In January 2025, the ICO reviewed the UK’s top 200 websites and flagged 134 of them for cookie compliance issues, giving them 30 days to fix things. Getting your PECR cookie strategy right isn’t optional—it’s business-critical.
Compliance can be overwhelming and feel scary for many website owners. But don’t worry – I’ve got your back!
In this guide, I’ll cover everything you need to know about PECR compliance and Google Analytics 4.
In This Article:
Legal Disclaimer: Due to the dynamic nature of websites, no single plugin can offer 100% legal compliance. Please consult a specialist internet law attorney to determine if you are in compliance with all applicable laws for your jurisdictions and your use cases. Nothing on this website should be considered legal advice.
What is PECR?
PECR stands for Privacy and Electronic Communications Regulations, and they sit alongside GDPR in the UK.
PECR is a set of rules specifically around electronic communications, like emails, texts, and marketing calls. They also apply to related technologies, like cookies, location data, and directory listings. In my experience helping site owners sort out their compliance, this cookie connection is the part most people miss.
According to the Information Commissioner’s Office:
Some of the rules only apply to organizations that provide a public electronic communications network or service. But even if you are not a network or service provider, PECR will apply to you if you:
- market by phone, email, text or fax;
- use cookies or a similar technology on your website; or
- compile a telephone directory (or a similar public directory)
Here’s what makes PECR different from GDPR:
- PECR focuses specifically on electronic communications technology
- GDPR covers broader data protection principles
- Both work together to protect user privacy
- Non-compliance penalties have been dramatically increased for 2025
The High-Stakes Reality Check
The enforcement landscape has transformed. The Data (Use and Access) Act 2025 raised the maximum fine for PECR breaches to mirror UK GDPR levels—up to £17.5 million or 4% of global turnover. That change took effect on February 5, 2026, and applies to violations from that date forward.
That’s a massive jump from the previous £500,000 cap. And the ICO isn’t just raising the ceiling—it’s actively enforcing PECR. In January 2024, it fined HelloFresh £140,000 for sending millions of unsolicited marketing texts and emails. Cookie compliance so far has drawn warnings rather than fines, but with the new penalty cap now in force, that’s unlikely to stay true for long.
So, how do you make sure your use of Google Analytics is compliant with PECR?
How to Make Google Analytics PECR Compliant
Since Google Analytics uses cookies, making it PECR compliant is a must.
If you’re familiar with GDPR and making your analytics GDPR compliant, this will be very much the same.
In fact, if you’ve already taken steps to make your website and Google Analytics GDPR compliant, then you are already PECR compliant without taking any further steps.
If you haven’t taken any action yet or would like to revise your compliance, read on!
Method 1: MonsterInsights EU Compliance (Recommended)
If you want to make your Google Analytics tracking compliant, there are two different methods you can use to make that happen.
Method One: If you’re on WordPress, in a few clicks you can download MonsterInsights, the WordPress analytics plugin, at the Plus level. Then, go to Insights » Addons and toggle EU Compliance on.
Once you’ve got the addon installed and activated, you’ll be able to turn on these GDPR-compliant features:
- Anonymize IP addresses
- Disable demographics and interest reports for remarketing and advertising
- Disable UserID and author name tracking
Go to Insights » Settings and then click the Engagement tab.
Then, go to EU Compliance to adjust your settings.
To really dive into these features and understand why you might want to turn them on, read our complete guide to GDPR and Google Analytics.
Method 2: Cookie Consent Management
You can use a cookie acceptance plugin to obtain explicit consent before loading the Google Analytics tracking script.
MonsterInsights integrates with Cookiebot, one of the top cookie plugins for WordPress. So, if you choose to use a plugin, we recommend this one.
With Cookiebot installed, any website visitors will be able to consent to being tracked or opt out of tracking.
Pro Tip: Look for a consent tool that can block Google Analytics specifically until consent is given, rather than one all-or-nothing toggle for every script on your site.
Which PECR Compliance Method is Right for Your Website?
I recommend using both together rather than picking one or the other. Here’s why:
- MonsterInsights EU Compliance reduces what your analytics setup tracks in the first place—anonymizing IPs, and disabling remarketing/advertising signals and UserID tracking—so there’s less that needs consent at all
- A cookie consent tool (like Cookiebot) handles what’s left: getting explicit, informed consent before Google Analytics cookies load
- We stay up-to-date on UK and EU privacy law and update the plugin as requirements change
- Together, they’re a more defensible compliance posture than either alone
It’s true that a consent popup means some visitors won’t opt in, so you’ll have gaps in your tracking data for those sessions. That’s a real tradeoff—but it’s the tradeoff PECR asks you to make. Google Analytics cookies aren’t currently exempt from consent (see the FAQ below), so skipping the consent step isn’t a compliance shortcut, even with anonymization in place.
Get Started with MonsterInsights Today!
More Resources on Explicit Consent
I’ve gone over the basics here about how to set up your website and Google Analytics for GDPR and PECR compliance.
For more details about explicit consent and compliance for your website, check out these resources:
- GDPR and Google Analytics – How to Make Your Site Compliant
- How to Make a WooCommerce Site GDPR Compliant
- What are PECR? via the Information Commissioner’s Office
- How to Make Google Analytics Opt-out Links With MonsterInsights
- 7 Best GDPR Plugins to Help You Avoid Heavy Fines
Not using MonsterInsights Plus or above? Upgrade your license to access the EU Compliance addon, plus many other features!
And don’t forget to follow us on YouTube for more helpful Google Analytics tips and tutorials.
FAQs About PECR Compliance for Google Analytics
Do all website cookies require consent under PECR?
No, only PECR cookies that aren’t strictly necessary for core website functionality require consent. Essential cookies for shopping carts, user authentication, and security don’t need consent, but analytics, advertising, and social media cookies do.
How is PECR different from GDPR?
While GDPR covers general data protection, PECR focuses specifically on electronic communications including cookies, emails, and marketing calls. PECR sits alongside GDPR with its own specific consent requirements and penalties.
What are the penalties for PECR non-compliance?
Since February 2026, PECR compliance violations can result in fines up to £17.5 million or 4% of global annual turnover under the Data (Use and Access) Act 2025—the same level as GDPR penalties, up from a previous £500,000 cap. The ICO has already shown it will use its enforcement powers, including a £140,000 fine against HelloFresh in 2024 for unlawful marketing messages, plus its ongoing review of cookie compliance across the UK’s top 1,000 websites.
Can I use Google Analytics without explicit cookie consent?
Generally, no—Google Analytics cookies count as non-essential under PECR and need consent. The Data (Use and Access) Act 2025 did add a narrow exemption for cookies used solely for aggregate, non-identifying statistics about your own site, with clear notice and a simple opt-out. But most current legal analysis concludes Google Analytics likely doesn’t qualify for it, since Google’s own terms let it use GA4 data for its own advertising and product purposes—which disqualifies it as a pure processor acting solely on your behalf. The safer approach is still to pair MonsterInsights EU Compliance (to shrink what you’re tracking and anonymize what remains) with a cookie consent tool for what’s left.
Do PECR regulations apply to non-UK businesses?
Yes, if your website targets UK users or processes data from UK visitors, you must comply with PECR regulations regardless of your business location. The rules apply to any organization accessible from the UK.
What’s the simplest way to achieve PECR compliance?
The easiest approach is pairing MonsterInsights EU Compliance with a cookie consent tool. EU Compliance automatically implements privacy-preserving measures—anonymizing data and disabling non-essential tracking—without technical complexity, so there’s less left for a consent tool to have to gate. That combination gets you PECR compliant while preserving as much of your analytics insight as the law allows.
That’s it! I hope this article helped you understand how to keep your Google Analytics tracking PECR compliant. If you liked this article, check out the following beginner-friendly guides:
- Google Analytics CCPA Compliance: Make Your Site Compliant
- How to Add a WordPress Cookie Consent Banner
- Announcing CookieYes and Complianz Integrations + Email Summary Improvements
- Introducing the Forms Report and the New EU Compliance Addon for MonsterInsights
Follow us on Twitter, Facebook, and YouTube for more Google Analytics tips.