Do I have to accept cookies on a website?
Short answer
No. Only strictly necessary cookies can be set without your consent — everything else, including analytics and advertising, needs it. A “reject all” option must be as easy to find and use as “accept all”, and it must sit on the first layer of the banner.
Cookie consent is governed by Regulation 6 of the Privacy and Electronic Communications Regulations 2003 (PECR), which sits alongside UK GDPR. Before setting a cookie or similar technology on your device, an organisation must give clear information about what it does and obtain your consent — with one exception.
Essential versus everything else
Strictly necessary cookies need no consent because the service cannot function without them: the session cookie holding your shopping basket, the authentication cookie keeping you logged in, security cookies. Everything else requires prior consent — analytics, advertising, social media tracking and personalisation, including Google Analytics and Meta Pixel, and even where the data is described as anonymised. PECR applies to mobile apps too, so analytics SDKs and advertising identifiers are caught in the same way. Both first-party and third-party cookies need consent if non-essential.
The consent itself must meet the UK GDPR standard: freely given, specific, informed and unambiguous. Pre-ticked boxes, bundled consent and consent made a condition of using the service all fail that test. The ICO's guidance is explicit that a "reject all" option must be as prominent and accessible as "accept all", and must appear on the first layer of the banner — a big green Accept button next to a small grey "manage preferences" link is likely to be a breach.
Marketing, and how to complain
Regulation 22 covers unsolicited electronic marketing. Marketing emails and texts to individuals need prior consent; the "soft opt-in" lets an organisation market similar products to existing customers only where it took your details during a sale and offered a clear opt-out then and in every message since. Every marketing message must carry a free and easy way to opt out, and continuing after you opt out is a breach.
Raise the issue with the organisation first, then report it to the ICO — there is a dedicated spam reporting tool for marketing, and keep every message received after you opted out, as that is what makes a report stick. The ICO can fine up to £500,000 for serious PECR breaches, rising to £17.5 million or 4% of global turnover where UK GDPR is also engaged. One limitation to know: PECR itself gives no private right to sue for damages, so a compensation claim has to be built on an accompanying UK GDPR breach under Article 82.
Related guides
Cookie Consent and PECR: Your Digital Privacy Rights
Cookie banners, marketing emails, and tracking technologies are governed by the Privacy and Electronic Communications Regulations 2003 (PECR) alongside UK GDPR. Understanding your rights — and the obligations on organisations — helps you push back when consent is manufactured rather than freely given.
6 min
UK GDPR Rights for Individuals
The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018) give individuals in the UK eight legally enforceable rights over how organisations collect, store, and use their personal data. These rights apply whether the data is held by a business, public body, or online platform.
6 min
Right to Erasure (Right to be Forgotten)
The right to erasure — sometimes called the "right to be forgotten" — allows you to request that an organisation delete your personal data in certain circumstances. It is one of eight rights under UK GDPR and can be a powerful tool for removing outdated, irrelevant, or unlawfully held data about you from online platforms and databases.
6 min
When a Company Has a Data Breach: Notification and Next Steps
A personal data breach occurs when an organisation accidentally or unlawfully destroys, loses, alters, discloses, or gives access to your personal data without authorisation. This guide covers the organisation's duty to tell you and to tell the regulator, and what you should do in the days afterwards to limit the damage. If you have already decided you want to complain to the ICO or claim compensation, go straight to <a href="/complaints-ombudsmen/data-breach-complaints">data breach compensation and ICO complaints</a>.
6 min
More digital questions
Disclaimer