Back to All Articles Regional Spotlight - Europe & UK SMEs

Cookie Consent for Small Business Websites: UK and EU Rules in 2026

The UK relaxed some cookie rules in 2026 and raised the fines at the same time. The EU did not relax anything. Here is what a small business website needs to show, block and record, in plain English.

Umer Shafique
Umer Shafique
Founder & Business Growth Expert
9 min read
Cookie Consent for Small Business Websites: UK and EU Rules in 2026

Short answer: if your website uses advertising pixels, Meta or LinkedIn tags, or most third-party analytics, you still need opt-in cookie consent before they load, in both the UK and the EU. What changed in 2026 is that UK sites can now run some first-party analytics without asking first, and that the maximum UK fine for getting cookies wrong jumped from £500,000 to £17.5 million or 4% of global turnover.

Most small business owners we speak to have a cookie consent banner because a plugin added one years ago. Very few know whether it blocks anything. That gap matters more now than it did two years ago, so this guide covers what cookie consent law asks for, what a compliant banner looks like, and how to check your own site in about fifteen minutes.

On this page

What changed in the UK in 2026

Cookie consent rules in the UK sit in the Privacy and Electronic Communications Regulations (PECR), not in UK GDPR itself. The Data (Use and Access) Act 2025 amended PECR, and the cookie changes came into force on 5 February 2026.

The headline change is a set of new exemptions from cookie consent. The analytics exemption comes with conditions: you must tell visitors clearly what you collect and give them a simple, free way to object. The data has to be about how the site is used, not who is using it, and it cannot feed advertising or profiling. If an outside provider runs the analytics, it has to act as your processor and not reuse the data for its own purposes. The ICO's guidance on storage and access technologies is the reference to read before relying on it.

You no longer need prior consent for storage and access used only for:

  • Statistics about your own service, so you can see how people use the site and improve it.
  • Remembering how a visitor set up the site, such as language, font size or layout choices.
  • Security and fraud prevention.
  • Delivering software updates and emergency location, which rarely apply to a brochure site.

Much bigger fines for cookie breaches

PECR fines used to top out at £500,000. They now match UK GDPR: up to £17.5 million or 4% of annual worldwide turnover, whichever is higher. A florist in Leeds is not going to receive a seven-figure penalty, but the ICO now has a proportionate stick where before it barely had one.

The Act also added a complaints duty. From June 2026, organisations need a way for people to complain about how their data is handled, and must acknowledge and respond before those people escalate to the ICO. For a small business this can be a named email address in your privacy policy and a simple log.

The EU position has not moved

If you sell to customers in Ireland, France, Germany or anywhere else in the EU, the ePrivacy Directive still applies, as implemented by each member state. There is no equivalent analytics exemption across the EU, although France's CNIL allows narrowly configured audience measurement tools without consent.

The practical takeaway: if your business serves both markets, build your cookie consent to the EU standard. It satisfies the UK too, and you only maintain one setup.

The EDPB cookie banner taskforce report set out what regulators across the EU look for. The points that catch small sites out most often:

  • No "Reject" option on the first layer when there is an "Accept" button.
  • Pre-ticked boxes for analytics or marketing.
  • A reject link styled so it barely looks clickable.
  • Claiming "legitimate interest" to run tracking that needs consent.
  • No easy way to change your mind later.

Which cookies need consent

A cookie consent banner that shows but lets tracking fire before the visitor clicks anything is the most common failure we find. It looks compliant and is not. If you are adding a chat widget, our guide to AI chatbots for small business websites covers the privacy side of that too.

Here is how the common tools on a small business website usually fall. Check each against your own configuration, because settings change the answer.

  • No consent needed: session cookies for a shopping basket or login, security cookies from your firewall or form spam protection, and the cookie that stores the visitor's consent choice.
  • Possibly exempt in the UK only: first-party analytics configured without advertising features, data sharing or cross-site tracking. Many advisers do not treat a default Google Analytics 4 setup as meeting this bar, because data flows to Google for its own purposes unless you switch those settings off.
  • Consent needed in both the UK and EU: Meta Pixel, Google Ads remarketing, LinkedIn Insight Tag, TikTok Pixel, Microsoft Clarity and Hotjar session recordings, embedded YouTube videos in standard mode, and most chat widgets that set tracking cookies.

What a compliant cookie consent banner looks like

Visitor choosing cookie consent settings for analytics and marketing on a mobile preferences panel with equal accept and reject buttons

If you also run Google Ads, you need Google Consent Mode v2 wired to the banner so Google receives the visitor's choice. Without it, conversion tracking for EEA and UK traffic degrades badly. Beyond that, a banner that will stand up in the UK and EU has these features:

  • Equal choices on the first screen. "Accept all" and "Reject all" are the same size and visual weight, with a "Preferences" option alongside.
  • Categories off by default. Analytics and marketing toggles start unticked.
  • Nothing loads early. Tags that need consent stay blocked until the visitor accepts that category.
  • Plain wording. "We use analytics to see which pages help people and marketing cookies to show our ads to past visitors" beats three paragraphs of legal text.
  • A way back. A "Cookie settings" link in the footer that reopens the preferences.
  • A record. Consent choices are logged so you can show what a visitor agreed to and when.
  • A matching cookie policy listing each cookie, its purpose, provider and duration. Our own cookie policy shows the format.

Check your own site in 15 minutes

You do not need special software, just Chrome on a laptop. Work through the steps below. If any of them fails, the banner is decoration. That is fixable in an afternoon on most WordPress sites, and it is a good moment to review the rest of your site's legal basics, including European Accessibility Act requirements if you sell to EU consumers.

  • Step 1: open your site in an Incognito window so no earlier cookie consent is stored.
  • Step 2: before touching the banner, press F12, open the Application tab and look under Cookies. Anything named _ga, _fbp, _clck, _gcl_au or li_ at this point means tracking fires before consent.
  • Step 3: switch to the Network tab, reload, and filter for "facebook", "clarity" or "google-analytics". Requests appearing before you click anything are the same problem.
  • Step 4: click "Reject all", clear the filter and reload. Tracking requests should stay absent.
  • Step 5: look at the banner on your phone. Reject must be as easy to reach as accept.
  • Step 6: find the footer link that reopens cookie settings. If there is none, add one.

Setting up cookie consent on WordPress

WordPress Core Web Vitals report used to check that the cookie consent banner does not slow the site

After setup, run the 15-minute test again, then again after any new plugin or marketing tag goes in. Adding a tracking pixel for a new ad campaign is the usual way a compliant site stops being compliant.

A cookie consent setup also affects speed. Banner scripts that load late can shift the layout and hurt Core Web Vitals, which feeds into rankings. Our technical SEO checklist covers how to test that. On WordPress, the reliable setup has four parts:

  • A cookie consent plugin such as Complianz, CookieYes or Cookiebot that can block scripts, not just display a notice.
  • The WP Consent API enabled, so plugins such as Site Kit and WooCommerce can read the visitor's choice.
  • Google tags loaded through Consent Mode v2, with default states set to denied for UK and EEA visitors.
  • Blocking rules for tags injected outside WordPress, such as those loaded through Google Tag Manager. This is where most setups leak, because the plugin never sees tags added inside GTM.

Questions we get asked

Do I need a cookie banner if I only use Google Analytics?
For EU visitors, yes. For UK visitors, you may be able to rely on the new statistics exemption, but only if the analytics measure site usage without advertising features or data sharing, you explain it clearly, and you offer an easy opt-out. If in doubt, ask for cookie consent. It costs you some data and removes the risk.

Is a "By using this site you agree to cookies" notice enough?
No. Continuing to browse is not consent under UK or EU rules. Cookie consent needs a clear action, such as clicking "Accept".

My site is hosted in the UK. Do EU rules apply?
Where your server sits does not decide it. If you target customers in EU countries, for example with euro pricing, EU delivery or EU-language pages, expect EU rules to apply to those visitors.

Will rejecting cookies wreck my analytics?
You will see fewer visits in Google Analytics, sometimes a lot fewer. Consent Mode v2 models some of the gap, and server-side or cookieless analytics can fill more. Decide based on what you need to measure, not on keeping the numbers high.

How often should I review the setup?
Every time you add a plugin, tag or embed, and at least twice a year. Cookie scanners in most consent plugins can run monthly and alert you to new cookies.

Want your cookie consent setup checked?

We set up and audit cookie consent on WordPress and WooCommerce sites for small businesses in the UK and Europe, including GTM blocking and Consent Mode v2. It can be done on its own or as part of our small business website service, and you can see our pricing here. Send us your URL and we will tell you what fires before consent.

This article explains the rules in general terms and is not legal advice. For decisions specific to your business, speak to a data protection adviser.

Devsio Engineering Consultation

Have questions about implementing this architecture?

Speak with our senior engineers. We review codebases and design roadmaps with 2-hour response guarantees.

Book Technical Discovery

More Engineering Articles