The Information Commissioner’s Office has finalised its updated guidance on the use of storage and access technologies under the Privacy and Electronic Communications Regulations (PECR) following amendments introduced under the Data (Use and Access) Act 2025. The rules apply broadly to any technology that stores information or accesses information stored on a user’s device, including cookies, tracking pixels and similar tools. The guidance provides clarity on when consent is required, and in particular, how the new “statistical” (analytics) and “appearance” exceptions operate in practice.
What are storage and access technologies?
Storage and access technologies cover a range of technical features that store or access information on a user’s “terminal equipment” (for example, a smartphone, laptop, tablet, connected TV, or IoT device). This includes:
- Cookies: Small text files stored in the browser, useful for things like remembering what’s in an online shopping basket.
- Tracking Pixels: Tiny images or code tracking when users access content/ email or visit confirmation pages.
- Link decoration/ navigational tracking: Extra information added to URLs to track campaigns or user journeys.
- Device fingerprinting: Collecting unique combinations of device/ browser attributes to identify devices.
- Web storage: Local or session storage via browser APIs, often for settings and preferences.
- Scripts/ Tags: Code snippets executed to collect data, often managed via tag managers.
The Regulations apply wherever these technologies are used, including apps and connected devices, not just websites.
Who must comply?
Any organisation operating an online service accessible to UK users must comply, even if hosted outside the UK. “Subscriber” generally means the person paying for the service, while “user” is anyone using the device - both are in scope of the rules.
When is consent required?
The default rule is that storing or accessing information on user devices requires prior consent (to the standard set out in UK GDPR), unless an exception applies: The exception will apply where it is
- Communication: for the sole purpose of transmitting a communication;
- Strictly necessary: to provide the service requested by the user;
- Statistical purposes (analytics): to collect information about how a service is used;
- Appearance: to adapt the appearance or functionality of a service to user preferences; and
- Emergency assistance: to identify a user’s location in an emergency.
The new analytics and appearance exceptions
A key aspect of the updated guidance is what now falls within the statistical purposes (analytics) and appearance exceptions. These exceptions recognise that some low-risk tracking activities do not require consent. However, unlike the other exceptions, these exceptions do not remove transparency obligations. Organisations must still ensure that they:
- Provide clear and comprehensive information about the use of the technology; and
- Give users a simple, free and effective way to object (opt out).
In practice, this means that organisations will still need to provide a pop-up or similar mechanism to explain to users what tracking is being used and enable users to easily opt out of that tracking.
The statistical purposes exception
The ICO’s guidance explains that the statistical purposes exception does not apply to all analytics. The exception applies where the sole purpose is to collect information about how your website or app is used. In other words, the focus of the analytics should be “how” not “who”. It does not apply where the technology is tracking or monitoring users or for online advertising, but rather the creation of aggregated statistical information used for the purposes of improving your services.
While third party analytics services can be used, information must not be shared with third parties other than for the purpose of enabling that third party to assist with making improvements to your website or app. The third party cannot use the information for its own purposes.
The guidance goes on to provide practical examples on what analytics technology is and is not within scope and what you must do if using a third party service provider.
Finally, the ICO reminds organisations that despite the focus on “how” not “who” analytics technology within the scope of the exception may collect personal data, if this happens then organisations must also comply with UK GDPR.
The Appearance exception
The appearance exception applies where the sole purpose of the tracking and storage technology is to adapt the way a website or app appears or functions in line with the user’s preference or otherwise enhance the appearance or functionality when accessed or displayed on the user’s device.
The ICO’s guidance emphasises that in order for this exception to apply, any adaptation to appearance must either be driven by the user’s preference or type of device. It does not apply where the appearance of a website or app is adapted based on known or inferred interests or browsing history (for example to promote certain content).
As with the statistical purposes exception, the ICO’s guidance provides practical examples of activities that the ICO considers do or do not fall within the scope of the appearance exception.
Cookie control configuration: good and bad practice
Finally, the guidance also provides helpful direction on cookie controls and user interfaces, including examples of good and bad practice, particular in relation to how consent is obtained.
Good practice
- Consent should be specific to the purpose and, where appropriate, offered on a granular basis;
- Avoid bundled consent;
- Provide separate options for each category (e.g. analytics, marketing);
- Ensure users can withdraw consent as easily as it was given;
- Use clear, plain language to explain what each category of technology does; and
- Provide accessible and prominent controls to allow users to make informed choices.
Poor practice
- Consent requests that are unnecessarily disruptive to the user experience;
- Repeated prompts that pressure users into making a choice;
- Lack of specificity (e.g. only offering a blanket “accept all” option);
- Making it more difficult to refuse than to accept tracking technologies; and
- Using unclear or misleading wording about what users are agreeing to.
The ICO’s focus here reflects a continued emphasis on fairness and user control, as well as compliance and safeguarding.
More information
You can access the updated guidance on the ICO’s website.
The guidance introduces a more flexible but still carefully structured regime for storage and access technologies. For many organisations, the key challenge will be properly categorising their technologies and ensuring their cookie mechanisms reflect the distinctions in the guidance.
If you would like to discuss the guidance in more detail or your organisation’s use of storage and access technologies, please contact Martin Sloan, Rachel Lawson or Ussamah Nasar.
Contributors
Partner
Associate
Senior Solicitor
Second year Trainee