Analytics and Tracking

Consent

A clear, freely given and specific agreement to a use of personal data or to cookies being set, which can be withdrawn as easily as it was given.

Quick facts: Consent

Category
Analytics and Tracking
Level
Beginner
Affects
Cookie use, analytics data, email marketing, ad audiences, legal compliance
Where to see it
Consent management platform, consent log, email platform subscriber records, browser developer tools
In this article4
  1. How consent works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

Consent, in marketing and data protection, is a person’s clear and freely given agreement to a specific use of their personal data, or to something being stored on or read from their device, such as an analytics cookie. Under UK law it only counts if they had a genuine choice, understood what they were agreeing to and actively said yes.

Two sets of rules rely on it, and UK marketers need to satisfy both.

UK GDPR

UK GDPR treats consent as one of six lawful bases for using personal data. To be valid it must be:

  • Freely given The person can say no without losing out, and agreeing is not bundled into accepting your terms.
  • Specific Separate choices for separate purposes, so signing up for a newsletter is not also agreeing to ad targeting.
  • Informed They know who you are, what you will do with their data and that they can withdraw.
  • Unambiguous A clear positive action, such as ticking an empty box or pressing an accept button. Silence, pre-ticked boxes and carrying on browsing do not count.

Withdrawing must be as easy as agreeing, and you must be able to show who consented, when and to what.

PECR

The Privacy and Electronic Communications Regulations add rules for two things marketers do every day. Storing or reading information on someone’s device, which covers cookies, pixels and similar technologies, needs consent unless it is strictly necessary for a service the person has asked for. Marketing emails and texts to individuals need consent too, unless the soft opt-in applies: you collected their details while selling them something, you are marketing your own similar products, and you gave them a simple way to refuse at the time and in every message since. Where PECR requires consent, it means consent to the UK GDPR standard.

The Data (Use and Access) Act 2025 relaxes the device rule for a few low-risk uses, such as some analytics that only help you improve your own site, provided people are told and can object. At the time of writing (October 2026), check the ICO’s current guidance on which of these changes are in force and on their conditions. Advertising and cross-site tracking still need consent.

Why it matters

Consent decides what you can measure and who you can market to. Every visitor who rejects cookies on a compliant UK site drops out of GA4 and out of your ad platforms’ audiences, which is the gap Google’s consent mode and modelled conversions try to fill. Getting it wrong costs you either way: collect without valid consent and you risk complaints and ICO action; ask clumsily and fewer people agree, leaving thinner data and a smaller email list.

It is also not always the right basis. Processing an order usually rests on contract, and some business-to-business contact can rest on legitimate interests. Relying on consent where another basis fits better causes trouble later, because people can withdraw consent at any time and you then have to stop.

Common mistakes

  • A cookie banner with a bright “Accept all” button and no equally easy way to refuse on the first screen.
  • Analytics and ad tags that fire before the visitor has made a choice.
  • One tick box covering the newsletter, partner offers and advertising audiences together.
  • Uploading a whole customer list to Google or Meta for ad targeting when customers were never told their details could be used that way.
  • No record of consent, so you cannot prove that anyone agreed, or to which wording.
  • Making withdrawal hard: an unsubscribe link that needs a login, or no way to reopen cookie settings.

How to act on it

  1. List every place you ask for or rely on consent: the cookie banner, newsletter forms, checkout, lead forms and ad audiences.
  2. For each, check that the wording is specific, any box starts unticked, and the choice is stored with the date and the wording shown.
  3. Test the banner in a private browser window. Nothing non-essential should load before a choice, and “Reject all” should keep it that way. A properly configured consent management platform handles most of this for you.
  4. Make withdrawal a single step: an unsubscribe link in every email, and a permanent link to cookie settings in the site footer.
  5. Update your privacy notice so it describes what actually happens.

Paid campaigns now run on consented data, so getting consent right is part of the groundwork for performance marketing, not something to bolt on once the ads are live.

Do and do not

Do

  • Give separate choices for separate purposes
  • Record who agreed, when and to what wording
  • Make withdrawing as easy as agreeing

Do not

  • Use pre-ticked boxes or treat browsing as agreement
  • Fire non-essential tags before a choice is made
  • Rely on consent where another lawful basis fits better

Questions people ask about this

Do I need consent to email my existing customers?

Often not, if the soft opt-in applies: you collected their email address during a sale or negotiation for a sale, you are marketing your own similar products, and you offered a clear opt-out at collection and in every message since. It does not cover new prospects, bought-in lists or other companies' offers. Emails to staff at limited companies fall under different PECR rules, though sole traders and some partnerships are treated as individuals.

Can I make visitors accept cookies before they can use my site?

A cookie wall that blocks access unless people accept is risky under UK rules, because consent demanded as the price of entry is unlikely to be freely given. The ICO has said some consent-or-pay models can comply if the alternative is fair and clearly explained, but it judges each case on its facts. For most small business sites, an ordinary banner with a genuine choice is the safer route.

How long does consent last?

UK law sets no fixed expiry, but consent should be refreshed when your purposes change, and it should not be stretched to cover activity people would not reasonably expect years later. Most consent management platforms let you set how long a cookie choice is remembered, and six to twelve months is a common setting. Whatever period you choose, record it and apply it consistently.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.