Skip to content
Apply
Guides / The law

Counting visits without a consent tick.

Since 5 February 2026, UK sites can count visits without consent, within limits. What the statistics exemption covers, what it never covers, and how to stay inside it.

Since 5 February 2026, a UK website can count its visits without asking for consent first. The Data (Use and Access) Act 2025 added an exception to PECR, the rules on cookies and anything else stored on a visitor's device, for statistics about your own site.

Most cookie banners haven't changed. Most marketers haven't noticed. And the exception is narrower than the headlines suggest, so it's worth reading exactly what it says.

What the exception says

You don't need consent to store or read something on a visitor's device if, in the words of the law:

"the sole purpose of the storage or access is to enable the person … to collect information for statistical purposes about how the service is used with a view to making improvements to the service, or … about how a website by means of which the service is provided is used with a view to making improvements to the website."

The ICO's plain-English version: the exception is about "the creation of aggregate statistical information about visitors to your service" and "your use of this information for the purpose of improving it".

The conditions, in plain English

  1. Statistics must be the only purpose. The word that matters is "sole". The moment the same cookie also feeds ads, the exception is gone for it.
  2. About how the site is used, not who uses it. The ICO: "It is about how your service is used, not about who uses it. It is not for identifying, tracking or monitoring people or groups of people who use your service."
  3. The result must be aggregate. You can collect visit-level information to build the statistics, but you must aggregate it, and the ICO says you can't keep the individual-level information afterwards or make decisions about people from it.
  4. Tell people clearly. You must give "clear and comprehensive information about the purpose".
  5. Give a simple, free way to object. An opt-out that works, and stays honoured.
  6. No one else uses it for their own ends. A third-party analytics provider is allowed, but it "must be a processor, not a joint controller", and may only use the information to help you improve your site.

What it never covers

The ICO is blunt: the exception "doesn't apply to things like online advertising". In practice, these all still need a yes first:

  • Ad pixels, retargeting and lookalike audiences.
  • Linking someone's visit or purchase to an ad they clicked. The ICO names this exact case as needing consent.
  • Profiling visitors by age, gender or interest to decide what to show them.
  • Anything sent to a platform that uses it for its own purposes.

Two examples from the ICO

The ICO gives a worked example. A publisher uses a third-party analytics script to measure scroll depth, time on page and bounce rate, to decide what to write next. That's inside the exception.

Then the publisher adds parameters to segment visitors by age group and gender, to decide which content to promote to whom. The ICO's verdict: it "cannot rely on the statistical purposes exception", because that "goes beyond the exception's scope by including profiling to target content".

Same script, same site. The purpose decides.

Does GA4 qualify?

A default GA4 setup sends data to Google, which can use it for its own purposes. So a default GA4 setup isn't built for the exemption. That isn't a ruling, and some configurations may get closer. But if your plan is to drop the banner and keep GA4 as it is, get advice first.

GA4 sets first-party cookies, on your domain. The question was never the cookie type. It's who the data goes to, and what they do with it.

Why it matters more now

PECR maximum fine
Before the 2025 ActAfter
£500,000£17.5m or 4% of global turnover, whichever is higher

Liability also changed. It now covers whoever sets or instigates the storage, not only the party whose code sets it. If your agency installed the pixel for you, that's worth a conversation.

The EU hasn't changed

This is a UK change. In the EU, the ePrivacy Directive still requires consent before storing or reading anything on a device that isn't strictly necessary. The EU has proposed similar changes, but they aren't law. If you have EU visitors, they still need a yes before anything non-essential.

A checklist for counting without consent

  1. Separate the purposes. The ICO suggests it may be easier to use a separate technology for each purpose. Statistics in one place, ads behind consent in another.
  2. Keep it on your own domain, with a provider that is your processor under a data processing agreement.
  3. Store nothing identifying in the statistics: no email, no IP address, no user agent.
  4. Say what you count in your privacy notice, in plain words.
  5. Put the opt-out where people will find it, and make sure it actually stops the counting.
  6. Keep the banner for everything else. Reject must be as easy as accept.

Where Clickfall fits. Clickfall's counting was built for this exception. It runs on your own subdomain, stores nothing identifying, keeps statistics only, and honours an opt-out. Ads and replay sit behind the banner. Splitting every report into counted, consented and estimated columns is in build.

This explains the law in plain English. It isn't legal advice.

Sources

  1. ICO: What are the exceptions? Guidance on the use of storage and access technologies
  2. ICO: Guidance on the use of storage and access technologies
  3. Data (Use and Access) Act 2025, legislation.gov.uk
  4. Directive 2002/58/EC (ePrivacy Directive), Article 5(3), EUR-Lex

Every source was checked on 3 Oct 2026. Spotted something out of date? Tell us and we'll correct it.

About the author

Seth Leech · Founder, Clickfall

Draft. The author's bio and photo go here before launch, in their own words.