WhatsApp Us

Consent setup · PECR and UK GDPR · for UK websites

UK GDPR cookie banner setup that blocks tags until people say yes

A UK GDPR cookie banner is only as good as what happens behind it: whether analytics, ad pixels and chat widgets actually wait for a choice. BtechWaleTech is three freelance developers in India who audit the scripts on your site, then build or fix the banner so Reject all sits beside Accept all, nothing non-essential fires early, and Google Consent Mode v2 passes the right signals to GA4 and Google Ads. New sites include it from US$150; existing sites get an itemised fix quote.

  • Included in new websites fromUS$150
  • Ecommerce stores with consent built in fromUS$750
  • Existing site fixItemised after a script audit
  • Typical turnaroundDays for one site, longer for many tags
  • QuoteIn about 2 working days
  • Ongoing checksCare plan from US$120/mo after 2 free months
  • Equal Accept all and Reject all
  • No pre-ticked toggles
  • Tags held until consent
  • Consent Mode v2 for GA4 and Ads
  • DUAA 2025 analytics exemption reviewed
  • Script audit before any change
  • Your lawyer signs off the wording

Three freelance developers in India · WhatsApp 7 days a week · UK late mornings overlap our afternoons

  • 0Non-essential tags allowed before a choice
  • 2Equal buttons on the first layer
  • 4Consent Mode v2 signals we map
  • 3Developers who check the build

The short answer

What does a UK GDPR cookie banner need to do in 2026?

A UK GDPR cookie banner must stop non-essential cookies and tags until the visitor makes a positive choice, show Reject all as clearly as Accept all, keep every optional toggle off by default, and let people change their mind as easily as they agreed. BtechWaleTech builds this into new sites from US$150 and ecommerce stores from US$750, and fixes existing banners after an itemised audit.

Accessibility of the banner itself matters too, which our website accessibility audit page covers, and shops should read the DMCC Act checkout guide alongside this one.

Last updated

UK GDPR cookie banner setup at a glance
Laws involvedPECR for storing and reading data on devices, UK GDPR for the personal data collected
First layerAccept all and Reject all with equal weight, plus a link to settings
Default stateEvery non-exempt category switched off
Google tagsConsent Mode v2 defaults set to denied before any measurement
New site with bannerFrom US$150
Shop with bannerFrom US$750
Legal sign-offYour solicitor or privacy adviser approves wording and categories

Cookie and consent work

What we set up, fix or rebuild

Most UK sites need two or three of these, not all of them. The script audit shows which.

Script and cookie audit

A list of every tag, pixel, embed and cookie on your pages, what sets it, when it fires today, and which consent category it belongs in.

Banner build or rebuild

A first layer with equal Accept all and Reject all, a settings panel with toggles off by default, and a footer link that reopens it.

Consent Mode v2 wiring

Default denied states for ad_storage, analytics_storage, ad_user_data and ad_personalization, updated when the visitor chooses.

Tag Manager clean-up

Triggers rebuilt so each tag checks consent before it fires, with duplicate and forgotten tags removed.

WordPress and WooCommerce

Plugin configured properly or replaced, theme-hardcoded scripts moved behind consent.

Shopify stores

Store privacy settings, customer privacy API and app pixels checked so apps respect the shopper's choice.

Embeds and widgets

Video, maps and chat loaded behind click-to-load placeholders when they drop cookies.

Quarterly re-check

New scripts caught before they leak, in the care plan from US$120/mo.

Why choose us

Three ways UK businesses end up with a cookie banner

The banner people see is the easy part. What differs is whether anything checks the tags behind it.

Three ways UK businesses end up with a cookie banner
What matters Free plugin on default settings Paid consent platform you configure alone Set up by BtechWaleTech
Reject all on first layer Often hidden or styled as a link Available, depends on your settings Always, same size and weight as Accept all
Tags blocked before consent Only scripts the plugin recognises Only if tags are mapped correctly Every tag mapped and tested in a clean browser
Consent Mode v2 Sometimes missing or partial Usually supported, needs wiring Wired to GA4 and Ads, basic or advanced by your choice
Hardcoded theme scripts Usually missed Usually missed Found in the audit and moved behind consent
DUAA analytics exemption Not considered Toggle may exist, logic is yours Reviewed with you and your adviser before use
Consent records Basic or none Logged by the platform Logged, with retention agreed
Ongoing cost None, until something breaks Monthly subscription by traffic One-off fix, optional care from US$120/mo
Who checks it after changes Nobody Whoever remembers Re-scan in the care plan

A paid consent platform can be exactly the right tool; we often configure one rather than write a banner from scratch. What we add is the audit and the testing that prove it works.

Pricing

What UK GDPR cookie banner work costs with us

A consent banner is part of every new website we build, from US$150 for a static site and US$750 for an ecommerce store, so there is no separate line for it. For an existing site, we audit first and then quote the fix itemised: how many tags, how many templates hardcode scripts, whether Tag Manager needs rebuilding, and whether you want Consent Mode v2 in basic or advanced mode. Any subscription to a consent platform is billed to you by that provider. After launch, two months of fixes are free; the care plan from US$120/mo includes re-scans when you add new tools. Invoices are in USD, paid from GBP by Wise, bank wire or PayPal.

Starting prices in INR and USD
ServiceIndia (INR)Worldwide (USD)Typical timelineWhat is included
Static website from ₹10,000 from US$150 1 to 2 weeks Up to 100 pages, Responsive design, Contact form and enquiry setup, Basic SEO tags and sitemap
SEO website (299+ pages) from ₹20,000 from US$300 3 to 5 weeks 299+ SEO pages, Keyword and page planning, Schema, sitemap, and internal linking, Design to deployment included
Ecommerce store from ₹50,000 from US$750 4 to 8 weeks Product and category pages, Payment gateway setup, Order and inventory basics, Performance tuning
Android & iOS app from ₹40,000 from US$600 6 to 10 weeks Android and iOS app (Flutter or React Native), Login, forms and push notifications, Admin panel and API connection, Google Play and App Store publishing
Custom web app or software from ₹60,000 from US$900 6 to 12 weeks Custom features and APIs, User accounts and roles, Admin panel, Deployment and handover
AI automation from ₹40,000 from US$600 2 to 4 weeks Workflow mapping, Tool and CRM integrations, AI agent or automation build, Testing and handover
Monthly SEO from ₹10,000/mo from US$150/mo Ongoing, monthly Technical fixes, On-page and content work, Local SEO and listings, Search Console reporting
Maintenance and support from ₹8,000/mo from US$120/mo Ongoing, monthly Content updates, Bug fixes, Backups and security checks, Speed and uptime checks

All prices are starting points, quoted in INR for India and USD for international clients, not fixed quotes. Final cost depends on the number of pages, features, integrations, content, and timelines. Share your requirement and you get an itemised estimate with nothing hidden. See full pricing.

What must a UK GDPR cookie banner actually do?

A UK GDPR cookie banner has one job: ask before anything non-essential is stored on, or read from, a visitor's device, and then respect the answer everywhere on the site. The words on the banner matter less than the behaviour underneath it.

In practice that breaks down into five behaviours we test on every site. Nothing optional loads before a choice. Accept all and Reject all are equally easy on the first screen. Optional categories in the settings panel start switched off. The choice is remembered and applied on every page, including checkout and blog templates that someone built years ago. And the visitor can reopen the settings and withdraw consent just as easily as they gave it, usually from a footer link.

The ICO's guidance on storage and access technologies says consent mechanisms should make it as easy to refuse as to accept, should not pre-enable anything non-exempt, and must allow withdrawal with the same ease. Those three points are where most banners we audit fall down, not on the wording.

A banner that looks correct but lets Meta, TikTok or Google Ads pixels fire on page load is worse than useless: it tells visitors they have a choice they do not really have. That is why our setup always starts with what the browser actually sends, not with the design.

  • Stop: no non-essential cookie, pixel or storage write before a positive choice
  • Equal: Reject all given the same prominence as Accept all
  • Off by default: optional toggles unticked in the settings layer
  • Everywhere: the choice applies across all templates and subdomains you control
  • Reversible: a persistent link to change or withdraw consent

PECR or UK GDPR: which law is your cookie banner really about?

Both, but for different parts of the job. The Privacy and Electronic Communications Regulations (PECR) set the rule about storing or accessing information on someone's device, which is what cookies, local storage, pixels and fingerprinting do. UK GDPR governs what happens to any personal data you collect as a result, and it sets the standard for what valid consent looks like.

That is why people search for a “UK GDPR cookie banner” even though the consent requirement for cookies comes from PECR. The ICO regulates both, and its guidance explains how they fit together: PECR decides whether you need consent to set the cookie at all, and UK GDPR's consent standard (freely given, specific, informed, unambiguous, a clear positive action) decides whether the consent you collected counts.

For a developer, the practical consequence is simple. The banner must gather a UK GDPR-standard consent for anything PECR does not exempt, and your privacy notice must explain what is collected, why and for how long. We build the mechanism; the privacy notice text and the lawful-basis decisions belong to you and your adviser.

One more distinction worth knowing: PECR applies whether or not the cookie holds personal data. A first-party cookie with no identifier still needs consent unless an exemption applies. Plenty of site owners assume “no personal data, no banner”, and that assumption is where many UK GDPR cookie banner problems begin.

What did the Data (Use and Access) Act 2025 change for cookie banners?

The Data (Use and Access) Act 2025, which the ICO says became law on 19 June 2025, amended PECR to add new exceptions to the consent rule. You still need a banner for advertising and most third-party tracking, but some cookies that used to need consent may now run with a clear explanation and an easy way to object.

The ICO's updated guidance on storage and access technologies lists the new exceptions alongside the old “strictly necessary” one. They cover collecting statistical information about how your service is used in order to improve it, adapting how your site appears or functions to a user's preference, and specific emergency-assistance cases. The ICO finalised its guidance on these changes in 2026, after consultations in 2024 and 2025.

What did not change matters just as much. The ICO is explicit that online advertising never falls under the strictly necessary exception, so ad pixels, remarketing tags and cross-site tracking still need consent. Equal-prominence choices, no pre-enabled tags and easy withdrawal all still apply to anything that is not exempt.

The ICO also says the PECR enforcement regime is changing because of the Act and that it will update its enforcement guidance once the new regime is in force. For a site owner that means two sensible moves: review whether any of your analytics could use the new exception, and make sure the tags that cannot are properly held back. Your UK GDPR cookie banner will probably get shorter, not disappear.

Can analytics cookies run without consent in the UK now?

Sometimes, if they meet every condition of the new statistical purposes exception, and many common setups will not. The ICO's guidance says the exception covers storage or access used to collect statistical information about how your service is used, with a view to improving it.

The conditions are specific. You must give clear and comprehensive information about the purpose. You must give people a simple and free means of objecting. And, as the ICO puts it, the information collected must not be shared with any other person except to help you make improvements to the service or website. Analytics that feeds advertising, audience building or data sharing beyond that purpose does not fit.

That last condition is where configuration matters. An analytics property linked to advertising products, with signals used for remarketing, is doing more than measuring how your site is used. A stripped-back, first-party analytics setup that only reports page and journey statistics is much closer to what the exception describes.

Our approach is practical rather than legal. We show you, tool by tool, what each analytics script collects and where the data goes, and we can build an objection switch into the banner's settings panel so exempt analytics can be turned off. Whether you rely on the exception is a decision for you and your privacy adviser; if you are unsure, keeping analytics behind consent is the cautious choice, and we build it that way by default.

Closer to the exception

First-party page statistics, used only to improve the site, not shared for advertising, with a clear notice and a simple opt-out.

Still needs consent

Analytics linked to ad platforms, audience or remarketing features, session replay that captures personal details, and anything shared beyond improving the service.

Does a UK GDPR cookie banner need a Reject all button?

In practice, yes. The ICO's guidance on managing consent calls for equally prominent options to accept all or reject all, and says refusing should be as easy as accepting. A banner where Accept all is a big coloured button and rejecting means three clicks into a settings panel does not meet that.

Equal prominence is about more than having both buttons. We match size, colour weight, font and position so neither looks like the “correct” answer. We avoid wording that guilt-trips people (“No, I prefer a worse experience”), and we do not hide Reject all behind a “More options” link or put it in grey text on grey.

Three other design traps come up often in UK audits. Pre-ticked boxes in the settings panel, which the ICO's guidance rules out by requiring non-exempt toggles off by default. Legitimate-interest tabs that switch vendors back on after someone rejects, which undermines the rejection. And repeated prompting: the ICO says you should not keep asking after someone refuses, and suggests six months is a suitable period before asking again.

A good UK GDPR cookie banner is short. One sentence on what you use cookies for, two equal buttons, a settings link and a link to the cookie policy. People answer banners they can read in five seconds, and a clear answer is what you need.

Consent Mode v2 is how Google's tags learn what the visitor chose on your banner. Google's developer documentation describes four consent types: ad_storage, analytics_storage, ad_user_data and ad_personalization, each set to granted or denied. You set a default before any measurement and update it when the visitor chooses.

Why it matters in the UK: Google's EU user consent policy applies to end users in the European Economic Area, the UK and Switzerland, so advertisers using Google Ads measurement or remarketing need to pass consent signals for UK visitors.

Google offers two implementations. In basic mode, Google tags do not load until the visitor consents, so nothing is sent before a choice. In advanced mode, tags load with consent denied by default and send cookieless pings that Google uses for modelling when consent is refused. Google's help centre is clear that basic mode gives you less modelled data. That trade-off is yours to make with your adviser; we build either and explain exactly what each sends.

The most common failure we see is ordering. The default consent command runs after the Google tag has already fired, or a platform plugin sets granted by default for UK visitors. We check the order in Tag Manager's preview and in the browser's network panel, so the first request Google receives already carries the right state.

  • Set defaults to denied for all four types before the Google tag loads
  • Update on Accept all, Reject all and each settings change
  • Map banner categories to types: analytics to analytics_storage, marketing to the three ad types
  • Choose basic or advanced mode deliberately, not by accident
  • Verify in Tag Assistant and the network panel, not just the banner

How do you audit the scripts already running on your site?

Open the site in a clean browser profile, refuse everything on the banner, then record every request and every cookie or storage write. Anything non-essential that appears after a refusal is a leak. That one test finds most problems in under an hour.

Our audit goes further because UK sites collect scripts over years. A marketing agency adds a pixel through Tag Manager, a developer pastes another into the theme header, an app store plugin injects a third, and a video embed drops its own cookies. Nobody has a full list. We build one: each script, who added it, how it loads, what it stores, where it sends data and which consent category it belongs in.

We test more than the home page. Checkout, account pages, blog templates, landing pages built in a page builder and any subdomain you control often load different scripts. We also test the second visit, after consent is saved, and the withdrawal path, because a banner that works on first load but ignores a later change of mind is a common fault.

The output is a plain spreadsheet you keep. It doubles as the source for your cookie policy table and is the first thing a privacy adviser will ask for. It also usually turns up tags you can delete, which makes the site faster as a side effect; our technical SEO audit work finds the same kind of dead weight.

Consent platform, plugin or a custom-built cookie banner?

Use a reputable consent management platform when you run many third-party tags or several sites; use a well-configured plugin or your platform's built-in tools for a simple site; build a custom banner only when your stack makes the others awkward. The banner technology is rarely the problem. Configuration is.

A consent platform brings scanning, a vendor list, consent logging and translations, usually for a monthly fee. The ICO's guidance reminds you to consider the roles and responsibilities of both parties under UK GDPR when you use one, which may mean a controller-processor arrangement. Read its terms before choosing.

WordPress consent plugins range from excellent to cosmetic. The good ones block scripts by category and integrate with Consent Mode; the weaker ones show a banner and block very little. Shopify has its own customer privacy settings and an API that well-behaved apps respect. Custom React, Next.js or Astro sites are often easiest with a small, audited script that we write and you own outright.

Whichever route you take, the same UK GDPR cookie banner tests apply: clean-browser refusal test, equal buttons, toggles off, withdrawal working, Consent Mode order correct. We will recommend the lightest option that passes, not the one with the most features.

Choose a platform when…

you run many ad and analytics vendors, several domains, or need consent logs and multiple languages out of the box.

Choose a custom banner when…

your site is a custom build with a handful of tags and you want no third-party script or subscription for consent.

Cookie banner setup on WordPress, Shopify, Wix and custom sites

Each platform fails in its own way, so the fix differs. The target behaviour is the same on all of them: no optional tag before a choice, and the choice respected everywhere.

WordPress and WooCommerce

Themes and plugins often print scripts straight into the header, outside any consent tool. We move them into Tag Manager or the consent plugin's blocking, check the checkout and my-account pages, and confirm caching plugins do not serve one visitor's consent state to another.

Shopify

The store's privacy settings and customer privacy API tell apps whether marketing and analytics are allowed. We check each installed app and custom pixel, because apps that ignore the API are the usual leak, then test the checkout flow separately.

Wix and Squarespace

Built-in cookie tools cover the platform's own scripts. Custom code blocks and third-party embeds you added need their own category assignment, and some embeds need a click-to-load placeholder to stay silent until consent.

Custom builds (React, Next.js, Astro, Laravel)

We add a small consent script that sets Consent Mode defaults first, stores the choice, and loads other tags only through a gate. Single-page apps also need the choice rechecked on client-side route changes.

Moving platform at the same time? Plan consent into the new build rather than bolting it on afterwards; our website redesign projects include it by default.

The best-performing banners are short, plain and usable with a keyboard and screen reader. Clarity helps compliance and it helps you: a visitor who understands the question is more likely to give an answer you can rely on.

We write the first layer in one or two sentences that name the real purposes, such as measuring visits and showing ads on other sites, rather than vague phrases about “enhancing experience”. The buttons say what they do. The settings panel lists categories with a line each, and links to the full cookie policy.

Accessibility is part of the build, not an extra. Focus moves into the banner when it appears, every control is reachable by keyboard, buttons have proper labels, contrast meets WCAG 2.2 AA, and the banner does not trap focus or cover content in a way that makes the page unusable at high zoom. A banner that blocks disabled visitors from even reaching your site creates a different legal risk, covered on our accessibility audit page.

On mobile, a bottom sheet that covers a third of the screen is usually enough. Full-screen walls that block the page until someone accepts raise separate questions; the ICO guidance addresses cookie walls and “consent or pay” models, and we suggest taking advice before using one.

Consent records, withdrawal and when to ask again

Keep evidence of what each visitor was shown and what they chose, make withdrawal as easy as consent, and do not re-ask someone who refused for a sensible period. Those three habits separate a working consent system from a pop-up.

Under UK GDPR you need to be able to demonstrate consent. For cookies that usually means logging a random consent ID, the timestamp, the banner version, and the categories accepted or refused, without storing more personal data than necessary. Consent platforms do this for you; on a custom build we write the log to your own database with a retention period you agree with your adviser.

Withdrawal needs a visible route. A “Cookie settings” link in the footer on every page is the usual answer. When someone withdraws, the site must stop setting the cookies concerned and, where possible, delete those already set by first-party scripts. Third-party cookies on other domains cannot be deleted by your site, which is exactly why they should never be set before consent.

On re-prompting, the ICO says you should not repeatedly ask people who have already refused, and suggests six months is a suitable timeframe before asking again. We set the stored choice to expire accordingly, and we re-prompt earlier only when your purposes genuinely change, for example when you add a new advertising platform.

Does a UK GDPR cookie banner hurt SEO or Core Web Vitals?

A well-built one does not. A badly built one can hurt Largest Contentful Paint, cause layout shift and slow interaction, all of which show up in Core Web Vitals reports in Google Search Console.

The usual culprits are a heavy consent script loaded synchronously in the head, a banner that pushes content down when it appears (a layout shift), and a banner image or text block that becomes the page's largest element. We load the consent script early but lightly, overlay the banner instead of inserting it into the page flow, and keep it small enough that your hero content stays the largest element.

Search engines do not need to consent, and your content must not be hidden behind the banner in the HTML. We make sure the page's main content is in the markup whether or not the banner is open, so crawlers and AI search systems that read your pages see the text. Our AI search optimisation work relies on the same principle.

One side effect to expect: after a proper setup, analytics will show fewer tracked sessions because refusals are now respected. That is the data becoming honest, not traffic falling. Search Console's click data does not depend on your cookies, so use it as your steady baseline while analytics settles.

What happens if your UK GDPR cookie banner breaks the rules?

The ICO regulates cookies under PECR and can take enforcement action against sites that set non-essential cookies without valid consent. It also says the PECR enforcement regime is changing because of the Data (Use and Access) Act 2025 and that it will update its guidance when the new regime is in force.

Under UK GDPR itself, the ICO's published higher maximum fine is £17.5 million or 4% of annual worldwide turnover, whichever is higher. The Act brings PECR penalties much closer to that scale than the old PECR cap, which is a reason to treat consent as a real engineering task. For current figures and your own risk, ask your adviser and check the ICO's latest enforcement guidance.

Realistically, most small UK businesses meet the problem through a complaint, an ICO letter or a client's procurement checklist before any fine. Agencies and larger buyers now ask suppliers to show that their sites hold tags until consent. A clean audit spreadsheet and a tested banner answer that question in minutes.

There is also a trust cost. Visitors notice banners that ignore “reject”, and privacy-aware browsers and extensions flag trackers. Fixing your UK GDPR cookie banner properly tends to make the site faster and the analytics more honest, which is a better reason to do it than fear of a fine.

How much does UK GDPR cookie banner setup cost?

With us, a correct cookie banner is included in new builds: static websites from US$150, SEO websites from US$300 and ecommerce stores from US$750. For an existing site, you get an itemised quote after the script audit, because the effort depends on what is already there.

Quotes vary widely across the UK market, from free plugins you install yourself to consultancy projects that include legal review. What actually drives the development effort is easy to list: the number of tags and vendors; whether scripts are hardcoded into themes or managed in Tag Manager; how many templates, subdomains and languages you run; whether you want basic or advanced Consent Mode; whether consent logs need custom storage; and whether an existing consent platform needs repairing or replacing.

Things that are not in our price: a consent platform subscription if you choose one (billed by that provider), and legal review of your cookie policy and privacy notice, which should come from your own solicitor or privacy adviser. We give you the audit spreadsheet they need, which usually shortens their work.

After launch, two months of fixes are free. The care plan from US$120/mo adds periodic re-scans, so a tag added by a marketing contractor next spring does not quietly bypass your banner.

Getting your UK GDPR cookie banner fixed by a team in India

It works well because consent work is almost entirely remote: we need access to your Tag Manager, your CMS or code, and a list of the tools your marketing uses. There is no site visit to arrange, and no hardware.

Our working day overlaps the UK business day from late morning, so a call at 11am in London is an afternoon call for us. Most communication happens on WhatsApp and email, with screen-share calls for the audit walkthrough. We work in English and can explain the findings to your marketing contractor directly if that saves you relaying messages.

Access is granted, not shared. You add us as a user in Tag Manager and your CMS with the minimum role needed, and remove us afterwards. Changes go to a staging copy or a Tag Manager workspace first, so nothing reaches visitors until you approve it.

Quotes and invoices are in USD from India; UK clients usually pay from a GBP account by Wise, or by bank wire or PayPal. Nothing is billed before you approve the written quote. You own everything we produce: the audit, any custom consent script and the Tag Manager container stay in your accounts.

  • Days 1–2: access granted, clean-browser test, script inventory started
  • Days 3–4: audit spreadsheet and walkthrough call, categories agreed
  • Days 5–8: banner and tag changes in staging, Consent Mode wired
  • Days 9–10: your review, adviser sign-off on wording, go-live and re-test

Worked example: a Bristol gift shop fixing its UK GDPR cookie banner

Say a small gift shop in Bristol sells on Shopify, runs Google Ads and a social media pixel, and has a free banner app that shows Accept and a tiny “settings” link. This is a hypothetical scenario to show the process, not a client story.

The clean-browser test shows the social pixel and a review widget loading before anyone clicks, and the Google tag sending granted by default for UK visitors. The settings panel has marketing pre-ticked. None of this is unusual.

The fix follows the audit. We switch the store's privacy settings to require consent for UK and EEA visitors, check which installed apps respect Shopify's customer privacy API, move the pixel so it waits for marketing consent, and set Consent Mode defaults to denied for all four types. The review widget goes behind a functional category. The banner's first layer gets two equal buttons.

The owner then decides, with an adviser, whether first-party analytics could rely on the new statistical exception. They choose to keep it behind consent for now. Result: after launch, analytics shows fewer sessions, conversion reporting in Google Ads shifts to modelled figures in advanced mode, and the shop has an audit spreadsheet to show a wholesale buyer who asked about its privacy practices. If the same shop later reviewed its checkout pricing, our DMCC Act compliance page would be the next stop.

UK GDPR cookie banner checklist before you go live

Run this list in a private browser window on your home page, a product or service page, the checkout or contact form, and one blog post. If any line fails, the banner is not finished.

  • No non-essential cookie, storage write or tracking request before a choice
  • Accept all and Reject all on the first layer with equal size, colour and position
  • Settings panel with non-exempt categories switched off by default
  • Consent Mode v2 defaults set to denied before the Google tag loads
  • Reject all tested: no marketing or non-exempt analytics requests afterwards
  • Choice remembered across pages, subdomains you control and repeat visits
  • Footer link reopens settings; withdrawal stops the relevant tags
  • Exempt analytics (if used) explained clearly, with a simple way to object
  • Embeds such as video and maps held back or click-to-load where they set cookies
  • Banner usable by keyboard and screen reader, readable at 200% zoom
  • Cookie policy table matches the audit spreadsheet
  • Privacy notice and wording approved by your solicitor or adviser

If you want the same rigour applied to the rest of the site's legal plumbing, the small business website design page lists what a UK site should include by default.

Cookie categories

Which cookies need consent under PECR after the 2025 changes

A development starting point, based on the ICO's storage and access technologies guidance. Your adviser confirms how each of your tools is classified.

Which cookies need consent under PECR after the 2025 changes
CategoryTypical examplesConsent needed?What the build does
Strictly necessary Basket, login session, security, load balancing, storing the consent choiceNoRuns always; listed in the cookie policy
Statistics to improve the service First-party page and journey analytics, not shared for adsNot if every exception condition is metClear notice plus a simple opt-out switch, or held for consent
Appearance and preferences Remembering dark mode, text size, language chosen by the userNot if exception conditions are metNotice and a way to object
Analytics linked to advertising Analytics feeding ad audiences or remarketingYesBlocked until the visitor accepts
Advertising and remarketing Ad platform pixels, conversion tags, remarketing listsYes, alwaysBlocked until marketing consent; Consent Mode ad types denied by default
Third-party embeds Video players, maps, social feeds that set cookiesUsually yesClick-to-load placeholder or held until consent
Session replay and heatmaps Tools recording clicks, scrolls, form interactionsTreat as needing consentBlocked until consent, form fields masked

Consent Mode v2

Signal names from Google's consent mode documentation. Defaults are set to denied before any Google tag fires.

How banner choices map to Google's consent signals
Visitor choiceanalytics_storagead_storagead_user_dataad_personalization
No choice yet (default) denieddenieddenieddenied
Reject all denieddenieddenieddenied
Accept all grantedgrantedgrantedgranted
Statistics only granteddenieddenieddenied
Marketing without personalised ads per statistics togglegrantedgranteddenied
Consent withdrawn later back to deniedback to deniedback to deniedback to denied

Scope and timing

Typical cookie banner jobs, effort and where the price sits

Timelines assume quick access and feedback. Existing-site fixes are quoted item by item after the audit.

Typical cookie banner jobs, effort and where the price sits
SituationMain workTypical timePriced as
New brochure site Banner and tag gating built inWithin the 1–2 week buildPart of the site, from US$150
New online shop Store privacy settings, app checks, Consent ModeWithin the 4–8 week buildPart of the store, from US$750
Existing site, few tags, plugin misconfigured Audit, reconfigure, testA few daysItemised quote after audit
Existing site, hardcoded scripts and Tag Manager mess Audit, move scripts, rebuild triggers, Consent ModeOne to two weeksItemised quote after audit
Several sites or subdomains Shared consent setup and cross-domain testingTwo weeks or moreItemised quote after audit
Ongoing protection Re-scans when new tools are addedPeriodicCare plan from US$120/mo

Cookie banner fixes across the UK

UK businesses we set up consent for, remotely

We work from India with no UK office; everything is done through access you grant and calls you book. These are typical needs by area.

  • London

    Agencies, fintech start-ups and professional firms running many ad and analytics vendors, where clients and procurement teams now ask to see tested consent before signing.

  • Manchester

    Ecommerce and digital brands with heavy paid social spend, whose pixels often fire before consent and whose Consent Mode setup needs rebuilding properly.

  • Birmingham

    Manufacturers, trade suppliers and dealerships whose older WordPress sites carry scripts hardcoded into themes years ago by different contractors.

  • Leeds

    Financial services and legal firms wanting cookie consent evidence and a clean audit trail they can hand to compliance colleagues.

  • Bristol

    Independent retailers and ethical brands on Shopify who want honest analytics and a banner that matches the values they sell on.

  • Glasgow

    Hospitality groups and event venues with booking widgets and ad pixels spread across several sites that need one consistent consent setup.

  • Edinburgh

    Tourism operators and festival-season businesses with embedded maps, videos and booking engines that often set cookies before visitors agree.

  • Cardiff

    Public-facing service businesses and charities with bilingual sites, where the banner and settings panel need consistent wording in both languages supplied by the client.

  • Liverpool

    Retail and leisure businesses running remarketing campaigns who need Google Ads consent signals passed correctly for UK visitors.

  • Newcastle upon Tyne

    Software and SaaS firms whose marketing sites and web apps share subdomains, so consent must carry across both correctly.

  • Nottingham

    Clinics and health-adjacent businesses using session replay and chat tools, where sensitive form fields must never be recorded before consent.

  • Sheffield

    Engineering and B2B firms with lead-generation forms and LinkedIn tags who have never checked what their site sends before a choice.

  • Belfast

    Businesses selling to both Northern Ireland and Ireland, wanting one banner that works for UK and EU visitors alike.

  • Brighton

    Creative agencies and small brands needing a lightweight, accessible banner on custom-built sites without a monthly consent subscription.

How it works

How a cookie banner setup runs with us

  1. Share access and tools

    Grant limited access to Tag Manager and your CMS, and list the marketing and analytics tools you think are running. We will find the ones nobody remembers.

  2. Clean-browser test

    We refuse everything on the current banner and record what still loads. You get a short video and the list of leaks within the first days.

  3. Audit spreadsheet and categories

    Every script categorised with its purpose and destination. We agree categories with you, and flag any analytics that might fit the new statistical exception.

  4. Itemised quote

    A USD quote listing each change: banner, triggers, Consent Mode mode, embeds, logging. Nothing is billed until you approve it in writing.

  5. Build in staging

    Changes go into a Tag Manager workspace or staging site. Your adviser reviews the banner wording and cookie policy table before anything goes live.

  6. Go live and re-test

    We publish, repeat the clean-browser test on key templates, hand over the spreadsheet, and cover fixes free for two months.

Questions

UK GDPR cookie banner: questions UK site owners ask

Do I legally need a cookie banner on my UK website?

You need one if your site stores or reads anything on visitors' devices that is not covered by a PECR exception, which includes almost every advertising pixel and most third-party tools. A site that only uses strictly necessary cookies, and perhaps analytics meeting the new statistical exception, may not need a consent banner, but it still needs clear information. Ask your adviser to confirm for your setup.

What is the difference between PECR and UK GDPR for cookies?

PECR is the rule that requires consent before storing or accessing information on a device, whether or not personal data is involved. UK GDPR governs the personal data you collect and defines what valid consent means. A UK GDPR cookie banner therefore collects consent under PECR to the standard set by UK GDPR, and both are regulated by the ICO.

Does my cookie banner need a Reject all button?

The ICO's guidance on managing consent expects equally prominent options to accept all or reject all, and says refusing should be as easy as accepting. In practice that means a Reject all button on the first layer with the same size and visual weight as Accept all, not a small link or a route through several settings screens.

Can I use Google Analytics without cookie consent in the UK now?

Possibly, if your setup meets every condition of the statistical purposes exception added by the Data (Use and Access) Act 2025: statistics about how the service is used, aimed at improving it, clear information, a simple free way to object, and no sharing beyond helping improve the service. Analytics linked to advertising features will not fit. Your adviser should confirm before you rely on it.

What changed for cookies under the Data (Use and Access) Act 2025?

The Act amended PECR to add new exceptions to the consent rule, covering certain statistical, appearance and emergency-assistance uses. Advertising cookies still need consent, and the ICO says the PECR enforcement regime is also changing. The ICO finalised updated guidance on storage and access technologies in 2026, which is the best starting point for any review.

What is Google Consent Mode v2 and do UK sites need it?

Consent Mode v2 passes your visitors' banner choices to Google tags through four signals: ad_storage, analytics_storage, ad_user_data and ad_personalization. Google's EU user consent policy covers users in the UK, so sites using Google Ads measurement or remarketing for UK visitors should pass these signals. It works alongside your banner; it is not a banner itself.

Should I use basic or advanced Consent Mode?

Basic mode keeps Google tags from loading until the visitor consents, so nothing is sent before a choice. Advanced mode loads tags with consent denied and sends cookieless pings that Google uses for modelling. Google says basic mode gives you less modelled data. Which suits you is a privacy and business decision; we build either and document what each sends.

How much does a UK GDPR cookie banner setup cost?

A correct banner is included in our new websites from US$150 and ecommerce stores from US$750. For an existing site we audit the scripts first and then send an itemised quote, since effort depends on the number of tags, hardcoded scripts, templates and whether Consent Mode needs rebuilding. Consent platform subscriptions and legal review are separate.

How long does it take to fix a UK GDPR cookie banner?

A site with a few tags and a misconfigured plugin usually takes a few days, including testing. Sites with scripts hardcoded into themes, a messy Tag Manager container, several subdomains or a platform switch take one to two weeks or more. Waiting for your adviser to approve wording is often the longest step.

Are pre-ticked boxes allowed in a UK GDPR cookie banner?

No. The ICO's guidance says toggles for non-exempt storage and access technologies should be turned off by default, and consent must come from a clear positive action. A settings panel with marketing or analytics already switched on does not collect valid consent, even if the visitor clicks save.

How do I check whether my current banner actually works?

Open your site in a private browser window, click Reject all, then look at the browser's network and storage panels while you browse a few pages. If advertising pixels, remarketing requests or non-exempt analytics appear, your banner is not blocking them. We do this test first on every audit and share the recording.

Can a UK GDPR cookie banner slow down my site or hurt SEO?

A heavy consent script loaded in the page head, or a banner that pushes content down, can harm Core Web Vitals such as Largest Contentful Paint and layout shift. We load consent code lightly and overlay the banner so it does not shift the page. Search engines do not need to consent, and your content stays readable in the HTML.

Why did my analytics numbers drop after fixing the banner?

Because visitors who refuse are no longer tracked. Before the fix, analytics may have counted people who had said no, or who never answered. The drop reflects more honest data, not fewer visitors. Google Search Console click data does not depend on cookies, so it is a useful steady reference while you adjust.

How long should a cookie consent choice last?

The ICO suggests you should not keep asking people who have refused, and indicates six months is a suitable timeframe before asking again. We usually store the choice for that period and re-prompt earlier only if your purposes change, for example when a new advertising platform is added to the site.

Do I need to keep records of cookie consent?

UK GDPR requires you to be able to demonstrate valid consent. For cookies that usually means logging a random consent ID, the time, the banner version and the categories chosen, without storing extra personal data. Consent platforms log this automatically; on a custom build we store it in your own database with an agreed retention period.

Are cookie walls allowed in the UK?

Cookie walls, which block access unless visitors accept, and consent-or-pay models are addressed in the ICO's guidance on storage and access technologies and depend heavily on the circumstances. We can build either pattern technically, but we recommend getting advice from your solicitor or privacy adviser before using one on a UK site.

Will you write my cookie policy and privacy notice?

We produce the technical inputs: a spreadsheet of every cookie and script, its purpose, duration and where data goes, and a draft cookie table for the policy. The final policy and privacy notice wording, and decisions about lawful bases and exemptions, should come from your own solicitor or privacy adviser. We do not give legal advice.

Can you fix a UK GDPR cookie banner on Shopify?

Yes. We check the store's customer privacy settings, confirm which installed apps and custom pixels respect the shopper's choice, move non-compliant scripts behind consent, set Consent Mode defaults, and test the storefront and checkout separately. Apps that ignore the privacy API are the most common reason Shopify banners leak.

Can you fix a WordPress cookie plugin that is not blocking scripts?

Usually. The common causes are scripts hardcoded into the theme or another plugin, a page cache serving the wrong consent state, or Tag Manager triggers that ignore consent. We find which applies, reconfigure or replace the plugin, and test each template. Sometimes a lighter plugin with proper blocking beats a complicated one.

Is it safe to give a developer in India access to our Tag Manager?

Access is the safety control, not location. You add us as a user with the minimum role, changes go into a separate workspace or staging site for your approval, and you remove access when the job ends. Your container, CMS and any code we write stay in your accounts. Confidentiality terms can be agreed in the written quote.

How do UK businesses pay for cookie banner work?

Quotes and invoices are in USD from India. UK clients usually pay from a GBP account through Wise, or by bank wire or PayPal, against the written quote they approve. Nothing is billed before approval. As an overseas supplier we do not add UK VAT; your accountant will know how to record the purchase.

Next step

Find out what your site loads before visitors say yes

Send your website address on WhatsApp. We run a clean-browser refusal test, tell you what leaks, and follow with an itemised quote in about two working days. New sites with consent built in start at US$150.