PECR fines after DUAA 2026: what the new £17.5m ceiling actually means
The Data (Use and Access) Act raised the maximum PECR/cookie fine from £500k to £17.5m or 4% of turnover, in force 5 February 2026. Here's what changed, who's exposed, and what to do about it.
For twenty years, PECR — the Privacy and Electronic Communications Regulations — was the toothless cousin of UK data law. The maximum fine was £500,000. For a company doing real revenue, that was a rounding error, and everyone treated it that way.
That ended on 5 February 2026.
What DUAA changed
The Data (Use and Access) Act 2025 (DUAA) raised the maximum penalty for PECR breaches — which includes cookie and tracking violations — from £500,000 to £17.5mor 4% of global turnover, whichever is higher. That aligns PECR penalties with UK GDPR.
The number that matters isn't £17.5m. It's 4% of global turnover. For most SMBs that's the higher figure, and it scales with your success.
At the same time, the ICO published its Online Tracking Strategy, naming cookies and similar technologies an enforcement priority. So the ceiling went up and the appetite to use it went up in the same window.
Who is actually exposed
The uncomfortable truth from scanning real sites: the businesses most exposed aren't the ones with no cookie banner. They're the ones with a banner that doesn't work.
- Analytics and advertising cookies (
_ga,_gid,_gcl_au,_fbp) set before the user consents. - Trackers firing network requests to Google, Meta or Hotjar before the "Accept" click.
- A Consent Management Platform (CMP) installed but never configured to actually block those tags.
A working banner enforces consent. A decorative one just records that you knew you needed one.
What "compliant" requires under PECR
- No non-essential cookies or trackers before consent. Strictly-necessary cookies are fine; analytics and ads are not, until the user agrees.
- A genuine choice. Reject must be as easy as accept — no pre-ticked boxes, no cookie walls that punish declining.
- Consent that propagates to your tags. This is where most setups fail: the banner shows, the user clicks, but the tags fired on page load regardless.
The connection to Google Ads
Here's the part most compliance articles miss: fixing consent properly usually reduces your reported conversions by 15–40%, because you were counting data you weren't allowed to collect.
That's not a reason to avoid fixing it. It's a reason to fix it and recover the signal legitimately — through Google Consent Mode v2 (which lets Google model the conversions consent hides) and, where the numbers justify it, server-side GTM.
Consent isn't only a legal line item. Done right, it changes what Google Ads sees — and therefore how Smart Bidding spends your budget. That's why we treat it as a performance project, not a checkbox.
What to do this quarter
- Scan your own site. Find out what actually fires before consent — run our Google Ads consent checker or cookie scanner.
- Fix enforcement, not just the banner. Wire consent into your tags so nothing fires early. See how we fix Consent Mode v2.
- Recover the signal. Set expectations for the data drop, then use Consent Mode modelling and server-side tagging to get the legitimate signal back.
The £500k era let everyone procrastinate. The 4%-of-turnover era doesn't. The good news: the fix is well understood, fully reversible, and pays for itself in cleaner bidding data.