A complete, practical guide for UK businesses to understand, implement, and maintain compliant cookie consent banners on their websites

If your business website uses cookies, UK law means you can’t just ignore consent banners or privacy notices anymore. The rules have tightened, the Information Commissioner’s Office (ICO) is paying attention, and getting cookie compliance wrong puts you at risk of fines and reputational damage. This guide will demystify exactly what UK cookie law requires, how consent banners should really function, and the practical steps you must take to stay compliant—without ruining your user experience or stalling your marketing.
The so-called 'cookie law' in the UK refers primarily to the Privacy and Electronic Communications Regulations (PECR), which sit alongside the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. These laws govern how you collect, store, and use information from website visitors. Despite Brexit, the UK still follows a GDPR-aligned regime, and the rules around cookies haven’t softened. If you use cookies for anything other than what’s 'strictly necessary' for your website to function, you must obtain the user’s informed consent before placing them on their device.
The Information Commissioner's Office (ICO) is the UK regulator enforcing these rules. ICO guidance is clear: organisations must be transparent about what cookies do and why, and users must have a genuine choice over non-essential cookies. There’s no exception for small businesses or low-traffic sites—if you target UK users and use cookies, you’re in scope.
Fines for non-compliance can be significant. Under PECR, the ICO can issue penalties of up to £500,000. Under UK GDPR, breaches involving personal data can attract even higher fines—up to £17.5 million or 4% of annual global turnover, whichever is higher. In practice, the ICO tends to focus on egregious or repeated breaches, but any business ignoring cookie consent is taking a real risk.
‘Cookies’ include any technology that stores or accesses information on a user’s device. This covers not just browser cookies but also local storage, web beacons, tracking pixels, and similar technologies.
Not all cookies require consent under UK law. The distinction is between 'strictly necessary' cookies, which are essential for the operation of your site (such as those that remember what’s in a shopping basket or keep users logged in), and non-essential cookies, which include analytics, advertising, and social media tracking.
Most cookies used for marketing, behavioural tracking, website analytics (like Google Analytics), or personalisation require users to opt in. Even cookies set by third-party plugins or embedded content (e.g., YouTube videos, social feeds) often require consent, as they can track users across sites.
A frequent mistake is assuming analytics cookies are 'necessary'—the ICO is explicit that they are not. Only cookies that are vital for core site functionality are exempt. If in doubt, treat cookies as requiring consent unless you can justify otherwise.
| Cookie Type | Requires Consent? | Examples |
|---|---|---|
| Strictly Necessary | No | Session cookies, login/authentication, basket contents |
| Analytics/Performance | Yes | Google Analytics, Matomo, Hotjar |
| Functionality (Non-essential) | Yes | Language preference, remembering choices (if not vital) |
| Advertising/Tracking | Yes | Facebook Pixel, Google Ads, LinkedIn Insights |
| Third-Party Embedded Content | Yes | YouTube video embeds, Twitter feeds |
In 2023, the ICO issued warnings to over 100 UK organisations for failing to meet cookie consent standards, and several received public reprimands.
A compliant cookie banner must do more than just tell users that cookies are used. The ICO requires that users are given clear, specific information about what cookies are set, what they do, and must be offered a real choice to accept or reject non-essential cookies. Pre-ticked boxes or implied consent (such as 'by using this site you agree to cookies') are not acceptable.
The banner must appear when a user first visits your website—before any non-essential cookies are set. Users should be able to reject all non-essential cookies just as easily as accept them, and must have access to a detailed cookie policy. You must also record users’ consent choices and provide a way for users to change their mind later.
Design matters: banners should not be disguised, hidden, or use 'dark patterns'—tricks that nudge users into accepting. The language should be plain English, not legalese. You should name each type of cookie, its purpose, and who sets it.
The ICO says relying on browser settings (like Do Not Track) is not enough to demonstrate consent. You must actively collect and record the user’s choices on your site.
Before you can build a compliant banner, you need to know exactly what cookies your site sets. Many small business owners are surprised to find their website (or plugins) sets far more cookies than expected. This is especially true if you use third-party services, embedded videos, or website builders.
A cookie audit is a systematic process for identifying every cookie and similar technology in use. This involves scanning your website with automated tools, but also reviewing code, plugins, and embedded content. You should record the name, type, purpose, duration, and provider of each cookie.
Once you have a list, categorise each cookie as 'strictly necessary', 'analytics/performance', 'functional', or 'advertising/tracking'. This categorisation determines which cookies require user consent and how you describe them in your banner and policy.
Once you’ve audited your cookies, you’ll need a way to manage user consent. Most UK small businesses use a Consent Management Platform (CMP) to automate the display of banners, collect choices, and block non-essential cookies until consent is given. CMPs range from free, basic plugins to sophisticated enterprise systems.
When choosing a CMP, you need to ensure it offers true compliance with UK law. Look for solutions that allow granular consent (separate toggles for analytics, marketing, etc.), easy rejection as well as acceptance, and the ability to customise wording. Many free plugins do not actually block cookies before consent—using these can leave you non-compliant.
Implementation involves more than pasting a script. You must configure your CMP to block all non-essential cookies by default and test that cookies are not set until the user consents. You should also ensure your consent records are stored securely and can be exported if needed. The ICO expects you to be able to demonstrate compliance on request.
| CMP Provider | Free Tier? | Granular Consent? | Blocks Before Consent? | UK Support |
|---|---|---|---|---|
| Cookiebot | Yes | Yes | Yes | Yes |
| OneTrust | No | Yes | Yes | Yes |
| Complianz | Yes | Yes | Yes | Partial |
| CookieYes | Yes | Yes | Yes | Partial |
| Osano | Yes | Yes | Yes | No |
Always test your site in a private browser window to verify that no non-essential cookies are set before consent, regardless of what your CMP promises.
A cookie policy (or a dedicated section in your privacy policy) is mandatory for UK sites using cookies. This policy must explain what cookies are used, why, their duration, who sets them, and how users can control them. The ICO expects this information to be detailed, accurate, and kept up to date.
Many small businesses copy generic templates, which rarely meet ICO standards. Your policy should be tailored to your actual cookies, using plain English and avoiding technical or legal jargon. For each cookie category, explain its function, and provide a table listing individual cookies, their providers, and expiry periods.
You should also explain how users can change their preferences after giving or refusing consent. This usually means linking to your CMP’s 'cookie settings' feature or providing clear instructions for adjusting browser settings (with the caveat that browser settings alone are not sufficient for consent).
Many UK small businesses fall into the trap of thinking a simple 'We use cookies' notice is enough. The ICO has repeatedly stated this is not compliant. Another frequent error is failing to block non-essential cookies until after consent is given—analytics scripts and advertising pixels are the usual culprits.
Don’t rely on free plugins alone. Many WordPress or Shopify cookie banners only inform, but do not prevent cookies from being set before consent. You must test your site after implementation, as technical misconfigurations are common. Remember, if you use third-party tools (like Google Analytics or Facebook Pixel), you are responsible for ensuring they are only activated after valid consent.
Another mistake is failing to update your cookie audit and policy after adding new plugins or embedded content. The digital landscape changes fast—your compliance must keep up. Finally, be wary of 'cookie walls' (banners that block all access unless cookies are accepted). These are rarely permitted under UK law except where strictly necessary for a service the user has requested.
Plugins or themes can set cookies outside your control. You are still legally responsible for these, so always check and test after updates or new installations.
Cookie compliance is not a set-and-forget job. New marketing campaigns, website updates, or changing regulations can affect your obligations. The ICO expects businesses to monitor their website for new cookies, keep consent records, and respond promptly to user requests to change preferences or withdraw consent.
You should review your cookie audit and policy at least annually, and whenever you add new features or plugins. Consent records (which user opted into what, and when) should be stored securely for at least as long as you use the cookies in question. If a user withdraws consent, you must stop processing their data for that purpose and, where possible, delete existing identifiers.
If you receive a complaint or data subject request regarding cookies, you need to be able to demonstrate your compliance: your audit logs, consent records, cookie policy, and technical measures. The ICO gives businesses a reasonable period to rectify minor issues, but persistent or major failures risk enforcement action.
| Compliance Task | Recommended Frequency | Responsible Party |
|---|---|---|
| Cookie audit | Every 6-12 months and after major changes | Website owner / Data protection lead |
| Policy review | Annually | Website owner |
| Consent record check | Ongoing | CMP provider / IT |
| User request response | Within 1 month | Website owner / Data protection lead |
Many small business owners worry that strict cookie banners will hurt their analytics or marketing. It’s true that only a portion of users will consent to non-essential cookies—current UK opt-in rates for analytics range from 40-70% depending on banner design. However, non-compliance is not a viable alternative: fines, complaints, and loss of customer trust carry far greater long-term cost.
To maximise opt-ins while staying compliant, focus on transparency and user control. Explain the value of cookies (e.g., 'We use analytics to improve your experience') and avoid aggressive or manipulative designs. The ICO has warned against banners that make 'accept' the only prominent option. Make sure your site still functions for users who refuse cookies—this is not just a best practice, it’s a legal requirement.
If you rely heavily on analytics, consider using solutions that offer anonymised, cookie-free tracking, or aggregate data that does not identify individuals. Some platforms (like Plausible or Fathom) are designed to minimise or avoid cookie use and may fall outside the strict consent regime, but you need to check carefully and document your reasoning.
Average opt-in rate for analytics cookies on UK SME websites is 55%, according to FSB and ICO studies.
If the ICO contacts you about a cookie compliance issue, don’t panic—but don’t ignore it either. Most enforcement begins with a letter or email outlining the issue and requesting remedial action. Respond promptly, be transparent, and provide evidence of your cookie audit, policy, and consent records.
Penalties are usually reserved for persistent, wilful, or egregious breaches, but the ICO can issue fines of up to £500,000 under PECR, and higher under UK GDPR for breaches involving personal data. Small businesses are rarely fined for a first offence if they take swift action, but repeat or flagrant non-compliance can be costly. Public reprimands can also damage your reputation and SEO.
If you discover a breach (e.g., cookies set before consent, or consent records missing), act immediately: fix the technical issue, update your policy, and document what you’ve done. If the breach involved personal data and creates a risk to individuals, you may need to report it to the ICO within 72 hours.
The ICO offers a dedicated helpline for small businesses: 0303 123 1113. The Federation of Small Businesses (FSB) also provides members with legal and data protection advice.

Ready for the next step? Open a business bank account to keep your finances organised.

Get 7,500 free points (worth £75) on your first transaction. No annual fee. Instant decision.
Affiliate disclosure: we may earn a commission via our links. This does not affect our editorial independence.


Affiliate links. We may earn a commission. Editorial independence maintained.