UK GDPR + PECR requirements
After Brexit the UK retained the GDPR as domestic law alongside the Data Protection Act 2018, and cookies remain governed by Regulation 6 of PECR, which requires consent before storing or accessing information on a device except where strictly necessary. The Information Commissioner's Office enforces both. The Data (Use and Access) Act 2025 made two changes that matter here: it raised the maximum PECR fine from £500,000 to the UK GDPR level of £17.5 million or 4 percent of global turnover, and it permitted a narrow set of low-risk purposes, such as first-party analytics, to proceed without consent subject to an opt-out. The ICO has publicly reviewed the UK's most-visited websites for banner compliance and written to those whose reject options did not work. The compliance question is whether the banner's choices actually control the tags.
UK GDPR + PECR articles and analysis
The Privacy Laws That Can Send Executives to Prison
Executives face criminal liability under global privacy laws, including prison sentences in the U.S., EU, and beyond. This guide breaks down where the risk exists...
Read More
Server-Side Fingerprinting Explained: How Tracking Works Without Cookies
Server-side fingerprinting links user sessions even when browser signals change. This post explains how it works, why traditional defenses fail, and the risks it creates...
Read More
What Changed in GDPR Enforcement in 2025? How Regulators Shifted from Policy Audits to Operational Accountability
By 2025, European regulators made a clear shift in approach: compliance is no longer judged by the wording of a privacy policy, but by the...
Read More
Other International Privacy Laws
See what your sites and apps actually send
Get a free site analysis: every tracker, mapped to the laws that apply to it.