What is PECR?
The Privacy and Electronic Communications Regulations (PECR) are the UK rules implementing the EU ePrivacy Directive, retained after Brexit. They require consent before storing or accessing information on a user's device for anything not strictly necessary. The ICO has stated plainly that analytics cookies are not strictly necessary.
Explanatory, not legal advice. Consult a solicitor about your own obligations.
What it requires
Consent before setting or reading anything on a device, unless that storage is strictly necessary for a service the user asked for. PECR sits alongside UK GDPR: PECR governs the device access, UK GDPR governs what you then do with any personal data.
The ICO’s guidance on analytics has been consistent — analytics cookies are not strictly necessary, so they require consent. The ICO has also said it considers non-compliant cookie banners, particularly ones that make refusing harder than accepting, an enforcement priority.
Why a British site cannot ignore the EU version
Post-Brexit, a UK site serving UK visitors follows PECR and UK GDPR. But the ePrivacy Directive and GDPR still apply to EU visitors regardless of where the site is hosted, so most sites are subject to both regimes at once.
They are similar enough that one compliant approach usually satisfies both, and different enough that “we’re not in the EU any more” is not a strategy.
The route that avoids the question
PECR is triggered by device storage. Analytics that sets no cookie, writes nothing to local storage and does no fingerprinting does not perform the act the regulation governs, so the consent requirement does not arise.
That is how sonex works, and it is why sites running it show no cookie banner for analytics. If you use other cookies — advertising pixels, embedded video, a chat widget — those still need consent on their own terms. Removing one banner trigger does not remove the others.