Legal and accounting support for UK businesses and individuals
office@yudey.uk
Data protection and digital business guides · 5 min read

Cookie consent for a business website

Review UK website cookie consent and the current PECR exceptions, with practical checks on scripts, information and user choices.

Jurisdiction: United Kingdom.

UK cookie rules apply to technologies that store or access information on a person's device, not only files called cookies. Check each purpose and technology before deciding whether consent or an exception applies. The ICO's updated guidance includes narrowly conditioned exceptions, including statistical and appearance purposes.

Do not label every analytics tool exempt. The statistical exception has conditions, including its sole purpose and information and objection requirements. Advertising and other uses need their own assessment. Where consent is required, control the technology before consent and provide a workable way to change the choice.

Inventory technologies by what they do

Begin with a clean browser session and a list of all installed scripts, embeds and plugins. Include local storage, pixels, device identifiers and tools introduced through a tag manager. Ask the marketing agency what each item does before and after a visitor makes a choice. A scan can identify technical activity, but it cannot by itself establish the business purpose or every recipient's subsequent use.

Record the provider, purpose, duration and trigger for each technology. A video embed may behave differently before playback, and a chat widget may load tracking before the visitor asks a question. Distinguish delivery of a requested feature from advertising measurement. This inventory becomes the specification for the consent system; choosing a banner product first can leave the actual classification work unfinished.

Assess exceptions purpose by purpose

The current ICO guidance describes conditional exceptions, including statistical purposes and appearance or functionality uses. Information and a simple means of objecting are part of the relevant conditions. [1] Check the complete conditions for the actual technology. A supplier's category labelled essential or analytics is not a legal conclusion, especially where one identifier supports several different uses.

For mixed-purpose tools, obtain a written explanation of whether advertising, cross-site profiling or the provider's own reuse can be disabled. Keep evidence of the chosen settings. If the proposed exception cannot be demonstrated, do not remove consent merely because a recent legal change sounds permissive. Personal data processing also needs its own UK GDPR assessment; device access rules are only one layer of the review.

Turn the assessment into testable behaviour

Where consent is required, specify which scripts must wait and what event allows them to run. Test a fresh visit, refusal, partial selection and later withdrawal. Check embedded third-party content and pages reached directly from a search result. A banner that stores a preference without changing script behaviour creates a misleading interface rather than an effective control.

Make choices understandable and avoid designing the refusal route to be needlessly difficult. Keep an accessible way to revisit settings. Where an exception requires an objection mechanism, test that mechanism separately instead of assuming the consent withdrawal button covers it. Document the expected result for each technology so future developers can identify regressions when a plugin or marketing tag changes.

Keep the explanation aligned with configuration

The cookie information should describe actual purposes and relevant duration, not an untouched vendor template. Give the website owner a process for approving new tags before release. A seasonal campaign often introduces a new pixel through an agency account, outside the ordinary development workflow. Requiring a short purpose and settings review prevents that route from bypassing the agreed controls.

Use Collecting information through website forms for related form collection issues and Data protection when using cloud software when assessing the underlying software providers. For Website terms and cookie review, prepare the technology inventory, current banner wording and observations from consent tests. The useful output is a clear classification and implementation list. Allocate responsibility for both drafting and technical changes, then retain the test results for the configuration that actually went live.

Test the agency's change process

Create a release example in which an agency adds a conversion tag to a campaign landing page. Ask how the tag is inventoried, who classifies its purpose and where the required blocking rule is configured. Then check a direct visit to that page using a fresh browser profile. Testing only the home page may miss a separate template or tag container.

Save the relevant configuration identifier with the test observations so a later reviewer can reproduce the result. Include the consent management platform itself in change control: an updated default or a new integration can affect previously approved behaviour. Give the business an escalation route for unexpected tracking, including who can disable the affected tag while its purpose and settings are checked. This is a maintenance task as well as an initial launch task.

Illustrative scenario

A website uses one analytics script both to improve its service and to support advertising audiences. The business cannot assume that calling the tool analytics brings every use within a statistical exception. It documents the purposes and data flows, then configures the consent approach against the current ICO conditions.

Preparation checklist

  • Inventory scripts, embedded media and storage technologies.
  • Record purposes, providers and duration.
  • Assess each claimed exception against every condition.
  • Test refusal, withdrawal and any required simple objection route.

Frequently asked questions

Are all analytics cookies exempt from consent now?

No. The current exception has conditions relating to purpose and operation. Mixed advertising or independent provider uses require separate assessment against the full ICO guidance.

Does a cookie scanner prove compliance?

It provides technical evidence about detected behaviour. Someone still needs to establish purposes, recipients, applicable rules and whether the configured choice or objection controls work as intended.

What should happen when someone withdraws consent?

The affected future activity must respond to the changed choice. Test the real scripts and relevant storage behaviour; merely changing the banner display is not sufficient evidence.

Who should approve a new marketing pixel?

Assign an owner who can assess purpose and data use with technical and marketing input. Keep approval tied to the actual settings, not just the supplier's product name.

Official sources

Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.

  1. ICO: Storage and access technology exceptions

General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.

Report a correction