Cookies and Consent: the ICO’s Cookie Review
- 06 February 2025
- Privacy and Data Protection
In the digital age, cookies play a crucial role in how websites operate and interact with users. Companies use cookies to help websites remember preferences, track user behaviour, and deliver personalised content. Whilst this can lead to a more effective and personalised service, the non-consensual use of these cookies has raised significant privacy concerns, leading to stringent regulations on how they should be managed. The Information Commissioner’s Office (ICO) has been at the forefront of ensuring that people’s rights are upheld by the digital advertising industry. As part of this, the ICO has announced that it is expanding its review of cookie usage from the top 200 websites in the UK to the top 1,000 websites, to bring them into compliance with data protection law.
Cookies are small text files that are placed on user devices by websites that the user visits. These can be broadly categorised into essential and non-essential (or analytics) cookies. Essential cookies are necessary for the basic functioning of a website, such as maintaining user sessions or remembering items in a shopping cart. Non-essential cookies, on the other hand, are used for purposes like analytics, advertising, and personalisation. These cookies often track user behaviour across different websites, and the ICO has flagged the potential harm that can be caused from the use of this, such as gambling addicts being targeted with more betting ads due to their browsing history.
Under the UK General Data Protection Regulation (GDPR), websites must obtain explicit consent from users before placing non-essential cookies on their devices. This means users should be informed about the types of cookies being used, their purposes, and must be given a clear choice to accept or reject them.
In January 2025, the ICO announced an ambitious plan to review the cookie usage of the top 1,000 most-visited websites in the UK. This initiative is part of the ICO’s broader strategy to ensure online tracking gives people clear choices and confidence in how their information is used.
The review follows a successful assessment of the top 200 websites, where the ICO identified significant compliance issues. Out of these 200 websites, 134 were found to have shortcomings in their cookie usage practices, prompting the ICO to communicate their concerns to these organisations, setting clear regulatory expectations that the organisations must comply with. The expanded review aims to build on this progress, ensuring that a larger number of websites adhere to data protection laws.
Non-essential cookies, on the other hand, are used for purposes like analytics, advertising, and personalisation.
The ICO’s review has highlighted several common issues with cookie compliance:
To address these issues, the ICO has issued new guidance and best practices for websites:
The ICO’s review of the top 1,000 websites in the UK underscores the importance of transparency and user control in cookie practices. By adhering to the ICO’s guidance, websites can build trust with their users and ensure compliance with data protection regulations. As the digital landscape continues to evolve, responsible data use will remain a cornerstone of user privacy and trust.
Keep up to date with the latest tips, analysis and upcoming events by our legal experts, direct to your inbox.
Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.