Free policy template

Cookie policy

Easily set up a cookie policy to keep your website compliant with UK data and privacy laws and improve user experience.

What's inside

  • Compliance with regulations
  • Simple explanation of cookies
  • Details types of cookies used
  • Offers cookie preference controls

Word document. Drafted by Lawyerly's commercial solicitors. Last updated September 2026.

Download your free copy

Tell us who you are and the file is yours straight away.

Cookies: what the law requires since February 2026

Cookie rules in the UK come from the Privacy and Electronic Communications Regulations rather than from the UK GDPR directly, and they changed materially on 5 February 2026, when the commencement regulations brought the relevant parts of the Data (Use and Access) Act 2025 into force. A policy written before that date is very likely to overstate what consent is needed for.

What no longer needs consent

Three new exemptions sit alongside the existing one for cookies strictly necessary to provide a service the user asked for. Cookies used solely for your own statistical purposes, meaning measuring how the service is used. Cookies that adapt the appearance of the service to a user's preferences, such as language or accessibility settings. And cookies used to locate a device in order to provide emergency assistance after a request.

The exemption is not a free pass. For the statistical and appearance categories you still have to tell people the cookies are being set and give them a simple way to object, free of charge. You have to inform and allow opt-out; you no longer have to ask first.

What still needs consent

Advertising and targeting cookies, and analytics where the data is shared with a third party or used for targeting rather than solely for your own statistics. In practice that distinction is where most sites will land or fall: an analytics tool that sends data to a provider who uses it for its own purposes is not covered by the new exemption.

Where consent is required it has to meet the UK GDPR standard, which means freely given, specific, informed and an unambiguous act. Nothing beyond the exempt categories may be set before the visitor has chosen, and refusing must be as easy and as prominent as accepting.

The penalties changed at the same time

The maximum penalty under these Regulations rose from £500,000 to the UK GDPR level, which is the greater of £17.5m or 4 per cent of worldwide annual turnover. The Information Commissioner's Office can issue that without needing to show a separate data protection breach.

Completing the template

Schedule 1 asks for the cookies your site actually sets, and it cannot be filled in from memory. Load the site in a clean browser profile, refuse everything, and list what is set anyway, then accept and list the rest, recording the name, the provider, the purpose and the duration of each. Tag managers, embedded video, chat widgets and advertising pixels all set cookies the site owner rarely put there deliberately. Clause 5 carries an option block on cookie walls and consent or pay: keep the one that is true for your site and delete the other.

The policy and the banner have to agree with each other, and a mismatch is the usual problem rather than a missing policy. Our UK GDPR and data protection solicitors review both together, alongside the data protection policy and your privacy notice.

Need more than a template?

Talk to a solicitor about your situation

A template gets you started. When the facts are yours, one of our commercial solicitors will tailor it, or tell you plainly that you need something else. The first conversation is free.

Willem van der Merwe

Co-Founder

Read profile