International Privacy Law

UK GDPR + PECR

UK data protection and cookie rules enforced by the ICO. 2025 reforms raised PECR fines to £17.5M or 4% of global turnover.

UK GDPR + PECR requirements

After Brexit the UK retained the GDPR as domestic law alongside the Data Protection Act 2018, and cookies remain governed by Regulation 6 of PECR, which requires consent before storing or accessing information on a device except where strictly necessary. The Information Commissioner's Office enforces both. The Data (Use and Access) Act 2025 made two changes that matter here: it raised the maximum PECR fine from £500,000 to the UK GDPR level of £17.5 million or 4 percent of global turnover, and it permitted a narrow set of low-risk purposes, such as first-party analytics, to proceed without consent subject to an opt-out. The ICO has publicly reviewed the UK's most-visited websites for banner compliance and written to those whose reject options did not work. The compliance question is whether the banner's choices actually control the tags.

See what your sites and apps actually send

Get a free site analysis: every tracker, mapped to the laws that apply to it.