UK privacy rules just got sharper for anyone running paid media, programmatic or email campaigns. The Privacy and Electronic Communications Regulations (PECR) govern when you may store or read data on a device, and when you may send direct marketing. Every cookie banner you see from UK users traces back to these rules.
The consent rule that decides your reach
Regulation 6 is the part performance marketers need to understand. It prohibits storing information on, or gaining access to information stored in, a device unless the user gets clear information about the purpose and gives consent. The rule is technology-neutral: cookies, pixels, web beacons, JavaScript and device fingerprinting all count. The ICO’s final guidance of April 29, 2026 treats fingerprinting alongside cookies and pixels.
PECR does not define consent itself. The ICO says the rules borrow the UK GDPR standard: freely given, specific, informed and unambiguous. That means no advertising scripts before a choice, no pre-ticked boxes and a reject option as easy as accept. Legitimate interests is not a basis for setting a consent-required cookie.
February 2026 changed the stakes
The Data (Use and Access) Act 2025 brought major changes into force on February 5, 2026. The penalty ceiling jumped from £500,000 to £17.5 million or 4% of global annual turnover, whichever is higher. That puts cookie failures in the same bracket as serious UK GDPR breaches.
The act also added a new Schedule A1. From February 5, 2026, exceptions exist for statistical purposes, website appearance and emergency assistance. But these are opt-out exceptions, and advertising sits outside every exception. Analytics shared with third parties for their own purposes still needs consent.
What this means for performance teams
Consent is now a revenue variable. Every impression without consent is sold without cross-site targeting, retargeting or user-level attribution. Higher consent rates expand addressable inventory; lower consent rates force you toward contextual and first-party strategies.
- Audit your CMP setup: confirm tags are held until a choice is made and the reject option is equally easy.
- Check Consent Mode or equivalent: make sure consent signals reach your ads and analytics tags correctly.
- Model the consent gap: measure how much of your UK reach loses identifiers and test contextual or aggregated measurement there.
- Keep email and SMS lists clean: marketing messages need prior consent, with only the soft opt-in for similar products after a sale.
Watch the low-risk ad framework
On May 18, 2026, the ICO published advice to government proposing a first-party framework. Ad delivery, contextual targeting, first-party frequency capping, region or city-level location targeting and aggregated measurement could run without consent. Cross-device frequency capping and behavioural advertising would stay inside the consent perimeter. No amending regulations were published as of September 2026.
Platforms are already adapting. On September 9, 2026, Google told AdSense publishers reaching the EEA, UK or Switzerland it would add fallback consent messaging where requests arrive without a TC string. The compliance numbers sound strong — the ICO said in May 2026 that 99% of the top 1,000 websites met its checks at the time of testing — but that does not measure consent quality downstream in the bidstream.
The practical play: treat UK consent not as a compliance checkbox but as an inventory planning layer. Audit your tags, protect your legitimate email programmes and prepare for a future where contextual and first-party signals do more of the heavy lifting.
Source: PPC Land



