UK ICO Releases Timely Additional Guidance on Cookie Compliance
Time 2 Minute Read

On May 25, 2012, the UK Information Commissioner’s Office posted updated guidance on how to comply with amendments to EU data protection law requiring businesses to obtain consent from website visitors to store information on their computers and retrieve that information in the form of cookies. Last year, the ICO gave organizations a grace period expiring on May 26, 2012, to comply with the new cookie rules.

The ICO’s guidance includes the following observations:

  • there is no “one-size-fits-all” solution to suit every organization;
  • being “clear, honest, open and upfront about cookies” is an easy first step towards compliance;
  • the ICO recognizes that this is not an easy area for organizations to comply with; and
  • using monetary penalties as an enforcement option has not been ruled out, but formal undertakings and enforcement notices are likely to be more useful in achieving compliance.

The guidance also reiterates a point made in earlier guidance that implied consent can be a valid form of consent, but only where it is clear that the user understands that their actions will result in a cookie being deployed. An example of an implied consent mechanism is used in the ICO’s blog post itself, which includes the following banner above a link to a video: “NB: playing YouTube video sets a cookie.”

The guidance stresses that work is “ongoing,” and, accordingly, it is unlikely that we will see a deluge of ICO enforcement actions following the expiration of the grace period tomorrow. That said, the ICO has written to 50 organizations to ask about their cookie compliance programs.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 2 Minute Read

On March 25, 2026, the UK Information Commissioner’s Office and the UK Office of Communications released a joint statement addressing the intersection of online safety and data protection in relation to age assurance.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page