Skip to content
PeekWellThe Rulebook
Join now

UK cookie law: cookies set before consent

At a glance

UK-01CriticalPECR reg. 6 and Sch. A1 (DUAA 2025 s. 112, Sch. 12); penalties PECR Sch. 1 (DUAA 2025 Sch. 13)

Peeky looks for advertising, analytics and other non-essential cookies that load before a UK visitor has answered the cookie banner.

Last checked against the source:

I need to fix thisI need the rule

The rule

Since 5 February 2026, regulation 6(1) of PECR reads: “Subject to Schedule A1, a person must not store information, or gain access to information stored, in the terminal equipment of a subscriber or user.” Regulation 6(2) adds that references to storing or accessing information “include a reference to instigating the storage or access”. The Data (Use and Access) Act 2025 (DUAA), section 112, substituted the regulation, and SI 2026/82 brought it into force.

The wording does not mention cookies. It reaches any storage on, or access to, a device, so a tracking pixel or a script that reads a device identifier is inside it.

The default is a prohibition with exceptions listed in Schedule A1. The main route is consent: the person must be “provided with clear and comprehensive information about the purpose of the storage or access” and must give “consent to the storage or access” (para. 2). Two exceptions are carried over from the old text: technical storage “for the sole purpose of carrying out the transmission of a communication” (para. 3), and storage “strictly necessary for the provision of an information society service requested by the subscriber or user” (para. 4). Paragraph 4(2) now gives examples, among them security, fraud prevention, authentication and “maintaining a record of selections made on a website”.

DUAA also added two new exceptions, which matter for what counts as non-essential. Paragraph 5 allows storage whose sole purpose is statistics about how the service or website is used, to improve it, but only if the information is not shared except to help with those improvements, the visitor is clearly told, and the visitor has a simple, free means of objecting and does not object. Paragraph 6 covers adapting how a website looks or works to the visitor’s preferences, on similar conditions.

PECR takes its meaning of consent from the UK GDPR (reg. 2(1), as the ICO’s guidance quotes it). The ICO’s guidance says that means a clear positive action: continuing to use a website “does not constitute valid consent, nor does the use of a pre-ticked box”. It also says organisations “must not pre-enable non-exempt storage and access technologies”, and that third parties have to be named, not hidden behind “partners”.

On analytics the ICO reads the new exception narrowly. Counting visits, scroll depth, device types and A/B test results are likely to fit. Logs of individual visitors, profiling and anything tied to online advertising do not. A third-party analytics provider can fit only as a processor acting on the site’s behalf, not as a joint controller.

Penalties changed on the same date. Schedule 13 of DUAA applies the Data Protection Act 2018’s penalty provisions to PECR, and for infringements of regulation 6 the higher maximum applies. The quoted wording is s. 157(5) of the 2018 Act, which Schedule 13 makes apply to regulation 6: for an undertaking, “£17,500,000 or 4% of the undertaking’s total annual worldwide turnover in the preceding financial year, whichever is higher”.

Two limits are worth stating. The transitional rules in SI 2026/82 (reg. 11) keep the earlier regime for acts or omissions before 5 February 2026. And a ceiling is not a tariff: it says what the law allows, not what any authority will do.

On the record, the ICO’s cookie work has run mostly through letters, reprimands and compliance sweeps. On 4 December 2025 it reported that 979 of the 1,000 most-visited UK websites met its checks, 415 of them with no intervention and 564 after engagement, and that it had issued preliminary enforcement notices in 17 cases. Its tests included whether non-essential advertising cookies were stored before the visitor chose. We found no ICO monetary penalty for pre-consent cookies under the new ceiling as of 7 October 2026. The one reprimand set out below was decided under the UK GDPR, not PECR.

What PeekWell checks and how

UK-01 asks one question: did anything that is not exempt load before the visitor answered the banner? The scan answers it from what the browser did.

The method is the same as for EU-01: a fresh browser context with no saved choices, every request and cookie recorded as the page loads, no click on the banner. Request domains and cookie names are compared with a maintained list of tracker signatures, grouped by purpose. The UK ruleset then applies the exceptions before anything is flagged. First-party statistics that stay in the operator’s hands are not flagged. Advertising pixels and Google Analytics 4 are on the flagged side of the list.

The decision is made by code. A language model may help word the explanation in the report, but it never decides that a cookie was set.

The exceptions depend on facts a visit cannot see, such as whether a simple means of objecting exists and what an analytics provider does with the data. The scan works from the category on its list, so a finding for an analytics tool is a prompt to check those conditions.

The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. It records cookies and requests; other forms of storage the law also covers are outside it unless they show up as a tracker request. It does not read your contracts or decide what a tag is for beyond the category on its list. Collection on a server, or inside an app, is outside what a browser visit can see. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.

Why it matters for a company

The ICO can establish this fact from outside. In the Bonne Terre reprimand, the ICO found that a pixel from an advertising platform the company had contracted set about 40 third-party marketing cookies before visitors had set their preferences in the banner. The banner told visitors that accepting all cookies meant agreeing to storage for marketing; the ICO found the pixel’s cookies were already in place before that choice was made. The ICO alerted the company on 2 March 2023; by 3 March 2023, the next day, it had taken steps to fix the problem, and the ICO verified that by technical testing on 17 March.

The reprimand was issued under UK GDPR Articles 5(1)(a), 6(1)(a) and 7(1), because the cookies carried personal data and the company relied on consent. PECR regulation 6 sits beside those articles, and since February 2026 it carries the same top-tier ceiling.

For a company the consequences are practical. A regulator can answer whether a tag fired first with a clean browser, so a banner that is not wired to the tags proves little. And data sent to a vendor before the choice has already gone; changing the banner afterwards does not recall it.

Smaller companies and larger companies

PECR regulation 6 has no size threshold. The ICO’s guidance says the rules apply to any organisation running an online service, and the same facts decide it for a five-person startup and a listed group.

In a smaller company the site is often a template or a hosted builder. Someone in marketing adds an analytics tag, an advertising pixel and a chat widget, and a banner plugin is switched on. The banner is real, but one tag was pasted into the theme and loads on every visit before the banner is answered. There is usually no privacy team to notice. We could not confirm a published ICO decision against a smaller company; the guidance applies to everyone.

In a larger company there are more moving parts. A tag manager holds many tags owned by different teams and agencies, a campaign adds a pixel, and an advertising partner’s script loads further scripts of its own. The Bonne Terre reprimand shows the shape: the cookies came from a vendor’s pixel, not from the company’s own code, and the ICO still treated the company as responsible, because it had embedded the technology on its site.

Enforcement cases

Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

The Officer, squinting at a file.

Larger companies

  • Bonne Terre Limited (Sky Betting and Gaming)

    ICO (United Kingdom), 2024Reprimand, no fine

    The ICO found that, from 10 January to 3 March 2023, a pixel from MediaMath, an advertising platform the company had contracted, set about 40 third-party marketing cookies on visitors' devices on skybet.com before they had set their preferences in the cookie banner. The reprimand, issued under UK GDPR Arts. 5(1)(a), 6(1)(a) and 7(1) rather than PECR, found the data was processed without valid consent. By 3 March 2023, a day after the ICO alerted it, the company had taken steps to fix the issue; the ICO verified this by technical testing on 17 March 2023.

    Read the ICO (United Kingdom) publication about Bonne Terre Limited (Sky Betting and Gaming)

Smaller companies

No published ICO decision on cookies set before consent against a smaller company could be confirmed at the ICO's own site, so none is listed.

How to fix it

The order of events matters more than the tool you use. The steps below fit most consent tools and tag managers.

  1. See what loads first. Open your site in a private window with the browser’s network tab open. Do not touch the banner. Write down every third-party request and cookie, and note what each one is for.
  2. Sort each one against the exceptions. A basket, login or security cookie is essential. A visit counter that stays with you and has an objection route may fit the statistics exception. Advertising, retargeting, session recording and social tracking need consent.
  3. Block by default in your consent tool. Mark the consent-needing categories as off until the visitor accepts. Check that the categories in the tool match what each tag really does.
  4. Start tags from the consent tool’s accept event. In a tag manager, fire each tag on that event rather than on page load. Scripts pasted into the theme, a plugin or a template need the same treatment, or need to go. The mechanics are the same as in EU-01.
  5. Name the third parties in the banner. The ICO asks for real names, not “partners”.
  6. Re-scan. Clear cookies and storage, reload, and run a scan again. The finding should disappear once nothing that needs consent loads before the choice.

Whether a given setup meets the exceptions is a question for your legal adviser. Peeky reports only what it sees.

Questions

Can a UK website set cookies before the visitor agrees?

Only the ones the site needs to work, such as a login or a basket. Advertising cookies and most analytics cookies wait until the visitor says yes.

The rule is PECR regulation 6, and the exceptions sit in Schedule A1. The rule has the wording.

What counts as a non-essential cookie?

A cookie the site could work without, and that no exception covers. Advertising cookies always need consent, according to the ICO. A login or basket cookie is essential because the visitor asked for that feature.

The line follows purpose, not the cookie's name.

Do UK analytics cookies still need consent after the 2025 Act?

Often not, if they only produce statistics to improve your own site and the visitor can object. The Data (Use and Access) Act 2025 added that exception in February 2026.

It has conditions. The ICO says tracking individual visitors, or sharing data for advertising, falls outside it.

What are the cookie banner requirements in the UK?

A positive click before non-essential cookies are set, plain information about what each does and who else receives data, and a refusal as easy as acceptance. The ICO says continuing to use a site is not consent, and pre-ticked boxes do not count.

The banner and the tags both have to work, or the banner proves little.

How does Peeky check for cookies before consent?

Peeky opens your public page in a clean browser with no saved choices and writes down every cookie and request that appears before anyone touches the banner. It never clicks Accept and never signs in. How a scan works has the full path.

Filed with

The rule

Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), reg. 6, as substituted by the Data (Use and Access) Act 2025, s. 112

Read the rule (Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), reg. 6, as substituted by the Data (Use and Access) Act 2025, s. 112)

A case

Bonne Terre Limited (Sky Betting and Gaming)

ICO (United Kingdom), 2024

Read the decision (Bonne Terre Limited (Sky Betting and Gaming))

Your site

Is your website affected? Join now to find out.

Join now

Sources

  1. PECR 2003, regulation 6 (as substituted 5 February 2026), legislation.gov.uk
  2. Data (Use and Access) Act 2025, Schedule 12 (inserts PECR Schedule A1), in force 5 February 2026
  3. Data (Use and Access) Act 2025, Schedule 13 (PECR enforcement powers), in force 5 February 2026
  4. Data Protection Act 2018, section 157 (maximum amount of penalty)
  5. The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82)
  6. ICO, Guidance on the use of storage and access technologies: What are the PECR rules? (finalised April 2026)
  7. ICO, Guidance on the use of storage and access technologies: What are the exceptions? (finalised April 2026)
  8. ICO, Guidance on the use of storage and access technologies: How do we comply with the PECR rules? (finalised April 2026)
  9. ICO, Guidance on the use of storage and access technologies: How do we manage consent in practice? (finalised April 2026)
  10. ICO, ICO action secures increased cookie compliance (4 December 2025)
  11. ICO, Reprimand to Bonne Terre Limited t/a Sky Betting and Gaming (2 September 2024)
  12. ICO, Action taken against Sky Betting and Gaming for using cookies without consent (17 September 2024)

Last checked against the source:

For information only. Not legal advice.