The Nullware Standard0 trackers on this page
Articles / Law and practice

The badge replaces the banner

Since February 2026, a UK site that counts visitors without tracking them usually needs no cookie banner. Here is what the law now says, what still applies, and where the EU is different.

Roland Erich·Draft, checked 20 Sep 2026·7 min read
In short
01
In the UK, since 5 February 2026, you no longer need consent for storage used only to count how your site is used, as long as you tell people clearly and give them a simple, free way to object.
02
A site that meets the Nullware core rule (no ad pixels, first-party aggregate counting) will usually need no consent banner in the UK. You still need a privacy notice.
03
The EU is stricter. Consent is still the default there, with narrow national exceptions. A proposed change is still being negotiated.
01

Most cookie banners exist because the site hands its visitors to someone else: the ad pixel, the analytics tag that feeds an ad network, the video embed that phones home. Take those away and, in the UK, the legal case for the banner mostly goes with them.

What changed in the UK

The rules on cookies and similar technologies sit in the Privacy and Electronic Communications Regulations 2003 (PECR), regulation 6. The rule is simple: you may not store information on someone’s device, or read information already stored there, without consent, unless an exception applies.

The Data (Use and Access) Act 2025 rewrote those exceptions into a new Schedule A1 to PECR. That schedule came into force on 5 February 2026. The same change raised the maximum PECR fine to UK GDPR levels: £17.5 million or 4% of global annual turnover, whichever is higher.

Schedule A1 now lists four exceptions:

  • Strictly necessary. Storage or access that is strictly necessary to provide the service the person asked for. The schedule now spells out examples, including keeping the service and the device secure, preventing or detecting fraud, detecting technical faults, and remembering what someone put in their basket or that they have logged in. There is no separate “security” exception; security sits here.
  • Statistical purposes. Storage or access used only to collect statistics about how your service is used, with a view to improving it.
  • Appearance and functionality. Storage or access used only to adapt how the service looks or works to the person’s own preferences, such as language or text size.
  • Emergency assistance. Finding a device’s location to help someone who has asked for emergency help.

The conditions on the statistics exception

This is the one that matters for most sites, and it comes with conditions. Under paragraph 5 of Schedule A1 and the ICO’s guidance, you need all of these:

  • Sole purpose. The storage or access is only for statistics about how your service is used, with a view to improving it. Not advertising. Not building profiles.
  • Clear information. You tell people what you do, in clear and comprehensive terms.
  • A simple, free way to object. People can say no easily, at no cost, and you respect it. The ICO’s guidance has a section on what “simple” means.
  • No onward sharing, except to help you improve. You may use a provider, but the information goes to others only to help you make improvements.
  • Your analytics provider works for you. The ICO says a third-party provider must be a processor, not a joint controller, and must not use the information for its own purposes or link it with other data.

The appearance exception has the same pattern: clear information and a simple, free way to object.

The exception swaps a consent request for an opt-out. It does not remove the duty to tell people. The banner becomes a line in your privacy notice and a working “don’t count me” control.

What this means for a Nullware member

The Standard’s core rule already asks for most of what the exception requires (clause NFS-2.1). Analytics must count, not follow: first-party, aggregate, no identifier that lasts beyond a day, IP address discarded (ruling R-007). Ad pixels are out, consent-gated or not (R-003). GA4 and Firebase Analytics are out (R-006), because the data does not stay with you.

So a site that meets the core rule is in a good position. There are two cases.

Your counting tool stores something on the device. A short-lived first-party cookie, say, or an entry in local storage. PECR applies, but the statistics exception will usually cover it if you meet the conditions above. No consent banner needed.

Your counting tool stores nothing and reads nothing from the device. Some tools count page views on the server, from requests the browser sends anyway. If nothing is stored on or read from the device, regulation 6 may not be engaged at all. Be careful with “may”. The ICO’s guidance applies PECR to fingerprinting and to server-side setups whenever information is stored on or read from a device. A script that reads screen size or other device details to help count visitors is reading from the device. If your tool does that, treat PECR as applying and meet the statistics conditions anyway. It costs you one paragraph and a toggle.

Either way, the badge on your site can do the job the banner was pretending to do: tell visitors plainly what happens to them.

What still needs doing

The banner going away does not mean the paperwork goes away. You still need:

  • A privacy notice that explains your counting, what it collects, how long you keep it, and how to object. UK GDPR still applies to any personal data involved, including IP addresses, however briefly you hold them.
  • A working opt-out for anything relying on the statistics or appearance exceptions.
  • A data map (NFS-4.1). Every service that receives customer or visitor data, what it gets and why. Members publish theirs.
  • Processor contracts with your analytics and hosting providers (NFS-1.4), so the provider cannot use the data for itself.
  • Consent for anything else. Live chat that loads a third-party tracker, a video embed, a map. If it stores or reads on the device and is not strictly necessary, statistical or preference-based, you need consent or a click-to-load design (R-018 covers embeds).

What to check on your own site

  1. Open your site in a private window with the browser’s developer tools on. List every cookie and local-storage entry, and every third-party request made before you click anything.
  2. For each one, name the exception it relies on. If you can’t, it needs consent or it needs to go.
  3. Read your analytics provider’s terms. Does it act only as your processor? Does it use the data for its own products or benchmarks?
  4. Check your opt-out works. Object, then reload. Are you still counted?
  5. Update your privacy notice to match what you found.

The EU is different

If you serve people in the EU, the ePrivacy Directive still governs. Article 5(3) requires consent for storing or accessing information on a device, unless it is needed to carry a communication or strictly necessary for a service the user asked for. There is no general statistics exception in the Directive.

Some regulators have carved out room. France’s CNIL treats audience-measurement tools as exempt from consent when strict conditions are met: purely audience measurement for one publisher, no cross-referencing with other data, no onward sharing, the last byte of the IP address removed, trackers lasting no more than 13 months, and users informed and able to object. The CNIL itself warns that most large analytics products do not qualify. Other member states differ, so check the regulator in each country you target.

Cookieless is not a free pass in the EU either. The European Data Protection Board’s guidelines on the technical scope of Article 5(3), adopted in October 2024, read it broadly, covering tracking pixels, URL tracking and some IP-based tracking.

Change has been proposed. In November 2025 the European Commission published the Digital Omnibus, which would move the rules for personal data on devices into the GDPR, with a list of purposes that need no consent, including first-party audience measurement used only for the site’s own purposes, and add machine-readable browser signals for consent. As of September 2026 it is a proposal still under negotiation between the Parliament and the Council. It is not law, and the final text may differ.

For now, if you sell into the EU, assume you need consent for non-essential device storage unless a national exemption clearly applies.

What the Standard says

The Standard does not ask whether something is legal. It asks whether a customer was handed to someone else. Consent does not cure a breach (NFS-1.3): a click on “Accept” does not make an ad pixel acceptable. The flip side is that the Standard’s own rules for analytics (NFS-2.1, R-007) line up closely with the UK’s new statistics exception. Meet one and you will usually meet the other. We check your counting set-up and your data map (NFS-4.1) as part of review. Whether you still need a banner is a legal question for you and your adviser, not a certification finding.

Read the StandardRulings registerTake the self-check
Sources (11), checked 20 September 2026
  1. Data (Use and Access) Act 2025, Part 5 Chapter 2 (legislation.gov.uk)
  2. PECR Schedule A1, exceptions (legislation.gov.uk)
  3. ICO: Guidance on the use of storage and access technologies
  4. ICO: What are the exceptions?
  5. ICO: What are storage and access technologies?
  6. Clifford Chance: Key aspects of the Data (Use and Access) Act take effect (February 2026)
  7. CNIL: Sheet no. 16, use analytics on your websites and applications
  8. EDPB Guidelines 2/2023 on the technical scope of Art. 5(3) ePrivacy Directive, version 2
  9. European Parliament Legislative Train: Digital Omnibus Regulation proposal
  10. MediaLaws: Digital Omnibus legislative tracker
  11. iubenda: EU Digital Omnibus GDPR changes explained
This article is general information, not legal advice.
02

Keep reading

All articles
Guide7 min · Draft
Measuring marketing without following anyone
Geo experiments and marketing-mix models for businesses with real media budgets. No personal data needed.
Position7 min · Draft
Consent doesn’t cure it
Why a click on “Accept” doesn’t make handing a customer to an ad platform acceptable to us, and where consent still does its job.
Position6 min · Draft
The pixel you can’t see: server-side tracking
Moving tracking to a server hides it from scanners. It doesn’t change where the data ends up.