PERFMETRIX — in data we trust
All articles
PECR24 June 2026·Updated 25 July 2026·6 min read

PECR fines after DUAA 2026: what the new £17.5m ceiling actually means

DUAA raised the maximum PECR/cookie fine from £500k to £17.5m or 4% of turnover, in force 5 February 2026. What changed, and who's exposed.

DeBy Denis · Perfmetrix

Short answer: the maximum PECR fine went from £500,000 to £17.5m or 4% of global turnover on 5 February 2026, and it applies to conduct from that date onwards — earlier breaches still sit under the old cap. The businesses most exposed aren't the ones without a cookie banner. They're the ones with a banner that renders but doesn't block anything, because that's a breach that looks like compliance from the inside. Scan your own site before you do anything else; you cannot reason about your exposure from the admin panel.

This is not legal advice, and the enforcement picture is still forming. What follows is what changed and what we'd check.

For twenty years, PECR — the Privacy and Electronic Communications Regulations — was the toothless cousin of UK data law. The maximum fine was £500,000. For a company doing real revenue, that was a rounding error, and everyone treated it that way.

What DUAA changed

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and the majority of its provisions came into force on 5 February 2026. It raised the maximum penalty for PECR breaches — which includes cookie and tracking violations — from £500,000 to £17.5mor 4% of global turnover, whichever is higher. That aligns PECR penalties with UK GDPR, and it is roughly a 35-fold increase in the cap.

The number that matters isn't £17.5m. It's 4% of global turnover. For most SMBs that's the higher figure, and it scales with your success.

One detail that gets lost in the headline, and that matters if you're assessing historic risk: the ICO has confirmed the new powers apply to conduct occurring after 5 February 2026. A breach that happened before that date is still judged against the old £500,000 ceiling. So the question isn't "were we ever non-compliant" — it's "are we non-compliant now, and for how long have we been so since February."

The Act also widened what the ICO can do procedurally, including compelling witnesses to interview and requiring technical reports. That's arguably the more significant change for a tracking dispute, because the technical facts of what your site fires are exactly the kind of thing a technical report settles.

The regulator was already moving

The penalty change didn't arrive in a vacuum. The ICO had spent the previous year running a programme against cookie compliance specifically.

It began by assessing the UK's top 200 websites and writing to 134 of them setting out where they fell short. It then extended the exercise toward the top 1,000, opening investigations where engagement didn't produce change and issuing preliminary enforcement notices in a number of cases. By December 2025 it was publishing results on how many of those sites had improved.

Two things follow from that. First, the ICO has a working method for this — it doesn't need a complaint to find you, it scans. Second, the pattern of enforcement so far has been graduated: letter, then investigation, then notice. The £17.5m ceiling is what sits at the end of that path, not the opening move.

If you're a mid-market UK business, you are not currently in the top 1,000 websites and are unlikely to be scanned tomorrow. That's a reason to fix this calmly rather than a reason to ignore it — the ICO has said it will keep testing periodically, and the method scales.

Who is actually exposed

The uncomfortable truth from scanning real sites: the businesses most exposed aren't the ones with no cookie banner. They're the ones with a banner that doesn't work.

  • Analytics and advertising cookies (_ga, _gid, _gcl_au, _fbp) set before the user consents.
  • Trackers firing network requests to Google, Meta or Hotjar before the "Accept" click.
  • A Consent Management Platform (CMP) installed but never configured to actually block those tags.

A working banner enforces consent. A decorative one just records that you knew you needed one.

What "compliant" requires under PECR

  1. No non-essential cookies or trackers before consent. Strictly-necessary cookies are fine; analytics and ads are not, until the user agrees.
  2. A genuine choice. Reject must be as easy as accept — no pre-ticked boxes, no cookie walls that punish declining.
  3. Consent that propagates to your tags. This is where most setups fail: the banner shows, the user clicks, but the tags fired on page load regardless.

The connection to Google Ads

Here's the part most compliance articles miss: fixing consent properly will reduce your reported conversions, because you were counting data you weren't allowed to collect. Expect the number to fall, and plan for the conversation with whoever owns the target.

We're deliberately not quoting you a percentage. The size of the drop depends on your consent rate, your traffic mix and how badly the previous setup was over-collecting, and there is no public benchmark we'd trust enough to repeat. Anyone quoting you a precise figure before looking at your site is guessing.

That drop is not a reason to avoid fixing it. It's a reason to fix it and recover the signal legitimately — through Google Consent Mode v2 (which lets Google model some of what consent hides) and, where the numbers justify it, server-side GTM.

Consent isn't only a legal line item. Done right, it changes what Google Ads sees — and therefore how Smart Bidding spends your budget. That's why we treat it as a performance project, not a checkbox.

What to do this quarter

  1. Scan your own site. Find out what actually fires before consent — run our Google Ads consent checker or cookie scanner.
  2. Fix enforcement, not just the banner. Wire consent into your tags so nothing fires early. See how we fix Consent Mode v2.
  3. Recover the signal. Set expectations for the data drop, then use Consent Mode modelling and server-side tagging to get the legitimate signal back.

The £500k era let everyone procrastinate. The 4%-of-turnover era doesn't. The good news: the fix is well understood, fully reversible, and pays for itself in cleaner bidding data.

Sources

  1. 1.ICO — Statement on the commencement of the Data (Use and Access) Act · February 2026
  2. 2.ICO — Our work on online tracking · Checked 2026-07-25
  3. 3.ICO — Action to tackle cookie compliance across the UK's top 1,000 websites · January 2025
  4. 4.ICO — Action secures increased cookie compliance · December 2025
  5. 5.Perfmetrix — UK private clinic consent benchmark (our own scan data) · 2026-07-08

Find out what your site leaks — in 30 seconds

Run the free consent checker on your own domain, or book a call and we'll walk your setup together.