← Back to Blog

UK Cookie Law Changed in 2026: What Your Website Needs Now

UK cookie law changes in 2026 — what your website needs now

If your website has a cookie banner, you need to read this. If it does not have one, you definitely need to read this.

UK cookie law changed twice in 2026. First, the Data Use and Access Act 2025 (DUAA) came into force on 5 February, rewriting parts of the rules that govern how websites collect consent. Then, on 29 April, the ICO finalised new guidance that spells out exactly what a compliant cookie banner looks like. The maximum fine for getting it wrong jumped from £500,000 to £17.5 million.

Most UK small business websites are not compliant with the new rules. Not because the owners do not care, but because nobody told them the rules changed. This article fixes that.

What Actually Changed

The original UK cookie law comes from the Privacy and Electronic Communications Regulations (PECR), which has been around since 2003 and was updated in 2011 to require consent for non-essential cookies. For over a decade, the enforcement approach was soft. The ICO issued warnings. Businesses added vague banners that said "by using this site you accept cookies." Everyone looked the other way.

That era is over. Two things changed:

The DUAA created new exemptions. Schedule A1 of the Act now exempts certain first-party cookies from needing consent at all. These include cookies used purely for website analytics (where the data stays with you and is not shared with third parties), cookies that store appearance preferences like dark mode or font size, cookies essential for security, and cookies needed to respond to emergencies. In plain English: if a cookie exists only to make your site work properly and you are not sending the data to Google or anyone else, you no longer need to ask permission for it.

The ICO tightened everything else. The April 2026 guidance makes it clear that for any cookie that does not qualify for an exemption, consent must be real, informed, and freely given. That means your banner must offer "Accept All" and "Reject All" at the first layer with equal prominence. No dark patterns. No hiding the reject button behind a settings menu. No pre-ticked boxes. No cookie walls that block the site until someone accepts.

The key number: PECR fines were capped at £500,000. Under the DUAA, the ICO can now issue penalties up to £17.5 million or 4% of global annual turnover — whichever is higher. That is the same ceiling as GDPR. The regulator has teeth now.

The "Equal Prominence" Rule

This is the change most businesses will need to act on. The ICO's new guidance says that if you show an "Accept All" button, the "Reject All" option must be equally easy to find and use. Same size, same colour, same position, same level of effort. One click each.

Take a look at your current cookie banner right now. Is the "Accept" button big and colourful while "Manage preferences" is a small grey text link underneath? That is no longer compliant. The reject option needs to sit right next to accept, looking just as inviting.

This is not theoretical. The ICO has stated publicly that it will be auditing websites for this specific requirement. France's CNIL has been enforcing the same standard since 2022 and has issued over 100 fines. The UK is following suit.

The New "Instigator" Concept

Here is something most guides will not mention. The DUAA introduced a concept called "instigator liability." Previously, only the website operator was responsible for cookie compliance. Now, liability can extend to anyone who instigates the processing of personal data through cookies.

In practice, this means that if an advertising network or analytics provider pushes you to install tracking cookies on your site, they share responsibility for whether those cookies comply with the rules. It does not let you off the hook — you are still on the hook — but it does mean the companies building these tools have a legal incentive to make them compliant by default. If your analytics provider is still telling you "just paste this script tag and you are fine," they are giving you bad advice that now carries legal risk for them too.

What a Compliant Banner Actually Looks Like

Forget the banners you see on most websites. Here is what the ICO now expects:

First layer (what visitors see immediately): A clear statement about what cookies you use and why. Two equally prominent buttons: "Accept All" and "Reject All." No pre-selected options. No cookie wall. The banner should not disappear if someone clicks elsewhere on the page.

Second layer (if someone wants to customise): Granular controls that let people toggle cookie categories on and off individually. Essential cookies should be listed but not toggleable — they are necessary for the site to function. Analytics, marketing, and preference cookies each get their own switch, all set to "off" by default.

After consent: If someone rejects non-essential cookies, your site must still work. They should be able to browse, read content, and use basic features. The only thing that changes is that you do not load tracking scripts or third-party analytics. If your site breaks when cookies are refused, something is wrong with your implementation.

Platform-Specific Pitfalls

If your website runs on a platform like Wix, Squarespace, or Shopify, you might assume the built-in cookie tools handle all of this. They do not — at least, not fully.

Wix and Squarespace offer cookie banner widgets, but they cannot block scripts at the code level. They manage the banner UI, but the underlying tracking code from third-party integrations (Google Analytics, Facebook Pixel, advertising tags) often loads before consent is given. Under the new rules, that is a problem. Blocking scripts before consent requires access to your site's code — something these platforms restrict.

WordPress has better options through plugins like Complianz or CookieBot, which can integrate with Google Tag Manager to conditionally load scripts based on consent. But you need to configure them properly. Installing the plugin is not enough — you need to map every script your site loads and categorise it correctly.

Custom-built sites give you full control. You can implement consent management that blocks every non-essential script until the visitor agrees. This is the approach we take at Daedalus Design — consent management is built into the site architecture from day one, not bolted on afterwards.

Does Google Analytics 4 Still Need Consent?

Short answer: yes, almost certainly.

The DUAA's new exemption for first-party analytics covers situations where the data stays with you and is not shared with third parties. Google Analytics 4 sends data to Google's servers. Even with the "anonymise IP" feature enabled, GA4 collects device identifiers, user behaviour data, and cross-site signals that Google uses for its own purposes. That does not qualify for the exemption.

If you want analytics without consent headaches, you have options. Privacy-focused tools like Plausible, Fathom, or Umami run on your own server or a compliant EU/UK host and do not share data with third parties. Under the new rules, these can qualify for the analytics exemption, meaning you can run them without a cookie banner for that specific tool. We include privacy-first analytics as standard with our hosting packages.

Your 6-Point Self-Check

Run through this list on your own website. If you answer "no" or "not sure" to any of these, your site needs attention:

1. Is there a link to your privacy policy in the footer? It should be on every page, clearly visible, and written in plain English — not copied from a template that references EU laws the UK no longer follows.

2. Is your privacy policy dated and current? A policy last updated in 2023 does not reflect the DUAA changes. If it still references the "EU GDPR" as your primary framework without mentioning UK GDPR or PECR, it is outdated.

3. Does a cookie banner appear on first visit? Open your site in a private/incognito window. If no banner appears and your site uses any non-essential cookies (analytics, ads, social widgets), you are non-compliant.

4. Can visitors reject all cookies in one click? If the only option is "Accept" or "Manage Settings," that does not meet the equal prominence requirement. There must be a visible, equally styled reject option.

5. Are tracking scripts blocked before consent? Open your browser's developer tools (F12), go to the Network tab, load your site in a private window, and do not click accept. If you see requests to google-analytics.com, facebook.net, or any advertising domains, your scripts are loading without consent.

6. Is there a named contact route for data enquiries? Your privacy policy should tell visitors exactly who to contact about their data and how. A generic email address is the minimum. A named data protection officer is better if you process significant amounts of personal data.

Quick test: Open your website in a private browser window right now. Do not click anything. Open the Network tab in your developer tools. If you see requests going to domains you did not explicitly consent to, that is your answer.

What This Costs If You Ignore It

The £17.5 million headline number grabs attention, but the realistic risk for small businesses is different. The ICO has indicated it will focus enforcement on sites that make no effort at all — no banner, no privacy policy, no attempt at compliance. A site with a banner that needs tweaking is far less likely to face action than a site with no banner and a Google Analytics script running freely.

That said, the ICO's enforcement track record is evolving. In 2025, it issued its first PECR fines against websites (as opposed to email spammers). In 2026, with the higher penalty ceiling and new guidance, expect more. The safest position is to be compliant now, before your site comes to someone's attention for the wrong reason.

There is also the customer trust angle. A 2026 Deloitte survey found that 68% of UK consumers are more likely to trust a business whose website handles cookies transparently. Compliance is not just about avoiding fines. It is about showing visitors you take their privacy seriously.

What To Do Next

If your website needs updating, here is the order of operations:

First, audit what cookies and scripts your site actually loads. You might be surprised how many third-party scripts fire on every page. Second, decide which ones you genuinely need and which are leftover from something you tried two years ago and forgot about. Third, implement a consent mechanism that blocks non-essential scripts until the visitor agrees. Fourth, update your privacy policy to reflect the DUAA changes and your current data practices. Fifth, test the whole thing in a private browser window to make sure it actually works.

If that sounds like a lot of work, it can be. But it is also an opportunity to clean up your site, remove scripts that slow it down, and give your visitors a better experience. Most businesses find they do not need half the tracking they have installed.

Not sure if your website is compliant?

We run a free compliance check that audits your cookie setup, privacy policy, and script loading against the current ICO guidance. No jargon, no scare tactics — just a clear report on what needs fixing and what is already fine.

Get Your Free Website Health Check

Or request a compliance review.