Analytics Cookies Under PECR: Are They Strictly Necessary or Not?
Analytics cookies feel essential to running a business, but PECR's 'strictly necessary' test asks a narrower question than that. Here's how the ICO actually draws the line.
Analytics cookies sit at the center of the most persistent misclassification in cookie compliance. Businesses reasonably feel that measuring traffic is essential to running a website, and so a lot of consent banners quietly file Google Analytics or similar tools under “necessary,” locked, and unrejectable. Under PECR, that’s not a defensible classification, and it’s worth understanding exactly why, since “we need this data” and “this cookie is strictly necessary” are answering two different questions.
What “strictly necessary” actually tests for
PECR’s exemption (paralleling the same exemption under the EU’s ePrivacy rule) applies only to cookies without which the specific service the user requested cannot be provided. The test is about the user’s request, not the business’s operational needs. A shopping cart cookie is strictly necessary because the user asked to buy something and that literally cannot happen without it. A page loading normally, and a visitor reading it, doesn’t require you to measure that visit, the page works identically whether or not analytics runs.
The ICO’s position specifically on analytics
The ICO’s cookie guidance has been consistent on this point: analytics cookies, even from a single, first-party analytics provider, do not qualify for the strictly necessary exemption, including so-called “privacy-friendly” analytics tools, unless a specific implementation genuinely avoids setting any identifier or storing any device information at all (uncommon for tools that provide per-visitor session data). If your analytics tool sets a cookie or writes to local storage to recognize a returning visitor, it needs consent under Regulation 6, full stop.
Why this specific misclassification is a common enforcement target
Because analytics is nearly universal and the “isn’t this basically necessary” reasoning is common, mislabeling analytics as strictly necessary is one of the most frequently cited technical gaps found during cookie compliance audits and ICO-prompted sweeps. It’s an easy thing for an auditor, or a motivated competitor, journalist, or regulator, to check: load the site, look at what’s already set before any consent action, and see whether an analytics identifier is already present.
What a correct classification actually looks like
- Analytics cookies go in a separate, non-essential category, unchecked by default.
- The analytics script itself doesn’t execute until that category is affirmatively accepted, not just “the cookie consent value gets recorded while the script runs anyway.”
- Rejecting analytics has to actually stop analytics, verified the same way described in our cookie banner requirements guide: check the Network tab, not just the visible UI.
What about GA4’s consent mode?
Google’s Consent Mode lets GA4 send limited, cookieless “pings” even when analytics consent is denied, for modeled conversion estimation. This doesn’t change the underlying classification, GA4 with full tracking is still not strictly necessary, and Consent Mode’s reduced-data pathway isn’t a loophole around obtaining consent, it’s a separate, more limited data flow Google offers specifically because full tracking requires consent it may not always get.
CookieYes
Since analytics tools are the most frequently misclassified 'necessary' cookie on real sites, it's worth confirming your specific setup is gated correctly rather than assuming it already is. CookieYes ships with analytics tools pre-categorized as non-essential by default, rather than leaving the classification to a manual judgment call.
The bottom line
If a visitor could complete every task on your page with analytics fully blocked, and they can, since analytics measures behavior rather than enabling it, the cookie isn’t strictly necessary under PECR, regardless of how important that data is to your business decisions.
This guide is educational and not legal advice. Consult a privacy attorney or technical auditor to confirm the classification of your specific analytics implementation.