Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

Cookies and PECR for UK Business Websites

In short

UK cookie rules come from PECR, not just GDPR. In short: you can set strictly necessary cookies without asking, but almost everything else — analytics, advertising, embedded media — needs genuine, opt-in consent before it loads. This article explains what needs consent, what a compliant cookie banner looks like, and how to keep using analytics without breaking the rules.

Cookies are a PECR issue, not just a GDPR one

Most small businesses assume cookie rules come from GDPR. They actually come mainly from PECR — the Privacy and Electronic Communications Regulations — which sit alongside UK GDPR and are enforced by the ICO. PECR is the reason you see consent banners everywhere, and it is stricter than people expect: for most cookies, you need consent before they are set, not after.

The rules are not limited to “cookies” in the narrow sense. They cover any technology that stores information on, or reads it from, a visitor’s device — cookies, tracking pixels, local storage, device fingerprinting and similar. If it drops a tracker or reads one, PECR applies.

There is one key exception to the consent rule: strictly necessary cookies. These are the ones essential to provide a service the user has actively asked for. Think of remembering what is in a shopping basket, keeping someone logged in during a session, or security and load-balancing. You can set these without asking — though you should still describe them in a cookie or privacy notice.

Everything else needs consent before it loads, including:

  • Analytics (such as Google Analytics) — measuring traffic is useful to you, but it is not strictly necessary to the visitor.
  • Advertising and remarketing cookies.
  • Social media buttons and embedded feeds that track.
  • Embedded media, such as a YouTube video that sets cookies when the page loads.
  • Personalisation and A/B testing tools.

A common mistake is treating analytics as “basic” and letting it fire automatically. Under PECR it is not necessary, so it needs consent like the rest.

The ICO has been clear, and public, about what fair consent means. The single biggest issue it raises is balance: it must be as easy to say no as to say yes.

A banner that only offers “Accept” — with no equally easy way to reject — is not consent. Under PECR, refusing must be as simple as agreeing.

A compliant approach generally includes:

  • No non-essential cookies before consent. Nothing beyond strictly necessary should fire until the visitor opts in. This is the technical detail most home-made banners get wrong — the banner appears, but the analytics script has already loaded behind it.
  • Equal choices. “Accept all” and “Reject all” should be equally prominent and equally easy — same page, same effort. No hiding “reject” behind extra clicks.
  • Granular options. Let people accept some categories and not others (for example analytics but not advertising).
  • No pre-ticked boxes. Consent must be a clear, affirmative action.
  • Clear information. Say what the cookies do, who sets them, and how long they last, usually via a linked cookie notice.
  • Easy to change your mind. Provide a way to withdraw or update consent later — as straightforward as giving it.

“By continuing to browse you accept cookies” is not valid consent. Neither is a wall of legalese with a single glowing “Accept” button.

Handling analytics without breaking the rules

You do not have to give up understanding your website. You have a few honest options:

  1. Ask first. Load analytics only after the visitor consents. You will measure fewer people, but the numbers you get are lawful.
  2. Use privacy-focused, cookieless analytics. Some analytics tools are designed to measure traffic without setting cookies or identifying individuals. Where a tool genuinely avoids storing or reading information on the device, the strict consent requirement may not bite in the same way — but check each tool’s specific claims rather than taking the marketing at face value, and always be transparent about what you use.
  3. Keep it proportionate. A small brochure website often needs far less tracking than businesses assume. Measuring less can be simpler and safer.

Whichever route you take, describe it plainly in your privacy and cookie notices.

Cookies and your wider privacy duties

Cookies rarely sit alone. Once a cookie identifies or profiles someone, UK GDPR duties come into play as well — lawful basis, transparency and people’s rights. If you are still getting the fundamentals in place, our GDPR basics for UK small business is a good companion to this article, and it is worth making sure your privacy notice and cookie notice actually match what your website does.

It is also worth remembering that PECR governs more than cookies — it covers electronic marketing too, such as the rules around email and SMS campaigns. If you run newsletters or promotions, the same regulations shape how you can contact people and when you need consent.

Getting it right without the guesswork

Cookie compliance is one of those tasks that looks trivial and then quietly goes wrong in the technical detail — usually a banner that looks fine but lets trackers load before anyone clicks. As a managed IT and cyber-security provider in Leeds and Yorkshire, DACROS can audit what your website actually sets, configure a consent tool that blocks non-essential cookies until opt-in, and make sure your cookie and privacy notices reflect reality.

If you would like your site checked over, take a look at our services or get in touch — we will tell you plainly what needs fixing and what is already fine.

Frequently asked questions

Do I really need a cookie banner?

If your website only uses strictly necessary cookies — the ones needed to make the site work, such as keeping a shopping basket or a login session — you may not need a consent banner at all, though you should still explain those cookies in a cookie or privacy notice. As soon as you add analytics, advertising, social media or embedded video, you need to ask for consent before those load, which in practice means a banner or similar consent tool.

What counts as a 'strictly necessary' cookie?

Strictly necessary means essential to provide the service the user has actually asked for — not merely useful to you. Examples include remembering items in a basket, keeping someone logged in during a session, or load-balancing for security. Analytics, marketing and personalisation are not strictly necessary, even if they feel important to your business, so they need consent.

Can I use Google Analytics without consent?

No. Analytics cookies are not strictly necessary, so under PECR you must obtain consent before they are set. That means the analytics script should only load after the visitor opts in. If you want measurement without a consent barrier, consider privacy-focused, cookieless analytics approaches — but check the specific tool's claims carefully, and be transparent about whatever you use.

Is a banner that says 'by using this site you accept cookies' enough?

No. Consent must be freely given, specific, informed and a clear affirmative action. 'Implied consent' from continuing to browse does not meet the standard, and pre-ticked boxes are not allowed. Non-essential cookies must not fire until the visitor has actively agreed, and rejecting must be as easy as accepting.

Who actually enforces cookie rules in the UK?

The Information Commissioner's Office (ICO) enforces PECR, the Privacy and Electronic Communications Regulations, which sit alongside UK GDPR. The ICO has publicly focused on cookie banners that make rejecting harder than accepting, so a fair, balanced banner is the single most important thing to get right.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.