
ICO cookie guidance: tracking that carries on after reject or withdrawal
At a glance
UK-04CriticalPECR reg. 6 and Sch. A1 (from 5 Feb 2026); UK GDPR Arts. 7(3), 83(5)(a)
Peeky tests the reject click, not withdrawal: it clicks Reject all on a fresh visit and compares what loads with the accept-all visit, looking for tracking that carries on after the visitor said no.
Last checked against the source:
The rule
UK-04 asks what happens after a visitor has made a choice. The rule that decides whether a cookie may be set at all is covered in UK-01. This check covers whether the site respects a refusal, and whether it stops when consent is taken back.
Regulation 6(1) now reads: “Subject to Schedule A1, a person must not store information, or gain access to information stored, in the terminal equipment of a subscriber or user.” Regulation 6(2) adds that this includes “instigating the storage or access”. The version in force was substituted on 5 February 2026 by section 112 of the Data (Use and Access) Act 2025. Schedule A1 sets out the exceptions, and its consent route applies where the user “gives consent to the storage or access” having been “provided with clear and comprehensive information”.
The consent in PECR is the UK GDPR’s. Regulation 2 says consent by a user or subscriber “corresponds to the data subject’s consent in the UK GDPR”. Article 7(3) of the UK GDPR then says: “The data subject shall have the right to withdraw his or her consent at any time.” It also says that “It shall be as easy to withdraw as to give consent”, and that withdrawal does not affect the lawfulness of processing done before it.
The two narrow exceptions in Schedule A1, for collecting statistics about how a service is used and for adapting how a page looks to the user’s preferences, each carry a further condition. The user must be given “a simple means of objecting, free of charge”. So even a cookie under one of those two exceptions has to stop when the visitor objects.
The ICO’s guidance turns this into instructions. If someone withdraws consent, “you must: stop using them; cease any processing of personal data the technologies undertake; and tell any third parties you are working with that the person has withdrawn their consent.” It adds that a withdrawal must be treated as a request for erasure of what was gathered under that consent. Where a visitor has not clicked any option, “you must not use the storage and access technologies that require consent.” And the guidance lists as an expectation that the mechanism “functions as intended. Storage and access technologies are only set when valid consent is gathered, or when they meet an exception.”
How enforcement has treated this is clearest in the ICO’s own letters. On 21 November 2024 it wrote to website operators that it had tested whether non-essential advertising cookies were placed “even if the user did not consent to such cookies”. Where a site offered a consent mechanism but placed the cookies despite the visitor choosing reject all, the ICO said the later processing was likely to lack a lawful basis under Article 6 of the UK GDPR, was therefore likely to infringe Article 5(1)(a), and might also infringe PECR regulation 6. It set a deadline of 10 January 2025 and said it planned to publish the names of organisations that did not act.
Penalties moved on 5 February 2026. The ICO’s commencement statement says it can now issue fines of up to 17.5 million pounds or 4% of global turnover under PECR. UK GDPR Article 83(5)(a) already placed the conditions for consent, including Article 7, in that upper tier.
What PeekWell checks and how
UK-04 asks the same question as EU-02: after the visitor clicked Reject all, did anything non-essential still run? The method is the same reject-and-compare engine with the UK ruleset on top, so this section stays short.
The scan opens a public page in a fresh browser context, finds the Reject all button using common consent-tool selectors and label heuristics, and clicks it. It records every request and cookie that follows. A second clean visit clicks Accept all and records the same things. Any tracker from the maintained signature list that appears in the reject visit is a finding, and the exact requests are logged as evidence. Code makes that decision. A language model may help read an unusual label or write the explanation, and never decides that a tracker fired.
The title of this check says withdrawn consent, and the scan’s test is narrower. It tests a refusal on a first visit. It does not accept, then withdraw through a settings link, then record again, so it cannot say whether tracking stops after a later withdrawal. That sequence is worth checking by hand.
The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. The button is found with common consent-tool selectors and label heuristics, so an unusual banner may not be recognised. Collection on a server or inside an app is outside a browser visit. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.
Why it matters for a company
The ICO has made this a target. Its December 2025 release says it assessed whether any non-essential advertising cookies were placed even though a user had not consented, across the UK’s top 1,000 websites. It reports that 979 sites met its checks at the time of the latest test and 21 did not. Of the 979, 415 passed without intervention and 564 improved after initially failing; the other 21 did not meet its checks, and 17 received preliminary enforcement notices. The ICO says: “We are pleased that this threat of enforcement action has led to nearly all of the websites concerned bringing themselves into compliance.”
The ICO’s December 2025 release names no sites. A named outcome on cookies is the reprimand of Bonne Terre Limited, trading as Sky Betting and Gaming, on 17 September 2024. The ICO said the company’s advertising cookies and data sharing began before visitors could accept or reject, from 10 January to 3 March 2023, and that it changed its setup in March 2023 so people could reject before data was shared. That case is about the order of events. It still shows how the ICO reads the sequence: a choice offered after tracking starts is not treated as a choice.
The risk has changed since the ICO’s first letters. The ICO’s commencement statement says it can now issue fines of up to 17.5 million pounds or 4% of global turnover under PECR.
Smaller companies and larger companies
PECR and Article 7(3) have no size threshold. The ICO’s letters went to the most visited sites first, and its December 2025 results are all about the largest 1,000, but nothing in the rule exempts a smaller operator.
In a small company the banner usually comes from a plugin or a website builder’s built-in tool. The plugin records the choice but only controls the tags it knows about. A script pasted into the theme, a chat widget or an embedded video keeps running after reject. Nobody tests it, because the banner looks right and the button clicks.
In a larger company the work spreads over teams. A tag manager holds many tags, a release changes which fire, and the choice has to reach every domain and app. Withdrawal is harder than refusal at that scale, because tags that started after an earlier yes must be stopped and third parties told, as the ICO’s guidance asks.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
Bonne Terre Limited (trading as Sky Betting and Gaming)
The ICO said that between 10 January and 3 March 2023 the company placed advertising cookies and shared personal information with advertising technology companies before people could accept or reject cookies. The ICO issued a reprimand on 17 September 2024. This case is about the timing of the choice rather than a rejection that was ignored; the ICO's separate cookie letters test for rejection directly.
Read the ICO (United Kingdom) publication about Bonne Terre Limited (trading as Sky Betting and Gaming)
Smaller companies
No ICO decision on cookies naming a smaller company could be confirmed at the ICO's own pages.
How to fix it
Make the visitor’s choice control every tag, and make it reversible. The ICO’s guidance gives the target: a mechanism that “functions as intended”, with storage and access technologies set only when valid consent is gathered or an exception applies.
- Reproduce it. Open your site in a private window with the network tab open. Click Reject all, reload two or three pages, and write down every third-party request and cookie that appears afterwards.
- Find what sits outside the banner tool. Scripts pasted into the theme, plugins that add their own tracking, embedded videos and chat widgets ignore the banner unless they are put behind it. Move them under the consent tool’s categories or remove them.
- Start tags only from the accept event. In the tag manager, give each non-essential tag a trigger tied to the consent tool’s accept event, and leave a reject with none. Check that a saved Reject is honoured on the next page.
- Add a way back. Put a permanent Cookie settings link in the footer. When a visitor withdraws, stop the tags, delete the cookies you set, and tell any vendor that needs to know, as the ICO’s guidance says.
- Check the exceptions. If you rely on the statistics exception for analytics, check there is a simple, free way for visitors to object and that the objection stops the tag.
- Re-scan. Clear cookies and storage, click Reject all, and run a scan again. Then accept, withdraw through the settings link, and check by hand that the requests stop.
Whether a particular setup satisfies the ICO is a question for your legal adviser, and Peeky reports only what it sees.
Questions
Does the ICO say a website must stop tracking when I reject cookies?
In its November 2024 letters to website operators the ICO tested whether non-essential advertising cookies were placed even if the visitor chose reject all. It said that was likely to lack a valid lawful basis under Article 6 of the UK GDPR and may infringe PECR regulation 6.
For a visitor who clicks nothing, its guidance says you must not use storage and access technologies that require consent.
How do I withdraw cookie consent on a UK website?
Through a settings link or icon that people can reach at any time, often called Cookie settings. The ICO says a site must let people withdraw consent with the same ease as they gave it.
When consent is withdrawn the site must stop using the technologies, stop the processing they carry out, and tell any third parties involved.
What do the PECR cookie rules say?
Regulation 6 says a person must not store information on a visitor's device, or gain access to it, unless an exception in Schedule A1 applies. The main route is consent given after clear and comprehensive information. Two narrow exceptions, for statistics and for how a page looks, also require a simple, free way for the visitor to object.
Did the cookie rules change in 2026?
Yes. From 5 February 2026 the Data (Use and Access) Act 2025 replaced regulation 6 with a version that points to a new Schedule A1 of exceptions. It also brought PECR fines in line with UK GDPR, up to 17.5 million pounds or 4% of worldwide turnover.
Where can I read the ICO's cookie guidance?
On the ICO website under guidance on the use of storage and access technologies. It was first published in draft in December 2024 and finalised on 29 April 2026. The page on managing consent in practice covers withdrawal, refusal and what a working consent mechanism looks like.
Filed with
The rule
Privacy and Electronic Communications (EC Directive) Regulations 2003, reg. 6 and Sch. A1, as substituted by the Data (Use and Access) Act 2025, s. 112 and Sch. 12
Read the rule (Privacy and Electronic Communications (EC Directive) Regulations 2003, reg. 6 and Sch. A1, as substituted by the Data (Use and Access) Act 2025, s. 112 and Sch. 12)A case
Bonne Terre Limited (trading as Sky Betting and Gaming)
Read the decision (Bonne Terre Limited (trading as Sky Betting and Gaming))Sources
- PECR 2003 (SI 2003/2426), regulation 6, as in force from 5 February 2026
- PECR 2003, Schedule A1 (storage and access exceptions), version of 5 February 2026
- PECR 2003, regulation 2 (definition of consent)
- Data (Use and Access) Act 2025, section 112 (storing information in terminal equipment)
- UK GDPR, Article 7 (conditions for consent)
- UK GDPR, Article 83 (administrative fines)
- ICO, Statement on the commencement of the Data (Use and Access) Act (5 February 2026)
- ICO, Guidance on the use of storage and access technologies (final, 29 April 2026)
- ICO, How do we manage consent in practice?
- ICO, template letter to website operators on cookie banner compliance (21 November 2024)
- ICO, ICO action secures increased cookie compliance (4 December 2025)
- ICO, Action taken against Sky Betting and Gaming for using cookies without consent (17 September 2024)
Last checked against the source:
For information only. Not legal advice.


