As businesses operating online services continue to rely on data-driven ways to efficiently target their audience and advertise, there has been increased use of the “consent or pay” model for cookies. Under this model, users can either consent to a platform’s personalised advertising or alternatively pay a fee to have an ad-free experience.
In light of the UK’s Data (Use and Access) Act (DUA Act), which redefines the rules on cookies, it is important that businesses understand what these models involve, the legal risks involved, and how to operate in the changing regulatory framework.
What are cookies and how are they used?
Cookies are the small text files of information stored on a user’s device, such as their phone or computer. These act as a unique identifier for the individual user of the device and enable online service providers to recognise who is accessing their services.
Some cookies are essential, such as those which are used for core functionality of a website (e.g. keeping items in a shopping basket or remembering login details). However, other cookies can be used to support the operator in analysing activity on their platform, or personalising advertising delivered to the user.
“Strictly necessary” cookies, such as those required for the functionality of the service, are exempt from consent requirements because they are essential for providing the service that the user wants to receive. All other non-essential cookies require users to provide active, opt-in consent. These include those in relation to marketing or advertising, analytics and performance.
The Legal Framework for Cookies: PECR and UK GDPR
In the UK, the Privacy and Electronic Communications Regulations (PECR) govern cookies and similar technologies that store information on, or access information stored on, a user’s device. They also regulate certain electronic direct marketing activities, the security of public electronic communications services, and specified aspects of customer privacy. Where information obtained through cookies or similar technologies constitutes personal data, the UK GDPR governs the processing of that personal data.
Unless an exemption applies, organisations must:
- Clearly inform users about what cookies are being used and why,
- Obtain positive consent from the user to collect cookies.
What are “Consent or Pay” Cookie Models?
A “consent or pay” model offers users a choice to either:
- Consenting to the use of cookies for personalised advertising,
- Paying a fee to access an ad-free version that does not rely on personal data, or
- Choose not to use the service at all.
These models are becoming increasingly used by organisations looking to ensure advertising revenues are maintained.
These differ from Cookie Walls, which instead adopt a “take it or leave it approach” to personalised advertising.
The Information Commissioner’s Office (ICO) has stated that in most cases, this approach will not comply with the requirement for consent to be freely given as the user lacks a genuine choice.
However, the ICO’s guidance on the “consent or pay” model is that it may be compliant with data protection laws, provided that businesses are able to demonstrate that users are able to freely give consent.
When is cookie consent “freely given”?
The key legal challenge to the “consent or pay” model therefore is whether consent can be “freely given”.
The ICO has identified four key factors in determining whether consent can be “freely given”:
- Power imbalance
Where users heavily rely on a service due to its market dominance, importance or lack of alternatives, consent may not be freely given. This means that the model is more likely to fail where the operator is in a position of power.
- Appropriate fee
The price of the ad-free version must be reasonable, proportionate and not designed as a deterrent. If the fee is too high, users may be financially pressured into giving consent, meaning it cannot be “freely given”.
- Equivalence of service
The core service provided should remain the same whether a user pays or consents to personalised ads. Optional extras can differ, but any degradation of the core service undermines the freedom of consent.
- Neutral and privacy-respecting design
The choice presented to the user must be presented clearly and neutrally. Rejecting should be as easy as giving consent, and users must understand what they are agreeing to.
How the Data (Use and Access) Act (DUA) Changes Cookie Rules:
Exemptions from consent
Consent will no longer be required for the following:
- Statistical cookies used purely to improve service performance,
- Functional cookies required to display a service properly (provided that the organisation gives clear, accessible information and an easy opt-out), and
- Emergency location cookies.
Setting-based consent
It will be easier to obtain user consent as free choice will be able to be given through a user’s browser or app settings, not just through cookie banners.
Stronger PECR penalties
Maximum fines for certain PECR breaches have been increased to align with UK GDPR-level fines of up to £17.5 million or 4% of annual worldwide turnover, whichever is higher.
This is a substantial increase from the previous maximum of £500,000 under PECR.
In addition, certain telecommunications service providers must report PECR personal data breaches to the ICO within 72 hours, with failure to notify potentially attracting a £1,000 penalty.
What the DUA Act and Consent or Pay Models Mean for Businesses
- Organisations adopting consent or pay models must be ready to justify it
The ICO have stressed the importance of organisations documenting an assessment in a Data Protection Impact Assessment (DPIA) whereby they apply the above factors to their cookie use. Failing to complete a DPIA, or completing one superficially, exposes organisations to significant enforcement risk, especially given the heightened penalties under the DUA Act.
- The DUA Act broadens possibility, but increases risk
With cookie use exemptions broadening, this will reduce reliance on intrusive cookie banners and simplify the regulatory landscape for some categories of cookies. However, this has come with a corresponding increase in enforcement risk, with higher penalties potentially resulting in multi-million-pound fines. Organisations must assume that any consent or pay implementation will be examined closely by the ICO to avoid the potential consequences of getting it wrong.
- International businesses must navigate dual compliance
A model acceptable in the UK may still breach EU GDPR due to the European Data Protection Board (EDPB) taking a stricter view, stating that consent and pay models “in most cases” would be incompatible with EU rules. Therefore, businesses operating across both jurisdictions must remain vigilant to their dual compliance obligations to avoid paying severe penalties for non-compliance.
Conclusion
The UK is moving toward a more flexible regime for cookies, particularly with the exemptions introduced by the DUA Act. While this can streamline the user experience, it also raises compliance risk through the potential for increased penalties and heightened regulatory attention.
“Consent or pay” models are not unlawful by default in the UK, but they are only lawful if the organisation can demonstrate users have a genuine, unpressured choice, supported by robust assessment and transparent design.
For businesses, now is the time to:
- Reassess existing cookie practices in light of the ICO guidance; and
- Consider whether consent‑or‑pay is appropriate and lawful for use in the context of their business.
As regulatory expectations continue to develop, organisations should regularly review their use of cookies, consent mechanisms and wider data collection practices. Taking a proactive approach now can help demonstrate accountability, strengthen user trust and minimise compliance risk.
If you would like support reviewing your existing arrangements or implementing a consent or pay model, please contact us.




