Guidance on the Use of Storage and Access Technologies (ICO)
The UK Information Commissioner’s Office’s guidance on Privacy and Electronic Communications Regulations (PECR) compliance for cookies and similar technologies, finalised 29 April 2026. This page draws specifically on the “How do we manage consent in practice?” section — the ICO’s own checklist for what a compliant consent mechanism (a cookie banner, in practice) actually has to do.
License: Open Government Licence v3.0 — https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/
Key points
- A consent mechanism must make it as easy to refuse as to accept — an “accept all” with no equally prominent “reject all” (only a buried “more options” path) is named bad practice.
- Consent must require a genuine positive action before non-exempt storage/access technologies are set; silence, inactivity, or continuing to browse past an unanswered banner doesn’t count as consent.
- Consent requests must be specific to the purpose, which in practice means granular per-category toggles — a long, undifferentiated checkbox list is flagged as a real risk (people disengage rather than actually read it), and a bundled single consent covering multiple unrelated purposes is unlikely to be valid.
- Consent must be kept separate from terms and conditions — a service cannot obtain consent to cookies by folding it into a T&Cs acceptance.
- A “legitimate interests” toggle defaulted on alongside a separate “consent” toggle defaulted off is named explicitly as bad practice — it’s designed to make the true consent option look secondary.
- Any consent mechanism must let a user withdraw consent with the same ease they gave it, tell them how, and be technically capable of actually removing what was already set.
- Re-prompting for consent shouldn’t happen indefinitely once someone has refused — six months is offered as a general guideline for how long a refusal should be respected before asking again, except when the purpose or technology itself has genuinely changed.
- A banner designed for desktop can fail on mobile (hard to read or interact with), which can itself invalidate any consent gathered that way — implementation across device types needs real consideration, not just legal wording.