UK GDPR and PECR for Analytics
Date: 2026-08-16
Two regimes apply and people conflate them. PECR governs reading or writing anything on the device and demands consent almost always; UK GDPR governs what you then do with the data. You have to satisfy both, and PECR bites first.
Not legal advice. This is the mechanism as I understand it, for orienting a conversation with someone qualified. [CHECK: verify against the ICO’s own guidance before acting — this area moved in February 2026 and the sources below are secondary.]
Two regimes, two questions
| Governs | Question it asks | |
|---|---|---|
| PECR — Privacy and Electronic Communications Regulations | Storing or accessing information on a user’s device | May I set or read this cookie? |
| UK GDPR | Processing personal data | May I process this data, and on what lawful basis? |
PECR applies to the storage access regardless of whether the data is personal. That’s the part people miss — a cookie containing a random string still needs PECR consent, because the regulation is about touching the device, not about what’s in it.
Satisfying GDPR does not satisfy PECR. You need both.
The default position
Analytics cookies are not strictly necessary, so PECR consent is required. “Strictly necessary” means necessary to provide the service the user asked for — a basket cookie qualifies, a measurement cookie does not, however much you need it commercially.
Legitimate interest is not available as a route around this. A recognised legitimate interest for analytics was proposed and did not make it into the Data (Use and Access) Act. For the PECR question, consent is the mechanism.
The February 2026 exception
Since 5 February 2026, PECR Schedule A1 provides a narrow exception for first-party, statistics-only analytics. The conditions are tight:
- First-party only — the data stays with the website operator
- Statistical purposes only, for improving the service
- No sharing beyond that purpose
- Clear information given to the user
- A free and easy opt-out
The practical consequence for most UK retail sites: it probably doesn’t cover the tool you use. Google Analytics sends data to Google for Google’s own purposes, which takes it outside “stays with the operator” — so consent is still required for GA4 in the UK.
[CHECK: this is the most consequential claim in the note and it comes from consent-vendor commentary rather than the ICO directly. Confirm before relying on it.]
Where it does land: a self-hosted, first-party analytics tool with no data sharing has a plausible route to running without a consent banner. That’s a genuine architectural argument, not just a compliance one.
What follows for implementation
- Analytics tags fire only after consent, unless you’ve established the exception applies — Consent Management
- Consent state travels with the event, so downstream systems know what they may do with it
- Server-side collection changes nothing here. Consent attaches to the device access and the processing, not to which machine sends the request — a server-side event carrying a cookie-derived identifier still depends on that cookie — Server-Side Tag Management
- Denied consent means denied, not modelled around. Vendor conversion modelling is a separate question from lawfulness — Modelled Conversions
The GDPR half
Once you’re lawfully collecting, UK GDPR still governs the data:
- Pseudonymous is still personal. A persistent device identifier singles someone out, so “we only collect anonymous data” is usually inaccurate — Pseudonymisation and Anonymisation
- Purpose limitation. Collected for analytics means used for analytics. Repurposing for advertising is a new purpose needing its own basis
- Data minimisation. Collect what you’ll use. The “attach everything” instinct in Events and Properties has a legal counterweight
- Retention limits. Keep it as long as you need it, and no longer — Data Retention
- Subject rights. Access, erasure and portability apply to analytics data, which means being able to find and delete one person’s events — PII in Analytics
The commercial reality worth naming
Consent rates materially affect what you can measure, and the measurable population is not a random sample of your traffic — it skews away from privacy-conscious users. Every metric derived from consenting users carries that bias, and no amount of modelling removes it. See Ad Blockers and Tracking Loss for the same structural problem from a different cause.