
ICO cookie guidance: reject as easy as accept
At a glance
UK-02HighPECR reg. 6 and Sch. A1; UK GDPR Art. 4(11); DUAA 2025 Sch. 13
Peeky looks at the cookie banner's top layer and counts how many steps it takes to reject non-essential cookies compared with accepting them.
Last checked against the source:
The rule
In the UK, cookies are governed by two instruments at once: the Privacy and Electronic Communications Regulations 2003 (PECR) for the storing and reading, and the UK GDPR for the consent that unlocks it.
Regulation 6(1), as it now reads, says that “a person must not store information, or gain access to information stored, in the terminal equipment of a subscriber or user”, subject to the exceptions in Schedule A1. Storing includes instigating the storage, and access includes collecting or monitoring information automatically emitted by the device (reg. 6(2)). The substituted regulation took effect on 5 February 2026.
Schedule A1 sets the exceptions. Storage that is strictly necessary for a service the visitor asked for is one. Collecting statistics to improve the service, and adapting the site’s appearance to the visitor’s preferences, are two others, and each is conditional on clear information and a simple, free means of objecting. Advertising cookies fit none of these, so consent is still the route for them, and that is where the shape of the banner matters.
The ICO’s position in its letters is that PECR has no definition of consent, so the UK GDPR’s applies. Article 4(11) defines consent as “any freely given, specific, informed and unambiguous indication of the data subject’s wishes” given “by a statement or by a clear affirmative action”. The letters add the ICO’s own guidance that “a consent mechanism that emphasises ‘agree’ or ‘allow’ over ‘reject’ or ‘block’ represents a non-compliant approach, as the online service is influencing users towards the ‘accept’ option”.
The wording of Schedule A1 now in force asks for consent after clear and comprehensive information about the purpose, and does not itself refer to the UK GDPR. The ICO’s letters pre-date that text, so check its current guidance on whether it has restated the link.
The ICO’s current guidance carries the point into its checklist: “Our consent mechanism makes it as easy to refuse consent as it is to accept.” The guidance illustrates it with Accept all and Reject all buttons of equal prominence on mobile and desktop.
The letters spell out the test the ICO applied. It asked whether users could “reject non-essential advertising cookies as easily as they can accept them”, and where a banner “contains a button allowing immediate consent to cookies” but does not give “similar means to refuse the storage of these cookies as easily or in one click”, the ICO was concerned that consent given on the first layer could not be regarded as freely given. It asked for a way of refusing at the same point consent is sought, “for example, by providing a button to ‘reject all’ or another equivalent and non-ambiguous solution that is equally prominent as the option to accept cookies.”
Penalties changed this year. Schedule 13 of the Data (Use and Access) Act 2025, in force from 5 February 2026, applies the provisions of the Data Protection Act 2018 on information notices, assessment notices, enforcement notices and penalties to PECR, and provides that the maximum penalty is the higher maximum amount.
What PeekWell checks and how
UK-02 asks one question: on the banner’s top layer, is rejecting non-essential cookies about as easy as accepting them? The scan answers it from the rendered page, in the same way as the EU check, with a UK rule set. EU-03 describes the engine in full.
The scan opens a public page in a fresh browser context with no saved choices. It finds the banner and lists the buttons and links on the top layer: whether there is an Accept all, whether there is a Reject all or an equivalent at the same level, and how the two compare in size and the number of clicks each takes. It then clicks the banner’s own controls, as a visitor could, and counts the steps needed to refuse everything non-essential and to accept. The click count is measured by code. Prominence is reported as measurements, not as a conclusion, because how much difference counts is for the reader and the ICO to weigh.
A language model may help only where a button label is ambiguous. It never decides the click count. The finding states what was seen, for example “Accept all on the top layer; Reject all after one further click on Manage preferences”, and not that the banner breaks a rule.
The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. It tests the banner it was shown on the visit, so a banner that varies by visitor or device may look different elsewhere. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.
Why it matters for a company
The ICO has made this one of its most visible cookie tests. In November 2023 it wrote to the operators of websites in its top 100 by UK user time after assessing their banners on 23 October 2023. The letter named three tests: advertising cookies before consent, rejection as easy as acceptance, and cookies placed despite a refusal. It asked for changes within one month and said operators who did not address its concerns could be named or face enforcement or penalty notices. A second round followed on 21 November 2024, covering a further 100 sites, with a deadline of 10 January 2025 and a request to say which consent management platform each used.
The work later widened to the top 1,000 sites. On 4 December 2025 the ICO reported that 979 of the 1,000 had met its testing criteria at their latest test. Of those, 415 passed without intervention and 564 improved after an initial failure. It issued preliminary enforcement notices in 17 cases and was continuing against 21 sites that had not passed. It said the threat of enforcement had led to nearly all of the sites concerned coming into line. No operator was named and no fine was published in that update.
The practical consequences are of three kinds. The ICO tests the same screen any visitor sees, so it needs no inside access. Consent obtained through a lopsided banner is consent the ICO said it was concerned could not be regarded as freely given, which colours what is collected afterwards. And since February 2026 PECR penalties for storing or accessing information on a device (regulation 6) are tied to the higher maximum amount.
Smaller companies and larger companies
PECR and the UK GDPR have no size threshold for this rule, but the ICO’s reviews were aimed at the biggest sites. No decision against a smaller company on banner asymmetry could be confirmed at the ICO’s own site, and the reviews are not a sign that smaller sites are outside the rule. The same screen is judged the same way.
In a smaller company the banner usually comes from a plugin or a site builder. The default has a bright Accept all and a plain Settings link, and the Reject all button is a setting somebody has to switch on. The fix is a setting, not a rebuild.
In a larger company the banner is often a managed product, run by a consent management platform and changed by a central team. Variants get tested for opt-in rates, regional rules are layered on top, and a redesign can slip a second click back in. The ICO’s 2024 letter asked each operator to say which platform it used, and a single configuration on a shared platform can apply to many pages at once.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
Top 1,000 UK websites (operators not named)
The ICO tested the top 1,000 UK websites on whether non-essential advertising cookies were stored before consent, whether rejecting was as easy as accepting, and whether cookies were placed without consent. By its December 2025 update, 415 sites had passed without intervention, 564 had improved after an initial failure, and 17 had received preliminary enforcement notices. Action continued against 21 sites that had still not passed.
Read the ICO (UK) publication about Top 1,000 UK websites (operators not named)Top 100 UK websites (letter sent to operators, not named)
The ICO assessed banners on 23 October 2023 and wrote on 15 November 2023. Where a banner contained a button allowing immediate consent but did not give similar means to refuse in one click, the letter said the ICO was concerned that consent given on that layer could not be regarded as freely given, because there was no equally prominent Reject All or equivalent. It gave one month to act and said it might publish names or use enforcement or penalty notices.
Read the ICO (UK) publication about Top 100 UK websites (letter sent to operators, not named)
Smaller companies
No ICO decision against a named smaller company on banner asymmetry could be confirmed at the ICO's own site; its cookie reviews have not published operator names.
How to fix it
The aim is a top layer where saying yes and saying no each take one action. These steps fit most consent tools.
- Look at the top layer as a visitor. Open the site in a private window and write down the buttons. Count the clicks to accept everything and to reject everything non-essential. A difference is what a scan will report.
- Put Reject all beside Accept all. Most platforms have a setting for a reject button on the first layer. Switch it on and use the same kind of control for both, the same size, in the same row.
- Use plain labels. Say Accept all and Reject all. Avoid labels such as Continue or Got it, and avoid a refusal that exists only as a link in a paragraph.
- Match colour, weight and contrast. Both buttons should be readable against their background. Matching them removes the argument about which one stands out.
- Leave non-essential categories off by default. In the settings view, toggles for advertising and similar categories start off. Pre-ticked boxes do not count as a positive action.
- Make a refusal stick. After Reject all, nothing non-essential should be stored or set. The ICO’s letters list cookies placed despite a refusal as a separate concern.
- Re-scan. Clear cookies and storage, reload, and run a scan again. The finding should show the same number of clicks to reject and to accept.
If you use only cookies that Schedule A1 exempts, such as those strictly necessary for the service, you may not need a consent banner for them at all. Whether a given set of cookies falls inside an exception is a question for your legal adviser. Peeky reports what it saw.
Questions
Does the ICO require a reject all button?
The ICO expects a way to refuse at the same point you ask for consent, as easy to use as the way to accept. Its guidance checklist says the consent mechanism should make it as easy to refuse consent as to accept. Its letters give a Reject All button, or an equivalent that is equally prominent, as the example.
Can the reject option sit on the second layer of the banner?
The ICO's letters treat that as a concern. They describe a banner with a button for immediate consent and no similar way to refuse in one click, and say the ICO was concerned that consent given through it could not be regarded as freely given. If a second layer exists, the refusal still needs to be available at the first.
What did the ICO test in its review of the top 1,000 websites?
Three things: whether non-essential advertising cookies were stored before consent, whether rejecting was as easy as accepting, and whether cookies were placed without consent. In its December 2025 update the ICO reported that 979 of the 1,000 sites had met its testing criteria at the latest test, with 21 still outstanding.
Can the ICO fine a company over its cookie banner?
Yes, it has the power. Schedule 13 of the Data (Use and Access) Act 2025 applies the higher maximum amount to PECR penalty notices for infringements of regulations including regulation 6, from 5 February 2026. The ICO's published cookie work so far has used letters and preliminary enforcement notices, and the ICO's December 2025 update reports no fine from these reviews.
How does Peeky check the reject option?
Peeky opens your public page, finds the banner, and lists the buttons on its top layer. It counts the clicks needed to reject non-essential cookies and compares them with the clicks needed to accept. It signs in nowhere and fills in no forms. How a scan works has the full path.
Filed with
The rule
Privacy and Electronic Communications (EC Directive) Regulations 2003, reg. 6 (substituted by DUAA 2025, s. 112) and Schedule A1 (inserted by DUAA 2025, Sch. 12)
Read the rule (Privacy and Electronic Communications (EC Directive) Regulations 2003, reg. 6 (substituted by DUAA 2025, s. 112) and Schedule A1 (inserted by DUAA 2025, Sch. 12))A case
Top 1,000 UK websites (operators not named)
Read the decision (Top 1,000 UK websites (operators not named))Sources
- PECR 2003, regulation 6, legislation.gov.uk (current version, as substituted from 5 February 2026)
- PECR 2003, Schedule A1 (exceptions), legislation.gov.uk
- Data (Use and Access) Act 2025, section 112 (storing information in terminal equipment)
- Data (Use and Access) Act 2025, Schedule 13 (commenced 5 February 2026)
- UK GDPR, Article 4, legislation.gov.uk
- ICO, Guidance on the use of storage and access technologies: How do we manage consent in practice?
- ICO, Compliance of your organisation's cookie banner with the requirements of PECR and UK GDPR (letter of 15 November 2023)
- ICO, Cookie letters project phase 2 template letter (21 November 2024)
- ICO, ICO action secures increased cookie compliance (4 December 2025)
Last checked against the source:
For information only. Not legal advice.


