Cookie banners are easy to ignore until something changes in the law, the analytics setup, or the advertising tools behind a website. The UK Data (Use and Access) Act 2025 has made that review more urgent, especially for small businesses that rely on Google Analytics, Meta pixels, embedded videos, booking tools, live chat, remarketing tags, or email tracking.
The useful point is not that every website needs a more aggressive pop-up. In some cases, the new rules may make low-risk analytics simpler. In other cases, tracking still needs proper consent and a working way for visitors to say no. The practical task is to know which technologies your site uses, why they are there, and whether the choice you give visitors is still accurate.
What Has Changed?
The Data (Use and Access) Act 2025 updates several parts of UK data and digital information law. For websites, two areas matter most: changes to the Privacy and Electronic Communications Regulations, usually called PECR, and updated expectations from the Information Commissioner’s Office.
The ICO says the Act amends, rather than replaces, UK GDPR, the Data Protection Act 2018 and PECR. That means existing privacy notices, cookie banners and consent records are still relevant, but they may need checking against the new rules and guidance.
GOV.UK’s factsheet on the changes to PECR explains that the Act keeps the basic restriction on storing or accessing information on a user’s device, unless consent is given or an exception applies. It also adds new exceptions, including one for collecting statistical information to improve a website or online service.
Cookies Are Not the Whole Story
The ICO now frames the issue as storage and access technologies, not just cookies. That wider category can include:
- cookies used for logins, shopping baskets, analytics, advertising or consent settings;
- tracking pixels in websites or marketing emails;
- scripts and tags loaded through tools such as tag managers;
- local storage in the browser;
- device fingerprinting;
- link decoration and navigational tracking.
This matters because a website can look simple while third-party scripts do a lot in the background. A small-business website might have a contact form, a booking widget, an embedded map, a YouTube video, a chat tool and an advertising pixel, each with different data and consent implications.
The New Analytics Exception Is Useful, but Narrow
The change most likely to interest small businesses is the statistical purposes exception. The ICO’s guidance on exceptions says some storage or access can happen without consent where its sole purpose is collecting statistical information about how the service or website is used, with a view to improving it.
That does not turn every analytics product into an automatic opt-out tool. To rely on the exception, the purpose has to stay within service improvement, the resulting information must be aggregate statistical information, and visitors must receive clear information plus a simple, free way to object. The ICO is clear that the exception is not for identifying, tracking or monitoring people, and it does not apply to online advertising.
In practical terms, a basic analytics setup that counts visits, pages viewed, scroll depth, device type or how people reached the site may be easier to justify if it is configured carefully. Analytics connected to remarketing, profiling, cross-site tracking or advertising measurement is a different matter and should not be treated as exempt just because it appears in the same dashboard.
Advertising and Tracking Still Need Care
For most small businesses, the highest-risk mistakes are not obscure legal points. They are ordinary website changes made in a hurry: adding a Meta pixel before a campaign, enabling Google Ads remarketing, embedding a third-party booking widget, switching on heatmaps, or placing video embeds that set trackers as soon as the page loads.
If no exception applies, the ICO says businesses must obtain prior consent. Consent mechanisms also need to work technically. If the visitor rejects non-essential technologies, those technologies should not load anyway. If a visitor changes their mind later, withdrawal should be as easy as giving consent.
A banner that says “by continuing to use this site you accept cookies” is unlikely to be enough for non-exempt tracking. Nor is a banner useful if it appears after advertising tags have already fired.
What To Check on a Small-Business Website
A sensible review can be practical rather than legalistic. Start with the technology that is actually on the site, then decide what needs consent, what may fit an exception, and what should be removed because it is no longer useful.
- List every tag, pixel, cookie and embed. Include analytics, advertising, forms, maps, videos, live chat, booking systems, payment tools, A/B testing, heatmaps and email tracking.
- Assign a purpose to each one. Do not label everything as “analytics” if some tools support advertising, profiling or cross-site measurement.
- Separate essential from optional. Login security, basket functionality and consent-preference storage may be treated differently from marketing pixels or behavioural tracking.
- Check whether analytics is truly aggregate. If the setup identifies visitors, retains user-level data longer than necessary, or feeds advertising audiences, the statistical purposes exception may not apply.
- Make refusal as easy as acceptance. Visitors should not have to hunt through several screens to reject non-essential technologies.
- Block non-exempt tags until consent is given. The banner, tag manager and scripts need to agree with each other technically.
- Name third parties clearly. If information is shared with analytics, advertising or platform providers, visitors need understandable information about who receives it and why.
- Keep a record of decisions. Document why each technology is essential, exempt, consent-based or removed. This makes future website changes easier to control.
Do Not Let the Banner Harm the Website
Compliance should not mean a clumsy user experience. Cookie notices can damage enquiries when they cover the whole screen, break on mobile, hide forms, or interrupt every page view. The better approach is a clear first layer, equal accept and reject choices, a manageable preferences panel, and a persistent way to revisit settings.
For many service businesses, the best outcome may be a leaner tracking setup. If an advertising pixel has not been used for months, removing it is often better than maintaining consent journeys for data that provides no commercial value.
What This Means for Website Owners
The Data (Use and Access) Act does not mean every small business needs to rebuild its website. It does mean cookie compliance should be part of routine website maintenance rather than a one-off banner installed years ago.
The most useful next step is a short audit: what is loaded, why it is loaded, whether it waits for consent where required, and whether the privacy and cookie wording matches reality. That gives the business a cleaner website, better trust signals, and fewer surprises when marketing tools are added later.
This article is general guidance, not legal advice. Businesses with complex advertising, health data, children’s services, financial services, or large-scale tracking should take specialist advice before relying on an exception.