Glossary

PECR

The Privacy and Electronic Communications Regulations 2003: the UK instrument that actually contains the cookie consent rule, separately from the UK GDPR.

Full name
Privacy and Electronic Communications (EC Directive) Regulations 2003
Cookie rule
Regulation 6
Maximum fine
£17.5m or 4%, since 5 February 2026

What it covers

PECR implemented the ePrivacy Directive in the UK and survived Brexit. It governs cookies and similar technologies, electronic marketing by email, text and telephone, and the security and confidentiality of communications services. Regulation 6 is the cookie provision: information and consent before storing or accessing information on terminal equipment, with an exemption for what is strictly necessary for a requested service.

PECR does not define consent. It borrows the UK GDPR definition, which is why the operational standard matches the EEA one even though the instruments differ.

What changed in 2025

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and its PECR changes came into force on 5 February 2026. It introduced purpose-limited exceptions to the consent requirement (emergency assistance, statistical purposes, and appearance), which fall away the moment the technology is used for anything beyond the stated purpose. It also raised PECR’s enforcement ceiling to match the UK GDPR. The ICO has reframed its guidance around “storage and access technologies” rather than cookies, and StrongPrivacy does not implement a UK-specific exception: a GB visitor is treated as opt-in unless you add a region rule.

Read the current ICO guidance

This is the part of the UK regime most likely to have moved since this page was written. Confirm the position before narrowing a banner on the strength of it.

Common questions

Is PECR separate from the UK GDPR?

Yes. PECR contains the cookie and electronic marketing rules; the UK GDPR contains the general data protection regime and the definition of consent that PECR uses. The penalty ceilings used to differ sharply (PECR was capped at £500,000), but the Data (Use and Access) Act 2025 aligned them, so certain PECR breaches now reach £17.5 million or 4% of global annual turnover.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.