One of the main practical changes introduced by the Data (Use and Access) Act 2025 (the “DUAA”) relates to cookies and similar technologies (which we refer to collectively in this blog as “cookies”). With this in mind, we wanted to take the opportunity to demystify the rules around cookies under UK data protection law, and to provide a summary of the key changes introduced by DUAA in this area.
What are cookies, and what do they do?
Cookies are small text files that are ‘placed’ on users’ devices to identify (and, in some cases, remember) those devices when they access a website or other network. Some cookies can be ‘first party’, which means that they are created and owned by the website that the user is visiting, or ‘third party’, which means that they are created and owned by another website (for example advertisers, or social media platforms that want to track users’ movement across the internet).
Cookies can be extremely useful, and there are a number of different types of cookies that organisations tend to use. The most common are as follows:
- Essential (or ‘Necessary’) Cookies – These are cookies that are essential for the website to run. They might include, for example, cookies that keep users logged in when they browse different pages, or that enable users to submit forms or access the website properly.
- Analytics Cookies – These cookies gather information about how users interact with a website, for example how long they spend on a particular page and what parts of the website they visit the most.
- Performance Cookies – These cookies track how well a website is working, for example by measuring how long pages to take load.
- Functional Cookies – These cookies optimise user experiences (but are not essential for the site to work), for example by remembering a user’s preferences and providing tailored content based on the user’s past interactions with the website. NB Functional and performance cookies are often grouped together.
- Marketing Cookies – These cookies track user activity across websites and deliver targeted ads to those users (often on other sites). These are normally ‘third party cookies’.
What are the rules around cookies?
The Privacy and Electronic Communications Regulations 2003 (“PECR”) impose specific rules on organisations that place cookies on individuals’ devices. In particular:
- Transparency – Organisations are required to provide users with sufficient information about all of the cookies that might be used on the site, including information about the purposes of each cookie, any third parties who might store or access information in the user’s device (i.e. as part of a third party cookie), and the duration of each cookie (in other words, how long it stays on the user’s device).
- Consent – Organisations are required to obtain consent before placing various types of cookies on users’ devices. This is typically done via a Cookie Banner, a pop up which appears when a user accesses a site and which asks the user to consent to the placement of certain cookies.
We’ve set out some more specific information about these requirements, and key points to consider below.
So what’s changed?
Prior to DUAA, the consent requirement described above applied to all types of cookies except Essential Cookies. In other words, an organisation would need to obtain the opt-in consent of a user before placing a non-essential cookie on their device.
DUAA amends this position slightly, and extends the circumstances in which consent is not required. In particular, organisations are no longer required to obtain consent for cookies that are used for the sole purpose of:
- Collecting aggregated information for statistical purposes and/or using that information for the purposes of improving the service (the “Statistical Purposes Exemption”).
ICO Guidance makes clear that this can include statistical information, such as: how many people access your service (e.g. your site), what they access and how long they access it. As such, this exemption may well cover many Analytics Cookies. Note that an organisation must aggregate the relevant information to rely on this exemption, and the exemption doesn’t apply to online advertising or using web analytics tools to track users.
- Adapting the way your site appears or functions in line with a user’s preference, or otherwise enhancing the functionality of the site when displayed on or accessed by a user’s device (the “Appearance Exemption”).
This might include e.g. identifying the dimensions of a user’s device so that the website can adapt to that screen, remembering the language that a user selects or detecting other preferences that the user has selected on their device/operating system (such as ‘dark mode’). As such, this exemption may well cover Performance and/or Functional Cookies. Note that this exemption is only about appearance and functionality – it would not apply if an organisation wanted to e.g. use a user’s profile or browsing history to decide what content to promote on the site.
DUAA also introduces other exemptions to the consent requirement (including cookies used solely for communication and/or emergency purposes, but we have not gone into detail on those in this blog).
What does this mean for my organisation?
In order to rely on the Statistical Purposes or Appearance Exemptions, organisations must provide users with: (i) clear and comprehensive information about the use of the relevant cookie; and (ii) an easy way to object to this use.
Practically speaking, this means that organisations that want to rely on these exemptions will need to:
- Cookie Policy – Ensure that their Cookie Policies include sufficient information about the relevant cookies (and that the Cookie Policy makes clear when the organisation will and won’t ask for consent).
NB Many organisations include information about cookies in a general privacy notice. We would advise that, instead, information about cookies is put in a standalone policy to ensure that organisations are providing information about the cookies in sufficient detail.
- Cookie Banner – Ensure that their Cookie Banners make clear what users are consenting to, and that consent is as easy to reject as to provide. In other words, an organisation’s cookie banner should include: (i) an ‘Accept All Cookies’ option, (ii) a ‘Reject All Non-Essential Cookies’ option and (iii) a ‘Manage Cookies’ option, which enables users to toggle their preferences for different types of cookies (e.g. so that they can consent to Performance Cookies, but not Marketing Cookies).
NB Essential Cookies, and the cookies that are subject to the Statistical Purpose or Appearance Exemptions can be turned on by default, but individuals must be able to disable all cookies except the Essential Cookies, at any time. Organisations should therefore have a cookie management centre so that users can change their cookie preferences at any time (this is sometimes presented to users via a small button on the site, or via a link in the Cookie Policy).
Next Steps
Cookies can be complex and technical. However, they remain a key part of data protection compliance, and so it’s important that organisations consider their obligations carefully.
Organisations that currently have their transparency and consent processes in place may feel that it would be preferable to stick with those processes, even in light of the new exemptions introduced by DUAA.
However, if you are considering a review of your cookie compliance and/or are starting a new website or service, it would be worth considering how the new exemptions might work for you and how you intend to put in place processes to ensure that you are informing people about the cookies on your site and obtaining appropriate consent.
If you would like to discuss further, please don’t hesitate to reach out to one of the team: we have advised a number of organisations on cookies, and would be happy to assist.