← Back to blog

Fix UK cookie consent now: SATs rules developers must address

September 26, 2026
Fix UK cookie consent now: SATs rules developers must address

Yes: for most tracking, analytics and advertising uses you must obtain active consent under PECR, the ICO and UK GDPR. Provide an equal-weight reject option and granular purpose choices; never rely on silence, pre-ticked boxes or a banner that makes "accept" easier to find than "reject". Fix this on your banner today before you address anything else.


TL;DR:

  • Active, granular consent is mandatory for most tracking and analytics technologies, requiring clear options to accept or reject each purpose separately.
  • Consent must be freely given, specific, informed, unambiguous through positive action, and purpose-granular, with pre-ticked boxes or bundled accept/reject options failing legal standards.
  • Strictly necessary SATs are exempt from consent only if essential to deliver specific requested services, and documentation of reliance on these exceptions is required.
  • Implementing a compliant cookie banner involves equal prominence for reject options, technical blocking of non-essential scripts, and detailed record-keeping of consent actions and purposes accepted or rejected.
  • Regular testing, proper withdrawal handling, and recording of consent are essential for compliance, with ICO enforcement increasingly scrutinizing undeclared trackers and default vendor settings.

Webnora
Build a Faster, Search Ready Website
Webnora creates lightweight, mobile first websites with SEO fundamentals for UK small businesses, custom built from scratch.
Visit Webnora

Table of Contents

The Privacy and Electronic Communications Regulations (PECR) govern consent for cookies and, more broadly, for what the ICO now calls storage and access technologies, or SATs: pixels, local storage, fingerprinting scripts and anything that reads or writes information on a user's device. Where those SATs also involve personal data, UK GDPR and the Data Protection Act 2018 apply alongside PECR, so a single tracking script can trigger both regimes at once.

The Data (Use and Access) Act 2025 amended regulation 6 of PECR, adding specific exceptions that let certain statistical and appearance-related uses proceed without consent. The ICO followed with finalised SAT guidance:

  • PECR covers cookies and any comparable storage or access technology, not just browser cookies.
  • UK GDPR and the Data Protection Act 2018 apply whenever a SAT processes personal data.
  • The Data (Use and Access) Act 2025 narrowed the consent requirement for defined statistical and appearance functions.
  • The ICO's finalised guidance, published in April 2026, sets out how the regulator expects SATs to be assessed in practice.

Consent has to clear five hurdles at once, and missing any one of them invalidates the whole mechanism.

  1. Freely given: the user has a genuine, unpressured choice, with no service degradation for refusing.
  2. Specific: consent covers a named purpose, not a blanket "improve your experience" catch-all.
  3. Informed: the banner names the categories of cookies and third parties involved before consent is given.
  4. Unambiguous and by positive action: a clear click or toggle, never silence, scrolling or continued browsing.
  5. Purpose-granular: analytics, marketing and functional cookies each get their own switch, not a single bundle.

Pre-ticked boxes and bundled "accept all or leave" designs fail this test outright, according to the ICO's guidance on cookies and similar technologies. The ICO also suggests refreshing consent roughly every six months as a working default, adjusted whenever your purposes or vendor list change.

Only a narrow set of SATs are exempt, and the bar sits higher than most site owners assume.

  • Strictly necessary: the technology must be essential to deliver the specific service the user requested, such as a shopping basket or login session, never convenience or internal analytics.
  • Appearance exceptions: functions that only adjust how a page displays for the current visit, now clarified by the Data (Use and Access) Act 2025.
  • Statistical exceptions: certain first-party statistical measurement uses may now qualify without consent under the same 2025 amendment.
  • Documentation: record which exception you rely on, why, and the specific SAT it covers, so you can show your reasoning if the ICO ever asks.

Step-by-step implementation checklist for a compliant cookie/preferences flow

Building this correctly the first time saves you from retrofitting a banner across dozens of pages later.

  • Banner design: give "reject all" the same size, colour weight and one-click ease as "accept all"; never bury it in a settings link.
  • Preferences centre: list each purpose (analytics, marketing, functional) separately with the actual third-party names involved, following patterns similar to the GOV.UK Design System's cookie page guidance.
  • Technical blocking: prevent non-essential tags from firing until consent is recorded, whether you use a tag manager or a server-side setup, and test this on a fresh incognito session.
  • Record keeping: log the timestamp, the specific action taken, the purposes accepted or rejected, and the vendor list shown at that moment.
  • Storage location: keep consent logs somewhere you can retrieve and export quickly if a regulator or a user asks what they agreed to.
  • Vendor defaults: check your CMP's default cookie durations and retention periods rather than accepting them; justify and document whatever you keep.
  • Accessibility and devices: make the banner and preferences UI usable by keyboard and screen reader, and confirm choices carry across mobile and desktop sessions where technically possible.
  • Graceful fallback: when consent is absent or withdrawn, the site should still function, just without the non-essential scripts.

Pro Tip: Test your banner in a private browser window every time you add a new script; it is the fastest way to catch a tag firing before consent is given.

Common pitfalls and developer traps flagged by auditors and the ICO

Auditors repeatedly flag the same weak points, and most are fixable in an afternoon.

  1. Undeclared trackers: tracking pixels and fingerprinting scripts count as SATs and must be included in your consent inventory, not treated as exempt utilities.
  2. Blind trust in vendor defaults: a CMP's default expiry or scope is not automatically lawful; document why you kept or changed it.
  3. Incomplete withdrawal handling: when a user withdraws consent, erase the personal data collected under it where required, and notify any third parties who received that data.
  4. Quick fixes: audit every third-party script for consent gating, confirm your tag manager blocks by default, and re-check retention periods against actual business need.

Withdrawal has to be exactly as easy as giving consent in the first place.

  • Offer a persistent, always-visible way to reach the preferences centre, not just a one-time banner.
  • Where the ICO's guidance requires it, delete personal data gathered under the withdrawn consent and notify recipients who received it, where feasible.
  • Keep consent logs secure and exportable, since they are your evidence in any audit.
  • Test the whole flow periodically, including confirming third-party vendors actually action withdrawal requests you send them.

Webnora's own cookie policy sets out a working example of how these purposes and third parties can be disclosed in plain language.

Enforcement and practical exposure: what the ICO expects

The ICO's 2026 guidance signals closer scrutiny of SATs beyond browser cookies, alongside continued expectation that businesses give users meaningful control.

  • Expect informal guidance and correction requests first, escalating to formal enforcement notices for repeated or wilful non-compliance.
  • Serious or persistent breaches can lead to fines and public enforcement action, alongside the reputational cost of a public finding.
  • Resource-constrained sites should prioritise fixing pre-ticked boxes, undeclared trackers and missing reject options first, since these are the most visible failures.

Practitioner perspective: privacy compliance on a lightweight build

A compliant site does not need a bloated consent platform. Server-side consent checks, a handful of essential scripts and an accessible preferences panel usually outperform a heavyweight CMP, both for load speed and for actually giving users clear control.

— Ar

How Webnora can help you get this right

Some website developers build sites in the UK and can include a properly configured cookie banner and preferences centre as part of the build, rather than bolting one on afterwards. Because sites can be built from scratch, the consent flow can be tailored to fit actual scripts and vendors instead of a generic template guess.

Webnora

  • Business websites, personal websites, landing pages, website redesigns and SEO setup can be built with consent and privacy notices considered from the start.
  • Clients may review and approve the finished site before paying, helping to reduce financial risk while checking the consent flow works as expected.
  • See the full range on the services page or check how it works before getting in touch.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources

FAQ

Yes, for most non-essential cookies used for analytics, tracking or advertising, PECR requires active consent before the cookie is set, and the ICO's guidance confirms silence or continued browsing does not count. Strictly necessary cookies, and certain statistical or appearance functions clarified by the Data (Use and Access) Act 2025, are the main exceptions.

The Data (Use and Access) Act 2025 amended PECR to add specific exceptions for some statistical and appearance-related uses of storage and access technologies. The ICO's finalised 2026 guidance then extended its focus beyond cookies to pixels, fingerprinting and web storage generally.

UK GDPR applies alongside PECR whenever a cookie or similar technology processes personal data, reinforcing the same requirements for freely given, specific and informed consent. PECR is the primary rule for the cookie itself, while UK GDPR governs any personal data the cookie subsequently collects.

Can I refuse to accept cookies?

Yes, users must be able to reject non-essential cookies as easily as they can accept them, with an equally prominent reject option under ICO guidance. Refusing should not block access to the core service, only to the non-essential tracking or advertising features.

Made with the help of BabyLoveGrowth