On 29 April 2026, the Information Commissioner’s Office (ICO) published updated guidance on the use of storage and access technologies (SATs) [1]. The guidance clarifies how Regulation 6 of the Privacy and Electronic Communications Regulations (PECR) [2] applies to cookies and similar technologies, including tracking pixels, scripts and device identifiers. While the update does not represent a fundamental shift in approach, it provides important clarification on how the rules should be applied in practice, particularly following legislative changes introduced by the Data (Use and Access) Act 2025 [3].
Regulation 6 PECR and the Consent Requirement
The guidance confirms that consent remains the default position where organisations store or access information on a user’s device. However, Regulation 6 contains a limited number of exceptions, which the ICO continues to interpret narrowly.
Under Regulation 6, consent is not required where storage or access falls within one of the following exceptions:
- for the sole purpose of the transmission of a communication over an electronic communications network (communication exception);
- where it is strictly necessary to provide an information society service explicitly requested by the user, such as enabling core functionality, authentication or security (strictly necessary exception);
- where it is used solely for statistical purposes in order to collect information to improve a website or service (statistical purpose or analytics purpose);
- where it is used solely to adapt the appearance or layout of a website or service to user preferences (appearance exception) ; or
- where it is necessary for the provision of emergency assistance services (emergency assistance exception).
In each case, the ICO emphasises that the exception applies only where the relevant conditions are met and only for the specific purpose relied upon.
Interaction with the UK GDPR
The guidance reiterates that PECR operates alongside the UK GDPR [4]. Where SATs involve the processing of personal data, organisations must ensure compliance with UK GDPR obligations, including transparency, purpose limitation and accountability. Importantly, organisations are expected to assess compliance based on the purpose and effect of the technology, rather than its technical form or label.
New Guidance on Objections and Multi‑Purpose Technologies
The ICO has also introduced two new sections in the guidance which will be of practical significance to organisations providing online services.
First, the ICO clarifies the meaning of providing a “simple means of objecting”, a requirement attached to the statistical and appearance exceptions. While PECR does not prescribe how this must be implemented, the ICO makes clear that organisations relying on these exceptions must allow users to object easily and free of charge. If a user objects, the organisation must stop the relevant storage or access activity. Organisations should not assume that browser settings alone will satisfy this requirement and should consider how objections can be clearly and effectively captured.
Secondly, the guidance addresses the use of the same storage and access technology for multiple purposes. While a single technology may technically support multiple functions, the ICO emphasises that the Regulation 6 exceptions are purpose‑specific. In practice, this makes it difficult to rely on an exception where the same technology is also used for a non‑exempt purpose. Where one purpose does not meet the conditions of an exception, valid consent will be required, and users must be given granular control over the non‑exempt uses. The ICO suggests that, in many cases, using separate technologies for separate purposes may be a simpler route to compliance.
What This Means for Organisations
The updated guidance reinforces the ICO’s core position that users should retain meaningful control over non‑essential storage and access activities. While the new statutory exceptions provide greater flexibility in limited circumstances, organisations should expect continued regulatory focus on narrow interpretation, clear transparency and effective user choice. For many organisations, the update will be a prompt to review existing cookie and consent mechanisms to ensure that reliance on any Regulation 6 exception is robust and well documented.
Please contact Jose Saras for detailed advice on the above.
The material contained in this article is only for general review of the topics covered and does not constitute any legal advice. No legal or business decision should be based on its content.
This article is written in the English Language. Preiskel & Co LLP is not responsible for any translation of all or part of its content into any language.
[1] ICO – Guidance on the use of storage and access technologies
[2] Privacy and Electronic Communications Regulations 2003