Pandectes GDPR Compliance - 3,000+ Verified ⭐⭐⭐⭐⭐ 5/5 Reviews Worldwide - #1 on Shopify 🏅

← All posts

Privacy & Compliance

UK DUAA Implementation: What Changes for Consent and Cookies

UK DUAA Implementation What Changes for Consent and Cookies - icon

The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025, bringing reforms to the UK’s data protection and privacy framework. Most data protection provisions took effect on 5 February 2026, with new requirements for handling data protection complaints becoming effective on 19 June 2026.

  • DUAA does not replace UK GDPR, the Data Protection Act 2018, or PECR. It amends all three to modernize data use and access rules, support innovation, and tighten enforcement tools.
  • It is important to distinguish between the Privacy and Electronic Communications Regulations (PECR), which govern access to and storage of information on users’ devices (such as cookies), and the UK GDPR, which governs the processing of personal data. DUAA introduced changes primarily to PECR, specifically Regulation 6, by adding new exceptions allowing certain cookies and similar technologies to be used without prior consent under strict conditions.
  • The DUAA did not change the definition or legal requirements for consent under the UK GDPR. Consent under UK GDPR remains a separate and distinct requirement from consent under PECR.
  • Three key parts of the UK privacy framework are affected: the UK GDPR, the Data Protection Act 2018, and PECR, which regulates areas including electronic communications, cookies and similar technologies, and direct marketing.
  • UK data protection requirements can also apply to organizations based outside the UK. In particular, the UK GDPR may apply where an overseas business offers goods or services to people in the UK or monitors their behavior in the UK. Businesses serving UK users should therefore assess the territorial scope of both the UK GDPR and PECR rather than assuming that location outside the UK puts them out of scope.
  • The DUAA introduces a new lawful basis known as recognized legitimate interests for specified public-interest purposes. Unlike the ordinary legitimate interests basis, it does not require an organization to conduct the usual balancing test; it applies only to purposes prescribed by law.
  • The Information Commissioner remains responsible for regulating these rules and publishing guidance on DUAA implementation. Businesses should monitor current ICO and GOV.UK guidance as the regulatory framework continues to develop.

Make Your Shopify Store GDPR & Cookie Compliant in Minutes

Start Free on Shopify

DUAA’s most visible impact for online services is on cookie consent and other access technologies: cookies, pixels, local storage, fingerprinting, and similar scripts running on a user’s device.

  • Core PECR cookie rules remain intact. Setting or accessing cookies on a user’s device generally requires clear, comprehensive information and valid consent (opt-in), except in narrowly defined circumstances.
  • DUAA introduces additional exceptions for certain statistical measurement and appearance- or functionality-related uses of storage and access technologies. These exceptions are narrowly defined, apply only under strict conditions, and depend on the technology’s sole purpose.
  • The new exceptions do not remove the consent requirement for online advertising, cross-site tracking, behavioral profiling, retargeting, or cookies used for tracking user behavior. These categories of cookies continue to require strict prior consent (opt-in) under PECR and are not covered by any DUAA exceptions.
  • The DUAA distinguishes between PECR consent and UK GDPR consent requirements. Even if a cookie is exempt from PECR consent, if it processes personal data, a lawful basis under UK GDPR is still required.
  • A technology labeled “analytics” may or may not require consent depending on its actual purpose and configuration. For example, technology used solely to collect aggregate statistical information about service use to improve that service may qualify for the statistical purposes exception, while analytics used for advertising measurement, attribution, or tracking individual users will not.

Following the DUAA amendments, Schedule A1 to PECR contains five relevant exceptions to the general consent requirement: the existing communication and strictly necessary exceptions, together with new exceptions for statistical purposes, appearance or functionality, and emergency assistance.

Statistical purposes exception: Consent is not required where the sole purpose of storing or accessing information is to collect statistical information about how an information society service, or a website through which that service is provided, is used with a view to improving the service or website. The information may be shared with a third party only where the third party uses it for that improvement purpose. The user must also receive clear and comprehensive information about the purpose and be given a simple and free way to object. The exception does not apply where the technology is also used for purposes such as advertising, profiling, cross-site tracking, or advertising measurement.

For example, a Shopify store may rely on the statistical purposes exception where an analytics implementation is configured solely to measure use of the store to improve it, and all statutory safeguards are met. By contrast, analytics functionality used for advertising, advertising measurement, cross-service tracking, or profiling does not qualify and requires consent.

Appearance exception: Consent may not be required where storage or access is used solely to adapt the appearance or functionality of an online service to a user’s preferences, for example by remembering language or font settings. The exception can also cover certain enhancements to appearance or functionality, such as responsive design. Users must receive clear, comprehensive information about the purpose and be provided with a simple, free way to object.

Emergency assistance exception: Consent is not required where the sole purpose of the storage or access is to identify the geographical position of a subscriber’s or user’s device so that emergency assistance can be provided in response to an emergency communication.

Existing exceptions retained: The strictly necessary exception continues to cover storage or access that is essential to provide a service requested by the user. PECR also identifies activities such as securing terminal equipment, preventing or detecting fraud, preventing or detecting technical faults, authentication, and recording certain user selections as activities that may meet this exception where the statutory requirements are satisfied. The communication exception also applies where storage or access is strictly necessary to transmit a communication.

Because PECR exceptions are purpose-specific, organizations must assess every purpose for which they use a technology. Where all purposes satisfy the requirements of the same exception, consent may not be required. However, where a technology also serves a non-exempt purpose, such as advertising, consent is required for that storage or access. The statistical purposes and appearance exceptions are particularly narrow because they apply only where the relevant storage or access is carried out for the specified sole purpose.

EU and UK flags

Under DUAA, “why” and “how” a technology is used matters more than the label you assign to it.

The same analytics tool might qualify for the statistical exception on one site (where it is used solely to produce aggregate statistical information to improve the service) but require consent on another (where it links to ad platforms or is used for profiling). A cookie tagged “performance” in your consent banner is not automatically exempt; the actual data flow determines the legal status.

Old category-based consent models sorted cookies into buckets like strictly necessary, performance, analytics, and marketing. DUAA demands purpose-based assessments: is this cookie solely for service operation? Service improvement? Targeted advertising? Security? Document each technology with its specific purpose, the applicable PECR position (consent or an exception), any UK GDPR lawful basis where personal data is involved, and geographic scope.

Where an organization relies on the statistical purposes or appearance exception, it must provide clear, comprehensive information about the relevant purpose and give users a simple and free way to object. Other PECR exceptions have different requirements, although UK GDPR transparency obligations may still apply where personal data is processed.

Pandectes GDPR Compliance Shopify app supports this shift by allowing Shopify merchants to configure different purposes and behaviors per script, cookie, and region. You can apply DUAA exemptions for qualifying analytics on UK traffic while keeping full consent prompts for EU visitors, all within a single dashboard.

Make Your Shopify Store GDPR & Cookie Compliant in Minutes

Start Free on Shopify

Enforcement, Fines, and Data Protection Complaints Handling

DUAA arms the ICO with enforcement tools that match the scale of UK GDPR penalties. Maximum fines for certain PECR infringements can now reach £17.5 million or 4% of an undertaking’s total worldwide annual turnover, whichever is higher. Other PECR infringements are subject to a lower maximum penalty of £8.7 million or 2% of worldwide annual turnover, whichever is higher. Before DUAA, PECR fines were capped at £500,000; the maximum has therefore increased thirty-five-fold.

The DUAA also gives the ICO stronger investigatory and enforcement powers, including powers to compel witnesses to attend interviews and to require reports from approved persons. These sit alongside the significantly increased maximum penalties available for PECR infringements.

DUAA requires organizations to have a data protection complaints process. Organizations must take appropriate steps to facilitate complaints, including providing an electronic means of making a complaint, acknowledging complaints within 30 days, investigating them appropriately, and communicating the outcome without undue delay. These requirements came into force on 19 June 2026.

Robust consent and preference records can help demonstrate compliance during complaints or ICO investigations. Organizations should be able to show what information and consent mechanism a user was presented with, what choice was recorded, when it was recorded, and which technologies or purposes that choice covered.

While the article focuses on consent and cookies, DUAA also updates three areas that intersect with online tracking: automated decision making, children’s data, and broad consent for scientific research.

Automated decision-making: DUAA expands the circumstances in which organizations can make significant decisions based solely on automated processing. Such processing may potentially rely on a wider range of lawful bases, other than the new recognized legitimate interests basis, provided the required safeguards are in place. These safeguards include informing the individual about the decision, allowing them to make representations, obtain human intervention, and challenge the decision. Restrictions remain for special category data. Where storage and access technologies are used as part of profiling or automated decision-making, the organization must separately consider its PECR obligations and the applicable UK GDPR rules on profiling and automated decisions. Organizations should ensure that relevant automated decision-making and profiling activities are appropriately documented as part of their data protection governance, including the applicable lawful basis and safeguards.

Children’s data: Online services must take particular care when processing children’s personal data. The ICO’s Children’s Code applies to relevant information society services that are likely to be accessed by children, and profiling or personalized advertising involving children may attract heightened regulatory scrutiny.

Broad consent for research: DUAA clarifies that processing that genuinely falls within the UK GDPR concept of scientific research may, in defined circumstances, rely on broader consent covering research areas where it is not possible to fully identify the purposes at the time consent is collected. Further processing for new research purposes may also be permitted where the applicable UK GDPR requirements and safeguards are met. This does not mean that generic marketing or website analytics qualifies as scientific research; organizations must still identify an appropriate lawful basis and comply with PECR where storage or access technologies are involved.

A personalization engine that tracks browsing behavior across multiple websites is likely to raise PECR and UK GDPR profiling issues and may also engage the rules on automated decision-making if it is used to make solely automated decisions producing legal or similarly significant effects.

International Data Transfers, Direct Marketing, and the Wider Data Protection Landscape

DUAA is part of a broader UK effort to recalibrate data use and access rules post-Brexit while maintaining workable international data transfers.

  • DUAA reforms the UK’s international transfer regime, including introducing a “not materially lower” data protection test for government decisions approving transfers and for organizations relying on certain appropriate safeguards. UK adequacy regulations, sometimes referred to as “data bridges”, remain one route for restricted international transfers.
  • DUAA makes changes affecting direct marketing, including extending the PECR soft opt-in to certain charitable organizations. These changes do not create a general exemption from PECR’s rules on electronic marketing.
  • The new cookie exceptions do not provide a blanket route around consent for advertising technologies. The statistical purposes exception does not extend to online advertising, advertising measurement, cross-site tracking or profiling. In contrast, the appearance exception is limited to its specific appearance- and functionality-related purposes.
  • These elements connect back to overall data protection compliance. The Data Protection Act 2018 and UK GDPR require consistent lawful bases, transparency via a privacy notice, and records across all data use and access channels.

man on computer

DUAA’s cookie changes are UK-specific and do not alter EU GDPR or the ePrivacy Directive. A UK cookie compliance setup cannot simply be copied for EU visitors.

  • For users in the EU/EEA, cookie and similar storage-access rules continue to derive from the ePrivacy framework as implemented in national law. The DUAA exceptions apply only to the UK, so organizations should assess EU consent requirements separately and take account of the rules and regulatory guidance applicable in each relevant Member State.
  • Businesses operating across the UK and EU should therefore maintain region-aware consent configurations, applying the relevant UK exceptions only where their conditions are met and separately assessing the applicable requirements of each EU Member State.
  • Given the significantly increased PECR penalties, organizations should treat incorrect UK consent configurations as a material compliance risk alongside their EU obligations.
  • Pandectes helps Shopify stores run dual or multi-regional consent strategies by geotargeting banners, differentiating access technologies by region, and enforcing different consent rules for the UK, EU, and other jurisdictions from a single integration.

This section is a concise checklist for teams updating their UK privacy program in response to DUAA.

  1. Audit all storage and access technologies: Map every cookie, pixel, SDK, local storage item, and fingerprinting script on your store. Tag each with its purpose, vendor, personal data involved, and whether it targets UK users.
  2. Classify against DUAA criteria: For each technology, assess whether its purpose falls within the communication, strictly necessary, statistical purposes, appearance or emergency assistance exceptions, or whether consent is required. When assessing the strictly necessary exception, consider uses such as security, fraud prevention, and technical fault detection where relevant.
  3. Update cookie consent banners and consent flows: Where non-exempt technologies requiring consent are used, the consent mechanism should provide clear information and make refusing consent as easy as accepting it, with granular controls for different purposes. Separately, organizations relying on the statistical purposes or appearance exceptions must provide the information and objection mechanism required by those exceptions.
  4. Maintain appropriate consent records: Keep evidence of users’ consent and preference choices, including when the choice was made, what information was presented, and the purposes or technologies it covered. Where regional rules differ, ensure your implementation can demonstrate which consent experience applied.
  5. Update privacy notices and internal documentation: Privacy notices, relevant records of processing activities, policies and staff guidance should reflect the DUAA changes, including any reliance on the new PECR exceptions and the data protection complaints process. Organizations should also align their approach with the ICO’s final Storage and Access Technologies guidance, published on 29 April 2026.

Conclusion

The Data (Use and Access) Act 2025 changes the UK approach to storage and access technologies by introducing new, purpose-specific exceptions for statistical measurement, appearance and functionality, and emergency assistance, while retaining the existing communication and strictly necessary exceptions. Advertising, cross-site tracking and other non-exempt purposes continue to require consent.

Businesses within scope should review their storage and access technologies, determine whether each use qualifies for an exception or requires consent, update transparency and objection mechanisms where necessary, and maintain appropriate compliance records. For organizations operating across the UK and the EU, regional consent configurations are increasingly important because the DUAA exceptions apply only in the UK.

Make your Shopify Store's use of cookies and online tracking compliant today

Try for free