UK GDPR and PECR compliance
The UK runs its own version of the GDPR, and it is close to the EU original. For a website the more important instrument is PECR, the Privacy and Electronic Communications Regulations, which is what actually requires consent before anything is stored on or read from a visitor’s device. The UK GDPR then supplies the standard that consent has to meet.
- United Kingdom, since January 2021
- PECR governs cookies
- Enforced by the ICO
From €10 a month. No credit card, no per-visitor billing.
What the two instruments ask for
PECR decides when you need consent. The UK GDPR decides what counts as consent.
- Consent before storing or accessing anything on a device
- An exemption only for what is strictly necessary
- Consent meeting the UK GDPR standard, so freely given and specific
- Clear information about what each cookie does
- Withdrawal as easy as the original agreement
This page explains what the law asks for and what our software does about it. It is not legal advice, and it cannot tell you whether your organisation is compliant, because that depends on everything else you process.
What Consent Studio does about it
Ask first, release after
PECR bites on storage and access rather than on personal data, so it covers cookies that identify nobody. Prior consent is the only configuration that satisfies it: a tag you add in the tag manager waits for the answer by default, and a third-party script already in your markup is held once you mark it, then released when its category is granted.
- Prior consent by default
- Storage and access
Meets the consent standard by default
Refusing is as easy as accepting in the defaults we ship. The ICO has published guidance on exactly this asymmetry, and it is the finding most often raised against UK sites.
- Equal weight
- One click either way
- Withdrawal available
Keeps a consent record
Choices are stored with a timestamp against the wording that was shown. The UK GDPR carries the same accountability duty as the EU version, so being able to demonstrate consent is part of the obligation rather than good practice.
- Timestamped
- Versioned wording
- Exportable
Where UK sites go wrong
Legitimate interests is used for cookies
It is a valid lawful basis under the UK GDPR and it is not available for the PECR consent requirement. Storing something on a device needs consent, whatever your basis for the processing that follows, and this is the mistake teams make when they read only one of the two instruments.
Analytics is treated as strictly necessary
The exemption covers what is essential to deliver the service the visitor asked for, and measuring how they use it is not that. The ICO has been explicit, and analytics is the category most often misfiled into the exemption.
The EU banner is assumed to be enough
Usually it is close, because the standards are near-identical. What differs is the instrument being complied with, which matters the moment somebody asks you to justify a specific cookie and the answer has to cite PECR rather than a lawful basis.
Essential
€10/month
For a single site that has to be compliant, and stay that way.
- Unlimited pages and displays
- 200,000 consent actions a month
- The full stack, not a starter tier
Professional
€36/month
For growing teams that run on data, and the agencies serving them.
Try Professional for FreeEnterprise
From €250/month
For a volume, or an obligation, a standard plan cannot answer.
Explore EnterpriseAgencies & Resellers
Buy at a partner rate and resell client sites at your own price.
Discover Partner ProgrammePublic Sector
Government, healthcare and education run on Enterprise.
See Enterprise
Running under rules like these, in more than one country
Other rules that may apply to you
Common UK questions
Is the UK GDPR different from the EU GDPR?
Not in substance for most website purposes. It is the retained EU regulation as amended for domestic law, enforced by the ICO rather than by an EU authority. The practical difference on cookies is that PECR sits alongside it and is the instrument that requires consent.
Do I need consent for analytics cookies in the UK?
Yes. PECR requires consent for anything not strictly necessary to provide the service requested, and the ICO has been clear that analytics does not qualify for that exemption. Being first party or aggregated does not change it.
Can I rely on legitimate interests instead of consent?
No, not for storing or accessing information on a device. Legitimate interests is a lawful basis under the UK GDPR for processing, and PECR imposes a separate consent requirement that a lawful basis does not satisfy. This is the single most common misreading of the UK regime.
Do I need a separate banner for UK and EU visitors?
No. The standards are close enough that one configuration serves both correctly, and our defaults follow the visitor’s region for the places they diverge. What you should not do is assume the same is true of the United States, where the model is opt out rather than opt in.
Does Consent Studio make us compliant?
No single tool can, and any vendor saying otherwise is selling you something. Consent Studio handles the part a consent platform can handle: asking properly, holding every tag to the answer, keeping the record, and telling you when the site changes. What you process elsewhere is yours.
Where is our consent data stored?
In Amsterdam, on infrastructure owned and operated by Scaleway, a French company. Ownership matters more than location here: Scaleway is independently French rather than a European subsidiary of a US parent, so neither they nor we fall under the US CLOUD Act. Consent Studio itself is built and owned in the Netherlands.
Get Started with the Full Consent Stack
Everything you need in one bundle. Consent Studio provides you with a consent banner, scanner and client-side tag manager that guarantees no data ever gets transferred overseas.
Read the documentation
Our help center walks through every integration, plugin and template step by step, with screenshots. It is written and kept current by the people who build Consent Studio.






