Skip to content
PeekWellThe Rulebook
Join now

Advertising cookies: ad-tech loading before consent

At a glance

UK-05MediumPECR reg. 6(1), (2)(a) (DUAA 2025 s. 112(2)); Sch. A1; ICO guidance on online advertising

Peeky looks for advertising technology partners that load on a page before the visitor has agreed, and lists each one it saw.

Last checked against the source:

I need to fix thisI need the rule

The rule

Regulation 6(1) of PECR now reads: “Subject to Schedule A1, a person must not store information, or gain access to information stored, in the terminal equipment of a subscriber or user.” Regulation 6(2)(a) provides that a reference to storing or gaining access “includes a reference to instigating the storage or access”. The Data (Use and Access) Act 2025 (DUAA), section 112, substituted the regulation with effect from 5 February 2026.

The instigating words are new. The text of regulation 6 as it stood on 4 February 2026 spoke only of a person who would “store or gain access to information” and contained no reference to instigating. The statute does not define the word and does not name advertising technology. That is why this check is flagged as an emerging duty, and why it asks a narrower question than UK-01.

The ICO’s finalised guidance of April 2026 gives the site operator the primary role. PECR says that “a person” must not store or access information, and the guidance says that, as the service provider, “you have the primary responsibility for compliance”, because you decide what storage and access technologies to use, “including whether your service incorporates third-party features or if you enable third-party storage and access technologies”. On third-party technologies it says: “As the online service provider, it is your responsibility to understand the technologies you intend to use and ensure you comply with PECR.” On the pages read for this article, the guidance does not discuss the instigating wording or say how it applies to an advertising vendor. No published decision applying it to a vendor was found.

On advertising itself the position is settled. The ICO’s guidance says that “the use of storage and access technologies for online advertising purposes requires consent”, covering “the technical processes involved in ad selection and delivery, as well as any associated tracking and profiling”. Advertising measurement is part of that consent and does not need a separate one. The statistics exception does not help: the guidance lists as needing consent “information on whether users viewed or clicked on an advert displayed to them, for the purpose of measuring the performance of the advert” and says the exception “does not apply to purposes related to online advertising”. Schedule A1 contains no advertising exception; paragraphs 2 to 7 cover consent, transmission, strict necessity, statistics, appearance and emergency location. In its letter of 5 March 2024 to IAB UK and the Association of Online Publishers, the ICO said that online advertising cookies “are not exempt from PECR’s consent requirements and never have been”, including third-party cookies used for “frequency capping, ad affiliation, click fraud detection, market research, product improvement, debugging and any other purpose”.

The guidance also sets out what has to happen along the chain. When consent is collected, the operator must say who data will be shared with, and for what purpose; “any third party who relies on the consent you obtain from your users must be able to demonstrate that your users understand you intend to share the data with them”. If a visitor withdraws consent, the one who collected it “you are responsible for telling the third parties”.

The penalty provisions are those described in UK-01. For infringements of regulation 6 the higher maximum applies under s. 157(5) of the 2018 Act, as Schedule 13 applies it, which for an undertaking is “£17,500,000 or 4% of the undertaking’s total annual worldwide turnover in the preceding financial year, whichever is higher”. The transitional rules (SI 2026/82, reg. 11) keep the earlier regime for acts before 5 February 2026.

Section 112 also lets the Secretary of State add exceptions by regulations. This article states Schedule A1 as read on 7 October 2026.

What PeekWell checks and how

UK-05 asks one question: which advertising technology partners loaded on this page before the visitor had agreed? The method matches UK-01: a fresh browser context with no saved choices, every request and cookie recorded as the page loads, and no click on the banner.

What differs is the grouping. From the inventory of third-party requests and cookies, the scan tags each party that its maintained list marks as advertising technology, such as an ad exchange, a demand-side platform or a retargeting pixel, and checks whether it loaded before any consent event. The report lists each party seen, so you can see who is there, and marks the finding as an emerging-duty flag, since the instigating wording is new. Severity starts at medium for that reason.

The decision is made by code, from a mapping of domains to purposes and the timing of the requests. A language model never decides that a partner loaded.

The scan has limits, and the report says so. It sees which advertising domains a browser contacted, not who instigated the contact in the legal sense: that depends on contracts and on who configured what, and the scan does not read either. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. A request that a vendor makes from its own servers, for example through server-side tagging, is outside what a browser visit can see. A list only knows the vendors on it. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.

Why it matters for a company

A published ICO decision on a third-party advertising pixel shows what a regulator looks at. In its reprimand to Bonne Terre Limited, trading as Sky Betting and Gaming, the ICO found that MediaMath, an advertising platform contracted by the company, used a pixel embedded in skybet.com to set about 40 third-party marketing cookies before visitors had set preferences in the cookie banner. That ran from 10 January to 3 March 2023. The ICO alerted the company on 2 March; the company said it fixed the problem the next day.

The decision was addressed to the site operator. The ICO reasoned that the company “embeds third-party tracking technologies including cookies” and so “determines the purposes and means” of the processing. The advertising platform is named in the decision but was not its subject. The reprimand was issued under UK GDPR Articles 5(1)(a), 6(1)(a) and 7(1), not PECR, and it concerned a period before the instigating wording took effect. It shows how the ICO treats a vendor’s pixel on an operator’s site, not how it will apply the new wording.

For a company, three practical points follow. A vendor’s tag on your page is treated as your choice, so the list of vendors that load is a list you are answerable for. A contract with the vendor limits what it may do with data, and the ICO took such controls into account in assessing seriousness. And the new wording means a vendor may carry its own exposure for the cookies its code sets, so the duty may run in more than one direction.

Smaller companies and larger companies

The rule has no size threshold, and the ICO’s guidance applies to any organisation running an online service.

In a smaller company the ad technology arrives through a marketing plugin or a pasted pixel: a retargeting tag from an ad platform, a social network’s pixel, an affiliate script. Each one calls other partners, so a single pasted line can bring several vendors onto the page. We could not confirm a published ICO decision on this against a smaller company.

In a larger company the supply chain is longer. Media buyers, agencies and tag managers add partners, and each partner’s code may load further partners during the page load. The Bonne Terre reprimand notes the company’s statement that its demand-side platform worked under a master services agreement with contractual limits on its use of data, and the ICO took those limits into account in assessing seriousness. Contracts of that kind help with seriousness; they do not move the timing of the tag.

Enforcement cases

Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

The Officer, squinting at a file.

Larger companies

  • Bonne Terre Limited (Sky Betting and Gaming)

    ICO (United Kingdom), 2024Reprimand, no fine

    The ICO found that MediaMath, an advertising platform the company had contracted, used a pixel embedded in skybet.com to set about 40 third-party marketing cookies on visitors' devices before they had set preferences in the cookie banner, between 10 January and 3 March 2023. The reprimand was addressed to the site operator, which the ICO treated as a controller because it had embedded the third-party tracking technologies. It was issued under UK GDPR Arts. 5(1)(a), 6(1)(a) and 7(1), and it predates the 2026 'instigating' wording.

    Read the ICO (United Kingdom) publication about Bonne Terre Limited (Sky Betting and Gaming)

Smaller companies

No published ICO decision applying PECR's 'instigating' wording to an ad-tech provider, or any decision on this point against a smaller company, could be confirmed at the ICO's own site, so none is listed.

How to fix it

  1. List the ad partners that load first. Open your site in a private window with the browser’s network tab open. Do not touch the banner. Write down every request to an advertising, retargeting or ad-measurement domain. One partner’s script can call others.
  2. Decide who owns each one. For each partner, note the team, the contract and the purpose. If nobody can say why it is there, remove it.
  3. Put every ad partner behind consent. In your consent tool, put advertising and ad measurement in a category that is off until the visitor accepts. The ICO says ad measurement is part of the advertising consent, so it does not need a separate one.
  4. Start the tags from the accept event. In a tag manager, fire the ad tags on the consent tool’s accept event, not on page load. Pixels pasted into the theme or a plugin need the same treatment, or need to go. The mechanics match UK-01.
  5. Name the partners in the banner. The ICO asks for the real names of third parties, not “partners”, and for control over each one.
  6. Pass on a withdrawal. When a visitor withdraws consent, make sure your consent tool tells the partners and stops the tags. The reject and withdraw behaviour is covered in UK-04.
  7. Re-scan. Clear cookies and storage, reload, and run a scan again. The partner list should be empty until a choice is made.

Whether a given arrangement satisfies the instigating wording is a question for your legal adviser. Peeky reports only what it sees.

Questions

Do advertising cookies need consent in the UK?

Yes. The ICO says the use of storage and access technologies for online advertising requires consent, because the service can be provided without advertising.

That covers ad selection and delivery, tracking and profiling, and ad measurement. The 2025 Act added no exception for advertising.

What does instigating mean in PECR regulation 6?

It means the prohibition on storing or accessing information on a device now also covers a person who instigates that storage or access. Regulation 6(2)(a) says so in terms, and it has applied since 5 February 2026.

The regulation does not define instigating or name ad-tech. How far it reaches a particular vendor has not been tested in a published decision.

Are ad-tech companies responsible for cookie consent?

The ICO's guidance says the site operator carries the primary responsibility. The regulation's wording now also reaches whoever instigates the storage, which can include a third party.

The ICO also says any third party relying on consent the site collected must be able to show visitors understood their data would go to it.

What is the penalty for cookie infringements under PECR now?

For acts since 5 February 2026, up to £17.5 million or 4% of worldwide annual turnover, whichever is higher, for an undertaking. The Data (Use and Access) Act 2025 applied the Data Protection Act 2018's higher maximum to regulation 6.

That is a ceiling. Earlier acts stay under the earlier rules.

Has the ICO taken action against ad-tech companies over cookies?

Not in any decision we could find as of 7 October 2026. The ICO's published cookie action has been against site operators, such as the 2024 reprimand to Sky Betting and Gaming over a third-party advertising pixel.

The instigating wording is new, so a first decision on it may still come.

Filed with

The rule

Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), reg. 6(1) and (2)(a), as substituted by the Data (Use and Access) Act 2025, s. 112 (in force 5 February 2026)

Read the rule (Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), reg. 6(1) and (2)(a), as substituted by the Data (Use and Access) Act 2025, s. 112 (in force 5 February 2026))

A case

Bonne Terre Limited (Sky Betting and Gaming)

ICO (United Kingdom), 2024

Read the decision (Bonne Terre Limited (Sky Betting and Gaming))

Your site

Is your website affected? Join now to find out.

Join now

Sources

  1. PECR 2003, regulation 6 (as substituted 5 February 2026), legislation.gov.uk
  2. PECR 2003, regulation 6 as it stood on 4 February 2026 (before substitution), legislation.gov.uk
  3. Data (Use and Access) Act 2025, Schedule 12 (inserts PECR Schedule A1), in force 5 February 2026
  4. Data (Use and Access) Act 2025, Schedule 13 (PECR enforcement powers), in force 5 February 2026
  5. Data Protection Act 2018, section 157 (maximum amount of penalty)
  6. ICO, The Data Use and Access Act 2025 (DUAA): summary of the changes, Privacy and electronic communications
  7. ICO, Guidance on the use of storage and access technologies: How do the rules apply to online advertising? (finalised April 2026)
  8. ICO, Guidance on the use of storage and access technologies: How do we comply with the PECR rules? (finalised April 2026)
  9. ICO, Guidance on the use of storage and access technologies: How do we manage consent in practice? (finalised April 2026)
  10. ICO, Guidance on the use of storage and access technologies: What are the exceptions? (finalised April 2026)
  11. ICO, letter to the Association of Online Publishers and IAB UK on advertising cookies (5 March 2024)
  12. ICO, Reprimand to Bonne Terre Limited t/a Sky Betting and Gaming (2 September 2024)
  13. ICO, Action taken against Sky Betting and Gaming for using cookies without consent (17 September 2024)

Last checked against the source:

For information only. Not legal advice.