10 minutes read

UK DUAA Implementation: What Changes for Consent and Cookies

UK DUAA Implementation What Changes for Consent and Cookies - icon

Table of Contents

Introduction

The Data Use and Access Act 2025 is a reform legislation that was granted royal assent on 19 June 2025. Its provisions apply in stages: most cookie and data protection law changes took effect on 5 February 2026, while complaints-handling obligations activate on 19 June 2026.

  • DUAA does not replace UK GDPR, the Data Protection Act 2018, or PECR. It amends all three to modernize data use and access rules, support innovation, and tighten enforcement tools.
  • Three legal pillars are affected: UK GDPR (general data protection), the Data Protection Act (law enforcement and intelligence processing), and PECR (electronic communications, cookies, and direct marketing).
  • The DUAA applies to any website collecting data from UK visitors, regardless of where the business is based. A Shopify store in the US or Germany with UK customers falls within scope.
  • The DUAA introduces a seventh lawful basis for processing personal data: recognized legitimate interests. This basis does not require a balancing test, but it applies only to specific public-interest purposes such as crime prevention, safeguarding, and protecting public security. Commercial activities still require a full balancing assessment under the standard legitimate interests basis.
  • The DUAA also clarifies response time for data subject access requests. The one-month response clock starts upon receiving the request. Controllers must conduct reasonable and proportionate searches for requested information. A “stop the clock” rule allows organizations to pause the deadline while awaiting additional information from the requester.
  • The Information Commissioner’s Office (to be renamed the Information Commission) remains the regulator issuing regulatory guidance on DUAA implementation. Monitor ico.org.uk and GOV.UK for commencement regulations and updated guidance.

DUAA’s most visible impact for online services is on cookie consent and other access technologies: cookies, pixels, local storage, fingerprinting, and similar scripts running on a user’s device.

  • Core PECR cookie rules remain intact. Setting or accessing cookies on a user’s device generally requires clear, comprehensive information and valid consent, except in narrowly defined circumstances.
  • DUAA introduces additional exemptions for low-risk analytics and appearance-related cookies, but these are tightly scoped and purpose-based. The law introduces targeted exemptions for low-risk storage and access technologies.
  • The DUAA has separate provisions regarding the necessity of consent for advertising and profiling cookies. Advertisers must still obtain consent for cross-site tracking and behavioral profiling after DUAA implementation. Nothing in DUAA removes that requirement.
  • The DUAA maintains a distinction between PECR consent and UK GDPR consent requirements. Even if a cookie is exempt from PECR consent, if it processes personal data, you still need a lawful basis under UK GDPR.
  • The legal focus shifts from broad “cookie categories” (e.g., “performance cookies”) to concrete purposes. A cookie labeled “analytics” may or may not need consent depending on whether it solely collects aggregate statistics or feeds into ad attribution. The following sections unpack this distinction.

DUAA expands the list of PECR exceptions for website cookies and access technologies. The DUAA introduces five cookie consent exemptions in total, covering statistical measurement, appearance adaptation, emergencies, plus the existing strictly necessary and communication transmission exceptions.

Statistical exception: Consent is no longer required for cookies used for first-party analytics, provided the sole purpose is to collect aggregate statistics about service usage. Analytics cookies must not identify individual users to qualify for the statistical exception under DUAA. The data must remain aggregated; sharing is permitted only if the third party assists with service improvement, and the website operator must provide a clear opt-out that is simple and free to use.

For example, a Shopify store that uses a self-hosted analytics tool to count page visits and session durations, with no link to ad platforms, can rely on this exception. The same store using Google Analytics with advertising features, demographic reports, or Google Ads linking cannot; that configuration requires consent.

Appearance exception: User preferences regarding how a website appears can be stored without obtaining consent. This covers cookies that remember language selection, font size, dark mode, currency display, or layout choices. The cookie’s sole purpose must be adapting the site’s appearance or functionality based on the user’s explicit preference. If appearance adaptation is driven by inferred behavior, browsing history, or profiling, the exception does not apply.

Emergency assistance exception: Emergency communications may use specific tracking technologies without prior consent when the sole purpose is to identify a device’s geographic location so someone can request emergency assistance.

Existing exceptions retained: The DUAA allows organizations to use cookies for security and fraud prevention without consent (strictly necessary exception). Cookies for technical diagnostics and error fixing may operate under specific exemptions without consent. The communication transmission exception also remains unchanged.

Certain categories of tracking technologies are exempt from prior user consent under DUAA, but only when the purpose is sole and narrow. If even one additional purpose exists (advertising, profiling, cross-site sharing beyond service improvement), the exemption fails, and consent is required.

EU and UK flags

Under DUAA, “why” and “how” a technology is used matters more than the label you assign to it.

The same analytics tool might qualify for the statistical exception on one site (aggregated, internal metrics only) but require consent on another (where linked to ad platforms or user profiling). A cookie tagged “performance” in your consent banner is not automatically exempt; the actual data flow determines the legal status.

Old category-based consent models sorted cookies into buckets like strictly necessary, performance, analytics, and marketing. DUAA demands purpose-based assessments: is this cookie solely for service operation? Service improvement? Targeted advertising? Security? Document each technology with its specific purpose, legal basis (consent, exemption, or legitimate interests), and geographic scope (UK vs EU visitors). This documentation feeds directly into records of processing activities and your cookie inventory.

Organizations must now explain cookie use and offer opt-out options for any technology relying on a DUAA exemption. The opt-out must be simple, free, and visible without friction. Burying it in a multi-layer menu does not satisfy the requirement.

Pandectes supports this shift by allowing Shopify merchants to configure different purposes and behaviors per script, cookie, and region. You can apply DUAA exemptions for qualifying analytics on UK traffic while keeping full consent prompts for EU visitors, all within a single dashboard.

A Google-Approved Consent Platform for Shopify
Pandectes is an official Google Certified Consent Management Platform and is fully compatible with Google Consent Mode v2 and global privacy regulations.

Enforcement, Fines, and Data Protection Complaints Handling

DUAA arms the ICO with enforcement tools that match the scale of UK GDPR penalties. Maximum fines for cookie violations increased to Β£17.5 million or 4% of global annual turnover, whichever is higher. The ICO’s maximum fine for PECR breaches now matches UK GDPR levels. Before DUAA, PECR fines were capped at Β£500,000; the jump is thirty-five-fold.

The ICO can impose fines of up to Β£17.5 million for PECR breaches. The ICO can also compel witnesses to attend interviews, require specific documents for investigations, and appoint individuals to produce compliance reports. These powers apply to cookie consent violations, unlawful direct marketing, and non-essential cookies deployed without a valid basis.

DUAA requires organizations to implement a formal data protection complaints mechanism. The process must include an accessible electronic complaints form, acknowledgment of complaints within 30 days, investigation without undue delay, and an outcome communicated to the complainant before they escalate to the ICO. This obligation takes effect on 19 June 2026.

Robust consent logs and cookie records are the front line of defense when responding to complaints or ICO investigations. If a user complains that your store set persistent cookies or ran third-party tools without consent, you need timestamped, georeferenced proof of what banner was shown, what the user chose, and when. A consent management platform like Pandectes maintains this audit trail automatically for Shopify stores.

While the article focuses on consent and cookies, DUAA also updates three areas that intersect with online tracking: automated decision making, children’s data, and broad consent for scientific research.

Automated decision-making: DUAA permits significant automated decisions (those with legal or similarly significant effects) on a wider range of lawful bases, provided individuals receive notice, can contest the decision, and can obtain human intervention for review. Special category data still carries stricter restrictions. Automated processing that relies on profiling built from cookies or tracking technologies must satisfy both cookie consent rules and ADM transparency requirements. All ADM activities should be recorded in your records of processing activities with a valid lawful basis under UK GDPR as amended.

Children’s data: The DUAA requires online services to consider children’s needs in service design. Children’s data protection rules apply to users under 18 years old. Compliance with the ICO’s Age Appropriate Design Code is expected for any online services likely to be accessed by children. Profiling, personalized content, and targeted advertising towards children face higher scrutiny. Failure to comply with children’s data rules may invite regulatory action, including UK GDPR-level fines.

Broad consent for research: DUAA clarifies that scientific research, including commercial research and statistical processing, can proceed under broad consent in defined contexts. Reuse of data for new research may be permitted under appropriate safeguards. This does not convert generic marketing analytics into scientific research; marketers still need a valid basis such as consent or a qualifying exemption.

A personalization engine that adjusts product recommendations based on automated processing of browsing history across multiple websites is both an ADM concern and a cookie consent concern. Similarly, A/B testing for a children’s clothing store that tracks individual user behavior to optimize layouts would not qualify for the statistical exception and would require both consent and adherence to the Age Appropriate Design Code.

International Data Transfers, Direct Marketing, and the Wider Data Protection Landscape

DUAA is part of a broader UK effort to recalibrate data use and access rules post-Brexit while maintaining workable international data transfers.

  • The Act shifts terminology from “adequacy decisions” to “data bridges.” Organizations must still carry out transfer assessments and use standard contractual clauses or the International Data Transfer Agreement where no bridge exists.
  • DUAA confirms the role of legitimate interests for certain forms of direct marketing and extends soft opt-in concepts (for example, to charities). But PECR consent rules for email, SMS, and most electronic communications channels still apply.
  • Direct marketing by email, SMS, and many online tracking techniques remains tightly regulated. DUAA’s new cookie exemptions do not create a blanket pass for advertising technologies. The statistical and appearance exceptions specifically exclude advertising, cross-site tracking, and behavioral profiling.
  • These elements connect back to overall data protection compliance. The Data Protection Act 2018 and UK GDPR require consistent lawful bases, transparency via a privacy notice, and records across all data use and access channels.
man on computer

DUAA’s cookie changes are UK-specific and do not alter EU GDPR or the ePrivacy Directive. A UK cookie compliance setup cannot simply be copied for EU visitors.

  • For EU users, analytics cookies and similar access technologies generally still require prior consent unless they are strictly necessary for the service requested. The EU has no equivalent of DUAA’s statistical or appearance exceptions.
  • Businesses should maintain region-aware consent experiences. UK visitors may see more permissive defaults for qualifying low-risk analytics, while EU visitors must actively consent to non-essential cookies.
  • PECR penalties now rival EU GDPR fines, so misconfiguring cookie consent for UK or EU audiences is equally risky.
  • Pandectes helps Shopify stores run dual or multi-regional consent strategies by geotargeting banners, differentiating access technologies by region, and enforcing different consent rules for the UK, EU, and other jurisdictions from a single integration.
A Google-Approved Consent Platform for Shopify
Pandectes is an official Google Certified Consent Management Platform and is fully compatible with Google Consent Mode v2 and global privacy regulations.

This section is a concise checklist for teams updating their UK privacy program in response to DUAA.

  1. Audit all storage and access technologies: Map every cookie, pixel, SDK, local storage item, and fingerprinting script on your store. Tag each with its purpose, vendor, personal data involved, and whether it targets UK users.
  2. Classify against DUAA criteria: For each technology, determine whether it qualifies as strictly necessary, appearance adaptation, statistical analytics, advertising/marketing, security/fraud detection, or something else. Flag items that might qualify for exemptions and document why.
  3. Update cookie consent banners and consent flows: UK visitors should receive clear information, meaningful choices (including Accept All and Reject All), and granular controls aligned to purposes rather than generic categories. Website operators must provide clear and comprehensive information about tracking technologies to satisfy both PECR and DUAA.
  4. Georeference and timestamp consent logs: Record each user’s choices with location data for audit and complaint handling. Pandectes automatically maintains these records for Shopify stores.
  5. Update privacy notices and internal documentation: Your privacy notice, records of processing activities, internal policies, and training materials should reflect DUAA changes, including complaint handling routes, any reliance on DUAA cookie exemptions, and the new draft guidance from the ICO finalized on 29 April 2026.

How Pandectes Supports DUAA, PECR, and Data Protection Act Compliance

Pandectes GDPR Compliance app is a Google-certified consent management solution built for Shopify merchants who need coverage across GDPR, UK GDPR, PECR, CCPA, LGPD, and other global privacy frameworks.

  • The app scans Shopify stores to discover all cookies and access technologies, classifies them by purpose, and lets merchants configure DUAA-aligned categories: strictly necessary, statistical analytics, appearance, marketing, and more.
  • Region-specific behavior means UK visitors benefit from DUAA exemptions where appropriate, while EU and other regions continue to receive full consent prompts where local data protection law requires them.
  • Granular cookie consent banners with Accept All, Reject All, and detailed preference centers support multilingual configurations and legal templates that reference DUAA, the Data Protection Act 2018, and UK-specific rules.
  • Pandectes keeps audit-ready consent and preference logs, giving merchants evidence they can present during ICO investigations, data protection complaints, and broader compliance audits.

Conclusion

The UK Data Use and Access Act 2025 (DUAA) brings significant changes to consent and cookie management, emphasizing purpose-based assessments and introducing new exemptions for low-risk analytics and appearance-related cookies. With increased ICO enforcement powers and higher fines, compliance is more critical than ever. Businesses serving UK visitors must update their consent mechanisms, maintain detailed audit trails, and implement robust complaints handling to navigate the practical implications of DUAA effectively. Tools like Pandectes can simplify compliance, helping Shopify stores meet evolving UK data protection requirements with confidence.

Make Your Shopify Store Fully GDPR & CCPA Compliant Today
Pandectes GDPR Compliance App for Shopify
Share
Subscribe to learn more
pandectes