Choose Your Creation Method

Create your PECR-compliant Cookie Policy using either our guided interview or direct editor

One-time payment: ยฃ10

โœ“ Both methods create the EXACT SAME compliant policy - only the creation process differs!

Recommended
โœจ

Smart Interview

Answer simple questions step-by-step. We'll build your PECR-compliant cookie policy automatically.

Completion Time
8 minutes
โšก

Expert Editor

Full control for experienced users.

Completion Time
4 minutes
Legal Requirements

Why You Need a Cookie Policy

UK law requires every website that uses cookies to have a compliant cookie policy and consent mechanism

โš–๏ธ

Legal Requirement

PECR Regulation 6 and GDPR Article 13 mandate cookie policies and explicit consent for non-essential cookies.

๐Ÿ›ก๏ธ

Protect Your Business

Avoid ICO fines up to ยฃ500,000 for PECR violations and ยฃ17.5 million for GDPR non-compliance.

โœ“

Build Trust

Transparent cookie practices increase user confidence and comply with industry best practices.

๐Ÿ“‹

What Must Be Included (ICO & PECR Requirements)

โ–ผ

Under PECR Regulation 6 and GDPR Article 13, your cookie policy must clearly state:

  • What cookies are - clear explanation in plain language
  • Which cookies you use - comprehensive list by category (essential, functional, analytics, marketing)
  • Purpose of each cookie - why each cookie is set and what data it collects
  • Cookie duration - how long each cookie remains active (session vs persistent)
  • Third-party cookies - all external services that set cookies (Google Analytics, Facebook Pixel, etc.)
  • How to manage cookies - instructions for blocking/deleting cookies in all major browsers
  • Consent mechanism - explanation of how users provide consent
  • Contact information - how users can contact you about cookie usage
  • Policy updates - when the policy was last updated and how changes are communicated

Our template includes all mandatory sections to ensure full ICO and PECR compliance.

โš ๏ธ

Penalties for Non-Compliance

โ–ผ

ICO Enforcement Powers:

  • PECR fines: Up to ยฃ500,000 for violations of cookie consent requirements
  • GDPR fines: Up to ยฃ17.5 million or 4% of annual global turnover for data protection breaches
  • Enforcement notices: Formal orders requiring immediate compliance
  • Audits: ICO can audit your website and cookie practices
  • Public reprimands: Damage to reputation through published enforcement actions

Recent ICO Cookie Enforcement:

In 2023, the ICO issued multiple fines for cookie consent violations, including fines for pre-ticked consent boxes, unclear cookie information, and failure to obtain proper consent before setting non-essential cookies. Common violations include using cookies before consent, bundling consent with terms acceptance, and failing to provide clear information about cookie purposes.

Don't risk it. Get compliant today for just ยฃ10.

๐ŸŽฏ

What's Included in Our Template

โ–ผ

Full PECR & GDPR Cookie Compliance:

  • โœ“ Plain language explanation of what cookies are
  • โœ“ Comprehensive cookie categorization (Essential, Functional, Analytics, Marketing)
  • โœ“ Detailed cookie tables with name, purpose, duration, and provider
  • โœ“ First-party and third-party cookie distinction
  • โœ“ Session vs persistent cookie explanations
  • โœ“ Cookie consent mechanism description
  • โœ“ Browser-specific cookie management instructions (Chrome, Firefox, Safari, Edge, Opera)
  • โœ“ Mobile browser cookie instructions (iOS Safari, Android Chrome)
  • โœ“ Third-party opt-out links (Google Analytics, Facebook, etc.)
  • โœ“ Web beacon and tracking technology disclosures
  • โœ“ Do Not Track (DNT) signal handling
  • โœ“ Cookie policy update procedures
  • โœ“ Contact information for cookie queries

Professional, legally sound, and ready to publish.

โŒ

Common Mistakes to Avoid

โ–ผ

Don't Fall Into These Traps:

  • Pre-ticked consent boxes: Consent must be active opt-in, not opt-out. Pre-ticked boxes violate PECR.
  • Cookie walls: Blocking access to websites unless users accept all cookies is illegal under PECR unless service genuinely cannot function.
  • Setting cookies before consent: Non-essential cookies must not be set until after explicit consent is obtained.
  • Vague cookie descriptions: Each cookie must have clear purpose, duration, and provider information.
  • Missing third-party cookies: Must disclose ALL cookies, including those set by Google Analytics, Facebook Pixel, advertising networks, etc.
  • No browser instructions: Users must be told how to manage cookies in their specific browser.
  • Bundling consent: Cookie consent cannot be bundled with terms & conditions acceptance.
  • Implied consent: "By continuing to use this site you consent to cookies" is not valid consent under PECR.
  • Missing essential cookie justification: Even "essential" cookies need explanation of why they're necessary.
  • Outdated cookie list: Cookie policy must be updated whenever new cookies are added.

Our template prevents all these mistakes with clear, compliant language and proper structure.

Quick Comparison

๐ŸŽฏ
Best For
Smart Interview for first-time users, Expert Editor for repeat customers
๐Ÿ“„
Final Document
Both create identical PECR-compliant cookie policies
๐Ÿ’ฐ
Price
Same price: ยฃ10 for either method

Frequently Asked Questions

Is this cookie policy PECR and GDPR compliant?

Yes. Our template includes all mandatory disclosures required under PECR Regulation 6 and GDPR Article 13. It covers cookie categories, purposes, durations, third-party cookies, consent mechanisms, and browser management instructions required by the ICO.

Do I need a cookie policy if I only use Google Analytics?

Yes. Google Analytics sets cookies that track user behavior, which requires both a cookie policy explaining what data is collected and explicit user consent before the cookies are set. You also need a cookie consent banner that complies with PECR Regulation 6.

What's the difference between a cookie policy and a privacy policy?

A cookie policy specifically explains what cookies your website uses, their purposes, and how users can control them. A privacy policy is broader and covers all personal data processing. Both are required under UK law - they can be combined into one document or kept separate. Our templates work as standalone documents or can be cross-referenced.

Can I use implied consent for cookies?

No. Under PECR, consent for non-essential cookies must be explicit opt-in action. Implied consent ("By continuing to browse you accept cookies") is not compliant. You need a clear consent mechanism where users actively accept cookies before they are set. Essential cookies (strictly necessary for website function) don't require consent but must be clearly explained.

Why We Offer Two Methods

Different users prefer different approaches. Some like guided assistance to ensure nothing is missed, while others prefer seeing everything at once for faster completion. We've created both options to match your working style. The final Cookie Policy is identical regardless of which method you choose.