Understanding the legal requirements for cookies and implementing an effective consent framework is crucial.
Introduction
Cookies have been a feature of the internet since the mid-1990s, yet the law governing their use remains one of the most misunderstood areas of website compliance. Many businesses assume that displaying a simple banner stating, ‘this site uses cookies’ is sufficient. It is not. The legal requirements around cookie consent are specific, and the Information Commissioner’s Office has made clear that it expects businesses to comply with them properly.
The law governing cookies in the United Kingdom is found primarily in the Privacy and Electronic Communications Regulations 2003, commonly known as PECR, which sits alongside the UK GDPR. While the UK GDPR governs how personal data collected through cookies is processed, PECR governs the act of placing cookies on a user’s device in the first place. Understanding the interplay between these two regimes is essential to achieving compliance.
This article explains what the law requires, what constitutes valid consent, and how to implement a cookie compliance framework that satisfies both PECR and the ICO’s current guidance.
What Are Cookies and Why Do They Matter Legally
A cookie is a small text file placed on a user’s device by a website. Cookies serve a variety of purposes, from enabling basic website functionality to tracking user behaviour across multiple sites for advertising. The legal concern is straightforward: placing a file on someone’s device and using it to collect information about their browsing activity engages both privacy and data protection law.
PECR (Privacy and Electronic Communications Regulations) does not only cover traditional cookies. It applies to any technology that stores or accesses information on a user’s device. This includes pixels, scripts, fingerprinting techniques, and local storage. The legal test is whether information is being stored on, or retrieved from, the user’s terminal equipment. If it is, PECR applies regardless of the specific technology used.
The Consent Requirement Under PECR
Regulation 6 of PECR is clear: you must not store or access information on a user’s device unless the user has been given clear and comprehensive information about the purposes of the storage or access and has given their consent. This consent must meet the UK GDPR standard, meaning it must be freely given, specific, informed, and unambiguous.
In practical terms, this means that pre-ticked boxes do not constitute valid consent. Implied consent through continued browsing is not sufficient. Cookie walls that force users to accept all cookies as a condition of accessing the site are unlikely to represent freely given consent. The user must take clear affirmative action to indicate their agreement, and they must be able to refuse non-essential cookies without being penalised for doing so.
The ICO has confirmed this position repeatedly in its guidance and through its enforcement actions. Businesses that continue to rely on implied consent mechanisms are operating outside the law.
Strictly Necessary Cookies: The Exception
PECR provides one significant exception to the consent requirement. Cookies that are strictly necessary for the provision of a service explicitly requested by the user require no consent. This exemption covers cookies that are essential for the website to function, such as session cookies that maintain a user’s login state, shopping basket cookies on e-commerce sites, and security cookies that detect authentication abuse.
The exception is narrow. Analytics cookies, even first-party analytics, are not strictly necessary. Advertising cookies are not strictly necessary. Social media cookies are not strictly necessary. Preference cookies, which are used to remember a user’s language or display settings, are a borderline case; however, the ICO’s (Information Commissioner’s Office) current position is that these generally require consent. If in doubt, the safest approach is to obtain consent.
Implementing a Compliant Cookie Consent Mechanism
The Cookie Banner
Your cookie banner is the first point of interaction and must provide clear information about what cookies you use and why. It should present the user with a genuine choice: accept all cookies, reject non-essential cookies, or customise their preferences. The option to reject must be as prominent and accessible as the option to accept. A large ‘Accept All’ button paired with a small, hidden ‘Manage Preferences’ link does not represent a fair choice.
Granular Consent
Users should be able to consent to different categories of cookies independently. At a minimum, you should distinguish between analytics cookies, marketing or advertising cookies, and functionality cookies. Each category should be accompanied by a clear explanation of what the cookies do and which specific cookies are included. Users should be able to accept some categories and reject others without being required to make an all-or-nothing choice.
No Cookies Before Consent
Non-essential cookies must not be placed on the user’s device until consent has been obtained. This is a technical requirement that many cookie consent platforms fail to implement correctly. If your analytics tracking code fires before the user has interacted with the cookie banner, you are not compliant, regardless of what the banner says. Consent must be obtained before the cookies are set, not after.
Recording and Managing Consent
You must keep records of consent. This means recording when consent was given, what information was provided to the user at the time, and what the user consented to. Users must also be able to withdraw their consent as easily as they gave it. This typically means providing a persistent mechanism, such as a link in the footer of every page, that allows users to revisit and change their cookie preferences at any time.
The Cookie Policy
Separate from the consent mechanism, you should maintain a comprehensive cookie policy that provides detailed information about every cookie your website uses. For each cookie, you should identify the cookie name, its purpose, the data it collects, whether it is a first-party or third-party cookie, and its lifespan. This information should be regularly audited to ensure it remains accurate, as cookies can change whenever you update your website, add new features, or integrate new third-party services.
Your cookie policy should be easily accessible from your cookie banner and from your website footer. It forms part of the transparency information required under both PECR and UK GDPR, and a comprehensive cookie policy demonstrates to the ICO that you take your obligations seriously.
ICO Enforcement and the Current Landscape
The ICO has historically taken a relatively lenient approach to cookie compliance, focusing on education and guidance rather than enforcement. However, this position has been shifting. ICO has conducted reviews of major websites and written to organisations whose cookie practices fall below expected standards. The trend is clear: enforcement is on the rise, putting businesses who have not addressed their cookie compliance at increasing risk.
It is also worth noting that cookie compliance is one of the most visible aspects of your data protection practice. Every visitor to your website sees your cookie banner, unlike internal data processing activities. A non-compliant cookie banner signals to regulators, customers, and competitors that your approach to data protection may be lacking more broadly.
Common Mistakes
The errors we most frequently encounter include treating cookie consent as a one-time exercise rather than an ongoing obligation; failing to audit cookies regularly, leading to undisclosed cookies appearing on the site; using a cookie consent platform without properly configuring it, so that non-essential cookies are set regardless of the user’s choice; providing no mechanism for users to change their preferences after their initial choice; and relying on vague descriptions like ‘we use cookies to improve your experience’ without specifying what the cookies actually do.
Each of these mistakes undermines the validity of the consent obtained and exposes the business to regulatory risk.
Conclusion
Cookie compliance requires more than a banner on your website. It requires a genuine understanding of the cookies your site uses, a consent mechanism that provides real choice, a comprehensive cookie policy, and ongoing monitoring to ensure continued compliance. The legal requirements under PECR are specific, and the ICO’s expectations are clear. Businesses that invest in proper cookie compliance reduce their regulatory risk and demonstrate respect for their users’ privacy, which in turn builds trust and credibility.
Need help with your website compliance?
Lawdit Solicitors’ The StayLegal package provides comprehensive website compliance tailored to your business. Visit staylegal.co.uk or contact us at lawdit.co.uk to find out how we can help.
Next in this series: Article 4 – E-Commerce Regulations: Consumer Contracts, Cancellation Rights, and Distance Selling


