What must a UK GDPR cookie banner actually do?
A UK GDPR cookie banner has one job: ask before anything non-essential is stored on, or read from, a visitor's device, and then respect the answer everywhere on the site. The words on the banner matter less than the behaviour underneath it.
In practice that breaks down into five behaviours we test on every site. Nothing optional loads before a choice. Accept all and Reject all are equally easy on the first screen. Optional categories in the settings panel start switched off. The choice is remembered and applied on every page, including checkout and blog templates that someone built years ago. And the visitor can reopen the settings and withdraw consent just as easily as they gave it, usually from a footer link.
The ICO's guidance on storage and access technologies says consent mechanisms should make it as easy to refuse as to accept, should not pre-enable anything non-exempt, and must allow withdrawal with the same ease. Those three points are where most banners we audit fall down, not on the wording.
A banner that looks correct but lets Meta, TikTok or Google Ads pixels fire on page load is worse than useless: it tells visitors they have a choice they do not really have. That is why our setup always starts with what the browser actually sends, not with the design.
- Stop: no non-essential cookie, pixel or storage write before a positive choice
- Equal: Reject all given the same prominence as Accept all
- Off by default: optional toggles unticked in the settings layer
- Everywhere: the choice applies across all templates and subdomains you control
- Reversible: a persistent link to change or withdraw consent
PECR or UK GDPR: which law is your cookie banner really about?
Both, but for different parts of the job. The Privacy and Electronic Communications Regulations (PECR) set the rule about storing or accessing information on someone's device, which is what cookies, local storage, pixels and fingerprinting do. UK GDPR governs what happens to any personal data you collect as a result, and it sets the standard for what valid consent looks like.
That is why people search for a “UK GDPR cookie banner” even though the consent requirement for cookies comes from PECR. The ICO regulates both, and its guidance explains how they fit together: PECR decides whether you need consent to set the cookie at all, and UK GDPR's consent standard (freely given, specific, informed, unambiguous, a clear positive action) decides whether the consent you collected counts.
For a developer, the practical consequence is simple. The banner must gather a UK GDPR-standard consent for anything PECR does not exempt, and your privacy notice must explain what is collected, why and for how long. We build the mechanism; the privacy notice text and the lawful-basis decisions belong to you and your adviser.
One more distinction worth knowing: PECR applies whether or not the cookie holds personal data. A first-party cookie with no identifier still needs consent unless an exemption applies. Plenty of site owners assume “no personal data, no banner”, and that assumption is where many UK GDPR cookie banner problems begin.
What did the Data (Use and Access) Act 2025 change for cookie banners?
The Data (Use and Access) Act 2025, which the ICO says became law on 19 June 2025, amended PECR to add new exceptions to the consent rule. You still need a banner for advertising and most third-party tracking, but some cookies that used to need consent may now run with a clear explanation and an easy way to object.
The ICO's updated guidance on storage and access technologies lists the new exceptions alongside the old “strictly necessary” one. They cover collecting statistical information about how your service is used in order to improve it, adapting how your site appears or functions to a user's preference, and specific emergency-assistance cases. The ICO finalised its guidance on these changes in 2026, after consultations in 2024 and 2025.
What did not change matters just as much. The ICO is explicit that online advertising never falls under the strictly necessary exception, so ad pixels, remarketing tags and cross-site tracking still need consent. Equal-prominence choices, no pre-enabled tags and easy withdrawal all still apply to anything that is not exempt.
The ICO also says the PECR enforcement regime is changing because of the Act and that it will update its enforcement guidance once the new regime is in force. For a site owner that means two sensible moves: review whether any of your analytics could use the new exception, and make sure the tags that cannot are properly held back. Your UK GDPR cookie banner will probably get shorter, not disappear.
Can analytics cookies run without consent in the UK now?
Sometimes, if they meet every condition of the new statistical purposes exception, and many common setups will not. The ICO's guidance says the exception covers storage or access used to collect statistical information about how your service is used, with a view to improving it.
The conditions are specific. You must give clear and comprehensive information about the purpose. You must give people a simple and free means of objecting. And, as the ICO puts it, the information collected must not be shared with any other person except to help you make improvements to the service or website. Analytics that feeds advertising, audience building or data sharing beyond that purpose does not fit.
That last condition is where configuration matters. An analytics property linked to advertising products, with signals used for remarketing, is doing more than measuring how your site is used. A stripped-back, first-party analytics setup that only reports page and journey statistics is much closer to what the exception describes.
Our approach is practical rather than legal. We show you, tool by tool, what each analytics script collects and where the data goes, and we can build an objection switch into the banner's settings panel so exempt analytics can be turned off. Whether you rely on the exception is a decision for you and your privacy adviser; if you are unsure, keeping analytics behind consent is the cautious choice, and we build it that way by default.
Closer to the exception
First-party page statistics, used only to improve the site, not shared for advertising, with a clear notice and a simple opt-out.
Still needs consent
Analytics linked to ad platforms, audience or remarketing features, session replay that captures personal details, and anything shared beyond improving the service.
Does a UK GDPR cookie banner need a Reject all button?
In practice, yes. The ICO's guidance on managing consent calls for equally prominent options to accept all or reject all, and says refusing should be as easy as accepting. A banner where Accept all is a big coloured button and rejecting means three clicks into a settings panel does not meet that.
Equal prominence is about more than having both buttons. We match size, colour weight, font and position so neither looks like the “correct” answer. We avoid wording that guilt-trips people (“No, I prefer a worse experience”), and we do not hide Reject all behind a “More options” link or put it in grey text on grey.
Three other design traps come up often in UK audits. Pre-ticked boxes in the settings panel, which the ICO's guidance rules out by requiring non-exempt toggles off by default. Legitimate-interest tabs that switch vendors back on after someone rejects, which undermines the rejection. And repeated prompting: the ICO says you should not keep asking after someone refuses, and suggests six months is a suitable period before asking again.
A good UK GDPR cookie banner is short. One sentence on what you use cookies for, two equal buttons, a settings link and a link to the cookie policy. People answer banners they can read in five seconds, and a clear answer is what you need.
Setting up Google Consent Mode v2 with a UK GDPR cookie banner
Consent Mode v2 is how Google's tags learn what the visitor chose on your banner. Google's developer documentation describes four consent types: ad_storage, analytics_storage, ad_user_data and ad_personalization, each set to granted or denied. You set a default before any measurement and update it when the visitor chooses.
Why it matters in the UK: Google's EU user consent policy applies to end users in the European Economic Area, the UK and Switzerland, so advertisers using Google Ads measurement or remarketing need to pass consent signals for UK visitors.
Google offers two implementations. In basic mode, Google tags do not load until the visitor consents, so nothing is sent before a choice. In advanced mode, tags load with consent denied by default and send cookieless pings that Google uses for modelling when consent is refused. Google's help centre is clear that basic mode gives you less modelled data. That trade-off is yours to make with your adviser; we build either and explain exactly what each sends.
The most common failure we see is ordering. The default consent command runs after the Google tag has already fired, or a platform plugin sets granted by default for UK visitors. We check the order in Tag Manager's preview and in the browser's network panel, so the first request Google receives already carries the right state.
- Set defaults to denied for all four types before the Google tag loads
- Update on Accept all, Reject all and each settings change
- Map banner categories to types: analytics to analytics_storage, marketing to the three ad types
- Choose basic or advanced mode deliberately, not by accident
- Verify in Tag Assistant and the network panel, not just the banner
How do you audit the scripts already running on your site?
Open the site in a clean browser profile, refuse everything on the banner, then record every request and every cookie or storage write. Anything non-essential that appears after a refusal is a leak. That one test finds most problems in under an hour.
Our audit goes further because UK sites collect scripts over years. A marketing agency adds a pixel through Tag Manager, a developer pastes another into the theme header, an app store plugin injects a third, and a video embed drops its own cookies. Nobody has a full list. We build one: each script, who added it, how it loads, what it stores, where it sends data and which consent category it belongs in.
We test more than the home page. Checkout, account pages, blog templates, landing pages built in a page builder and any subdomain you control often load different scripts. We also test the second visit, after consent is saved, and the withdrawal path, because a banner that works on first load but ignores a later change of mind is a common fault.
The output is a plain spreadsheet you keep. It doubles as the source for your cookie policy table and is the first thing a privacy adviser will ask for. It also usually turns up tags you can delete, which makes the site faster as a side effect; our technical SEO audit work finds the same kind of dead weight.
Consent platform, plugin or a custom-built cookie banner?
Use a reputable consent management platform when you run many third-party tags or several sites; use a well-configured plugin or your platform's built-in tools for a simple site; build a custom banner only when your stack makes the others awkward. The banner technology is rarely the problem. Configuration is.
A consent platform brings scanning, a vendor list, consent logging and translations, usually for a monthly fee. The ICO's guidance reminds you to consider the roles and responsibilities of both parties under UK GDPR when you use one, which may mean a controller-processor arrangement. Read its terms before choosing.
WordPress consent plugins range from excellent to cosmetic. The good ones block scripts by category and integrate with Consent Mode; the weaker ones show a banner and block very little. Shopify has its own customer privacy settings and an API that well-behaved apps respect. Custom React, Next.js or Astro sites are often easiest with a small, audited script that we write and you own outright.
Whichever route you take, the same UK GDPR cookie banner tests apply: clean-browser refusal test, equal buttons, toggles off, withdrawal working, Consent Mode order correct. We will recommend the lightest option that passes, not the one with the most features.
Choose a platform when…
you run many ad and analytics vendors, several domains, or need consent logs and multiple languages out of the box.
Choose a custom banner when…
your site is a custom build with a handful of tags and you want no third-party script or subscription for consent.
Each platform fails in its own way, so the fix differs. The target behaviour is the same on all of them: no optional tag before a choice, and the choice respected everywhere.
WordPress and WooCommerce
Themes and plugins often print scripts straight into the header, outside any consent tool. We move them into Tag Manager or the consent plugin's blocking, check the checkout and my-account pages, and confirm caching plugins do not serve one visitor's consent state to another.
Shopify
The store's privacy settings and customer privacy API tell apps whether marketing and analytics are allowed. We check each installed app and custom pixel, because apps that ignore the API are the usual leak, then test the checkout flow separately.
Wix and Squarespace
Built-in cookie tools cover the platform's own scripts. Custom code blocks and third-party embeds you added need their own category assignment, and some embeds need a click-to-load placeholder to stay silent until consent.
Custom builds (React, Next.js, Astro, Laravel)
We add a small consent script that sets Consent Mode defaults first, stores the choice, and loads other tags only through a gate. Single-page apps also need the choice rechecked on client-side route changes.
Moving platform at the same time? Plan consent into the new build rather than bolting it on afterwards; our website redesign projects include it by default.
Designing a UK GDPR cookie banner that is clear, quick and accessible
The best-performing banners are short, plain and usable with a keyboard and screen reader. Clarity helps compliance and it helps you: a visitor who understands the question is more likely to give an answer you can rely on.
We write the first layer in one or two sentences that name the real purposes, such as measuring visits and showing ads on other sites, rather than vague phrases about “enhancing experience”. The buttons say what they do. The settings panel lists categories with a line each, and links to the full cookie policy.
Accessibility is part of the build, not an extra. Focus moves into the banner when it appears, every control is reachable by keyboard, buttons have proper labels, contrast meets WCAG 2.2 AA, and the banner does not trap focus or cover content in a way that makes the page unusable at high zoom. A banner that blocks disabled visitors from even reaching your site creates a different legal risk, covered on our accessibility audit page.
On mobile, a bottom sheet that covers a third of the screen is usually enough. Full-screen walls that block the page until someone accepts raise separate questions; the ICO guidance addresses cookie walls and “consent or pay” models, and we suggest taking advice before using one.
Consent records, withdrawal and when to ask again
Keep evidence of what each visitor was shown and what they chose, make withdrawal as easy as consent, and do not re-ask someone who refused for a sensible period. Those three habits separate a working consent system from a pop-up.
Under UK GDPR you need to be able to demonstrate consent. For cookies that usually means logging a random consent ID, the timestamp, the banner version, and the categories accepted or refused, without storing more personal data than necessary. Consent platforms do this for you; on a custom build we write the log to your own database with a retention period you agree with your adviser.
Withdrawal needs a visible route. A “Cookie settings” link in the footer on every page is the usual answer. When someone withdraws, the site must stop setting the cookies concerned and, where possible, delete those already set by first-party scripts. Third-party cookies on other domains cannot be deleted by your site, which is exactly why they should never be set before consent.
On re-prompting, the ICO says you should not repeatedly ask people who have already refused, and suggests six months is a suitable timeframe before asking again. We set the stored choice to expire accordingly, and we re-prompt earlier only when your purposes genuinely change, for example when you add a new advertising platform.
A well-built one does not. A badly built one can hurt Largest Contentful Paint, cause layout shift and slow interaction, all of which show up in Core Web Vitals reports in Google Search Console.
The usual culprits are a heavy consent script loaded synchronously in the head, a banner that pushes content down when it appears (a layout shift), and a banner image or text block that becomes the page's largest element. We load the consent script early but lightly, overlay the banner instead of inserting it into the page flow, and keep it small enough that your hero content stays the largest element.
Search engines do not need to consent, and your content must not be hidden behind the banner in the HTML. We make sure the page's main content is in the markup whether or not the banner is open, so crawlers and AI search systems that read your pages see the text. Our AI search optimisation work relies on the same principle.
One side effect to expect: after a proper setup, analytics will show fewer tracked sessions because refusals are now respected. That is the data becoming honest, not traffic falling. Search Console's click data does not depend on your cookies, so use it as your steady baseline while analytics settles.
What happens if your UK GDPR cookie banner breaks the rules?
The ICO regulates cookies under PECR and can take enforcement action against sites that set non-essential cookies without valid consent. It also says the PECR enforcement regime is changing because of the Data (Use and Access) Act 2025 and that it will update its guidance when the new regime is in force.
Under UK GDPR itself, the ICO's published higher maximum fine is £17.5 million or 4% of annual worldwide turnover, whichever is higher. The Act brings PECR penalties much closer to that scale than the old PECR cap, which is a reason to treat consent as a real engineering task. For current figures and your own risk, ask your adviser and check the ICO's latest enforcement guidance.
Realistically, most small UK businesses meet the problem through a complaint, an ICO letter or a client's procurement checklist before any fine. Agencies and larger buyers now ask suppliers to show that their sites hold tags until consent. A clean audit spreadsheet and a tested banner answer that question in minutes.
There is also a trust cost. Visitors notice banners that ignore “reject”, and privacy-aware browsers and extensions flag trackers. Fixing your UK GDPR cookie banner properly tends to make the site faster and the analytics more honest, which is a better reason to do it than fear of a fine.
How much does UK GDPR cookie banner setup cost?
With us, a correct cookie banner is included in new builds: static websites from US$150, SEO websites from US$300 and ecommerce stores from US$750. For an existing site, you get an itemised quote after the script audit, because the effort depends on what is already there.
Quotes vary widely across the UK market, from free plugins you install yourself to consultancy projects that include legal review. What actually drives the development effort is easy to list: the number of tags and vendors; whether scripts are hardcoded into themes or managed in Tag Manager; how many templates, subdomains and languages you run; whether you want basic or advanced Consent Mode; whether consent logs need custom storage; and whether an existing consent platform needs repairing or replacing.
Things that are not in our price: a consent platform subscription if you choose one (billed by that provider), and legal review of your cookie policy and privacy notice, which should come from your own solicitor or privacy adviser. We give you the audit spreadsheet they need, which usually shortens their work.
After launch, two months of fixes are free. The care plan from US$120/mo adds periodic re-scans, so a tag added by a marketing contractor next spring does not quietly bypass your banner.
Getting your UK GDPR cookie banner fixed by a team in India
It works well because consent work is almost entirely remote: we need access to your Tag Manager, your CMS or code, and a list of the tools your marketing uses. There is no site visit to arrange, and no hardware.
Our working day overlaps the UK business day from late morning, so a call at 11am in London is an afternoon call for us. Most communication happens on WhatsApp and email, with screen-share calls for the audit walkthrough. We work in English and can explain the findings to your marketing contractor directly if that saves you relaying messages.
Access is granted, not shared. You add us as a user in Tag Manager and your CMS with the minimum role needed, and remove us afterwards. Changes go to a staging copy or a Tag Manager workspace first, so nothing reaches visitors until you approve it.
Quotes and invoices are in USD from India; UK clients usually pay from a GBP account by Wise, or by bank wire or PayPal. Nothing is billed before you approve the written quote. You own everything we produce: the audit, any custom consent script and the Tag Manager container stay in your accounts.
- Days 1–2: access granted, clean-browser test, script inventory started
- Days 3–4: audit spreadsheet and walkthrough call, categories agreed
- Days 5–8: banner and tag changes in staging, Consent Mode wired
- Days 9–10: your review, adviser sign-off on wording, go-live and re-test
Worked example: a Bristol gift shop fixing its UK GDPR cookie banner
Say a small gift shop in Bristol sells on Shopify, runs Google Ads and a social media pixel, and has a free banner app that shows Accept and a tiny “settings” link. This is a hypothetical scenario to show the process, not a client story.
The clean-browser test shows the social pixel and a review widget loading before anyone clicks, and the Google tag sending granted by default for UK visitors. The settings panel has marketing pre-ticked. None of this is unusual.
The fix follows the audit. We switch the store's privacy settings to require consent for UK and EEA visitors, check which installed apps respect Shopify's customer privacy API, move the pixel so it waits for marketing consent, and set Consent Mode defaults to denied for all four types. The review widget goes behind a functional category. The banner's first layer gets two equal buttons.
The owner then decides, with an adviser, whether first-party analytics could rely on the new statistical exception. They choose to keep it behind consent for now. Result: after launch, analytics shows fewer sessions, conversion reporting in Google Ads shifts to modelled figures in advanced mode, and the shop has an audit spreadsheet to show a wholesale buyer who asked about its privacy practices. If the same shop later reviewed its checkout pricing, our DMCC Act compliance page would be the next stop.
UK GDPR cookie banner checklist before you go live
Run this list in a private browser window on your home page, a product or service page, the checkout or contact form, and one blog post. If any line fails, the banner is not finished.
- No non-essential cookie, storage write or tracking request before a choice
- Accept all and Reject all on the first layer with equal size, colour and position
- Settings panel with non-exempt categories switched off by default
- Consent Mode v2 defaults set to denied before the Google tag loads
- Reject all tested: no marketing or non-exempt analytics requests afterwards
- Choice remembered across pages, subdomains you control and repeat visits
- Footer link reopens settings; withdrawal stops the relevant tags
- Exempt analytics (if used) explained clearly, with a simple way to object
- Embeds such as video and maps held back or click-to-load where they set cookies
- Banner usable by keyboard and screen reader, readable at 200% zoom
- Cookie policy table matches the audit spreadsheet
- Privacy notice and wording approved by your solicitor or adviser
If you want the same rigour applied to the rest of the site's legal plumbing, the small business website design page lists what a UK site should include by default.