What marketing & data protection professionals need to know about the ‘relaxation’ of cookies rules

Wednesday 22nd July 2026

Most of the Data (Use and Access) Act (DUAA) came into force on 5 February 2026.

DUAA was introduced to amend existing UK data protection laws: the UK GDPR, Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR). PECR governs direct marketing, and the use of cookies and similar technologies (including tags, tracking pixels, scripts and trackers). PECR rules are triggered whenever technology stores or accesses information on a user’s device.

One of the provisions of interest to marketeers and data protection professionals alike is new Schedule A1 to PECR, which is commonly referred to as a relaxation of the requirement to obtain consent to place certain ‘non-essential’ cookies on a user’s device. In theory this allows organisations to place certain low-risk analytics cookies on a user’s device before they choose their preferences via the organisation’s consent management platform (cookie banner or “CMP”), allowing more widespread analytics to take place as soon as a user hits the website landing page.

Position under PECR

Cookies can be broadly categorised as “essential”, “functional” “analytics” and “advertising and marketing”.  Under PECR, an “essential” cookie must be  essential to the functioning of the relevant website (not essential to commercial operations or goals) and is exempt from the requirement to obtain  consent. Anything else needs affirmative consent via a cookie banner, with details of each cookie, its purpose and its retention period readily available to allow the user to make an informed choice. Consent under data protection laws is a high bar. It must be freely given, specific, informed, and unambiguous (Article 4(11) UK GDPR).

Indeed, the data protection regulator has taken PECR breaches seriously. In 2023, the Information Commissioner’s Office (ICO) sent a warning and began writing to organisations which they determined had breached cookies rules by miscategorising certain cookies as “essential”, and those which did not have a clear “reject all” button on their cookie banners. The ICO reinforced the legislation’s requirement that it must be as easy for a user to reject cookies as it is to accept them. This warned against the use of deceptive patterns in ‘opt-in’ situations to persuade a user to accept, as well as clearly requiring organisations to categorise cookies appropriately (see our wider commentary on Legal Considerations around Deceptive Patterns here).

DUAA Changes – now applicable in the UK

New Schedule A1 to PECR adds some limited exceptions to the requirement for consent, arguably making it easier for organisations to place low-risk analytics cookies on a user’s device without consent, deviating from PECR.

Specifically, consent is not required where:

  • the business provides an information society service (broadly all online services);
  • the sole purpose of the storage or access is to enable the business to:
    • collect information for statistical purposes about how the service is used, with a view to improving the service, or the sole purpose is to enable the way the website appears or functions to adapt to the user’s preferences;
    • collect information for statistical purposes about how a website is used with a view to improving the website;
    • enable the way the website appears or functions when displayed to adapt to the user’s preferences; and/or
    • otherwise enable an enhancement of the appearance or functionality of the website when displayed on, or accessed by, the terminal equipment.

This requires, however, that the user:

  • is provided with clear information about the purpose of the storage or access; and
  • is given a simple means of objecting, free of charge, to the access.

Applying the new rules in practice: is it as simple as it seems?

The new relaxations are arguably challenging when it comes to what constitutes genuine service improvement and what strays into marketing/advertising territory, including where a piece of statistical work has an ‘end goal’ of marketing. Many solutions won’t qualify for the exemption if there are multiple purposes for the collection of data, and the solution involves third party sharing. For those using Google Analytics, in many cases it will involve turning off certain features to fall within the ‘statistical’ exemption. ICO guidance will be helpful as organisations navigate the new rules.

Importantly, being able to rely on the new relaxations includes the creation (via the CMP or other clear and simple means) of an ‘opt out of analytics’ function which may affect user experience and should be considered carefully.

For those operating across the UK and EU, these rules only apply in the UK, so adoption would require separate regimes for different territories.

Summary

Ultimately, the new rules can help those organisations wanting to undertake very limited website analytics, where they can now legitimately bypass the need for consent. However, before implementation, organisations will need to review their cookie banners, each cookie and its categorisation, build a user friendly opt out mechanism and update privacy information. On balance, they may prefer the status quo of obtaining consent for all non-essential cookies if the benefits of using low-risk analytics cookies do not make the effort of implementing a different solution worthwhile. It is, unfortunately, not a case of re-categorising immediately.

As the DUAA also increases potential financial penalties for PECR breaches from £500,000 to the UK GDPR maximum of the greater of 4% of annual global turnover or £17.5m, organisations should take care to ensure changes are compliant before implementation.

To discuss how our data protection lawyers can help, get in touch with one of the team.