Practical guide · Starting a Website

Website Cookie Consent Requirements

A cookie banner is only the visible part of cookie compliance. The business first needs to know which technologies store information on, or access information from, a visitor's device, why they do it and whether consent…

A cookie banner is only the visible part of cookie compliance. The business first needs to know which technologies store information on, or access information from, a visitor's device, why they do it and whether consent or a legal exception applies. Cookies are only one example; similar rules can cover pixels, local storage, scripts, device fingerprinting and other storage or access technologies.

Information was checked on 21 July 2026. The Data (Use and Access) Act 2025 changed the UK rules, and the ICO finalised updated guidance on 29 April 2026. Do not rely on older articles that say every non-essential cookie always needs consent or, at the other extreme, that analytics never does.

Begin with an audit

Test the website before and after each consent choice. Record:

  • the technology or identifier;
  • the provider;
  • the purpose;
  • the information stored or accessed;
  • the duration;
  • whether data is shared or combined across services;
  • the legal route relied on;
  • how a user can object, refuse or withdraw.

Repeat the audit when plugins, tags, embedded media, advertising or analytics change.

Common routes under the UK storage and access rules
RouteTypical exampleImportant limitation
ConsentAdvertising tracking or profilingThe choice must be informed, specific, freely given and capable of withdrawal
Communication exceptionTechnology used solely to transmit a communicationOnly the necessary transmission purpose is covered
Strictly necessary exceptionShopping basket, security or a user-requested login functionConvenience for the business is not enough
Statistical purposes exceptionLimited measurement used to improve the organisation's own online serviceConditions apply, including safeguards and a simple means of objection
Appearance exceptionCertain user-selected presentation or interface settingsThe use must fit the statutory conditions and offer a simple objection where required
Emergency assistance exceptionLimited use required for emergency helpNot a general business-purpose exception

Do not assume all analytics are exempt

The statistical exception is not a blanket permission for every analytics setup. Assess whether the purpose is genuinely statistical measurement of the organisation's service, whether the information is used to improve that service, whether it is shared or reused for other purposes, and whether required safeguards and objection controls are present.

Advertising measurement, cross-site tracking, profiling and technologies used for several purposes may still require consent. A single tag can perform more than one function, so classify each purpose.

Where consent is required:

  • do not place the technology before the decision;
  • explain the purposes in plain language;
  • provide an obvious way to accept or refuse;
  • avoid making refusal materially harder than acceptance;
  • allow categories or purposes to be controlled where appropriate;
  • keep evidence of the choice;
  • provide a persistent route to change or withdraw it;
  • do not treat continued browsing as consent.

Consent wording should not be bundled into general terms and conditions.

Explain technologies clearly

The public information should identify the main purposes, providers and durations. It should also explain how choices can be changed. Avoid presenting hundreds of unexplained technical names as though that alone were transparency.

Test the implementation, not just the text

  1. Open the site in a clean browser session.
  2. Inspect storage, network requests and tags before making a choice.
  3. Refuse non-exempt purposes and confirm they remain blocked.
  4. Accept selected purposes and confirm only those activate.
  5. Withdraw the choice and verify future use changes appropriately.
  6. Repeat on mobile and important templates.

Embedded services need attention

Video, maps, social feeds, chat, payment tools and external fonts can trigger storage or transfers before a user interacts. Consider privacy-enhanced modes, click-to-load placeholders, self-hosting or alternative services where appropriate. Do not assume an embed is harmless because it is visually small.

Official source

The next practical step is to run a clean-browser audit and create a purpose-by-purpose register before choosing or reconfiguring a consent tool.

Keep the decision under your control

Retain the relevant accounts, source material, supplier terms and recovery information. Recheck changing prices, interfaces and rules before acting.