with the analytics exception below layered on top.
The ICO, the UK regulator, expects equally prominent accept and reject options, no pre-ticked boxes, no cookies before the visitor interacts, and easy withdrawal.
What the DUAA changed for analytics cookies
The Data (Use and Access) Act introduced a “statistical purposes” exception that lets analytics cookies operate without prior consent, but only when tight conditions are met. The cookies must be used only for statistics to improve the site or service, the data can be shared only with someone helping make those improvements, visitors must be told clearly, and they must get a simple, free way to object. The ICO says the exception doesn’t cover tracking individual visitors, and an analytics provider must act on your behalf and use the data only to improve your service. In effect, qualifying analytics moves from opt-in to opt-out in the UK.
Check each analytics tool against the ICO’s two tests. Tools whose provider uses the data for its own purposes, or that track individual visitors, fall outside the exception, so check your tool against both, including Google Analytics as you have it configured. A tool that fails either test still needs consent before it fires, the same as in the EU.
The ICO published updated guidance on storage and access technologies in 2026. The safe course for any tool you are unsure about is to keep requiring consent until you have confirmed it qualifies.
The bigger fines
The DUAA also raised the stakes. Since February 2026, PECR breaches, including cookie breaches, can be fined up to £17.5 million or 4 percent of worldwide annual turnover, in line with the UK GDPR. The previous cap was much lower, so a cookie failure now carries GDPR-scale exposure.
For specific ICO enforcement actions, see our Enforcement Watch tracker.
How to verify your UK setup
The questions that decide UK compliance are testable: does a non-essential tag fire before consent, and does a tag you are treating as exempt actually stay aggregate. DataTrue loads your site in a real browser, with consent granted and declined, and records what each tag sends. You can confirm that Google Analytics and advertising tags wait for consent, and see what any analytics tag you are relying on the exception for actually transmits, so you are not assuming it qualifies. Sensitive Data Detection inspects the payloads with fictitious personas. The result is a record that your UK setup does what you think it does.
See how consent verification works
This law is part of our UK website tracking compliance hub.
Questions
Do analytics cookies need consent in the UK?
Since the Data (Use and Access) Act, some do not. Analytics cookies can run without prior consent under a “statistical purposes” exception, but only if they are used for statistics to improve the site, the data is shared only with someone helping make those improvements, visitors are told clearly, and they get a simple, free way to object. The ICO adds that the exception doesn’t cover tracking individual visitors and the provider must act on your behalf. Tools that do not meet all of that still need consent.
Does Google Analytics need consent in the UK?
Check it against the ICO’s two tests. Tools whose provider uses the data for its own purposes, or that track individual visitors, fall outside the DUAA analytics exception. If your Google Analytics setup fails either test, it still needs consent before it fires, the same as in the EU.
What are the fines under PECR now?
Since February 2026, PECR breaches, including cookie breaches, can be fined up to £17.5 million or 4 percent of worldwide annual turnover, in line with the UK GDPR. The previous cap was much lower.
Is UK cookie law the same as the EU’s?
No longer. They were effectively identical until the Data (Use and Access) Act, effective February 2026, created an opt-out exception for genuinely aggregate analytics. For most advertising-linked tools, including Google Analytics, the consent requirement is unchanged.
Related guides
See what your tags do in every consent state
DataTrue loads your real pages as a visitor who accepts, rejects, or sends an opt-out signal, and reads what each tag sends. A tag that ignores the visitor’s choice shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
