;

4 | Changes to cookies legislation

What is happening?

The UK’s Data (Use and Access) Act 2025 (DUAA) amends the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) to update and expand the cookies regime.

The changes:

  • significantly increase PECR fines so that they now align with the UK GDPR maximum (up to £17.5m or 4% of annual group worldwide turnover, whichever is higher)
  • introduce some new exceptions from the need for consent for cookie placement
  • clarify the scope of the existing exception for “strictly necessary” cookies.

New exceptions

There are two new exceptions in PECR that are relevant to the industry:

  • website appearance/function – cookies that are for the sole purpose of enabling the website appearance or functions to adapt to a user’s preferences or otherwise enhance appearance or functionality
  • statistical purposes – cookies that are for the sole purpose of enabling you to collect information for statistical purposes about how the website/service is used with a view to making improvements to the website or service.

These two new exceptions require that you to give the user the means to opt out of the cookies being set.

What the new exceptions don’t cover

Social media tracking, cross-site tracking, advertising use cases and profiling are not covered by these new exceptions.

Strictly necessary cookies

The new text in PECR provide examples of cookies that are considered “strictly necessary”. These include cookies for security protection, fraud prevention/detection, technical fault prevention/detection, user authentication and maintaining records of selections made on websites (eg shopping baskets and cookie consent selections). This is not new law as such, but a codification of existing guidance on the application of this exception.

How might it impact your business?

  • If relying on either or both of the new exceptions, you’ll need to incorporate opt-out functionality (which may be a challenge to deploy in a way which does not create confusion with an existing consent request).
  • Exceptions are purpose-bound and only apply where the sole purpose meets the exception. Mixed uses (eg statistics plus marketing) will generally require consent.
  • The law is tech-neutral and applies to apps as well as websites.
  • Higher stakes for non-compliance: with fines aligned with UK GDPR levels, cookie governance and consent management become higher priority risk areas.

What action should you consider?

  • Review cookie deployments to see if you can take advantage of new clarifications and exceptions.
  • Be aware of limits on the applicability of the exceptions: for example, the statistical exception only permits sharing of cookie information with third parties who are helping you to make improvements to your service or website and not eg with third parties helping you to collect that data.
  • Keep an eye out for DSIT and ICO updates about their respective reviews of both advertising and other cookies, as the rules may be loosened further this year.
  • Cookie rules in the EU may also be simplified: see the Digital Omnibus’s proposals for exceptions for certain low-risk cookies.
  • Conduct regular scans of your sites, given the ICO’s top 1000 website review and cookie rule enforcement.

Key dates for your diary

The changes to the law came into force on 5 February 2026.

Further reading

Data (Use and Access) Act 2025

ICO guidance on DUAA

Government summary of changes brought in by DUAA

ICO information on PECR exceptions

EU Digital Omnibus

Jon Bartley

Partner

Profile

Helen Yost

Senior Associate

Profile
Return to top