Do PECR Rules Apply to My Website's Cookies?
If your site has any UK visitors and sets non-essential cookies, PECR almost certainly applies. Here's how the cookie rule actually works and where the exemptions genuinely sit.
If your website has UK visitors and sets any cookies beyond the bare minimum needed to make the site function, PECR’s Regulation 6 almost certainly applies to you, regardless of your business’s size, sector, or where you’re based. This is one of the most consistently under-recognized compliance obligations for smaller sites, in part because PECR’s cookie rule doesn’t require any minimum traffic, revenue, or data-volume threshold at all.
The actual rule: Regulation 6
PECR’s Regulation 6 requires that before storing information on, or accessing information already stored on, a user’s device (a cookie being the standard example, but the rule also covers local storage, tracking pixels, and device fingerprinting techniques), you must:
- Provide clear and comprehensive information about what the cookie does, and
- Obtain the user’s consent, unless a specific exemption applies.
There’s no size or sector carve-out. A five-page personal blog with UK visitors and a Google Analytics tag is, in principle, just as subject to this rule as a large e-commerce retailer.
The one meaningful exemption: strictly necessary cookies
Regulation 6 exempts cookies that are strictly necessary for a service the user has explicitly requested, this is the same “strictly necessary” test used under the EU’s parallel ePrivacy rule, covered from the general GDPR angle in our consent-for-every-cookie guide. The ICO’s own guidance gives session cookies, load-balancing cookies, and security cookies as clear examples of what qualifies. Analytics cookies specifically do not qualify for this exemption under current ICO guidance, a point significant enough to warrant its own dedicated look in our analytics cookies and PECR guide.
What “clear and comprehensive information” actually requires
The ICO expects more than a generic “this site uses cookies” notice. In practice, compliant disclosure means telling users, before consent is given:
- What categories of cookies are used (necessary, analytics, advertising, etc.)
- What each category actually does, in plain language, not just a technical name
- Which third parties, if any, receive data through those cookies
- How to withdraw consent later, just as easily as it was given
Common failure points the ICO has specifically flagged
- Cookie walls that block access to a site entirely unless the user accepts all cookies, the ICO has taken the position these generally don’t produce valid, freely given consent.
- No reject option, or a reject option that’s harder to find or use than the accept option.
- Cookies set before consent is captured, a technical implementation failure where the consent banner displays but the analytics or advertising script has already fired regardless.
- Vague or missing third-party disclosure, not naming who actually receives the data collected through a given cookie.
CookieYes
Getting the technical sequencing right, blocking non-essential scripts until consent is actually given, rather than just displaying a banner alongside scripts that already fired, is the single most common gap the ICO has flagged. CookieYes handles that script-blocking sequencing by default.
What to actually check on your own site
- Inventory every cookie your site sets, including ones set by embedded third-party content (social share buttons, video embeds), not just your own first-party tags.
- Classify each one: strictly necessary, or requires consent.
- Confirm non-essential cookies genuinely don’t fire until consent is given, test this in an incognito window with dev tools open.
- Check your disclosure language against the “clear and comprehensive” standard above, not just whether a banner exists.
See our full technical walkthrough of what a compliant banner actually needs to include in our PECR cookie consent guide.
This guide is educational and not legal advice. Consult a privacy attorney or technical auditor for your specific cookie inventory and disclosure requirements.