The cookie banner is the most resented rectangle on the internet, so when word spread that UK rules had relaxed, plenty of business owners heard what they wanted to hear: the banner can go. The truth is more useful than that, and worth getting precisely right, because the same law that relaxed the rules also raised the maximum penalty from £500,000 to £17.5 million or 4% of global turnover.
Here is the low-down: which cookies no longer need consent, which still do, and what we found when we ran the exercise every owner should run, auditing our own website against the new rules.
What changed in the law?
The Data (Use and Access) Act rewrote the UK's cookie consent rules by amending PECR, the regulation that has governed cookies since 2003. The changes took effect on 5 February 2026, and the Information Commissioner's Office published its finalised guidance on storage and access technologies in late April 2026, which is the document to bookmark if you want the source rather than the summary.
Two changes matter to a business website. First, a new schedule of exemptions: categories of cookie that no longer require a consent pop-up at all. Second, enforcement teeth: PECR breaches used to carry a maximum £500,000 penalty; they now carry the same ceiling as UK GDPR, £17.5 million or 4% of worldwide turnover, whichever is higher. The direction of the deal is clear enough: less friction for low-risk cookies, sharper consequences for misusing the rest.
Which cookies no longer need a consent pop-up?
Three families of cookie can now be set without asking first, subject to conditions we will come to:
- Statistics. First-party analytics cookies used solely to count and understand how your own site is used: visits, pages, journeys. The purpose has to be statistical, and the data has to stay in service of that purpose.
- Appearance and preferences. Cookies that remember how a visitor wants the site to look and behave: dark mode, language, font size, region.
- Security and function. Cookies for security, fraud prevention and fault detection, alongside the strictly-necessary basics like shopping baskets and logins that never needed consent in the first place.
Even for exempt cookies, visitors must still be given clear information about what is being set and why, and a straightforward way to object. So the exemption removes the blocking pop-up, not the transparency: your privacy or cookie page still needs to describe these cookies, and a visitor who objects needs a working route to do so. What disappears is the requirement to interrupt everyone before counting anyone.
Does the exemption cover Google Analytics?
This is the question most owners are really asking, and the honest answer is: not automatically, and for many setups, no.
The statistics exemption covers first-party analytics used solely for statistical purposes. Whether a given Google Analytics 4 installation fits that description depends on how it is configured. GA4 can be set up to share data with Google for its own purposes, to feed advertising features, to link with Google Ads and to build audiences for remarketing; any of those uses steps outside "solely statistical", and the ICO's guidance is written around purpose, not product names. A GA4 property with advertising features switched on is doing more than counting, and the exemption is not built for it.
That does not make the exemption useless. Self-hosted or privacy-focused analytics tools that keep data entirely first-party sit comfortably inside it, and a carefully configured GA4 property with sharing and advertising features off gets much closer. But "we use Google Analytics so we can drop the banner" is not a conclusion the rules support, and it is exactly the assumption most likely to be tested by a regulator with a new fining power.
We tried to delete our own banner. Here is why we could not.
We ran the audit on digitalotter.co.uk, to check if the banner is still a requirement. Our stack: Google Analytics 4, Microsoft Clarity for session insights, a Google Ads tag, and a Meta Pixel for measuring ad campaigns. Our setup denies everything by default; analytics and advertising storage only switch on if a visitor accepts the banner.
The audit's conclusion was clear: the banner stays. Not because of the analytics, which could plausibly be configured into the statistics exemption, but because of the advertising tags. The Google Ads tag and the Meta Pixel exist to measure and improve ad campaigns; no reading of a statistics exemption covers them, so consent is still the lawful route, which means the banner still has a job. The realistic slimming for a site like ours is scope rather than existence: fewer categories asked about, clearer information for the exempt ones, and the pop-up reserved for the cookies that still legally need it.
That finding generalises. If your site runs any advertising or remarketing tag, which describes most commercial sites doing paid marketing, the new rules do not remove your banner. If your site is a brochure site whose only non-essential cookie is first-party statistics, you are the business the reform was written for: with the right analytics configuration, clear information on your privacy page and an objection route, the pop-up can go.
What if your site sets no analytics cookies at all?
Then you may be carrying a banner you never needed, and the new rules are a good excuse to check. A brochure site with no analytics, no advertising tags and no embedded third-party content often sets nothing beyond strictly necessary cookies, and strictly necessary cookies have never required consent. Plenty of small sites run a consent pop-up anyway, because a page builder or plugin installed one by default years ago and nobody questioned it.
The reverse error is just as common: a site whose owner believes it sets nothing, while an embedded map, video player or social feed quietly sets third-party cookies with every visit. Embeds are the classic blind spot, because the cookie belongs to the embed provider rather than to any tool you signed up for. This is why the audit below starts with an inventory rather than an assumption, in either direction: some sites get to delete a banner they never needed, others discover the banner they have is not covering what the site does.
What should your website do now?
Five steps, in the order we ran them ourselves:
- Inventory the cookies. Your browser's developer tools, or any reputable cookie scanner, will list what your site sets, which is frequently a surprise in both directions.
- Classify each one by its real purpose against the categories above: strictly necessary, statistics, preferences, security, or marketing. The tool that set it does not decide the category; the purpose does.
- Stop asking about the exempt categories, and describe them properly on your cookie or privacy page instead, with a way for visitors to object.
- Keep real consent for marketing cookies: a banner where declining is as easy as accepting, and where nothing in that category fires before the choice is made. Ours works this way, with everything denied until a visitor says otherwise, and that default is worth checking on your own site because many older setups fire first and ask second.
- Update the privacy page so it tells the same story as the banner. Inconsistency between the two is the easiest thing for anyone to spot, and the first thing a complaint or a regulator would compare.
For most sites this is an afternoon with the settings of your analytics tool and your consent banner. If your banner was installed years ago by a plugin nobody has opened since, budget the afternoon; those legacy setups are where the fire-first-ask-later problems live.
What stays the same?
Everything about marketing consent, and everything about the data itself. Advertising cookies, remarketing pixels and social media tags still require prior consent, freely given and as easy to refuse as to accept. UK GDPR still governs whatever personal data your site collects, however the cookie that collected it was categorised. And the regulator's appetite in this territory is not hypothetical: the ICO's recent enforcement record against small businesses has been dominated by marketing and consent failures rather than dramatic breaches, a pattern we covered in our ecommerce security guide.
The wider legal picture for UK sites, from privacy policies to accessibility, is in our website legal requirements guide, and this post is the cookie chapter's 2026 update rather than its replacement.
If you would like the audit done properly on your own site, banner scope, tag behaviour and the settings behind both, feel free to get in touch.
Get in touch - we're happy to chat.



