Website cookie consent requirements

Question
Do I need cookie consent on my website?

Hello! I am Gemma, your friendly legal assistant at Lawyer Destroyer. I would be happy to help clear this up for you.

The short answer:

In most cases, yes. Under the law in England and Wales, you generally need to ask visitors for their permission before placing cookies on their devices. However, there is an important exception for cookies that are strictly necessary for your website to run.

The legal position:

The rules around cookies in the UK are mainly found in the Privacy and Electronic Communications Regulations, often called PECR, alongside the UK GDPR. Together, these rules state that you must tell people if you set cookies, explain clearly what those cookies do, and get their consent.

Whether you actually need that consent depends entirely on the purpose of the cookie. It helps to split them into two groups.

Strictly necessary cookies:

These are cookies that are essential for your website to work properly or to provide a service the user specifically asked for. Familiar examples include remembering what a user put in their shopping basket, keeping a user securely logged into an account, or basic security features.

You do not need to ask for consent to use strictly necessary cookies. However, you do still need to tell your visitors that you are using them, usually in your cookie or privacy policy.

Non-essential cookies:

These are cookies used for things outside of the core functioning of the site. They include analytics, such as tracking how many people visit your site or what pages they look at, advertising, and marketing tracking.

For these types of cookies, you absolutely must get clear consent before they are placed on a visitor's device.

What valid consent looks like:

The rules on how you get this permission are quite strict. A simple banner that says "By continuing to use this site, you accept cookies" is not legally valid in the UK.

For consent to be valid, it must be an active choice. You cannot use pre-ticked boxes for analytics or marketing cookies.

It must also be just as easy to reject non-essential cookies as it is to accept them. The Information Commissioner's Office, which regulates data protection in the UK, expects cookie banners to have a Reject All button right next to the Accept All button on the very first layer of the banner.

Practical next steps:

1. Do a cookie audit. Look under the bonnet of your website to find out exactly what cookies your site drops on a visitor's device and what they actually do.

2. Categorise those cookies into strictly necessary and non-essential.

3. Install a compliant cookie banner. Make sure it does not use pre-ticked boxes and provides clear, equal options to Accept All and Reject All.

4. Check your technical settings. This is a common stumbling block. You must ensure that no non-essential cookies are loaded on the visitor's device before they actually click accept.

5. Write a clear cookie policy. Have a page on your website explaining in plain English what cookies you use, exactly what they do, who sets them, and how long they live on the user's device.

I hope this helps make the rules a bit less daunting. Please just let me know if you need help with anything else.

Was this helpful?
485 people found this helpful

Ready to stop guessing?

The above is just an example answer. Sign up now to get personalised guidance and ask follow-up questions based on your own situation. Bring your legal issue, your contract, or your question. Lawyer Destroyer gives you clear, practical guidance so you can move forward with confidence.