Two days ago, on 19 June 2026, a provision in the Data (Use and Access) Act 2025 came fully into force that most UK website owners are entirely unaware of. The maximum fine for breaching cookie consent rules under the Privacy and Electronic Communications Regulations — commonly called PECR — increased from £500,000 to £17.5 million, or 4% of global annual turnover, whichever is higher.
That is a 35-fold increase in the maximum penalty. The Information Commissioner’s Office has already signalled that cookie consent enforcement is a priority area for 2026-27. If your website’s cookie banner has not been reviewed in the last twelve months, this is the week to fix that.
What PECR covers and why it matters
PECR governs how businesses use cookies and similar tracking technologies on websites and apps. It requires that users give informed, freely given, specific, and unambiguous consent before non-essential cookies are set. This covers:
- Analytics cookies — including Google Analytics and similar tools
- Marketing and advertising cookies — retargeting pixels, third-party ad networks
- Social media tracking pixels — Facebook Pixel, LinkedIn Insight Tag, TikTok Pixel
- Preference and personalisation cookies — anything beyond what is strictly necessary for the site to function
PECR has existed since 2003 and was updated significantly in 2011 when the EU cookie directive came in. What has changed is not the rule — it is the consequence of getting it wrong. A maximum penalty of £500,000 was low enough that many businesses implicitly treated cookie non-compliance as an acceptable risk. At £17.5 million, that calculation has changed completely.
Common cookie banner failures that now carry much higher risk
The ICO has been explicit about what it considers non-compliant, and these patterns are widespread across UK business websites:
The “continued use” trap. A banner that says “By continuing to use this site, you agree to our use of cookies” is not valid consent. Continued use of a website is not a positive, specific, freely given action — it is the absence of one.
The asymmetric accept/reject design. If “Accept All” is a prominent green button but rejecting requires navigating through a settings panel with multiple sub-menus, the ICO considers this a dark pattern that undermines free choice. Reject must be as easy as accept: same clicks, same visual weight.
Pre-ticked categories. Analytics, marketing, and preference cookies must be off by default. If a user has to untick a box to avoid being tracked, that is opt-out, not opt-in — and PECR requires opt-in.
No record of consent. You must be able to demonstrate that consent was given. If you cannot produce a log showing when a user consented, what they consented to, and through what mechanism, you cannot prove compliance in an investigation.
Third-party scripts loading before consent. This is one of the most common technical failures. Many websites fire Google Analytics, advertising pixels, or chat widgets the moment the page loads — before the user has had a chance to see, let alone interact with, the cookie banner.
A five-point check for your website this week
Run through this against your current setup:
- Does your cookie banner appear and block non-essential scripts before the user interacts with it? Not after scrolling, not on the second page — before any tracking fires.
- Is rejecting cookies as easy as accepting? Count the clicks. If accepting is one click and rejecting requires three, you have a problem.
- Are all non-essential cookie categories off by default? Toggle your own consent tool to the “no cookies” state and verify that only strictly necessary scripts load.
- Do you have an up-to-date cookie audit? Every cookie your site sets should be identified, categorised, and included in your cookie policy. Third-party tools add cookies without warning — your audit needs to be refreshed whenever you add a new integration.
- Are you storing consent records? A consent management platform (CMP) should be doing this automatically. If you built your own cookie banner in jQuery, it probably isn’t.
KeepSafe.Report includes ongoing monitoring of cookie and data compliance posture, and can flag when your website’s cookie behaviour drifts out of compliance — particularly useful if you regularly update your site or add new third-party tools.
For technical implementation — updating consent management platforms, configuring cookie banners to ICO standards, or auditing what scripts your site actually fires — CoolCoding.co.uk handles exactly this kind of compliance engineering work.
Updated cookie policy and privacy notice templates aligned to the Data (Use and Access) Act requirements are available at Smallprint.Legal, including guidance on what the ICO now expects from a compliant cookie policy.
The 19 June change is not theoretical. The ICO has the tools, the mandate, and now the penalty scale to make cookie consent enforcement meaningful. If your banner is non-compliant, the risk of staying that way has just risen significantly.