What it covers
PECR implemented the ePrivacy Directive in the UK and survived Brexit. It governs cookies and similar technologies, electronic marketing by email, text and telephone, and the security and confidentiality of communications services. Regulation 6 is the cookie provision: information and consent before storing or accessing information on terminal equipment, with an exemption for what is strictly necessary for a requested service.
PECR does not define consent. It borrows the UK GDPR definition, which is why the operational standard matches the EEA one even though the instruments differ.
What changed in 2025
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and its PECR changes came into force on 5 February 2026. It introduced purpose-limited exceptions to the consent requirement (emergency assistance, statistical purposes, and appearance), which fall away the moment the technology is used for anything beyond the stated purpose. It also raised PECR’s enforcement ceiling to match the UK GDPR. The ICO has reframed its guidance around “storage and access technologies” rather than cookies, and StrongPrivacy does not implement a UK-specific exception: a GB visitor is treated as opt-in unless you add a region rule.
Read the current ICO guidance
This is the part of the UK regime most likely to have moved since this page was written. Confirm the position before narrowing a banner on the strength of it.
Common questions
Is PECR separate from the UK GDPR?
Yes. PECR contains the cookie and electronic marketing rules; the UK GDPR contains the general data protection regime and the definition of consent that PECR uses. The penalty ceilings used to differ sharply (PECR was capped at £500,000), but the Data (Use and Access) Act 2025 aligned them, so certain PECR breaches now reach £17.5 million or 4% of global annual turnover.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- ICO: guidance on storage and access technologies
Regulator guidance
Checked
- ICO: exceptions to the storage and access rules
Regulator guidance
Checked
- ICO: commencement of the Data (Use and Access) Act 2025
Regulator guidance
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.