GuidesSME

Cookies just got easier: the consent exceptions explained

Some low-risk cookies no longer need a consent pop-up. The ICO finalised its guidance on 29 April 2026. Here is what is now exempt, what still needs consent, and how to update your banner without getting it wrong.

TheDutyDesk Editorial30 April 20263 min readReviewed 7 June 2026

The cookie banner is the most visible piece of data protection most people ever meet, and for years almost everything triggered one. That has loosened. A few low-risk cookies no longer need a consent pop-up at all, and on 29 April 2026 the ICO finalised the guidance that explains it.[20]

What is now exempt

The Data (Use and Access) Act added new exceptions, so you can now use certain cookies without asking first.[1] [20] The practical ones for most businesses are:

Basic analytics, used only to measure how your site is performing, such as counting visits and spotting errors.

Appearance settings, which remember a person's preferences like language or a chosen layout.

Emergency assistance, used to keep a service working safely when something goes wrong.

These join the cookies that were already allowed without consent, such as the ones that make a checkout or login actually work.

What still needs consent

The big one has not changed: advertising and tracking cookies still need clear, opt-in consent.[20] If a cookie follows people around to build a profile or to target ads, you must still ask, and the answer has to be a genuine yes.

So the rule of thumb is simple. Cookies that quietly help your own site run or measure itself: increasingly fine without a pop-up. Cookies that share data with advertisers or track people across the web: still need permission.

There is a sharp edge to be aware of. The penalties for getting cookies and marketing wrong have risen steeply, which we cover in a separate article. The relaxation is real, but so is the cost of misjudging it.

What this means for you

This is a chance to make your website less annoying and still compliant.

Ask whoever manages your site to list the cookies you actually use and sort them into two piles: the ones that now fall under an exception, and the ones that still need consent. You can stop pestering visitors about the first pile. You must keep asking properly about the second.

If you are not sure which pile a cookie belongs in, treat it as needing consent until someone confirms otherwise. That is the safe default.

Sources used in this article

  • [20]ICO guidance on storage and access technologies (final, April 2026)
  • [1]Data (Use and Access) Act 2025

Source verification and SHA-256 hashes are maintained in our sources index.

Last reviewed: 7 June 2026. Next review: 30 October 2026, or sooner if relevant guidance changes.

TheDutyDesk helps you manage data protection complaints with a structured process and an audit trail.