Where the cookie rule actually lives
As in the EU, the consent requirement for storage and access is not in the data protection statute. It is in regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), which implemented the ePrivacy Directive and survived Brexit. Regulation 6 requires clear and comprehensive information and the subscriber’s or user’s consent before storing or accessing information on their terminal equipment, with an exception for what is strictly necessary to provide a service the user requested.
The UK GDPR supplies the definition of consent that PECR borrows. So the operational standard is the same one an EEA site meets: a clear affirmative action, no pre-ticked boxes, refusal as easy as acceptance, and a record you can produce.
Where the UK has moved
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and its changes to PECR came into force on 5 February 2026. It introduced purpose-limited exceptions to the consent requirement (emergency assistance, statistical purposes, and appearance), which is genuinely new ground rather than a restatement of the EU position. The exceptions are limited to their stated purpose: use the technology for anything beyond it and consent is required again.
Confirm the current ICO position before narrowing a banner
StrongPrivacy does not implement a UK-specific exception, and treats a GB visitor as opt-in. The exceptions are purpose-limited, so the reasoning has to be about a specific purpose rather than about a category. Read the ICO’s guidance on storage and access technologies first. If you conclude a purpose falls inside one, express it with a region rule for GB rather than by loosening the property globally, and keep the reasoning written down.
The penalties have converged rather than diverged. Breaches of the UK GDPR reach £17.5 million or 4% of global annual turnover, and the Data (Use and Access) Act 2025 lifted PECR’s old £500,000 ceiling to match that framework for certain breaches. PECR remains the route the ICO reaches for on cookies and marketing, and it no longer carries a discount.
What each region profile resolves to
| Region profile | Resolved model | What the visitor sees |
|---|---|---|
| Regional defaults | opt-in | Nothing optional loads until a choice is made |
| Global strict | opt-in | Nothing optional loads until a choice is made, everywhere |
| Global balanced | opt-in | Nothing optional loads until a choice is made |
| EU and UK opt-in | opt-in | Nothing optional loads until a choice is made |
The "EU and UK opt-in" profile treats the EEA, the United Kingdom and Switzerland as opt-in and shows no banner elsewhere unless a region rule overrides it. It can fit a property whose assessed scope is limited to those markets. It should not be used as a conclusion that visitors elsewhere have no privacy rights; if a US state, Brazil or another regulated market is in scope, select or configure a model for that market.
How the ICO has approached this
The ICO has publicised action against high-traffic UK sites where rejecting advertising cookies was harder than accepting them, initially giving operators a period to correct the design and then following up. A recurring defect is a prominent "Accept all" control without an equally accessible refusal at the same level.
- Keep "Reject optional" at the same level of prominence as "Accept all" (the default copy does)
- Do not treat continued scrolling or navigation as consent
- Provide a persistent, easy-to-find route back to the preference centre after the first decision
- Be able to show, per visitor, what was granted and against which configuration version
This is a product reference, not legal advice
It describes how StrongPrivacy behaves and summarises published law so you can configure the product deliberately. Whether a particular configuration satisfies your obligations is a question for your own counsel, who knows your data flows and your risk position.
Common questions
Did Brexit change what a UK cookie banner has to do?
Not at the level of the banner. PECR regulation 6 still requires prior consent for non-essential storage and access, and the UK GDPR still defines what consent means. What changed is the enforcement route and, since the Data (Use and Access) Act 2025 came into force in February 2026, a set of purpose-limited exceptions the EU regime does not have, alongside a much higher PECR penalty ceiling.
Does StrongPrivacy treat the UK differently from the EU?
It detects the difference: a GB visitor’s runtime context carries the jurisdiction UK_GDPR, which is what the engine uses to choose the consent model. What the consent record stores is the resolved location (`GB`) rather than the jurisdiction name, so a UK decision is identifiable by country code. The model is opt-in under every profile that shows a banner, the same as the EEA, unless you add a region rule for GB.
Can I rely on the new PECR exceptions for analytics?
That is a decision for your own advisers, and it depends on the purpose and how the analytics is configured. The product does not make that call for you. If you make it, encode it as a GB region rule so it is visible, reversible and recorded rather than buried in a global setting.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- ICO: guidance on storage and access technologies
Regulator guidance
Checked
- ICO: exceptions to the storage and access rules
Regulator guidance
Checked
- ICO: commencement of the Data (Use and Access) Act 2025
Regulator guidance
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.