Cookie rules for UK websites changed on 5 February 2026, and almost nobody told small businesses the useful part: if your site runs nothing fancier than basic analytics, the consent banner you were pressured into adding may no longer be required. The stick got bigger at the same time. The maximum fine for breaking the cookie rules went from £500,000 to £17.5 million or 4% of global turnover, whichever is higher. Here is where your site actually sits now.

What changed in February
The Data (Use and Access) Act 2025 amended PECR, the Privacy and Electronic Communications Regulations, the law behind every cookie popup you have ever grudgingly clicked. Since 2003 those rules demanded consent before a website stored anything on your device, with one narrow carve-out for strictly necessary cookies. That is why a plasterer’s brochure site ended up with a banner built for Facebook.
Two new exemptions exist now:
- Statistics. Cookies that count page views, referrers and scroll depth can run without asking, as long as their sole purpose is improving your own service and the data goes nowhere else.
- Appearance and function. Cookies that remember a visitor’s language choice, dark mode preference or font size are exempt too.
Both come with strings attached. You must tell people clearly what you collect. You must give them a simple, free way to object, and honour it if they do. Skip either condition and the exemption evaporates.
| Cookie type | Before 5 Feb 2026 | Now |
|---|---|---|
| Aggregate first-party analytics (page counts, referrers) | Consent required | Exempt, if you inform visitors and offer a way to object |
| Remembering language, dark mode, layout choices | Consent required | Exempt, same conditions |
| Advertising, retargeting, social media pixels | Consent required | Still consent required |
| Analytics shared with a third party for its own purposes | Needed consent anyway | Kills the exemption, consent needed |
That last row matters more than it looks. The exemption dies the moment your analytics data feeds anyone else’s machine, whether for ads, profiles or their own product improvements.
The catch inside the exemption
Here is the part that will annoy people. Default-configured Google Analytics probably does not qualify. Google can use the data it collects on your behalf for its own purposes, which puts the tool outside the statistical exception. The ICO said as much in the guidance it finished in April 2026. Either configure your analytics so data stays yours alone, or keep asking permission.
Mixed-purpose cookies fail too. A script that counts visitors and drops an ad pixel is a marketing cookie wearing an analytics badge. It needs consent.
The exemptions are conditional: clear information, an easy way to object, and no onward sharing. Lose any one of the three and you are back to needing consent.
So do not rip out your banner yet. Audit first.
What the regulator actually does all day
Since January 2025 the Information Commissioner’s Office has been testing the UK’s top 1,000 websites against three checks: whether advertising cookies fire before a visitor makes a choice, whether refusing is as easy as accepting, and whether cookies get set after someone says no.
By December 2025, 979 of the top 1,000 passed. 564 of those only got there after ICO letters and, in 17 cases, preliminary enforcement notices. 21 sites were still being pursued. Separately, the consent platforms serving roughly 80% of the top 500 websites made their banner defaults compliant.
Nobody is auditing the village plumber today. The realistic risk for a small site is not a nine-figure penalty, it is a complaint from a competitor or a customer, an information notice landing in your inbox, and an afternoon lost proving you know what your own website does. With enforcement powers now identical to UK GDPR ones, ignoring it is a worse bet than it used to be.
Which setup is yours
Match your site to the right row and you have your answer:
| Your site runs | What the law expects |
|---|---|
| Nothing but hosting and a contact form | Nothing. No banner, no policy drama |
| First-party analytics that shares nothing | No consent gate. Say what you collect somewhere findable and provide a way to object |
| Google Analytics on default settings | Grey zone. Turn off the data-sharing settings or keep consent |
| Meta pixel, Google Ads tag, LinkedIn or TikTok tags, tracking chat widgets | Full opt-in before those tags fire, with reject as prominent as accept |
Most small business sites live in the second and fourth rows simultaneously without realising it. The owner adds a quiet analytics script, then a web designer bolts on a pixel “to see how ads do”, and the whole site quietly becomes a consent-banner site.
The half hour that fixes it
- Open your own site in a private browsing window with the browser’s network tab visible. Note every request that fires before you click anything.
- List the third-party domains in your page source. Each one gets classified: strictly necessary, statistics, appearance, or marketing.
- Marketing scripts get blocked until a visitor clicks accept. Reject and accept buttons get equal size.
- Statistics scripts get a plain-English mention on your cookie page and an objection route, even a contact email counts if it works.
- Rewrite the cookie policy to describe what the site actually does. A policy promising consent requests you no longer make is its own problem.
- Screenshot the settings and date the audit. If the ICO ever writes, contemporaneous notes are the difference between a shrug and an investigation.
One action for this week: open your website fresh in a private window, network tab open, and watch what loads before you touch anything. Anything marketing-shaped firing before a click is the breach that matters. Everything else is paperwork you can finish over a coffee.