PERFMETRIX — in data we trust
All articles
PECR28 July 2026·9 min read

"Pay to reject cookies": is it legal in the UK and EU?

The ICO says consent or pay can be lawful under four conditions. The EDPB says most large platforms will fail. What each requires, and what it costs your data.

DeBy Denis · Perfmetrix

Short answer: in the UK, yes, conditionally. The ICO published guidance on 23 January 2025 saying "consent or pay" models can be lawful if you can demonstrate that consent is still freely given, and it sets four factors to assess that: power imbalance, an appropriate fee, equivalence of the core service, and privacy by design. In the EU the bar is higher: the EDPB's Opinion 08/2024 says that in most cases a large online platform offering only "consent or pay" cannot obtain valid consent. If you are a mid-sized UK business with competitors a click away, a paywall for rejecting cookies is defensible on the ICO's framework — but you have to document the assessment, and you should assume the ground will shift.

This is not legal advice, and the position is unsettled on both sides of the Channel. What follows is what the regulators have actually published, with dates, and what the model does to your measurement.

The ICO says the model can be lawful, under four conditions

The ICO's guidance was published on 23 January 2025 and is direct about the principle: these models "can be compliant with data protection law if you can demonstrate that people can freely give their consent and the models meet the other requirements set out in the law."

The four factors it sets out are:

  • Power imbalance. Is there a realistic choice not to use you? Market position, network effects and switching costs all count. A social network with no substitute is in a different position from a regional news site.
  • Appropriate fee. Is the price of the "pay" option low enough that declining stays a real option?
  • Equivalence. Is the core service broadly the same whether someone consents or pays?
  • Privacy by design. Are both choices presented equally, with clear information and no design tricks?

Two obligations sit alongside those factors, and they're the ones people miss. You must assess the model "in the round" — no single factor decides it. And you must document that assessment inside a DPIA, because the ICO treats personalised advertising as processing likely to result in high risk. A consent-or-pay banner with no written assessment behind it fails on paperwork before anyone argues about the price.

"Equivalence" is about your product, not your banner

Equivalence has a narrow meaning that gets mangled in summaries. The ICO's test is whether your core service is broadly the same across the consent option and the pay option. You can add perks to either side; you cannot make the paid tier the only usable version of the product, and you cannot degrade the free-with-ads version to push people towards consent.

The EDPB uses similar-sounding language for a different idea. Its "equivalent alternative" is an alternative to consenting — a way to use the service without behavioural advertising and, ideally, without a fee. So the EU concept asks what else you offer beyond the binary; the UK concept asks whether the two things you already offer are the same product. Read a summary that blurs the two and you'll build the wrong thing.

The fee test ignores your costs and your lost revenue

This is the part of the ICO's guidance that most surprises people who read it properly, and the reason a "we modelled our ARPU" answer doesn't work.

The ICO says an appropriate fee means "the value that consumers associate with not sharing their personal data for the purposes of personalised advertising." It then rules three obvious methods out. Setting the fee from the revenue you'd lose reflects the value of advertising to you, not to the user. Setting it from your costs is a normal pricing input but not a data protection one. Benchmarking against what people pay for comparable services prices the service, not the privacy. All three, in the ICO's words, are "unlikely to be useful as a measure of whether a fee is appropriate in a data protection context."

What it asks for instead is evidence about your users: research into what they'd pay to avoid personalised advertising, both stated and revealed preferences, and an assessment of whether any group gets priced out. The ICO also says explicitly that it is not its job to set the number — the burden is on you to justify it.

One structural point worth building around: if you already charge a subscription, the fee under assessment is only the difference between the "consent" price and the "pay" price, not the whole bill. Bundling access to the product and avoidance of tracking into one combined price is what makes the fee look inappropriately high.

The EU position is stricter, and the guidelines that would settle it still don't exist

The EDPB adopted Opinion 08/2024 on 17 April 2024, at the request of the Dutch, Norwegian and Hamburg authorities. Its conclusion for large online platforms: "in most cases, it will not be possible for them to comply with the requirements for valid consent, if they confront users only with a choice between consenting to processing of personal data for behavioural advertising purposes and paying a fee." The Opinion's scope is limited to large online platforms — it does not settle the question for a normal business.

The EDPB said at the time it would produce broader guidelines. It hasn't. Its Work Programme 2026–2027, adopted on 11 February 2026, still lists "Guidelines on 'consent or pay' models" among guidance to be developed, and unlike three other projects in the same list it carries no marker showing that even a public-consultation draft exists. As of 28 July 2026 nothing broader has been adopted. If you see a blog citing a definitive 2026 EDPB position on consent or pay, check it against the EDPB's own documents before you act on it — we did, and the trail ends at the 2024 Opinion.

The enforcement that has actually happened came from a different instrument. On 23 April 2025 the European Commission fined Meta €200m under the Digital Markets Act for its binary pay-or-consent model, finding it did not give users the choice of a service using less of their personal data. On 8 December 2025 the Commission acknowledged Meta's undertaking to offer a third option — less personal data, more limited personalised advertising — presented to EU users in January 2026. That's the direction of travel in the EU: not a ban on charging, but pressure towards a genuine third door.

Your paying users become a hole in your advertising data

The commercial question is not whether you can charge. It's what the model does to the numbers your bidding depends on.

Every user who takes the "pay" option is, by design, invisible to your advertising stack: no personalised advertising means no advertising identifiers, no remarketing, no conversion attribution through the ads platform. That's not a bug to engineer around — routing their data to Google or Meta anyway through a tagging server would defeat the point of the option you sold them and hand a regulator a clean case. Treat the paying cohort as a segment you measure server-side against your own order data, and expect your Google Ads conversion count to sit below your real revenue by roughly that cohort's share.

The other effect is on the consenting cohort. Consent rates move when the choice architecture changes, and the ICO's privacy-by-design factor means you can't recover the difference by making "pay" deliberately unattractive. Whatever consent rate you land on is the one your Consent Mode modelling and your Smart Bidding will run on.

In the UK, the analytics exception changed more than the paywall did

If your interest in consent or pay is really "how do I stop losing my analytics", there's a cheaper answer that has nothing to do with charging anyone.

The Data (Use and Access) Act added exceptions to PECR, and the ICO finalised its guidance on them on 29 April 2026. The "statistical purposes" exception means you don't need consent for storage or access whose sole purpose is collecting statistical information about how your service is used, with a view to improving it. You still have to give clear information and "a simple means of objecting, free of charge".

The limits are strict, and the ICO spells them out. The exception covers aggregate statistics — visits, journeys, scroll depth, device types, referrers, A/B tests, page speed. It does not cover tracking or profiling individual visitors, and it does not cover online advertising at all. The ICO's table names the exact case that matters here: connecting a visitor ID to their site activity — a purchase, a conversion — "to be shared with advertising partners" requires consent. So a clean, aggregate, non-advertising analytics install may now run without a banner in the UK. Your Google Ads conversion tags never will.

Before you argue about paywalls, find out what your site does today. Our cookie scanner loads your live site and reports what fires before anyone clicks anything — which is where most exposure actually sits, as the PECR fine ceiling after DUAA made expensive.

Treat this as moving, because it is

The ICO's consent-or-pay guidance now carries a notice at the top of every page: because of changes made by the Data (Use and Access) Act, it "is under review and may be subject to change." As of 28 July 2026 neither section of the ICO's plans page that could hold it — general data protection, or privacy and electronic communications — lists a revised consent-or-pay guidance or a date for one. The only PECR item in development is an update to the small-organisation advice, due summer 2026.

So the honest summary for a UK business is: the four factors are the current published test, the guidance behind them is being revised with no announced date, and the EU's broader position is still unwritten. Build the model if the economics justify it, write the DPIA, keep the assessment somewhere you can update it, and don't let anyone sell you certainty about an area where the regulators have explicitly reserved their position.

If you want the measurement side handled properly — consent wired into your tags so the numbers match what people actually agreed to — that's what we do.

Sources

  1. 1.ICO — Consent or pay guidance (published 23 January 2025; carries an 'under review' notice following the Data (Use and Access) Act) · Published 23 January 2025, checked 2026-07-28
  2. 2.ICO — Consent or pay: appropriate fee · Checked 2026-07-28
  3. 3.EDPB — 'Consent or Pay' models should offer real choice (Opinion 08/2024) · 17 April 2024, checked 2026-07-28
  4. 4.EDPB — Work Programme 2026–2027, which still lists 'Guidelines on consent or pay models' as guidance to be developed · Adopted 11 February 2026, checked 2026-07-28
  5. 5.European Commission — Commission finds Apple and Meta in breach of the Digital Markets Act (€200m fine, Meta's pay-or-consent model) · 23 April 2025, checked 2026-07-28
  6. 6.European Commission — Meta commits to give EU users choice on personalised ads under the DMA · 8 December 2025, checked 2026-07-28
  7. 7.ICO — Guidance on the use of storage and access technologies, including the DUAA 'statistical purposes' exception · Finalised 29 April 2026, checked 2026-07-28

Find out what your site leaks — in 30 seconds

Run the free consent checker on your own domain, or book a call and we'll walk your setup together.