Privacy
UK cookie consent: the ICO rule most sites ignore.
Published 2026-04-15 · Last updated 2026-04-15 · Vantyris editorial
Under UK PECR + UK-GDPR, you can't set non-essential cookies (analytics, advertising, A/B testing) on a visitor's device until they've actively consented. Most cookie banners on UK SME sites break this rule in plain sight. Google Analytics loads with the page and fires before the visitor has even seen the banner asking them to 'accept cookies'. The ICO has been increasingly active on this since 2023. The fix is a configuration change, not a redesign.
What this means for your business
- Cookie consent under UK PECR + UK-GDPR is opt-in, not opt-out. The visitor must take an affirmative action (click 'Accept') before the non-essential tracking fires. Pre-ticked boxes don't count. Dark patterns ('Accept' styled prominently, 'Reject' hidden in small text) don't count.
- Essential cookies are exempt. A session cookie that keeps the visitor logged in doesn't need consent, and neither does a CSRF token or a basket-state cookie in an e-commerce flow. Analytics, advertising pixels, A/B testing, third-party social widgets and chat widgets that fingerprint the visitor all need explicit consent first.
- The ICO's guidance is specific. The Accept and Reject buttons must carry equal weight (same visual prominence, same number of clicks, both above the fold). Visitors who close the banner without choosing should be treated as having rejected.
How to fix
Block every non-essential tracker until the visitor clicks Accept, and make Reject as easy as Accept. Record the decision so the visitor's later browser sessions remember it.
- List every script that needs consent. Google Analytics + Google Tag Manager (analytics + advertising). Facebook Pixel. LinkedIn Insight Tag. Hotjar / FullStory / Microsoft Clarity (session recording). Stripe.js only if it sets persistent identifiers, which it mostly does NOT (Stripe is considered essential for payment). Chat widgets (Intercom, Drift) usually need consent. So do Mailchimp / HubSpot popups.
- Move every consent-required script behind a gate. The simplest version checks for a 'consent: granted' state in
localStoragebefore rendering each script tag. A consent-management platform (CookieYes, Cookiebot, Osano) does this for you. If you only have 2-3 trackers, a 30-line implementation of your own is enough (Vantyris's ownConsentBanner.tsxshows the pattern). - Build a banner with equal-weighted Accept and Reject buttons. Two buttons, identical styling, both visible at first paint. No pre-tick. No 'X' close button that bypasses the decision. If the visitor leaves without choosing, the state stays 'not yet decided' and the banner returns on the next visit. Non-essential trackers stay off until then.
- Add a 'Manage cookies' link in the footer. Visitors must be able to change their consent later, and a footer link that re-opens the banner is the cleanest way to do it. UK PECR requires it, and so does the 'right to withdraw consent' in GDPR Article 7.
- Document and surface your privacy policy. The consent banner must link to a privacy policy that names every processor (Google, Facebook, etc.) and what each one receives, along with the legal basis (consent for analytics, contract for essential). The ICO checks this when investigating.
Owner: Your developer, or your CMS administrator if your CMS has a consent-management plugin. · Time: 1-2 hours for a typical small business site with 2-5 trackers.
Common gotchas
- Don't use a consent-management platform that pre-ticks the accept boxes. That violates UK-GDPR, whatever the platform claims about compliance.
- Don't redirect users who reject to a different version of the site, or block them from the content. The ICO calls this a 'cookie wall' and explicitly disallows it for general-purpose sites. Some specific contexts allow it, but most SME marketing sites aren't one of them.
- Watch for indirect trackers. Google Fonts loaded directly from googleapis.com sends visitor IPs to Google, and under some interpretations that transfer needs consent in its own right. Self-host your fonts, or use Cloudflare's privacy-respecting font CDN.
- Vantyris follows this rule itself. Our consent banner is the reference implementation, and we built it the way we'd advise any UK SME to.
How to verify the fix
Open your site in an incognito window with DevTools on the Network tab, and reload. Don't touch the banner. Any request to google-analytics.com, facebook.com, doubleclick.net, or similar means a non-essential tracker fired before consent. Vantyris's Privacy category checks for exactly this pattern.
Common follow-up questions
Is the ICO actually enforcing this against small businesses?
Increasingly, yes. In 2023 the ICO ran a major sweep targeting the top 100 UK websites, and it reviews complaints against SMEs individually. For SMEs the usual outcome isn't a financial penalty. It's an enforcement notice requiring you to fix the problem by a deadline, and ignoring a notice escalates fast.
What about visitors from outside the UK?
EU visitors are covered by ePrivacy + EU-GDPR (essentially the same rules, sometimes stricter in individual member states). US visitors aren't covered by GDPR, but several states have similar consent rules, including California, Virginia and Colorado. The safest default is UK-GDPR-grade consent for every visitor.
Can I show different banners to different jurisdictions?
Yes, geo-IP-based banners are common. They take more work to build, and most SMEs find it easier to apply the strictest standard everywhere.
Does our chat widget really need consent?
Yes, if the widget fingerprints the visitor, persists state across sessions, or tracks them across sites. A simple stateless form-style widget that only activates on click doesn't. That counts as essential interaction. Read the vendor's documentation, because most modern chat widgets track by default.
References
- ICO: Cookies and similar technologies NCSC
- ICO: Direct marketing and privacy NCSC
- European Data Protection Board guidelines on consent Vendor
Related explainers
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris