Duty

Your cookie banner is now a board-level risk: fines up to £17.5m

The maximum fine for breaking the UK's cookie and electronic marketing rules has jumped from £500,000 to £17.5m. Here is what changed, why it matters even to small businesses, and the cheap fixes that remove most of the risk.

TheDutyDesk Editorial2 March 20263 min readReviewed 7 June 2026

For years, the rules on cookies and marketing emails carried a maximum fine of £500,000. That was the ceiling no matter how badly an organisation behaved. The Data (Use and Access) Act has removed that ceiling and replaced it with a much higher one.

The maximum is now up to £17.5m, or 4% of worldwide annual turnover, whichever is higher.[1] That is the same level as the main data protection fines. The thing many businesses treated as a minor compliance chore now sits in serious-money territory.

What the rules cover

These rules govern two everyday activities. The first is cookies and similar tracking on your website. The second is electronic marketing: the texts, emails and calls you send to promote your business.[20]

The classic mistakes are familiar. A cookie banner that drops tracking cookies before anyone clicks anything. Marketing emails sent to people who never agreed to receive them. A "consent" that was really just a pre-ticked box. None of these are new mistakes. What is new is the price of making them.

It is worth knowing that some cookie rules also got easier at the same time, with new exceptions for low-risk cookies. The relaxation and the bigger fines arrived together, which is exactly why getting the line right now matters.

What this means for you

You do not need to spend money to remove most of this risk. You need to check three things.

First, your cookie banner: does anything track visitors before they say yes? If so, fix it. Second, your marketing lists: can you show that the people on them agreed to hear from you? If not, clean the list. Third, your unsubscribe: does every marketing message offer an easy way out, and does it actually work?

These are small, practical checks. The reason to do them now is straightforward. The behaviour that used to risk a modest fine can now, in a bad case, risk a very large one. A morning spent tidying your banner and your lists is cheap insurance against that.

Sources used in this article

  • [1]Data (Use and Access) Act 2025
  • [20]ICO guidance on storage and access technologies (final, April 2026)

Source verification and SHA-256 hashes are maintained in our sources index.

Last reviewed: 7 June 2026. Next review: 2 September 2026, or sooner if relevant guidance changes.

TheDutyDesk helps you manage data protection complaints with a structured process and an audit trail.