Skip to main content
Find your template →
Menu

Cookie Policy UK: PECR & GDPR Compliance Guide 2025

We're not a law firm — we help you find the right legal support. For advice on your situation, speak to a legal adviser or find a solicitor.

Updated June 2026 · England & Wales
If your website drops cookies on visitors' devices, or uses similar tracking technologies like pixels and local storage, you need a cookie policy that reflects what UK law actually requires. The rules sit across two regimes: the Privacy and Electronic Communications Regulations 2003 (often shortened to PECR) and the UK GDPR. Together they shape when you need consent, how you gather it, and what you must tell people about the cookies running on your site. A cookie policy is the document that does the telling. It sits alongside your consent banner and privacy notice, and it has become one of the most scrutinised areas of online compliance, with the Information Commissioner's Office (ICO) taking an increasingly firm position. This page walks through what a UK cookie policy should cover, how to approach it practically, and where the common traps lie.

What this document is

A cookie policy is a public-facing notice that explains how your website uses cookies and comparable technologies. It is not the same as a consent banner, although the two work together. The banner captures the visitor's choice; the policy gives them the detail they need to make that choice meaningfully.

In the UK, the obligation to tell users about cookies comes from Regulation 6 of PECR, which requires clear and comprehensive information about the purposes of any storage or access to information on a user's device. Where cookies process personal data, which most tracking cookies do, the UK GDPR transparency obligations kick in as well, meaning your policy has to align with what your privacy notice says.

A good cookie policy names the cookies in use, explains what each one does, states how long it persists, identifies any third parties involved, and tells users how to withdraw or change their consent. It is a living document. Cookies change as you add new marketing tools, analytics platforms, or embedded content, so the policy needs regular review to stay accurate.

How to use this document

  1. Audit what your site actually sets. Before you draft anything, run a full scan of your website to identify every cookie, tag, pixel, and script that loads. Tools like browser developer consoles or dedicated cookie scanners can help. You cannot write an accurate policy without knowing what is actually happening, and third-party plugins often add trackers you did not realise were there.
  2. Classify each cookie by purpose. Group the cookies you find into categories: strictly necessary, functional or preference, analytics and performance, and advertising or targeting. Only strictly necessary cookies are exempt from the consent requirement under PECR. Everything else needs the user's prior, informed, and freely given agreement before it can load on their device.
  3. Draft the policy content clearly. Write the policy in plain English. Explain what cookies are, list the specific cookies your site uses with their names, purposes, durations, and whether they are first or third party. Include links to the privacy notices of any third parties you rely on, and describe how a visitor can change or withdraw their consent at any point.
  4. Connect the policy to your consent mechanism. Your banner and your policy should reinforce each other. The banner should not pre-tick boxes, should make rejecting non-essential cookies as easy as accepting them, and should link to the full policy. The ICO has been explicit that consent walls forcing acceptance are unlikely to be valid under UK law.
  5. Review and update on a schedule. Cookies and trackers change constantly as you add new tools or suppliers update their products. Put a review cycle in place, quarterly or at minimum twice a year, and re-audit whenever you deploy a new marketing or analytics tool. Keep a dated version history so you can show regulators what you disclosed at any given time.

Common questions

Q Do I actually need a cookie policy if my site only uses essential cookies?
Even if you rely solely on strictly necessary cookies, you still have to tell visitors what you are doing and why. The transparency requirement under PECR and the UK GDPR applies regardless of whether consent is needed. A short, accurate cookie policy is the cleanest way to meet that obligation, and it protects you if you later add anything that does trigger consent requirements.
Q Is a cookie policy the same as a privacy policy?
No, although they overlap and should be consistent with one another. A privacy policy covers how you handle personal data generally, across your whole organisation. A cookie policy focuses specifically on tracking technologies used on your website. Many businesses link the two together, with the cookie policy sitting as either a standalone page or a dedicated section within the wider privacy notice.
Q What counts as a strictly necessary cookie?
Strictly necessary cookies are the ones without which a service the user has requested cannot function. Think session cookies that keep someone logged in, cookies that remember items in a shopping basket, or security tokens that prevent fraud. Analytics, advertising, and most personalisation cookies are not strictly necessary, even if you find them commercially important. Only the narrow functional category is exempt from consent.
Q Can I rely on implied consent from continued browsing?
No. The ICO has made clear that implied consent is not valid under current UK rules. Users must take an affirmative action, such as clicking an accept button, before non-essential cookies are set. Simply continuing to scroll or navigate is not enough. Your banner needs a genuine choice, and non-essential cookies must stay dormant until that choice is made.
Q What happens if my cookie policy is out of date or inaccurate?
Inaccurate disclosures can expose you to enforcement action from the ICO, including monetary penalties under PECR and the UK GDPR. Beyond regulatory risk, users who feel misled may complain or lose trust in your brand. Keeping the policy current is not just a compliance tick-box; it is part of how you demonstrate good faith handling of personal data.
Q Do I need separate cookie policies for different markets?
If your site serves users in the EU as well as the UK, you will generally need to address both UK GDPR and EU GDPR, along with the EU ePrivacy Directive as implemented locally. Many businesses run one combined policy that flags any jurisdictional differences, while others geo-target different versions. The approach depends on your audience, but one-size-fits-all rarely works cleanly.
Q How often should I update my cookie policy?
At minimum, review it every six months, and always after deploying new analytics, advertising, or third-party tools on the site. Many organisations run quarterly audits. Keep dated records of each version so you can show what was disclosed at any point in time. Regulators and claimants often want to see the policy as it appeared when a specific user visited.

Sources

This guide is based on primary UK law and official guidance.

Brad Askew, Solicitor (non-practising)

Written & reviewed by

Brad Askew Solicitor (non-practising)

Brad is on the roll of solicitors of England & Wales but does not hold a practising certificate and does not provide legal advice. LegalDocuments.co.uk is not a law firm and does not provide regulated legal advice.

Legal disclaimer
This article is for general information only. It is a tool to help you find your way — not legal advice, and not a substitute for speaking to a qualified adviser about your situation.