FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
33of33items
Across 11 modules • Updated Jul 27, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 27, 2026
When do PECR cookie rules require consent?

What technologies and information does PECR cover?

Regulation 6 is broader than cookies and websites. It covers storage and access technologies that store information on or access information from terminal equipment such as computers, phones, tablets, smart TVs, wearables, connected vehicles, and other connected devices. Pixels, software development kits, local storage, scripts, tags, fingerprinting, and similar methods can all fall within scope.

The rule concerns information, whether or not it identifies a person. If the technology also processes personal data, the UK GDPR applies to that processing. Check PECR consent or exceptions first, then identify the UK GDPR basis, transparency duties, retention, security, rights, and any DPIA requirement.

  • Inventory first-party and third-party technologies, including components loaded after login, media playback, or another user action.
  • Record what each technology stores or accesses, each purpose, provider, recipients, duration, and device context.
  • Test each purpose separately. A familiar label such as analytics, security, or preference does not establish an exception.
  • Include technologies that operate in mobile apps and connected products, not only browser cookies.
Citations
When do PECR cookie rules require consent?

Which purposes can operate without consent?

There are five purpose-specific exceptions. The communication exception covers storage or access whose sole purpose is transmitting a communication and without which transmission is impossible. The strictly necessary exception covers what is essential to provide the online service the user requested. The emergency assistance exception applies after a device sends a request or another indication that the subscriber or user needs emergency assistance, where the sole purpose of the storage or access is to identify their geographical position so that assistance can be provided.

The statistical purposes exception is limited to aggregate, non-identifying statistics used solely to improve the service or website. The appearance exception is limited to adapting appearance or functionality to the user's preference or otherwise enhancing how the website appears or functions on the device. Both require clear and comprehensive information and a simple, free means to object.

Any purpose outside an exception requires consent before the storage or access occurs. Online advertising, cross-site or cross-device tracking, profiling, social-media tracking, and advertising measurement require consent. If one technology has both exempt and non-exempt purposes, do not enable the non-exempt purpose until consent is obtained.

  • Communication: confirm that transmission is impossible without the technology and that transmission is its sole purpose.
  • Strictly necessary: show which user-requested service would fail without the technology and why the chosen method is essential.
  • Statistics or appearance: document every condition, keep use within the sole purpose, explain it clearly, and provide a simple, free objection route.
  • Emergency assistance: confirm that the device sent a request or another indication that the subscriber or user needs emergency help, and limit use to identifying their geographical position so that assistance can be provided.
  • No exception: block the technology by default and request valid consent for each purpose.
Citations
PECR regulation 6

Binding rule prohibiting storage or access without consent unless an exception applies.

When do PECR cookie rules require consent?

What must the consent mechanism and evidence show?

Before requesting consent, tell the subscriber or user which technologies will operate, their purposes, whether third parties store, access, or receive information, and how long the storage or access will last. Consent must result from a clear positive action. Continuing to use a service, silence, inactivity, or a pre-ticked control is not enough.

The mechanism must make refusal as easy as acceptance, provide controls for non-exempt purposes, and allow withdrawal as easily as consent was given. Keep non-exempt technologies disabled until consent. Revisit consent when purposes or technologies change enough that the original choice no longer covers them.

Keep an audit showing the scan or inventory, purpose classification, exception assessment, information displayed, banner and preference-centre configuration, consent or objection records, withdrawal handling, third-party settings, test results, owner, and review date. Test the deployed service because a written policy does not show which requests, tags, SDKs, or pixels actually run.

  • Record the notice version, purposes offered, user's affirmative choice, timestamp, and later withdrawal or change.
  • Verify that reject, object, and withdraw controls work and do not trigger the technologies they are meant to stop.
  • Contract with third parties for the agreed purposes and confirm their deployed configuration and information use.
  • Repeat the assessment after adding a tag, SDK, vendor, purpose, recipient, or materially different retention period.
Citations
ICO - What are the PECR rules?

Explains clear and comprehensive information, third-party disclosure, duration, valid consent, refusal, withdrawal, and controls.

Page 3 of 3