← Back to blog
Cookie Policy

What is a Cookie Policy and Do I Need One for My UK Website?

By DataShark · 03 June 2026 · 5 min read
?>

Cookies are everywhere online — but what exactly is a Cookie Policy, do you legally need one, and what happens if your website doesn't have one? This guide covers everything UK small business owners need to know.

What are cookies?

Cookies are small text files that websites store on a visitor's device. They're used for everything from keeping users logged in, to tracking which pages they visit, to serving targeted advertising.

There are four main categories of cookies:

What is a Cookie Policy?

A Cookie Policy is a legal document that tells your website visitors:

Do I legally need a Cookie Policy?

Yes — if your website uses any cookies beyond strictly necessary ones, you are legally required to have a Cookie Policy under two pieces of UK law:

✅ If your site uses Google Analytics, Facebook Pixel, HotJar, LinkedIn Insight Tag, or any advertising cookies — you need a Cookie Policy and a cookie consent banner.

What about strictly necessary cookies?

Strictly necessary cookies — like session cookies that keep users logged in — don't require consent under UK PECR. However, you still need to disclose them in your Cookie Policy. You just don't need to ask permission before setting them.

You must tell users about ALL cookies you use, even the strictly necessary ones. The consent requirement only applies to non-essential cookies.

What must a UK Cookie Policy include?

A compliant Cookie Policy should cover:

Cookie Policy vs Privacy Policy — what's the difference?

These are two separate documents, though they're related:

Many UK websites have both documents, with the Cookie Policy either as a separate page or as a dedicated section within the Privacy Policy. Having them separate makes them easier for users to find and understand.

Do I need a cookie consent banner?

Yes, if you use non-essential cookies. Under UK PECR, you must get informed consent before setting analytics or marketing cookies. This means:

Common mistake: Having a cookie banner that says "By continuing to use this site you agree to cookies" does NOT constitute valid consent under UK PECR. Users must actively opt in to non-essential cookies.

What are the penalties for non-compliance?

The ICO can issue fines of up to £500,000 under UK PECR for serious cookie consent violations, and up to £17.5 million under UK GDPR. In practice, the ICO tends to issue warnings and improvement notices to small businesses first.

Summary

If your UK website uses Google Analytics, any advertising tools, or any cookies beyond those strictly necessary for the site to function — you need a Cookie Policy and a cookie consent mechanism. The Cookie Policy must clearly explain what cookies you use, why, and how users can control them.

Ready to generate your GDPR policy?

Answer a few questions about your business and get a personalised, legally-structured document in minutes.

Start free — from £29 →