Contents
Introduction
The Privacy and Electronic Communications Regulations (PECR) have governed cookies and similar technologies for more than two decades.
But calling them the "cookie rules" can be misleading.
Regulation 6 goes considerably further than small files stored in a browser. It can apply to tracking pixels, local storage, scripts, tags, device fingerprinting and other technologies that store information on, or access information from, a user's device.
The Data (Use and Access) Act 2025 (DUAA) did not remove those rules. It rewrote them.
For website owners, the biggest change is the introduction of new circumstances in which storage or access can take place without prior consent. That creates more flexibility, particularly for some forms of analytics and website functionality.
It does not mean cookie consent has disappeared.
This article looks at what changed, the five PECR exceptions now available, where consent is still required and what website owners should actually be checking.
The DUAA also changed PECR's direct marketing rules for email, SMS and telephone campaigns. Those changes are covered separately in PECR Marketing Rules After the DUAA: What Changed for UK Email and SMS Senders.
The dates that matter are:
- 5 February 2026: the main PECR reforms came into force under the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82). This included the rewritten Regulation 6, the new cookie exceptions and the new PECR enforcement regime.
- 29 April 2026: the ICO published its finalised Guidance on the use of storage and access technologies following two consultations.
The commencement date matters. The new PECR enforcement regime applies to conduct from 5 February 2026 onwards. Earlier conduct remains subject to the previous regime.
Chapter 1: The cookie rules changed but consent did not disappear
Section 112 of the DUAA replaced Regulation 6 of PECR and introduced a new Schedule A1 setting out when information may be stored on, or accessed from, someone's terminal equipment.
"Terminal equipment" is broader than a desktop computer or mobile phone. It can include connected devices, wearables, smart TVs and other equipment capable of receiving or transmitting information.
For an ordinary website owner, however, the practical starting point is straightforward:
If your website stores information on a visitor's device or accesses information from it, you need to know why it is doing so.
Unless consent has been obtained or one of the Schedule A1 exceptions applies, the storage or access is prohibited.
That means the first compliance question is not:
"Do I have a cookie banner?"
It is:
"What is my website actually storing or accessing, and why?"
A banner can only manage technologies that have first been identified and understood.
Chapter 2: Third-party technology can still be your problem
The rewritten Regulation 6 also makes an important clarification about who is caught by the rules.
Storage or access includes instigating that storage or access.
That matters because modern websites frequently depend on technology supplied by somebody else.
An embedded video player, analytics script, social media plugin, chat widget, tag manager or advertising pixel may technically belong to a third party. That does not mean the website loading it can simply treat the resulting storage or access as somebody else's compliance problem.
If your website causes that technology to load, you need to understand what happens next.
Regulation 6 also makes clear that gaining access can include collecting or monitoring information automatically emitted by a device. The DUAA's Explanatory Notes give Wi-Fi probe requests as an example of this type of "emissions data".
That is important because not every tracking technology needs to drop a conventional cookie.
Device fingerprinting is an obvious example. A system may construct an identifier from information exposed by a browser or device without placing a traditional tracking cookie on it.
So "we don't use cookies" is not necessarily the end of a Regulation 6 analysis.
Embedded content has a practical route
Embedded video is the clearest example of the instigation problem, and the ICO's guidance sets out a way through it.
Configure the embedded content so that it does not set storage and access technologies the moment somebody visits the page, including for analytics purposes. Then tell the user, underneath the embed, that storage and access technologies will be used if they choose to press play. Use a privacy mode where the platform offers one.
Handled that way, consent is not required. The user has been informed and has chosen to access the content.
The alternatives are to add a consent request to your existing consent mechanism, to seek consent just in time on the pages where the videos appear, or to use external links instead of embeds.
If you do add embedded video to your consent mechanism, the ICO expects you to explain what that means: that enabling the technologies may result in the video platform collecting information about the visitor's viewing, for example for analytics and advertising purposes, and that declining will mean they see external links instead.
Social media plugins turn on login state
Social media plugins are treated differently again, and the distinction is easy to miss.
Where a visitor to your service is also logged in to the social media platform, the storage and access carried out by that platform's plugins can be strictly necessary for functionality the visitor has asked for.
That does not extend to visitors who have logged out, or who are not members of that network at all. Unless the plugins are configured to store or access information only on devices used by logged-in members, consent is required.
And where a plugin, script, cookie or other technology tracks users, the exception does not apply at all. Consent is required for social media tracking technologies whether or not your visitors are members of the network.
Chapter 3: The five PECR exceptions
Schedule A1 now contains five exceptions allowing storage or access without consent where their individual conditions are satisfied.
1. Communication
Storage or access can qualify where its sole purpose is carrying out the transmission of a communication over an electronic communications network.
This is a narrow technical exception. It is concerned with technology genuinely required to transmit the communication, rather than technology that is merely useful to the organisation operating the service.
2. Strictly necessary
Storage or access can qualify where it is essential to provide the online service requested by the subscriber or user.
The important word is necessary.
A technology does not become strictly necessary simply because it is convenient, commercially useful or something the business would prefer to have running.
The question is whether the requested service can actually be provided without it.
The exception applies only to information society services, meaning services delivered over the internet such as a website or an app. If you run an online service, it is likely to be one.
3. Statistical purposes
Storage or access can qualify where its sole purpose is collecting statistical information about how the service or website is used, with a view to improving it. It applies where you are an information society service provider.
This is the change that has attracted the most attention because it potentially allows some website analytics to operate without prior consent.
But it is narrower than saying:
"Analytics no longer needs consent."
That is not what the new rule says.
4. Appearance
Storage or access can qualify where its sole purpose is adapting or enhancing the appearance or functionality of a service in relation to the user's preferences or device.
This can cover genuinely functional behaviour such as adapting how a service is presented.
It does not create a general exemption for personalisation, behavioural targeting or deciding which content or adverts somebody should see based on a profile built about them.
5. Emergency assistance
Storage or access can qualify where its sole purpose is identifying the geographical position of a subscriber or user's device so that emergency assistance can be provided.
For an ordinary business website this is unlikely to be the exception that matters day to day, but it forms part of the five-exception framework.
The first two exceptions existed in the previous Regulation 6 framework. The statistical, appearance and emergency-assistance exceptions are new.
There is another important point running through most of them:
purpose matters.
Several of the exceptions use a sole purpose test. If technology is doing something else at the same time, that can take it outside the exception.
Consent also remains available under Schedule A1 where the user receives clear and comprehensive information about the purpose of the storage or access and gives valid consent.
The list is not necessarily permanent either. Regulation 6A gives the Secretary of State power to add, vary or remove exceptions through secondary legislation following the required consultation process.
Chapter 4: "Strictly necessary" does not mean necessary to the business
This distinction deserves its own section because it is easy to get wrong.
A website owner may regard analytics as necessary because they need to understand whether marketing is working.
An advertising-funded service may regard advertising technology as necessary because advertising pays the bills.
A sales team may regard a tracking tool as necessary because it attributes enquiries to campaigns.
Those things may be commercially important.
That does not make them strictly necessary for the service requested by the user.
The test is centred on delivering the requested service, not on whether the technology is useful to the organisation.
PECR gives non-exhaustive examples of activities that meet the exception: ensuring the security of terminal equipment, preventing or detecting fraud, preventing or detecting technical faults, authenticating the subscriber or user, and recording information or selections the user makes on an online service.
The exception also covers storage or access used to comply with other legislation that applies to you, such as the security requirements of data protection law. That limb is narrower than it first appears. It only applies where the technology is the only reasonable and proportionate way to comply. If you could meet the requirement without storage or access technologies, or without the specific technology you have chosen, the exception does not apply.
The ICO puts the advertising point plainly. You might regard advertising cookies as strictly necessary because they bring in the revenue that funds your service, but they are not strictly necessary from the user's perspective. There are no advertising purposes that meet the strictly necessary exception.
The guidance goes further. Online advertising purposes are not exempt from PECR's consent requirements and never have been. That covers any advertising-related purpose, including frequency capping, ad affiliation, ad measurement and performance, click fraud detection, market research, product improvement and debugging.
Several of those sound like technical or research activity rather than advertising. They are still treated as advertising purposes, and they still require consent.
Chapter 5: Some website analytics can now operate without consent
The statistical purposes exception is probably the most commercially significant change for ordinary websites.
It can potentially cover statistical measurement such as understanding:
- how many people visit a website;
- which pages they visit;
- how long visitors spend on different pages;
- how users move through the site;
- how they reached the website;
- page loading performance, bounce rates and exit pages; or
- aggregated interactions with parts of a page.
But there are limits.
The DUAA did not create a blanket "analytics cookies no longer need consent" rule.
The statistical exception is about understanding how the service is used, not identifying who is using it.
There is also a specific carve-out. The statistical purposes exception does not apply to collecting or monitoring information automatically emitted by a device, such as Wi-Fi probe requests. The emissions data described earlier therefore cannot be brought inside this exception.
To rely on the exception, the sole purpose of the technology must be collecting statistical information with a view to improving the website or service.
Users must also receive clear and comprehensive information about what is happening and must be given a simple, free means of objecting.
There is another important requirement that can easily be missed.
The resulting information must become aggregate statistical information. Where individual-level information is collected as part of that process, it should not be kept for longer than necessary for aggregation.
The exception does not cover keeping individual visitor histories, making decisions about particular visitors, profiling them, tracking them between services or linking their activity to advertising systems.
That distinction is fundamental.
Using aggregated statistics to discover that 60% of visitors leave a particular page is one thing.
Building a history of what a particular visitor viewed, what advert brought them to the site, what they later purchased and what should be advertised to them next is something very different.
The second activity does not become exempt merely because the software supplying it calls itself an analytics platform.
What about third-party analytics providers?
Using a third-party analytics provider does not automatically prevent the statistical exception from applying.
But the provider cannot simply do whatever it wants with the information.
To remain within the exception, the information can only be shared with another party for the purpose of helping improve the website or service. The website owner also needs to consider the UK GDPR relationship with that provider where personal data is involved.
That relationship has to take a particular form. To rely on the exception, the provider must be your processor and not a joint controller. It can only act on your behalf, and only use the information to help you improve your own service.
You also have to tell users that you use a third-party provider and explain what that provider does with the information it collects. The provider must not link that information with other information it holds.
This is worth checking rather than assuming. It depends on the terms your provider offers and how the product has been configured, not on how the product is marketed.
If the provider uses the information for other purposes, for example, linking website behaviour to advertising profiles or combining it with information gathered elsewhere, the position changes.
Again, the name of the product is less important than what it actually does.
Chapter 6: The appearance exception is useful, but it is not a personalisation loophole
The appearance exception can cover technologies whose sole purpose is adapting how a service appears or functions for the user or their device.
That could include things such as:
- remembering a language selected by the user;
- responding to a device's dark-mode preference;
- adapting a website to different screen sizes or device capabilities; or
- remembering certain presentation or functionality preferences.
Users still need clear information and a simple, free means of objecting.
And there is an important boundary.
Changing the presentation of a service to suit the user's device or expressed preferences is different from changing content because the business has profiled that person.
Using previous browsing behaviour or inferred interests to decide what content to promote, or what advert somebody should see, is not what this exception is designed for.
Chapter 7: An opt-out has to do something
The statistical and appearance exceptions do not remove transparency and user control.
Instead of requiring prior consent, they require clear information and a simple means of objecting, free of charge.
That means there needs to be an actual mechanism behind the words.
The ICO says an organisation can use an existing consent or preference mechanism for this purpose. For example, statistical or appearance controls could initially be enabled while still allowing the user to switch them off.
But if somebody objects, the relevant storage or access must stop.
That is not permanent. If the visitor later changes their mind, for example by switching the toggle back on, you can rely on the exception again.
A privacy policy explaining that somebody can object is not much use if there is no practical way of doing it.
And browser settings alone are not enough. Organisations cannot simply assume every visitor has configured their browser to communicate these preferences.
The important point for the website owner is therefore:
If you rely on the objection-based exceptions, test the objection mechanism.
Do not only check that the button or toggle exists. Check that the underlying technology actually stops.
Chapter 8: One technology can have more than one purpose
This is another area where labels cause problems.
One cookie, script or identifier can be capable of doing several things.
Perhaps one purpose is genuinely statistical.
Another purpose might be conversion tracking.
A third might feed an advertising profile.
PECR looks at the purposes of the storage or access.
The ICO's final guidance makes clear that the Regulation 6 exceptions are purpose-specific. If one purpose meets the requirements of an exception but another does not, you must obtain consent for the storage or access.
This is particularly important for the statistical and appearance exceptions because both depend on a sole purpose requirement.
You cannot rely on the statistical exception to collect information for improving your website while also using the same storage or access to support online advertising.
In practice, the ICO even suggests that using separate technologies for separate purposes may make compliance easier than trying to force a multi-purpose product into an exception.
So the useful compliance question is not:
"What category has the provider put this cookie in?"
It is:
"What purposes is this technology actually being used for on this website?"
Chapter 9: Advertising and tracking still require consent
The new exceptions should not be read as a green light for advertising technology.
The ICO's current guidance is explicit that storage and access technologies used for online advertising require consent.
That includes the technology involved in ad selection and delivery as well as associated tracking and profiling.
Cross-site and cross-device tracking also requires consent.
So does using device fingerprinting for advertising purposes.
And advertising measurement does not suddenly become statistical-purpose analytics merely because it involves numbers. Where the measurement is part of online advertising, it remains part of the advertising purpose for which consent is required.
This is why the question:
"Is this an analytics cookie?"
Is often the wrong question.
The better question is:
"Exactly what is this technology doing with the information it stores or accesses, and does every purpose fall within an exception?"
One caveat is worth knowing about.
When the ICO published this guidance in April 2026, it said the guidance reflected the law as it currently stood and sat separately from its ongoing review of Regulation 6 of PECR for online advertising purposes.
On 18 May 2026, the ICO published the outcome of that work and its advice to government on potential changes to Regulation 6. Its work considered whether certain lower-risk forms of online advertising could operate without consent, while retaining consent requirements for more intrusive tracking and profiling.
The ICO completed its review in May 2026 and provided advice to government on potential changes to Regulation 6. No changes have been made so far, and the existing PECR consent rules continue to apply. However, the position may change in future if the government amends Regulation 6 through secondary legislation, potentially giving organisations greater flexibility for some lower-risk forms of online advertising.
Chapter 10: What has not changed
The DUAA changed the exceptions. It did not remove the underlying consent standard.
Where consent is required, it still has to meet the UK GDPR standard: it must be freely given, specific, informed and unambiguous and involve a clear affirmative action.
Silence, inactivity or pre-ticked boxes do not amount to valid consent.
Nor can an organisation treat the presence of a cookie banner as proof that consent has been handled properly.
If a non-exempt technology requires prior consent, it should not already be operating before that consent has been obtained.
A banner that records a choice while the tracking scripts have already fired is compliance theatre rather than effective consent management.
PECR and the UK GDPR also remain separate but connected.
PECR governs the storage of information on, and access to information from, the device.
Where the information involved is personal data, the UK GDPR then applies to the processing of that personal data as well.
Chapter 11: Regulation 6 now sits in the higher PECR penalty band
The DUAA also modernised PECR enforcement.
The previous maximum monetary penalty under PECR was £500,000. The new framework has two statutory maximum penalty bands.
Regulation 6, the provision containing the storage and access rules discussed throughout this article, is one of the PECR provisions placed in the higher band.
The higher maximum is £17.5 million or, for an undertaking, 4% of its total annual worldwide turnover in the preceding financial year, whichever is higher.
The standard maximum is £8.7 million or, for an undertaking, 2% of its total annual worldwide turnover in the preceding financial year, whichever is higher. PECR infringements that fall within this penalty notice framework but are not assigned to the higher band are subject to this standard maximum.
These are statutory maximums, not automatic penalties. The amount of any fine depends on the circumstances of the infringement and the ICO's assessment of the case.
The important point is simpler:
The £17.5 million figure is directly relevant to Regulation 6. It is not merely a headline maximum borrowed from another part of PECR.
The ICO is also actively testing cookie compliance.
Announcing the final storage and access technologies guidance in April 2026, William Malcolm, the ICO's Executive Director for Regulatory Risk and Innovation, said that 99% of the UK's top 1,000 websites now meet compliance standards for cookie banners, owing to focused ICO work with industry. He added that there is still more to do, and that the ICO's work and interventions will continue.
That does not mean cookie compliance is solved.
It shows that the regulator is actively examining how consent mechanisms operate in practice, rather than treating Regulation 6 as a rule that exists only on paper.
Chapter 12: What should UK website owners do now?
Do not start with the banner.
Start with the website.
Identify every technology that stores information on, accesses information from or otherwise interacts with a visitor's device.
That means looking beyond conventional cookies. Check:
- cookies;
- local and other web storage;
- embedded third-party services;
- analytics scripts;
- advertising and conversion tags;
- social media plugins;
- tracking pixels;
- fingerprinting technology; and
- other scripts or services capable of storage or access.
Then work out what each technology actually does.
For every technology, ask:
- What is its purpose?
- Does it have more than one purpose?
- Is an exception genuinely available?
- Does that exception contain a sole-purpose test?
- If consent is required, is the technology blocked until consent is given?
- If you rely on an objection-based exception, does the opt-out actually stop it?
- Is information being shared with a third party?
- Does the third party use it for anything else?
- Does personal data result, bringing the UK GDPR into play?
- Does the information you provide to visitors accurately describe what happens in the browser?
Finally, test the implementation.
A cookie policy written last year cannot tell you whether a script added three months ago behaves lawfully today.
A banner labelled "necessary cookies only" does not make every technology behind it necessary.
And calling a service "privacy-friendly analytics" does not establish that every configuration or purpose satisfies the statistical exception.
The DUAA gives website owners more flexibility than the previous Regulation 6 framework.
But it also makes correct classification more important.
There are now more routes by which storage and access can lawfully take place without prior consent.
That only helps if you know which route you are actually relying on, and whether the technology on the website really stays inside it.
Sources
- Data (Use and Access) Act 2025, sections 112 and 115, and Schedules 12 and 13 Data (Use and Access) Act 2025 - enacted contents Schedule 12 Schedule 13
- Explanatory Notes to the Data (Use and Access) Act 2025 - relevant PECR provisions DUAA Explanatory Notes - relevant PECR provisions
- Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82) SI 2026/82 - full instrument
- Department for Science, Innovation and Technology, Data (Use and Access) Act factsheet: PEC Regulations GOV.UK - DUAA factsheet: PEC Regulations
- ICO, Guidance on the use of storage and access technologies - finalised 29 April 2026 ICO - Guidance on the use of storage and access technologies
- ICO, What are storage and access technologies? ICO - What are storage and access technologies?
- ICO, What are the PECR rules? ICO - What are the PECR rules?
- ICO, What are the exceptions? ICO - What are the exceptions?
- ICO, How do we comply with the PECR rules? ICO - How do we comply with the PECR rules?
- ICO, How do we manage consent in practice? ICO - How do we manage consent in practice?
- ICO, How do the rules apply to online advertising? ICO - How do the rules apply to online advertising?
- ICO, The maximum amount of a fine under UK GDPR and DPA 2018 ICO - The maximum amount of a fine
- ICO, Calculation of the appropriate amount of the fine ICO - Calculation of the appropriate amount of the fine
- ICO, Final storage and access technologies guidance published - 29 April 2026 ICO - Final storage and access technologies guidance published
- ICO, Our advice to government on potential changes to online advertising rules - 18 May 2026 ICO - Our advice to government on potential changes to online advertising rules
This article provides general information about the Privacy and Electronic Communications Regulations following the Data (Use and Access) Act 2025. It is not legal advice. Organisations should consider their own circumstances and refer to current ICO guidance where appropriate.