Cookie Fines Now Match GDPR: What UK Businesses Need to Know
Most business owners know they need a cookie consent banner on their website. Fewer are aware that the maximum fine for getting it wrong has jumped from £500,000 to £17.5 million.
That change came into force on 5 February 2026 as part of the Data (Use and Access) Act – the biggest overhaul of UK data protection law since UK GDPR was introduced. The Act also introduced new rules around cookies that businesses need to understand, including some helpful simplifications alongside a sharply elevated risk for those who fall short.
What changed under PECR
PECR – the Privacy and Electronic Communications Regulations – are the rules that govern cookies, direct marketing emails, and electronic communications. They sit alongside UK GDPR but cover a different area: where UK GDPR focuses on how personal data is collected and processed, PECR focuses specifically on privacy in electronic communications and online tracking.
Until February 2026, the maximum fine under PECR was £500,000. The Data (Use and Access) Act aligned PECR penalties with UK GDPR levels: the maximum is now £17.5 million or 4 per cent of global annual turnover, whichever is higher. That is a 35-fold increase in the maximum exposure for cookie consent failures and unsolicited electronic marketing.
Alongside the fine increase, three new categories of cookies are now exempt from the requirement to obtain user consent:
- Analytics and statistics cookies – but only where the data is not used to track individuals across different websites or build behavioural profiles
- User interface customisation cookies – such as language preferences or colour scheme settings
- Emergency assistance cookies – required to deliver urgent safety information
For many businesses, the analytics exemption is the most practically relevant. If your website uses a privacy-respecting analytics tool that does not track users across different sites, you may no longer need to collect consent for those cookies. However, widely used tools such as Google Analytics typically include cross-site tracking features by default. Unless your implementation has been specifically configured to avoid that, consent is still required.
All other non-essential cookies – advertising, retargeting, social media tracking pixels – continue to require explicit consent. And the penalty for collecting them without it is now substantially higher.
Why this matters for your business
The ICO (the UK’s data protection regulator) has consistently treated cookie consent as an enforcement priority. With penalties now at GDPR levels, that is unlikely to change.
Two areas carry particular practical risk:
Marketing emails. PECR also governs direct marketing sent electronically. If your business sends marketing emails to individuals without documented consent, that is a PECR violation – and now subject to the same elevated fine regime. This is not a new rule, but the financial stakes are considerably higher than they were before February 2026.
Analytics assumptions. Many businesses believe they are compliant because they “only use Google Analytics.” Whether the new analytics exemption applies depends entirely on how the tool is configured on your website. Default configurations frequently include features that take analytics beyond simple session data into individual tracking – which still requires consent. If your web developer or marketing team has not reviewed this since the start of 2026, it is worth checking now.
The ICO has published updated guidance on cookies to reflect the new exemptions. If your cookie policy was last reviewed before 2026, it almost certainly needs updating.
What we help our clients with
Our managed IT services cover your infrastructure, devices, and security – and while cookie policy implementation sits with your web developer or marketing team, we help ensure that the data flowing through your IT environment is handled securely. Our IT security work includes helping businesses understand where technology decisions create compliance risk, including around data collection and processing.
If you have questions about what data your systems are collecting, or how your IT setup might affect your compliance position, our team can help identify areas that need attention and point you in the right direction.
What to check right now
If you have not reviewed your website or marketing processes recently, here is a practical starting point:
- Test your cookie consent banner. Does it give visitors a genuine opt-in choice? Pre-ticked boxes or “accept all” as the default are not valid consent under UK law.
- Audit which cookies your website sets. A cookie scanner or browser developer tools can show you whether advertising, social, or tracking cookies are being placed before or without consent.
- Check your analytics configuration. If you are relying on the new analytics exemption, confirm with your developer that your tool is actually configured in a way that qualifies.
- Review your marketing email consent records. Do you have a clear, documented legal basis for every person on your marketing list?
- Update your privacy notice. It should reflect what your website and systems are actually doing today.
If you are not sure whether your business is compliant, or you want to talk through what the Data (Use and Access) Act changes mean in practice, get in touch via our contact page. Achieving Cyber Essentials certification is also a useful starting point for businesses looking to build a strong foundation around data and systems security.
Fines at this level are not something small businesses can afford to deprioritise. A brief review of your cookie setup and marketing practices now is considerably less costly than a regulatory investigation later. Our IT support team is here if you have questions about where to begin.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


