UK GDPR and PECR compliance

The UK runs its own version of the GDPR, and it is close to the EU original. For a website the more important instrument is PECR, the Privacy and Electronic Communications Regulations, which is what actually requires consent before anything is stored on or read from a visitor’s device. The UK GDPR then supplies the standard that consent has to meet.

  • United Kingdom, since January 2021
  • PECR governs cookies
  • Enforced by the ICO

From €10 a month. No credit card, no per-visitor billing.

What the two instruments ask for

PECR decides when you need consent. The UK GDPR decides what counts as consent.

  • Consent before storing or accessing anything on a device
  • An exemption only for what is strictly necessary
  • Consent meeting the UK GDPR standard, so freely given and specific
  • Clear information about what each cookie does
  • Withdrawal as easy as the original agreement

This page explains what the law asks for and what our software does about it. It is not legal advice, and it cannot tell you whether your organisation is compliant, because that depends on everything else you process.

What Consent Studio does about it

  • Ask first, release after

    PECR bites on storage and access rather than on personal data, so it covers cookies that identify nobody. Prior consent is the only configuration that satisfies it: a tag you add in the tag manager waits for the answer by default, and a third-party script already in your markup is held once you mark it, then released when its category is granted.

    • Prior consent by default
    • Storage and access
  • Meets the consent standard by default

    Refusing is as easy as accepting in the defaults we ship. The ICO has published guidance on exactly this asymmetry, and it is the finding most often raised against UK sites.

    • Equal weight
    • One click either way
    • Withdrawal available
  • Keeps a consent record

    Choices are stored with a timestamp against the wording that was shown. The UK GDPR carries the same accountability duty as the EU version, so being able to demonstrate consent is part of the obligation rather than good practice.

    • Timestamped
    • Versioned wording
    • Exportable

Where UK sites go wrong

  1. Legitimate interests is used for cookies

    It is a valid lawful basis under the UK GDPR and it is not available for the PECR consent requirement. Storing something on a device needs consent, whatever your basis for the processing that follows, and this is the mistake teams make when they read only one of the two instruments.

  2. Analytics is treated as strictly necessary

    The exemption covers what is essential to deliver the service the visitor asked for, and measuring how they use it is not that. The ICO has been explicit, and analytics is the category most often misfiled into the exemption.

  3. The EU banner is assumed to be enough

    Usually it is close, because the standards are near-identical. What differs is the instrument being complied with, which matters the moment somebody asks you to justify a specific cookie and the answer has to cite PECR rather than a lawful basis.

Essential

€10/month

For a single site that has to be compliant, and stay that way.

  • Unlimited pages and displays
  • 200,000 consent actions a month
  • The full stack, not a starter tier
Try Essential for FreeNo credit card required. 7 day free trial.
  • Professional

    €36/month

    For growing teams that run on data, and the agencies serving them.

    Try Professional for Free
  • Enterprise

    From €250/month

    For a volume, or an obligation, a standard plan cannot answer.

    Explore Enterprise
  • Agencies & Resellers

    Buy at a partner rate and resell client sites at your own price.

    Discover Partner Programme
  • Public Sector

    Government, healthcare and education run on Enterprise.

    See Enterprise

Running under rules like these, in more than one country


  • Philips, the Dutch electronics group, using Consent Studio for cookie consent
  • Erasmus Universiteit Rotterdam, managing cookie consent with Consent Studio
  • America Today, a fashion retailer using Consent Studio across its webshop
  • Van Vulpen, an infrastructure contractor using Consent Studio for cookie consent
  • EuroParcs, a European holiday park operator running Consent Studio on its booking sites
  • Optica, a Dutch opticians chain using Consent Studio for consent management
  • Jeans Centre, a Dutch fashion retailer using Consent Studio for cookie consent
  • Mondiaen, a Tilburg primary school foundation, running Consent Studio across its school websites
  • Fiterman Pharma, a pharmaceutical company using Consent Studio for cookie consent
  • Eddie Rockets, a hospitality group managing cookie consent with Consent Studio
  • Veneta, a kitchen retailer using Consent Studio for consent management
  • MS Mode, a fashion retailer running Consent Studio across its European webshops
  • Dynamis
  • SB Supply
  • The Chosen

Common UK questions

Is the UK GDPR different from the EU GDPR?

Not in substance for most website purposes. It is the retained EU regulation as amended for domestic law, enforced by the ICO rather than by an EU authority. The practical difference on cookies is that PECR sits alongside it and is the instrument that requires consent.

Do I need consent for analytics cookies in the UK?

Yes. PECR requires consent for anything not strictly necessary to provide the service requested, and the ICO has been clear that analytics does not qualify for that exemption. Being first party or aggregated does not change it.

Can I rely on legitimate interests instead of consent?

No, not for storing or accessing information on a device. Legitimate interests is a lawful basis under the UK GDPR for processing, and PECR imposes a separate consent requirement that a lawful basis does not satisfy. This is the single most common misreading of the UK regime.

Do I need a separate banner for UK and EU visitors?

No. The standards are close enough that one configuration serves both correctly, and our defaults follow the visitor’s region for the places they diverge. What you should not do is assume the same is true of the United States, where the model is opt out rather than opt in.

Does Consent Studio make us compliant?

No single tool can, and any vendor saying otherwise is selling you something. Consent Studio handles the part a consent platform can handle: asking properly, holding every tag to the answer, keeping the record, and telling you when the site changes. What you process elsewhere is yours.

Where is our consent data stored?

In Amsterdam, on infrastructure owned and operated by Scaleway, a French company. Ownership matters more than location here: Scaleway is independently French rather than a European subsidiary of a US parent, so neither they nor we fall under the US CLOUD Act. Consent Studio itself is built and owned in the Netherlands.

Get Started with the Full Consent Stack

Everything you need in one bundle. Consent Studio provides you with a consent banner, scanner and client-side tag manager that guarantees no data ever gets transferred overseas.

Read the documentation

Our help center walks through every integration, plugin and template step by step, with screenshots. It is written and kept current by the people who build Consent Studio.

Which privacy policy?

We publish two, and they cover different audiences. Pick the one that describes you.