Customise a GDPR-friendly cookie banner, copy one snippet of code, and paste it into your site. No account, no monthly fee to start.
Paste it just before </body> on your site.
Cookies in the UK are governed by PECR β the Privacy and Electronic Communications Regulations β which sits alongside UK GDPR. PECR decides when you need consent to set a cookie. UK GDPR decides what that consent has to look like and what you then do with the data.
This matters because PECR applies to cookies regardless of whether they hold personal data. An analytics cookie with no identifying information still needs consent.
Strictly necessary cookies need no consent: the session cookie that keeps someone logged in, the one remembering a shopping basket, the one recording that they answered the cookie banner. The test is whether the service the user actually asked for would work without it.
Analytics is not strictly necessary. It is useful to you, not to the visitor completing their task. The ICO has been explicit about this, and treating analytics as exempt is the mistake most sites make.
You should be able to show that consent was given β when, and to what. For a small site, storing the choice and its date in a cookie is proportionate. Larger operations keep a consent log. Either way, if you cannot evidence consent, you do not have it.
Consent is not permanent. Re-asking every six to twelve months, or whenever your cookies materially change, is normal practice.
Yes. Analytics is not strictly necessary under PECR, so it needs consent before the cookie is set.
No. Refusing must be as easy as accepting. A banner offering only βAccept allβ is a common enforcement issue.
Strictly necessary ones β login sessions, shopping baskets, and the cookie recording the user's consent choice.
There is no fixed period, but re-asking every six to twelve months, or when your cookies change materially, is standard practice.