Do I still need a cookie banner in 2026? What actually changed for analytics
Yes — almost every UK website still needs a consent mechanism. Since 5 February 2026 a narrow set of analytics and appearance technologies no longer need consent, but only if you tell people what you are doing and give them a free, simple way to object. Nothing has changed for advertising.
Last updated 31 July 2026. This page explains the law as it stands on that date. It is general information, not legal advice.
The short answer
Most UK websites still need a consent banner. Three exceptions were added on 5 February 2026, and two of them — statistical analytics and website appearance — let you drop consent for some technologies, but only if you provide clear information and a free, simple means of objecting. That is a move to opt-out, not to nothing. No exception covers advertising or marketing of any kind.
What changed on 5 February 2026
Section 112 of, and Schedule 12 to, the Data (Use and Access) Act 2025 came into force on 5 February 2026 under SI 2026/82. Section 112(2) replaced regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), and the new Schedule A1 inserted into PECR is the one set out in Schedule 12 to the Act.
Regulation 6(1) now says simply that, subject to Schedule A1, "a person must not store information, or gain access to information stored, in the terminal equipment of a subscriber or user". All the detail moved into Schedule A1, which contains consent plus five exceptions.
| Purpose | Before 5 Feb 2026 | From 5 Feb 2026 |
|---|---|---|
| Transmitting a communication (eg load balancing) | No consent | No consent |
| Strictly necessary to provide the service requested (log-in, basket, security) | No consent | No consent |
| First-party analytics to improve your service or website | Consent | No consent, if all five conditions in paragraph 5 are met |
| Remembering language, dark mode, screen size | Consent | No consent, if the conditions are met |
| Finding someone's location solely to give emergency assistance | Consent | No consent |
| Advertising or marketing of any kind | Consent | Consent |
Note what is not on that list. The changes did not touch cookie rules for advertising, and they did not create a general "low-risk cookie" exemption.
Does that mean Google Analytics no longer needs consent?
Usually not. It depends entirely on how the tool is configured and what else the data is used for. Paragraph 5 of Schedule A1 sets a narrow test, and all of it must be satisfied:
- You provide an information society service (a website or app).
- The sole purpose of the storage or access is collecting statistical information about how your service or website is used, with a view to improving it.
- Any information collected is not shared with anyone else, except to enable them to assist you with making those improvements.
- The subscriber or user is given clear and comprehensive information about the purpose.
- The subscriber or user is given a simple means of objecting, free of charge — and does not object.
The ICO's guidance is direct about the limits. On advertising it says: "Online advertising purposes are not exempt from PECR's consent requirements and never have been." That covers frequency capping, ad affiliation, ad measurement and performance, click fraud detection, market research, product improvement and debugging. The exception also does not permit logs or recordings of individual visitors and the actions they took (unless obtained for security purposes), connecting a visitor ID to site activity, conversions shared with advertising partners, or tracking people across services.
The trap is the word 'sole'
The statistical and appearance exceptions apply only where storage or access is for that purpose *alone*. If the same tag also feeds ad targeting or builds visitor profiles, the exception falls away for the whole thing and you need consent. The ICO's new sub-chapter on multi-purpose technologies says it may in practice be easier to meet your PECR obligations by using a separate technology for each purpose.
Two more conditions catch out common set-ups. If you use a third-party analytics provider, it must act as your processor, not a joint controller, and must not link your data with anything else it works with. And under paragraph 5(2) the exception does not cover collecting or monitoring information automatically emitted by a device — the ICO gives wifi probe requests as its example.
You have moved to opt-out, not to nothing
Both new exceptions are conditional. Drop either condition and you are not using the exception correctly, which means you are back to needing consent.
Clear and comprehensive information
PECR does not define the phrase, but the ICO says you must tell people:
- what storage and access technologies you intend to use
- the purposes you intend to use them for
- any third parties who store, access or process the information, and what for
- how long information will be stored, or access granted, for (for example, cookie duration)
A simple means of objecting
This is one of the two sub-chapters the ICO added when it finalised its guidance. PECR does not define it either. The ICO says you could provide it through your existing consent mechanism — for example, with your statistical or appearance toggles switched on by default and the ability to switch them off at any time. If someone objects you must stop; if they later toggle back on, you can rely on the exception again. The ICO also warns that you must not rely solely on browser settings as an indication that someone has not objected.
What the ICO's final guidance covers beyond cookies
The ICO published its final Storage and Access Technologies (SATs) guidance on 29 April 2026, replacing its old detailed cookies guidance after two consultations. Despite the everyday name, it is not just about cookies. It covers cookies, tracking pixels, link decoration and navigational tracking, local storage, device fingerprinting, and scripts and tags — plus the UK GDPR where those technologies involve personal data.
It is equally clear about what it does not cover: other areas of PECR outside regulation 6, and wider UK GDPR and Data Protection Act 2018 obligations except where they bear on PECR. So it is not a complete data protection manual. The April 2026 update added two new sub-chapters — "what does a 'simple means of objecting' mean?" and "can we use the same storage and access technology for multiple purposes?" — along with clarifications requested during consultation.
How prominent do 'Accept all' and 'Reject all' have to be?
Equally prominent. The first item on the ICO's consent-mechanism checklist is that "our consent mechanism makes it as easy to refuse consent as it is to accept". Its good-practice illustration shows equally prominent "accept all" and "reject all" buttons alongside a "more options" button. Its bad-practice illustration is the familiar one: "accept all" plus "more options", with no way to reject in a single click.
The full checklist asks whether your mechanism:
- makes refusing as easy as accepting
- requires a positive action before non-exempt technologies are set — silence, inactivity or continued browsing is not consent
- actually works, so nothing is set until valid consent is given or an exception applies
- offers granular options for different purposes
- names the third parties data will be shared with, and lets users control each one
- tells users how to revisit their preferences
- does not incorrectly use legitimate interests as a lawful basis, with toggles pre-set to on
Neither PECR nor the UK GDPR sets a time limit on consent. The ICO says you should not repeatedly prompt people who have already refused, and recommends six months as a suitable general timeframe before asking again — sooner only if your purposes or activities change.
Is the UK about to scrap consent for contextual advertising?
Possibly, eventually — but nothing has changed in law. On 18 May 2026 the ICO published advice to government showing how regulation 6 could be amended to allow certain low-risk forms of online advertising without consent, while continuing to require consent for advertising that involves intrusive tracking and profiling of people over time and across services. Its assessment is that privacy risks are lower where advertising is based on the context of the content being viewed rather than information about a person's past online activity.
The ICO's own words, 18 May 2026
"It's important to remember that nothing has changed at this stage. The existing PECR rules still apply, and organisations must continue to comply with them."
Any change needs government action. New PECR regulation 6A lets the Secretary of State add, omit or vary exceptions, but only after consulting the Information Commissioner and such other persons as the Secretary of State considers appropriate, and a draft must be laid before and approved by both Houses of Parliament. As at 31 July 2026 no such regulations have been made. Do not rebuild your consent flow for a rule that does not yet exist.
Fines, enforcement, and what to change this month
PECR penalties changed on the same day as the cookie rules. Section 115(8) of, and Schedule 13 to, the DUAA replaced PECR Schedule 1 on 5 February 2026. Paragraph 18 of that Schedule modifies section 157 of the Data Protection Act 2018 so that breaches of regulations 5, 6, 7, 8, 14, 19, 20, 21, 21A, 21B, 22, 23, 24 and 32B(4)–(5) attract the higher maximum: £17,500,000 or, in the case of an undertaking, 4% of total annual worldwide turnover in the preceding financial year, whichever is higher. Regulation 6 — storage and access — is on that list. The old PECR ceiling was £500,000.
On enforcement, the picture is mixed and worth stating plainly. The ICO's published enforcement register shows its 2026 PECR penalties so far have been for marketing calls and texts, not cookies — for example KRA Consultancy Ltd, fined £300,000 on 20 May 2026 under regulations 22 and 23 for more than 5.5 million unlawful texts. Its cookie work has run through warning letters and industry engagement instead, and on 29 April 2026 it said 99% of the UK's top 1,000 websites now meet compliance standards for cookie banners. It has also said it will take action against organisations that act irresponsibly, and on 29 July 2026 it executed search warrants at residential and business premises linked to five companies over car finance marketing texts. PECR enforcement is live, even if cookies have so far been handled by persuasion.
- Step 1 Audit what your site actually sets List every cookie, pixel, script, tag and local storage item, on every template, including anything a third party drops. The ICO expects an audit, not a guess.
- Step 2 Sort each item into a bucket Communication, strictly necessary, statistical, appearance, emergency, or consent-required. Anything touching advertising, cross-site tracking, social plugins for logged-out users, or individual-level profiling goes in the consent bucket.
- Step 3 Check that 'sole purpose' really holds If one tag serves two purposes and only one is exempt, you need consent. Consider splitting the technology per purpose.
- Step 4 Fix the banner Make 'Reject all' as prominent as 'Accept all'. Set nothing non-exempt before a positive action. Make the categories granular and name your third parties.
- Step 5 Turn analytics into a genuine opt-out If you want to rely on the statistical exception, tell people plainly, keep the toggle switchable, and honour objections. If you cannot meet the conditions, keep analytics behind opt-in consent.
- Step 6 Check your analytics contract Your provider must be a processor acting only on your instructions, using the data solely to improve your service and not linking it to anything else. Check international transfers too.
- Step 7 Update your cookie notice Cover the technologies, purposes, third parties and durations, and explain how people change their mind later.
This page is general information about what the law says, not legal advice. If your set-up is complex — particularly if advertising, ad measurement or a large third-party stack is involved — check the ICO guidance itself or take specialist advice.
Common questions
Do I still need a cookie banner in 2026?
If your website uses anything beyond the exceptions — advertising cookies, social media tracking, cross-site or cross-device tracking, embedded content that tracks, or analytics that profiles individuals — then yes, you need a consent mechanism. Even sites that qualify for the new statistical and appearance exceptions must still tell people what they are doing and give them a free, simple way to object, so most sites will keep some form of banner or settings panel.
Can I switch my analytics cookies on by default now?
Only if your analytics meets every condition of the statistical purposes exception in paragraph 5 of PECR Schedule A1: you provide an information society service, the sole purpose is collecting statistics about how your service or website is used with a view to improving it, no sharing beyond helping you make those improvements, clear and comprehensive information given, and a simple free way to object that the user has not used. The ICO's own example of good practice shows an 'analytics' toggle on by default alongside 'social media tracking' and 'advertising' toggles off by default.
Does Google Analytics need consent in the UK?
It depends on configuration, and in most commercial set-ups the answer is still yes. If the same data feeds advertising targeting, conversion tracking shared with ad partners, or profiling of individual visitors, the statistical exception does not apply. Your provider must also act as your processor rather than a joint controller and must not link your data with other information it works with.
What is the maximum fine for getting cookies wrong?
Since 5 February 2026, a breach of PECR regulation 6 attracts the higher maximum under section 157 of the Data Protection Act 2018 as modified by PECR Schedule 1 paragraph 18: £17,500,000 or, in the case of an undertaking, 4% of total annual worldwide turnover in the preceding financial year, whichever is higher. The previous PECR ceiling was £500,000.
Has the UK scrapped consent for contextual advertising?
No. The ICO advised government on 18 May 2026 that regulation 6 could be amended to allow certain low-risk advertising without consent, but it said explicitly that nothing has changed at this stage. Any change requires the Secretary of State to make regulations under PECR regulation 6A, after consulting the Commissioner and with a draft approved by both Houses of Parliament. None had been made as at 31 July 2026.
Does 'Reject all' have to be as easy to click as 'Accept all'?
Yes. The first item on the ICO's consent mechanism checklist is that refusing consent must be as easy as accepting it. Its good-practice illustration shows equally prominent 'accept all' and 'reject all' buttons plus a 'more options' button; a banner offering only 'accept all' and 'more options' is shown as bad practice.
Sources
This page summarises the following primary sources. Where they disagree with this summary, they take precedence.
- PECR 2003, regulation 6 (as substituted 5 February 2026) — legislation.gov.uk
- PECR 2003, Schedule A1 — consent and the five exceptions
- PECR 2003, regulation 6A — power to add, omit or vary exceptions
- SI 2026/82 — Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, bringing ss.112 and 115 and Schs.12 and 13 into force on 5 February 2026
- Data (Use and Access) Act 2025, section 115 — Commissioner's enforcement powers (s.115(8) substitutes PECR Schedule 1)
- PECR 2003, Schedule 1 paragraph 18 — regulations attracting the higher maximum penalty
- Data Protection Act 2018, section 157 — higher and standard maximum amounts
- ICO — Guidance on the use of storage and access technologies (final, 29 April 2026)
- ICO — What are the exceptions? (statistical purposes, appearance, emergency assistance, 'a simple means of objecting')
- ICO — How do we manage consent in practice? (consent mechanism checklist, six-month guideline, multi-purpose technologies)
- ICO news, 29 April 2026 — Final storage and access technologies guidance published
- ICO blog, 18 May 2026 — Our advice to government on potential changes to online advertising rules
- ICO enforcement action — KRA Consultancy Ltd monetary penalty notice, 20 May 2026
- ICO news, 31 July 2026 — Multiple properties searched across UK after millions of car finance complaints
Related guidance
-
Marketing emails, texts and calls: the maximum fine is now £17.5m
From 5 February 2026 the maximum PECR fine rose from £500,000 to £17.5m or 4% of worldwide turnover. What changed for marketing emails, texts and calls.