UK regulator ICO is set to play cookie cop for the digital ad industry

This week, U.K. data protection authority the Information Commissioner’s Office issued a blunt reminder of how cookies should be used under the Privacy Electronics Communications Regulation. The reason: The law has now been updated to mirror the General Data Protection Regulation’s rules on consent.
Since last year, the wide interpretation of GDPR and a lack of standardization of consent management platforms, which relay consent-request messages to users — have resulted in a messy consumer experience.
The ICO wants to bust any misunderstandings around how and where cookies can be used in advertising and other online services. But it has only vetoed cookies that are “non-essential.” That means any cookie necessary for the delivery of the service a person has requested to use doesn’t need user consent.
“Cookie compliance will be an increasing regulatory priority for the ICO in the future,” wrote Ali Shah, head of technology policy for the ICO in the update. He added that all future action will be proportionate, but that businesses should run cookie audits.
The ad tech industry has already been on red alert since the ICO warned that current ad-targeting practices weren’t legal under GDPR, last month. Others believe this latest guidance takes that up another notch.
“The new guidance on use of cookies will have a significant impact on publishers, advertisers and ad tech vendors alike,” said Ryan Gracey, solicitor and technology law expert at law firm Gordons. “It’s a significant update which brings the use of cookies in line with the GDPR standard of consent and will ultimately change the way in which companies track people online.”
Here is a look at what the ICO has vetoed:
Farewell implied consent
Thanks to GDPR, (this was legal under PECR previously) implied consent can no longer be relied on for cookies or for processing personal data. That means users must give explicit consent to cookies which are deemed non-essential to their website visit or intentions for using an online service (like a purchase). Pre-ticked boxes (of which there are still many) or any tactic that means users are opted in by default are not allowed for non-essential cookies. Users must be given absolute control over what non-essential cookies are dropped on them and these kinds of cookies also can’t be set on landing pages before that user has given consent. Naturally, some businesses would argue that all their cookies are essential for performing their business or service to a user. That would be a risky assumption.
Analytics cookies need consent
It looks like the trusty analytics cookies are out of luck. The ICO has deemed these should require user consent, because otherwise users aren’t aware this type of cookie is being dropped on their computer when they use an online service. For that reason, the ICO has said they are aren’t necessary for the user to be able to access a service; therefore, they must have user consent.
“Time will tell how many people give consent for non-essential cookies, but it will undoubtedly restrict the reach of advertisers,” added Gracey.
Cookie walls: dead on arrival
An idea bandied around at one point ahead of GDPR was the notion of a “tracking wall” or what the ICO refers to as a cookie wall. The concept is that any visitor to a publisher’s site that has a tracking wall installed won’t be able to continue on the site, read or watch the content until they give consent to their data being used and stored by that publisher for advertising purposes. It also applies to a lot of assumed consent strategies. Many sites have added a message to the effect that using the site means giving consent to cookies. However, the ICO has stated this is not valid consent under GDPR.
Legitimate interest
As the ICO recently stated in its latest GDPR update, relying on legitimate interest for sending targeted advertising is a hard no. Same goes for PECR. In fact, the ICO claimed this had always been the case under PECR.
“PECR always requires consent for non-essential cookies, such as those used for the purposes of marketing and advertising. Legitimate interests cannot be relied upon for these cookies,” wrote Shah.
More in Media

Andre ‘Typical Gamer’ Rebelo hits 1 million followers on Fortnite
As Epic Games looks to establish Fortnite as an alternative to platforms such as Roblox for metaverse-interested brands, seeing an individual creator reach one million followers could help convince more marketers to turn their attention to Fortnite Creative.

The Independent bets big on individual talent-led verticals with the launch of Independent Studio
The U.K.-based digital news publisher has signed YouTube creator Alan Clery as creative director to kick off the launch of Independent Studios, a unit that will produce a new crop of individual talent-led videos, newsletters and podcasts.

Creators are ditching Substack over ideological shift in 2025
The writers who left Substack in early 2025 represent a second wave after an initial burst of Substack creators left the platform in January 2024.