The RoadmapSetupSetting Up a Website and Domain

Cookie Law Compliance and Consent Banners

A complete, practical guide for UK businesses to understand, implement, and maintain compliant cookie consent banners on their websites

12 minute read
Setup — Setting Up a Website and Domain
✓ Verified against GOV.UK
Claire Henderson
Written by Claire Henderson
Finance & Tax Editor · GuideToBusiness
Back to Setup

If your business website uses cookies, UK law means you can’t just ignore consent banners or privacy notices anymore. The rules have tightened, the Information Commissioner’s Office (ICO) is paying attention, and getting cookie compliance wrong puts you at risk of fines and reputational damage. This guide will demystify exactly what UK cookie law requires, how consent banners should really function, and the practical steps you must take to stay compliant—without ruining your user experience or stalling your marketing.

What Is Cookie Law in the UK? Understanding the Legal Landscape

The so-called 'cookie law' in the UK refers primarily to the Privacy and Electronic Communications Regulations (PECR), which sit alongside the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. These laws govern how you collect, store, and use information from website visitors. Despite Brexit, the UK still follows a GDPR-aligned regime, and the rules around cookies haven’t softened. If you use cookies for anything other than what’s 'strictly necessary' for your website to function, you must obtain the user’s informed consent before placing them on their device.

The Information Commissioner's Office (ICO) is the UK regulator enforcing these rules. ICO guidance is clear: organisations must be transparent about what cookies do and why, and users must have a genuine choice over non-essential cookies. There’s no exception for small businesses or low-traffic sites—if you target UK users and use cookies, you’re in scope.

Fines for non-compliance can be significant. Under PECR, the ICO can issue penalties of up to £500,000. Under UK GDPR, breaches involving personal data can attract even higher fines—up to £17.5 million or 4% of annual global turnover, whichever is higher. In practice, the ICO tends to focus on egregious or repeated breaches, but any business ignoring cookie consent is taking a real risk.

What counts as a cookie?

‘Cookies’ include any technology that stores or accesses information on a user’s device. This covers not just browser cookies but also local storage, web beacons, tracking pixels, and similar technologies.

Which Cookies Need Consent? Types and Examples

Not all cookies require consent under UK law. The distinction is between 'strictly necessary' cookies, which are essential for the operation of your site (such as those that remember what’s in a shopping basket or keep users logged in), and non-essential cookies, which include analytics, advertising, and social media tracking.

Most cookies used for marketing, behavioural tracking, website analytics (like Google Analytics), or personalisation require users to opt in. Even cookies set by third-party plugins or embedded content (e.g., YouTube videos, social feeds) often require consent, as they can track users across sites.

A frequent mistake is assuming analytics cookies are 'necessary'—the ICO is explicit that they are not. Only cookies that are vital for core site functionality are exempt. If in doubt, treat cookies as requiring consent unless you can justify otherwise.

Cookie TypeRequires Consent?Examples
Strictly NecessaryNoSession cookies, login/authentication, basket contents
Analytics/PerformanceYesGoogle Analytics, Matomo, Hotjar
Functionality (Non-essential)YesLanguage preference, remembering choices (if not vital)
Advertising/TrackingYesFacebook Pixel, Google Ads, LinkedIn Insights
Third-Party Embedded ContentYesYouTube video embeds, Twitter feeds
ICO enforcement is rising

In 2023, the ICO issued warnings to over 100 UK organisations for failing to meet cookie consent standards, and several received public reprimands.

What Does a Compliant Cookie Banner Look Like?

A compliant cookie banner must do more than just tell users that cookies are used. The ICO requires that users are given clear, specific information about what cookies are set, what they do, and must be offered a real choice to accept or reject non-essential cookies. Pre-ticked boxes or implied consent (such as 'by using this site you agree to cookies') are not acceptable.

The banner must appear when a user first visits your website—before any non-essential cookies are set. Users should be able to reject all non-essential cookies just as easily as accept them, and must have access to a detailed cookie policy. You must also record users’ consent choices and provide a way for users to change their mind later.

Design matters: banners should not be disguised, hidden, or use 'dark patterns'—tricks that nudge users into accepting. The language should be plain English, not legalese. You should name each type of cookie, its purpose, and who sets it.

  • Consent must be explicit (no pre-ticked boxes or 'soft opt-in')
  • Banner must appear before non-essential cookies are set
  • Options to accept or reject all non-essential cookies equally prominent
  • Link to a detailed cookie policy or settings page
  • Record of user consent (with date, time, and preferences)
Don’t rely on browser settings

The ICO says relying on browser settings (like Do Not Track) is not enough to demonstrate consent. You must actively collect and record the user’s choices on your site.

How to Audit and Categorise Your Cookies

Before you can build a compliant banner, you need to know exactly what cookies your site sets. Many small business owners are surprised to find their website (or plugins) sets far more cookies than expected. This is especially true if you use third-party services, embedded videos, or website builders.

A cookie audit is a systematic process for identifying every cookie and similar technology in use. This involves scanning your website with automated tools, but also reviewing code, plugins, and embedded content. You should record the name, type, purpose, duration, and provider of each cookie.

Once you have a list, categorise each cookie as 'strictly necessary', 'analytics/performance', 'functional', or 'advertising/tracking'. This categorisation determines which cookies require user consent and how you describe them in your banner and policy.

Identifying and Classifying Cookies on Your Website

1
Identify all pages and embedded content
List every unique page template and any third-party content (like YouTube, Google Maps, social feeds) that may set cookies.
2
Use a cookie scanner tool
Run a reputable scanner (such as Cookiebot, OneTrust, or open-source tools like Webbkoll) on your site to detect cookies and local storage.
3
Manually check plugins and scripts
Review your CMS plugins, analytics scripts, and marketing tags. Check their documentation to see what cookies they set.
4
Document cookie details
For each cookie, note its name, provider, purpose, duration, and whether it’s first- or third-party.
5
Classify cookies by necessity
Decide which cookies are strictly necessary (for site function) and which are not. When in doubt, err on the side of requiring consent.
  • Check after every major site update or plugin install
  • Include mobile and tablet versions of your site
  • Look for cookies set by embedded videos or maps
  • Review your findings at least twice a year

Choosing and Implementing a Consent Management Platform (CMP)

Once you’ve audited your cookies, you’ll need a way to manage user consent. Most UK small businesses use a Consent Management Platform (CMP) to automate the display of banners, collect choices, and block non-essential cookies until consent is given. CMPs range from free, basic plugins to sophisticated enterprise systems.

When choosing a CMP, you need to ensure it offers true compliance with UK law. Look for solutions that allow granular consent (separate toggles for analytics, marketing, etc.), easy rejection as well as acceptance, and the ability to customise wording. Many free plugins do not actually block cookies before consent—using these can leave you non-compliant.

Implementation involves more than pasting a script. You must configure your CMP to block all non-essential cookies by default and test that cookies are not set until the user consents. You should also ensure your consent records are stored securely and can be exported if needed. The ICO expects you to be able to demonstrate compliance on request.

CMP ProviderFree Tier?Granular Consent?Blocks Before Consent?UK Support
CookiebotYesYesYesYes
OneTrustNoYesYesYes
ComplianzYesYesYesPartial
CookieYesYesYesYesPartial
OsanoYesYesYesNo
Test, don’t trust

Always test your site in a private browser window to verify that no non-essential cookies are set before consent, regardless of what your CMP promises.

Drafting a Transparent and Effective Cookie Policy

A cookie policy (or a dedicated section in your privacy policy) is mandatory for UK sites using cookies. This policy must explain what cookies are used, why, their duration, who sets them, and how users can control them. The ICO expects this information to be detailed, accurate, and kept up to date.

Many small businesses copy generic templates, which rarely meet ICO standards. Your policy should be tailored to your actual cookies, using plain English and avoiding technical or legal jargon. For each cookie category, explain its function, and provide a table listing individual cookies, their providers, and expiry periods.

You should also explain how users can change their preferences after giving or refusing consent. This usually means linking to your CMP’s 'cookie settings' feature or providing clear instructions for adjusting browser settings (with the caveat that browser settings alone are not sufficient for consent).

  • List every non-essential cookie used, with purpose and provider
  • Make the policy accessible from every page (footer link)
  • Update regularly—at least every 12 months
  • Include instructions for withdrawing or changing consent

Common Pitfalls and How to Avoid Them

Many UK small businesses fall into the trap of thinking a simple 'We use cookies' notice is enough. The ICO has repeatedly stated this is not compliant. Another frequent error is failing to block non-essential cookies until after consent is given—analytics scripts and advertising pixels are the usual culprits.

Don’t rely on free plugins alone. Many WordPress or Shopify cookie banners only inform, but do not prevent cookies from being set before consent. You must test your site after implementation, as technical misconfigurations are common. Remember, if you use third-party tools (like Google Analytics or Facebook Pixel), you are responsible for ensuring they are only activated after valid consent.

Another mistake is failing to update your cookie audit and policy after adding new plugins or embedded content. The digital landscape changes fast—your compliance must keep up. Finally, be wary of 'cookie walls' (banners that block all access unless cookies are accepted). These are rarely permitted under UK law except where strictly necessary for a service the user has requested.

  • Never use implied consent—always get explicit, active agreement
  • Block analytics and marketing cookies until consent
  • Audit cookies after every major site change
  • Avoid 'all or nothing' cookie walls unless you have legal advice
  • Don’t copy-paste policies—tailor them to your actual cookies
Risk of third-party plugins

Plugins or themes can set cookies outside your control. You are still legally responsible for these, so always check and test after updates or new installations.

Maintaining Compliance: Updates, Records, and Responding to Requests

Cookie compliance is not a set-and-forget job. New marketing campaigns, website updates, or changing regulations can affect your obligations. The ICO expects businesses to monitor their website for new cookies, keep consent records, and respond promptly to user requests to change preferences or withdraw consent.

You should review your cookie audit and policy at least annually, and whenever you add new features or plugins. Consent records (which user opted into what, and when) should be stored securely for at least as long as you use the cookies in question. If a user withdraws consent, you must stop processing their data for that purpose and, where possible, delete existing identifiers.

If you receive a complaint or data subject request regarding cookies, you need to be able to demonstrate your compliance: your audit logs, consent records, cookie policy, and technical measures. The ICO gives businesses a reasonable period to rectify minor issues, but persistent or major failures risk enforcement action.

Compliance TaskRecommended FrequencyResponsible Party
Cookie auditEvery 6-12 months and after major changesWebsite owner / Data protection lead
Policy reviewAnnuallyWebsite owner
Consent record checkOngoingCMP provider / IT
User request responseWithin 1 monthWebsite owner / Data protection lead

Cookie Law and Small Business Marketing: Balancing Compliance and Conversion

Many small business owners worry that strict cookie banners will hurt their analytics or marketing. It’s true that only a portion of users will consent to non-essential cookies—current UK opt-in rates for analytics range from 40-70% depending on banner design. However, non-compliance is not a viable alternative: fines, complaints, and loss of customer trust carry far greater long-term cost.

To maximise opt-ins while staying compliant, focus on transparency and user control. Explain the value of cookies (e.g., 'We use analytics to improve your experience') and avoid aggressive or manipulative designs. The ICO has warned against banners that make 'accept' the only prominent option. Make sure your site still functions for users who refuse cookies—this is not just a best practice, it’s a legal requirement.

If you rely heavily on analytics, consider using solutions that offer anonymised, cookie-free tracking, or aggregate data that does not identify individuals. Some platforms (like Plausible or Fathom) are designed to minimise or avoid cookie use and may fall outside the strict consent regime, but you need to check carefully and document your reasoning.

  • Test banner wording and design to improve opt-in rates
  • Offer clear explanations for each type of cookie
  • Use privacy-friendly analytics if possible
  • Never condition core site access on cookie acceptance
  • Monitor opt-in rates and user feedback
UK opt-in rates in 2026

Average opt-in rate for analytics cookies on UK SME websites is 55%, according to FSB and ICO studies.

What to Do If You Get It Wrong: Enforcement, Fines, and Recovery

If the ICO contacts you about a cookie compliance issue, don’t panic—but don’t ignore it either. Most enforcement begins with a letter or email outlining the issue and requesting remedial action. Respond promptly, be transparent, and provide evidence of your cookie audit, policy, and consent records.

Penalties are usually reserved for persistent, wilful, or egregious breaches, but the ICO can issue fines of up to £500,000 under PECR, and higher under UK GDPR for breaches involving personal data. Small businesses are rarely fined for a first offence if they take swift action, but repeat or flagrant non-compliance can be costly. Public reprimands can also damage your reputation and SEO.

If you discover a breach (e.g., cookies set before consent, or consent records missing), act immediately: fix the technical issue, update your policy, and document what you’ve done. If the breach involved personal data and creates a risk to individuals, you may need to report it to the ICO within 72 hours.

  • Acknowledge ICO communications and respond within deadlines
  • Fix compliance gaps as soon as possible
  • Keep records of all remedial actions taken
  • If in doubt, seek legal or data protection advice
  • Learn from the incident and update your processes
Where to get help

The ICO offers a dedicated helpline for small businesses: 0303 123 1113. The Federation of Small Businesses (FSB) also provides members with legal and data protection advice.

Key Takeaways
  • Cookie law applies to every UK business website. There are no exemptions for size or traffic—if your site uses cookies, you must comply with PECR and UK GDPR.
  • You must obtain explicit, informed consent for non-essential cookies. This means no pre-ticked boxes, no 'soft opt-in', and no setting analytics or marketing cookies before consent.
  • A compliant banner requires a real choice. Users must be able to accept or reject non-essential cookies easily, with clear information and access to a detailed cookie policy.
  • Audit your cookies regularly. New plugins, features, or embeds can introduce new cookies, so audit your site at least annually and after major changes.
  • Choose a CMP that actually blocks cookies before consent. Many free tools only inform users but don’t prevent cookies from being set—test your implementation thoroughly.
  • Keep detailed records of consent and compliance. You must be able to demonstrate to the ICO that you have a lawful basis for any data collected via cookies.
  • Prioritise transparency and user control. Clear, honest communication builds trust and can improve opt-in rates without risking non-compliance.
  • Non-compliance can result in significant fines and reputational damage. The ICO’s focus on cookie law is increasing, so don’t assume you can fly under the radar.
⭐ Exclusive Partner Offers
Tide
Tide Business Account

Ready for the next step? Open a business bank account to keep your finances organised.

Code: REFER200
Claim £200 Free
Capital on Tap
Capital on Tap Card

Get 7,500 free points (worth £75) on your first transaction. No annual fee. Instant decision.

Code: SETTINGUP
Claim 7,500 Points

Affiliate disclosure: we may earn a commission via our links. This does not affect our editorial independence.