Counting Heads Without Asking: The UK's New Analytics Cookie Exemption
Picture a small shop on a high street in the north of England. At the door stands a clerk with a brass tally counter. His job is simple: click once for every person who comes in, so that at the end of the week the owner knows that Tuesdays are busy, that nobody visits the back room, and that the new window display did nothing at all.
For about fifteen years, the rules said the clerk had to ask first.
Ask each customer, that is. Before the first click, he had to explain the counter, the click and the number, and wait for a clear yes. Silence: no click. Walking past: no click. "Maybe later": remember it, do not ask again too soon, and do not forget to ask at all. So he got a clipboard. Then a laminated card with the options set out in equal font sizes. Then a second, "customise" card for the people who wanted to accept the clicking but not the tally sheet. Then a lawyer. By the end, the entrance to the shop was a narrow corridor lined with consent forms, the clerk had developed a nervous twitch, and the owner's weekly report said "visitors: some, probably".
That is roughly how analytics cookies have worked in the UK, which is why you cannot read a recipe for scones without first making a legal decision.
Put the clicker down for a second. On 5 February 2026, part of that changed. The UK's Data (Use and Access) Act 2025 added new exceptions to the cookie rules in PECR, the Privacy and Electronic Communications Regulations. One of them, the "statistical purposes" exception, lets a website count how it is used without asking first, as long as it tells people and gives them "a simple means of objecting, free of charge". The clerk can click. He just has to stop when someone rings the little bell and says, "Not me, thanks."
Clifford Chance, writing the day after the changes took effect, summarised the other half of the news in one line: the maximum fine for breaking the PECR rules rose from £500,000 to "£17.5 million or 4% of global annual turnover". So the same week the UK made cookie consent easier for some analytics, it made getting cookies wrong about thirty-five times more expensive.
The catch most of the celebration missed: the exception is narrow. It covers statistics about how your site is used, not tracking the people who use it, and nothing to do with advertising. If a third-party tool does the counting, that tool must work only for you. Whether you pass depends on four or five admin settings that most people clicked through once, years ago.
So my plan: what the law says, clause by clause, and where the fines come from. Then the idea underneath it, counting heads versus following people. Then the helper problem, where we open Google Analytics 4. Then the opt-out, down to the tag. Then a quick trip to Brussels, where a similar idea was still only a proposal as of February. And last, a worked check on one fictional shop that you can copy this week.
Let's get into it.
What Changed on 5 February
First, my usual disclaimer from the Google Analytics and GDPR post: I am not a lawyer. I can explain the machines; I am not your solicitor, and this is not legal advice.1 Happily, the legal part of this story is short.
The old rule, in one sentence
PECR regulation 6 says you must not store information on someone's device, or read it, unless they have consented after clear and comprehensive information. That covers cookies, local storage, pixels and fingerprinting scripts alike. Until February there were only two ways out: "communication" (needed to carry the message) and "strictly necessary" (the user asked for a service that cannot work without it). A basket cookie is strictly necessary. An analytics cookie never was.
The new rule: Schedule A1
The Act did not rewrite regulation 6. Section 112 and Schedule 12 insert a new Schedule A1 into PECR that lists the exceptions in one place. The government's Commencement No. 6 Regulations, made on 29 January 2026, switched section 112 and Schedule 12 on from 5 February, along with most of the other data protection changes in the Act. The Department for Science, Innovation and Technology described that instrument as bringing "the majority of the data protection and privacy provisions in Part 5" into force on that day.
Schedule A1 now holds five exceptions, and the ICO's draft guidance names them neatly: communication, strictly necessary, statistical purposes (which it says is "also known as the 'analytics' exception"), appearance, and emergency assistance. Appearance covers things like remembering a user's language; emergency assistance finds a device after someone asks for help. Neither is why your marketing team is excited.
Paragraph 5, the one that matters
The statistical purposes exception is paragraph 5 of Schedule A1. It is five conditions long, and every one of them must be true. Paraphrasing closely, the storage or access is allowed without consent if:
- (a) the person doing it provides an information society service (a website or app, in practice; paragraph 1 says "website" includes apps);
- (b) its "sole purpose" is to collect information for statistical purposes about how the service, or the website, is used, "with a view to making improvements" to it;
- (c) the information is "not shared with any other person except" to let that person help make those improvements;
- (d) the user is given "clear and comprehensive information about the purpose of the storage or access"; and
- (e) the user is given "a simple means of objecting, free of charge, to the storage or access and does not object".
Paragraph 5(3) says that for repeat use on the same device, (d) and (e) only have to be met "in respect of the initial use": tell people once, offer the opt-out once. Paragraph 5(2) says the exception does not cover "collecting or monitoring information automatically emitted by the terminal equipment", which rules out the shop-floor trick of counting phones by the signals they broadcast.2
Read them again with the clerk in mind. (b) is "you only count". (c) is "you only tell the owner, or someone helping her". (d) is the sign on the door. (e) is the little bell.
Where the £17.5 million comes from
Before February, PECR borrowed its fining power from the old Data Protection Act 1998, and the maximum was set at £500,000 by regulations in 2010. Section 115 and Schedule 13 of the new Act replace that with the enforcement regime of the Data Protection Act 2018, modified for PECR. Paragraph 18 of Schedule 13 then tells section 157 of the 2018 Act, the section on maximum penalties, which PECR regulations get the "higher maximum amount": regulation 5, 6, 7, 8, 14, 19, 20, 21, 21A, 21B, 22, 23 and 24. Everything else in PECR gets the "standard maximum amount". And section 157 itself sets the higher maximum for an undertaking at £17,500,000 or 4% of its total annual worldwide turnover, whichever is higher, and the standard maximum at £8,700,000 or 2%.
Regulation 6 is the cookie rule, so cookies sit in the top band, alongside the direct marketing rules in regulations 19 to 24.
A maximum is a ceiling, not a price list. The ICO's enforcement chapter, as it stood in late February, said the Regulatory Action Policy still applies to PECR and that the ICO will "reserve monetary penalties for the most serious infringements". Nobody will fine a local bakery £17.5 million for a wordy banner, but the ceiling changes the conversation in a boardroom.
And the ICO has shown that it is watching large sites. In December 2025, it said that 979 of the UK's top 1,000 websites met its compliance checks at their latest test, that it had issued 17 preliminary enforcement notices along the way, and that it would keep re-testing. Tim Capel, its interim executive director of regulatory supervision, said the aim was to make sure sites "do not simply revert to their previously unlawful practices because they think it will go under the radar". That was said when the cap was £500,000.
The guidance was still a draft
One more fact frames everything below. When the law changed on 5 February, the ICO's detailed guidance on cookies and similar technologies was still in draft. Its "About this guidance" page, as captured on 25 February, said the guidance was "still in draft form" and that the ICO would "finalise it following the second consultation on the new chapter". That consultation, on the chapter about the exceptions, closed on 26 September 2025. Clifford Chance's February note said further ICO guidance on storage and access technologies was expected in spring 2026.
So, as of February: a law in force, a regulator's draft, and no final word. Everything I quote from the ICO below is from that draft, and it may still change.
My favourite detail from that period is small. On the very page where the ICO's draft explained you may now run analytics on an opt-out basis, the ICO's own website, as captured on 25 February, was still showing a cookie banner that said, "We'd like to set analytics cookies to understand how you use this site", with buttons to accept or reject non-essential cookies.3 The regulator was still asking first. That is not a gotcha. It is the honest picture of the transition: the law had moved, and the sensible response was to look carefully before ripping out the banner.
Counting Heads Versus Following People
The whole exception rests on one distinction, and it is one you already make every day without a name for it.
You already know the difference
The clerk knows that 312 people came in on Tuesday, and not who any of them were. Now imagine a second employee who follows one customer round the shop with a notebook, notes that she came in last Thursday too, and hands the notebook to the shop next door so it can post her a flyer for walking boots. Both are "measuring the shop". Only one would make you call the police. The first is counting; the second is following.
The ICO's name for it
The ICO's draft puts the same line into words better than I can: the statistical purposes exception "is about how your service is used, not about who uses it". It goes on: "It is not for identifying, tracking or monitoring people or groups of people who use your service. It also doesn't apply to things like online advertising."
The draft's table of what is likely to fit is more generous than some expected. Likely inside, when you use aggregate statistical information:
- total visits to your website, page by page, to understand user journeys;
- interactions with pages, like average scroll depth or the total hits on a section;
- device types and browser or operating system versions;
- how people reached you, for example the referrer from an email campaign or a search result;
- A/B testing, where you split users into two groups to compare two versions of a page;4
- coarse geolocation, at city or region level, that does not identify anyone; and
- page loading speeds and exit pages.
And outside it, needing consent: logs or recordings of individual visitors and what they did; information on whether users viewed or clicked an advert, for measuring that advert; connecting a visitor ID to purchases so that the "conversions" can be shared with advertising partners; profiling individual visitors or categories of visitors; and monitoring browsing across different services.5
"User journeys" are in, but "recordings of individual visitors" are out. A journey, in the ICO's sense, is the pattern: "most people on the pricing page go to the FAQ next". A recording is the notebook. The pattern is allowed. The notebook is not.
How the machine does the counting
An analytics tool cannot see "312 people". It sees events: a script in the page sends a message to the provider each time something happens. To turn events into "visitors", it must know which came from the same browser. That is the cookie's job. Google Analytics 4, for example, sets a first-party cookie called _ga that Google's own help page says is "used to distinguish users", with a default expiry of two years, and a second cookie that holds the session state.
So even pure counting needs a moment of recognition: to say "312 people, not 900 page views", the tool must briefly know which events came from which browser. The count is anonymous. The raw material is not.
The ICO's draft deals with exactly this, and it is the most technical, most important passage in the chapter. It borrows the UK GDPR's definition of statistical purposes: processing to produce statistical results where the information "that results from the processing is aggregate data that is not personal data", and where the controller does not use it for "measures or decisions with respect to a particular data subject". It accepts that you will probably collect individual-level information along the way, which may be personal data. Then it sets two rules. You must aggregate it. And you must not "retain the individual-level information (after aggregating it)". It even suggests a rhythm: "You could consider daily aggregation to be appropriate for your service", and hourly for some data points on busy sites.
That is the real mechanism. The exception is not about whether a cookie exists; it is about what the system keeps. A counting system turns rows into totals and throws the rows away. A following system keeps the rows, because the rows are the product: segments, audiences, retargeting lists. Keeping the rows for months is exactly the part most tools are built to do.

What that means for GA4
GA4 keeps two kinds of data. Its standard reports are aggregated. Its explorations, the flexible screens where you build funnels and look at user paths, work on user-level and event-level data. Google's retention settings let you keep that user-level data for two months or 14 months on a standard property, and Google notes that the retention setting "does not affect standard aggregated reports". In other words, GA4 builds its totals and also keeps the rows, for as long as you tell it to.
Against the ICO draft, that is a tension: aggregate, then do not keep the rows, versus rows kept for at least two months by design. The draft gives no clean answer. My reading: a GA4 property set to the shortest retention, with nothing that identifies a real person attached to its rows, is the strongest case GA4 can make under paragraph 5. It is still an argument, not a certainty. A tool that aggregates and discards the rows by design makes the case without needing an argument at all.
One more GA4 detail. Google says GA4 "does not log or store IP addresses" and derives coarse location, down to city, from them. It also collects what it calls "granular location and device data" by default: city, browser user-agent string, device model, screen resolution and more, which you can switch off per region. City-level location sits inside the ICO's "coarse geolocation" example. A full user-agent string and screen resolution for every browser starts to look less like a count and more like a description of a particular device. If you are leaning on the exception, switching that collection off for the UK is cheap.
The Helper Problem: Processors, Controllers and Google

Condition (c) is where most real set-ups pass or fail.
The clerk from the agency
Say the owner does not hire her own clerk but uses a counting agency. The law is fine with that. Paragraph 5(1)(c) allows sharing the information with another person "for the purpose of enabling that other person to assist with making improvements to the service or website". The agency clerk can count, and can hand the number to the owner.
What the agency clerk cannot do is send a copy of his tally to head office so it can sell better counting to the shop across the road. Once the helper uses what it collected for its own purposes, it is working for itself as well.
The data protection name for that
Data protection law has words for these roles. A processor acts on your behalf, only on your instructions. A controller decides for itself why and how data is used; two organisations that each decide their own purposes are joint or independent controllers.
The ICO's draft is blunt about which one your analytics provider must be. "To rely on the exception, your third party provider must be a processor, not a joint controller." It adds that you must "ensure the provider only uses the information to improve your service and does not link it with other information from any other information it works with", and that you must tell your users that you use a third party and "explain what the third party does with the information it collects".
Then come the two most useful examples in the chapter. In the first, a website that publishes articles adds a third-party analytics script to measure scroll depth, time on page and bounce rate, and looks at the averages in the provider's dashboard. The ICO says it "can rely on the statistical purposes exception". In the second, the same site adds parameters to segment its most engaged readers by age group and gender, and plans to use that to decide what content to promote to those readers. The ICO says it cannot, because this "goes beyond the exception's scope by including profiling to target content".
Keep that second example in mind. It is about to return wearing a Google badge.

How Google describes its role
Google publishes a list of the services that are eligible to be in scope of its Ads Data Processing Terms, under which Google acts as a processor. As captured in February 2026, that list (last updated 23 October 2025) included Google Analytics under "Processor Services". So the processor relationship the ICO asks for exists in Google's own terms. That is the good half.
The other half is a group of four toggles in the GA4 admin screen called data sharing settings. Google's help page on them, as captured on 27 February, is unusually clear. When you turn on the one called "Google products & services", "Google can access and analyze data to better understand online behavior and trends, and use this data to improve Google products and services", with the example of improving Google Ads tools. And then the key sentence: data used under that setting is subject to controller-to-controller terms, and "Google is, for GDPR purposes, an independent controller of such data."
Next to the ICO's draft, that is plain: with this setting on, Google uses part of your data for its own purposes, as a controller. That is the clerk passing tallies to head office, and on my reading it fails condition (c) by itself. Google's page also says that "if all settings are OFF, your Analytics data is only used to provide and maintain the Analytics service". The one caveat it keeps, whatever the settings, is that data "may also be used only insofar as necessary to Maintain and protect the Analytics service". Whether "maintain and protect" is close enough to "assist with making improvements to the service" is the kind of question the final ICO guidance may answer. As of February, it was open, and I would not stake a big site on either answer.6
The page does not say which settings are on by default, only that you "must customize your data sharing settings when you sign up". So look, because whoever set up your property probably clicked through that screen in four seconds.
Google signals is the second ICO example
The other feature to find is called Google signals. Google describes it as session data "that Google associates with users who have signed in to their Google accounts, and who have turned on Ads Personalization". It enables cross-device remarketing, advertising reporting features, and "demographics and interests" reports.
Remarketing and advertising reporting are advertising. Demographics and interests are the ICO's second example almost word for word. I can find no reading of paragraph 5 where Google signals fits. If it is on, you need consent.
The same logic reaches further than signals. If your GA4 property is linked to Google Ads so that your conversions and audiences flow into your campaigns, then part of what that property does is advertising measurement. The ICO's table lists "information on whether users viewed or clicked on an advert displayed to them, for the purpose of measuring the performance of the advert" as needing consent. You cannot run one property that is half counting and half advertising and claim the exception for the whole thing. Paragraph 5 says "sole purpose", and the ICO's draft says you must only use the technology "for the purpose of improving your service or website, and not for any other purposes".
So, plainly: the exception is a good deal for sites whose analytics really are just analytics. It is not a way to run advertising measurement without asking. If your GA4 property feeds Google Ads, you have two honest choices: keep asking for consent, as you do now, or split the jobs into a counting set-up that qualifies and an advertising set-up that stays behind the consent banner. I wrote about the consent side of that machinery, and what Google's tags send before and after a click, in No Consent, No Conversions. None of it went away on 5 February.
The Opt-Out: What "Simple and Free" Looked Like in February
Now the bell on the rope.
What the law says
Condition (e) asks for "a simple means of objecting, free of charge", and that the user "does not object". Condition (d) asks for "clear and comprehensive information about the purpose". And paragraph 5(3) says both only have to be met on the initial use.
Three things follow from the wording alone.
First, it is an opt-out. Counting can start before the user does anything, as long as the information and the objection are there from the start. Under the old rule, the tag had to wait.
Second, "free of charge" rules out a "pay or accept" arrangement for analytics, and I would read it wider: an objection that makes the site worse is a cost.
Third, "simple" is not defined. As of February, the ICO's draft repeated the phrase ("a 'simple and free' means to object") and gave no test.
What the ICO's draft shows
We are not completely in the dark, though. Another chapter of the same draft, on managing consent in practice (dated December 2025), included an illustration of a good consent mechanism that is surprisingly relevant. The first layer shows three equally prominent buttons: "accept non-exempt", "reject non-exempt" and "customise". The second layer lists four categories: essential, analytics, social media tracking and advertising. And, in the ICO's own words, "The 'analytics' category is on by default. The other two categories are off by default."
That is an analytics toggle that starts switched on, next to advertising toggles that start switched off, in a regulator's example of good practice. I read it as the clearest picture of how the two regimes sit on one screen: exempt analytics on an opt-out, everything else waiting for a yes. The same chapter also shows the bad practice to avoid: "by continuing to use our website, you consent", or "to opt out, change your browser settings". A browser setting is not your objection mechanism.
My practical reading of "simple", until the ICO says more:
- the objection is on the first thing the user sees, not three links deep in a policy;
- it takes one action, and it is as easy as the thing it undoes;
- the user can find it again later, from every page, for example with a small persistent settings link; and
- it works: once someone objects, the tag stops storing and reading, at once and on every later visit.
That last one fails most often in real audits, so let's take it down to the wire.
What an objection does to a tag
An objection is only real if the tag obeys it. With Google's tags, the switch that controls this is consent mode. Google's developer documentation, as captured in February, shows a gtag('consent', 'default', …) command that sets the starting state of each storage type, such as analytics_storage, before any tags run, and a gtag('consent', 'update', …) command that changes it when the user makes a choice. It also supports a region parameter, using ISO 3166-2 codes, so that different countries can start in different states.
For the exception, that gives you a clean pattern. For UK visitors, the default for analytics_storage starts as granted, because the exception allows counting before any click. When the user rings the bell, your banner or settings panel calls the update command with analytics_storage: 'denied', and saves that choice so it is applied first on every later page. For everything that is not exempt (ad_storage, ad_user_data, ad_personalization), the defaults stay denied until the user says yes, exactly as before. For EU visitors, which we will come to in a moment, analytics_storage also starts denied.
Two details trip people up. The first is that remembering the objection needs its own small piece of storage. The strictly necessary exception covers that, and the ICO's draft gives the example of a cookie that remembers a user's consent preferences over time.7 The second is that the default command must run before the analytics tag loads. If the tag fires first and the consent state arrives half a second later, the cookie has already been set, and your opt-out is decorative. The gcs and gcd parameters I described in the consent mode post will show you, in the network tab, what state each request was sent in.
Meanwhile, in Brussels
The EU did not do the same thing at the same time, and that matters to any UK site with visitors from the Continent.
A proposal, not a law
On 19 November 2025, the European Commission published a package of simplification proposals it called the Digital Omnibus. Its press release promised to "reduce the number of times cookie banners pop up" and to let users give consent with one click and save their choices in their browser.
The legal text is in proposal COM(2025) 837. It would add a new Article 88a to the GDPR for personal data stored on or read from a person's device, and leave the old ePrivacy rule, Article 5(3), for everything else. Article 88a(1) keeps consent as the default. Article 88a(3) lists the exceptions, and point (c) is the analytics one:
creating aggregated information about the usage of an online service to measure the audience of such a service, where it is carried out by the controller of that online service solely for its own use
Article 88a(4) adds rules for when consent is used: the user must be able to refuse "with a single-click button or equivalent means", and after a refusal the site must not ask again for the same purpose "for a period of at least six months". Article 88b would require sites to respect automated, machine-readable signals of the user's choice, once standards for them exist. And Article 88a(5) says the article would apply six months after the regulation enters into force.
That last point is the whole story for February 2026: the Omnibus was a proposal in the EU's legislative procedure, with no date, and its text could change. For an EU visitor on your site, the rule that applied was the one that applied last year: Article 5(3) of the ePrivacy Directive, as each member state implements it. And under that rule, analytics cookies generally need consent.
Two exceptions, side by side
Three differences stand out.
The UK exception requires an opt-out. The EU exception, as written, does not require one. If it passed as drafted, qualifying audience measurement would simply be lawful without consent.
The UK exception lets you share with someone helping you improve the service. The EU text says "solely for its own use" and "carried out by the controller", which, read literally, is narrower. The EDPB and the EDPS, the EU's data protection board and supervisor, noticed that. In their Joint Opinion 2/2026, adopted on 10 February 2026, they said they "strongly support the aim" of dealing with consent fatigue and cookie banners, and asked for the analytics exception to be defined tightly: anonymous aggregated information, not further processed for another purpose, not combined with data from other services or third parties, and not shared with third parties. They also recommended clarifying that the data may be collected by the provider itself "or by a processor acting on behalf of this provider". That is the same helper rule the ICO wrote: a processor may help, a controller may not join in.
And the UK exception is in force, with a £17.5 million ceiling. The EU one is a paragraph in a proposal.

The French footnote that is not a footnote
One wrinkle: some national regulators already allow narrow exemptions under Article 5(3). The best known is France's CNIL, whose guidance since 2020 has let audience measurement run without consent if it meets strict conditions: tell users, give them the "ability to object", limit the tracker to a single publisher, truncate the last byte of the IP address, and keep the tracker's lifetime to 13 months. In the CNIL's words, when those conditions are met, "we therefore switch from an opt-in to an opt-out regime". The UK's new exception looks a lot like a statutory version of that French idea.
The CNIL's page also contains a sentence that anyone hoping to keep their default set-up should read twice: "Most large audience measurement offerings do not fall within the scope of the exemption, regardless of their configuration."8
For a UK site with EU visitors, the practical upshot is that you need one set of rules per visitor, not per site.

Morag Checks Her Set-up
Enough theory. Let's watch someone do it.
Morag runs a small online shop in Sheffield that sells bicycle parts: chains, brake pads, the tiny bolts that always go missing. Most customers are in the UK; about one in eight are in Ireland, and a few in the Netherlands and Germany. She uses GA4, a consent management platform and a few Google Ads campaigns. In February she saw "analytics cookies no longer need consent" and felt a small, dangerous flicker of hope.
She gives it one week, a cup of tea per step, and one question per condition.

Monday: what runs before anyone clicks
Morag loads her home page in a private window with the developer tools open and does not touch the banner. She checks the Application tab for cookies and storage, and the Network tab for requests leaving the page.
She finds the _ga cookie is not set, and GA4's requests go out with consent denied, which is correct for her current opt-in banner. She also finds a chat widget and a font library that load from third-party domains before any click. She makes a note: the ICO's draft says external font libraries may collect IP addresses and, where that happens, you must explain it and give people "a simple and free way to object". Her analytics were not the only thing on the page.
Tuesday: what the property is for
This is the decision day. Morag opens GA4's admin and answers one honest question: is this property only for understanding how the site is used, or is it also doing advertising work?
Her GA4 property is linked to Google Ads. Her Ads campaigns import GA4 key events as conversions. Google signals is on, because a blog post in 2022 said it would give her demographics. So her property is doing three jobs the exception does not cover: advertising measurement, cross-device remarketing and demographic profiling.
She can keep this property behind consent for everyone, or split the work: a counting-only set-up for UK visitors on an opt-out, and advertising measurement behind consent. She splits, because her conversion data only ever came from people who accepted her banner anyway.
Wednesday: the settings
For the counting-only set-up, Morag goes through the settings the conditions point to:
- Data sharing settings (Admin, Account details): she turns off "Google products & services". She also turns off "Modeling contributions & business insights" and "Recommendations for your business", because she does not need them and "only used to provide and maintain the Analytics service" is the sentence she wants to be true.
- Google signals (Admin, Data collection): off.
- Google Ads link: none on this property.
- User-ID: she does not send one. Nothing that identifies a real customer goes into these rows.
- Granular location and device data: off for the United Kingdom region.
- Data retention: two months, the shortest GA4 offers.
She notes the one part she is unsure of: GA4 still keeps user-level rows for two months. If the ICO's final guidance takes a strict line on that, her fallback is a counting tool that aggregates and discards by design.
Thursday: the notice and the bell
Morag's banner platform can already show different banners by region. For UK visitors, she changes the first layer to say, in plain words, that the site uses Google Analytics to count visits and see which pages work, that Google processes this for her, and that it is not used for advertising. It has a single "Turn off analytics" button next to the rest of the choices, and a small "Cookie settings" link in the footer of every page. Her advertising and social categories still start off, and still wait for a yes.
Then she changes the consent mode defaults, one region at a time:
// UK visitors: exempt analytics runs until the user objects.
gtag('consent', 'default', {
analytics_storage: 'granted',
ad_storage: 'denied',
ad_user_data: 'denied',
ad_personalization: 'denied',
region: ['GB']
});
// Everyone else, including the EU: nothing runs until the user agrees.
gtag('consent', 'default', {
analytics_storage: 'denied',
ad_storage: 'denied',
ad_user_data: 'denied',
ad_personalization: 'denied'
});
When a UK visitor presses "Turn off analytics", the banner calls gtag('consent', 'update', { analytics_storage: 'denied' }) and stores the choice, so the denied state is applied before the tag on every later page. Irish, Dutch and German visitors see the opt-in banner they saw last month, because for them nothing has changed.
She tests it as on Monday: a private window on a UK connection, press the button, reload, and check that no new _ga cookie appears and the requests carry the denied state. Then again without the button, to see the counting run.
Friday: the record
Last, she writes one page: the date, the exception (PECR Schedule A1, paragraph 5), the settings it covers, what stays behind consent, and the retention question, marked "review when the ICO's final guidance is out". If anyone asks, that page is the difference between "we thought about it" and "we heard it was fine now".
Morag still has a banner for EU visitors and for advertising. But her UK analytics now count the people who never click anything, which, on a bike parts shop, is most of them.
Final Thoughts
Back to the clerk at the door, with his brass counter and his nervous twitch. As of February 2026, in the UK, he is allowed to click again without the clipboard. He has to put a sign up. He has to hang a bell where people can reach it, and stop when it rings. And he must never, ever start following anyone round the shop with a notebook, or hand his tally to the shop next door, because that was never counting in the first place, and the fine for pretending otherwise is now £17.5 million.
If you remember one thing: the exception is about what your analytics do, not which tool you bought. Only counting, only for you, only totals, clearly explained, easy to switch off. The answer for GA4 sits in the data sharing settings, the Google signals switch, the Google Ads link and the retention setting, all of which you can check before lunch. If you want the longer backstory on consent itself, Consent Management: The What and Why is still a good place to start.
So this week, open your analytics admin and find out what your property is really for. If it is only counting, you may be able to stop asking UK visitors a question most never wanted to answer. If it also does advertising, keep asking, or split the jobs. Either way, write down what you decided, and put the ICO's final guidance in the diary.
As for me, I have been keeping my own count of the cups of tea I drink, about 1,820 a year. That is aggregate, it is only for my own use, and nobody has objected yet.
Notes
-
Every organisation's facts are different, and the ICO's guidance on these exceptions was still a draft in February 2026. Take this article as a map of the questions to ask, and take the answers to someone who is insured to give them. ↩
-
The ICO's draft gives wifi probe requests as the example: the small signals phones send while looking for networks. Counting passing phones that way stays outside the statistical purposes exception, however anonymous the total. ↩
-
A/B testing needs to put each browser in the same group on every visit, which needs a small piece of storage. The ICO's draft lists it as likely inside the exception, as long as what you keep is the comparison between the groups, not a record of each person. ↩
-
The referrer is on the allowed list and ad performance is not, which sounds like the same thing until you look closely. "People from the spring newsletter read more pages" is a statistic about your site. "This person clicked this advert and then bought a chain" is advertising measurement, and it still needs consent. ↩
-
Google also lists a "Modeling contributions & business insights" setting, which pools data with other sites for benchmarks and says the result "cannot be used to identify your organization, account, or users". It is not advertising, but it is also not only helping to improve your site, so if you rely on the exception, the simplest position is to switch it off. ↩
-
The EDPB and EDPS made the same point about the EU proposal in February 2026: remembering a refusal needs storage, and they suggested it should use a generic flag common to everyone who refused, not a unique identifier. That is good design on either side of the Channel. ↩


