A cookie banner is only the visible part of cookie compliance. The business first needs to know which technologies store information on, or access information from, a visitor's device, why they do it and whether consent or a legal exception applies. Cookies are only one example; similar rules can cover pixels, local storage, scripts, device fingerprinting and other storage or access technologies.
Information was checked on 21 July 2026. The Data (Use and Access) Act 2025 changed the UK rules, and the ICO finalised updated guidance on 29 April 2026. Do not rely on older articles that say every non-essential cookie always needs consent or, at the other extreme, that analytics never does.
Begin with an audit
Test the website before and after each consent choice. Record:
- the technology or identifier;
- the provider;
- the purpose;
- the information stored or accessed;
- the duration;
- whether data is shared or combined across services;
- the legal route relied on;
- how a user can object, refuse or withdraw.
Repeat the audit when plugins, tags, embedded media, advertising or analytics change.
Understand the main legal routes
| Route | Typical example | Important limitation |
|---|---|---|
| Consent | Advertising tracking or profiling | The choice must be informed, specific, freely given and capable of withdrawal |
| Communication exception | Technology used solely to transmit a communication | Only the necessary transmission purpose is covered |
| Strictly necessary exception | Shopping basket, security or a user-requested login function | Convenience for the business is not enough |
| Statistical purposes exception | Limited measurement used to improve the organisation's own online service | Conditions apply, including safeguards and a simple means of objection |
| Appearance exception | Certain user-selected presentation or interface settings | The use must fit the statutory conditions and offer a simple objection where required |
| Emergency assistance exception | Limited use required for emergency help | Not a general business-purpose exception |
Do not assume all analytics are exempt
The statistical exception is not a blanket permission for every analytics setup. Assess whether the purpose is genuinely statistical measurement of the organisation's service, whether the information is used to improve that service, whether it is shared or reused for other purposes, and whether required safeguards and objection controls are present.
Advertising measurement, cross-site tracking, profiling and technologies used for several purposes may still require consent. A single tag can perform more than one function, so classify each purpose.
Design a fair consent mechanism
Where consent is required:
- do not place the technology before the decision;
- explain the purposes in plain language;
- provide an obvious way to accept or refuse;
- avoid making refusal materially harder than acceptance;
- allow categories or purposes to be controlled where appropriate;
- keep evidence of the choice;
- provide a persistent route to change or withdraw it;
- do not treat continued browsing as consent.
Consent wording should not be bundled into general terms and conditions.
Explain technologies clearly
The public information should identify the main purposes, providers and durations. It should also explain how choices can be changed. Avoid presenting hundreds of unexplained technical names as though that alone were transparency.
Test the implementation, not just the text
- Open the site in a clean browser session.
- Inspect storage, network requests and tags before making a choice.
- Refuse non-exempt purposes and confirm they remain blocked.
- Accept selected purposes and confirm only those activate.
- Withdraw the choice and verify future use changes appropriately.
- Repeat on mobile and important templates.
Embedded services need attention
Video, maps, social feeds, chat, payment tools and external fonts can trigger storage or transfers before a user interacts. Consider privacy-enhanced modes, click-to-load placeholders, self-hosting or alternative services where appropriate. Do not assume an embed is harmless because it is visually small.
Official source
The next practical step is to run a clean-browser audit and create a purpose-by-purpose register before choosing or reconfiguring a consent tool.
Keep the decision under your control
Retain the relevant accounts, source material, supplier terms and recovery information. Recheck changing prices, interfaces and rules before acting.