Blog / Privacy Law

  • uk-law
  • pecr
  • cookies
  • analytics
  • data-protection
  • ico

Analytics Without a Cookie Banner: What PECR Now Allows

For years the honest answer was "no": if your analytics script set a cookie, you needed consent first. That changed. Since 5 February 2026 there is a specific exception for statistical analytics, and it is narrower than most blog posts about it suggest.

Below: what the law says, what the ICO says it means, and a quick sketch of the version that needs no device access at all.

What changed, and where it lives

The Data (Use and Access) Act 2025, section 112 amended regulation 6 of PECR. The prohibition on storing or accessing information on someone's device stays. But it now bites "unless an exception in new Schedule A1 applies", and Schedule 12 of the Act is what inserts that schedule.

The commencement information on legislation.gov.uk gives the general date as 5 February 2026 (S.I. 2026/82). The ICO has since published its guidance on storage and access technologies, including a chapter on the exceptions.

Schedule A1 has these headings:

  • Interpretation
  • Consent
  • Transmission of a communication over an electronic communications network
  • Storage or access strictly necessary to provide an information society service
  • Collecting information for statistical purposes
  • Website appearance etc
  • Emergency assistance

The one we care about is paragraph 5.

The statistical purposes exception, condition by condition

Paragraph 5 lets you store or access information without consent if every one of its conditions holds. Reading the legislation and the ICO's explanation together, they are:

  • You provide an information society service (a website or app, broadly).
  • The sole purpose is collecting statistical information about how the service is used, with a view to improving it.
  • The information is not shared with anyone except to help you make those improvements.
  • The user gets clear and comprehensive information about the purpose.
  • The user has a simple means of objecting, free of charge, and has not objected.

Note the last two. There is no banner requirement, but there is a transparency requirement and an opt-out. "No consent needed" is not the same as "no notice needed".

"Sole purpose" is where most setups fail

The ICO reads "sole purpose" strictly. Its guidance says the output must be aggregate statistical information that cannot be used to identify people. Tracking individual visitors, following people across sites or devices, and anything advertising-related take you outside the exception entirely.

That rules out a lot of the default behaviour of mainstream analytics products. If the tool builds per-user profiles, feeds an ad platform, or lets the vendor reuse the data for its own purposes, the exception does not cover it, whatever the vendor's marketing page says.

Third-party analytics can still qualify, according to the ICO, but the provider must act as your processor rather than a joint controller. It should only use the data to help you improve your service, and must not link it with data from other sources.

Quick detour: does "cookieless" get you out of PECR?

Not by itself. Regulation 6 is about storing or gaining access to information on the user's terminal equipment, not about cookies as such. localStorage, device fingerprinting and reading device attributes to build an identifier are all in scope of the ICO's definition of storage and access technologies.

So "we dropped the cookie" only helps if you really dropped the device access. Which brings us to the option that sidesteps the question.

The version with nothing to consent to

If your server never writes to or reads from the visitor's device, regulation 6 is not engaged. Counting requests on the server is enough for a lot of personal sites: which pages are read, roughly how often.

Here is a deliberately minimal Go middleware that counts hits per path and keeps nothing that identifies a visitor: no IP, no user agent, no cookie.

package main

import (
	"log"
	"net/http"
	"sync"
)

type hitCounter struct {
	mu   sync.Mutex
	hits map[string]int
}

func (c *hitCounter) wrap(next http.Handler) http.Handler {
	return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
		if r.Method == http.MethodGet {
			c.mu.Lock()
			c.hits[r.URL.Path]++
			c.mu.Unlock()
		}
		next.ServeHTTP(w, r)
	})
}

func main() {
	c := &hitCounter{hits: make(map[string]int)}
	mux := http.NewServeMux()
	mux.Handle("/", http.FileServer(http.Dir("./public")))
	log.Fatal(http.ListenAndServe(":8080", c.wrap(mux)))
}

This is simplified: it keeps counts in memory only, counts bots and prefetches, and does not deduplicate visitors. Those are the trade-offs. You get page popularity, not "unique visitors".

One caveat that people forget. Your web server's access log probably records IP addresses, and an IP address can be personal data under UK GDPR. PECR reg 6 is off the table here, but data protection law is not. You still need a lawful basis, a mention in your privacy notice, and a sensible retention period.

Practical checklist before you drop the banner

  1. List every script and pixel that touches the device, including the ones you did not add yourself (embedded widgets and tag managers are the usual culprits).
  2. Check that each one serves only your own service improvement, with no ad, profiling or cross-site use.
  3. Read the vendor's terms on whether they reuse your data. If they do, the exception is off.
  4. Put a plain-English description of the analytics in a place users will actually see it, and link to the fuller privacy notice.
  5. Provide an objection route that works and is honoured, then test it.
  6. Keep the UK GDPR side in order: lawful basis, retention, processor terms.

If any single line fails, that tool goes behind consent again. One non-qualifying script is enough to bring the banner back for it.

What this does not settle

Whether a particular product meets "aggregate" and "cannot identify people" is a factual question about how it is configured and what the vendor does behind the scenes. The ICO guidance is regulator interpretation rather than law, and a tribunal or court could read the words differently. This is general information, not legal advice; if you are running something commercial with a marketing team attached, get someone to look at your actual setup.

My own view: the exception is a real relief for small sites that only want to know which pages get read. For anything attached to advertising, it changes very little.