A Guide to Cookie Law 2022. Even after Brexit, the cookie law, also known as the GDPR cookie consent guidance, requires that website operators obtain user consent to store or access cookies on a user’s device.
Failure to comply with the new rules can result in hefty fines of up to €20 million or 4% of annual global revenue (whichever is greater).
As an e-commerce website owner responsible for collecting and storing personal data about your customers, you need to understand how this new regulation impacts your digital presence. The following guide will help you understand what the cookie law means for your business and what steps you need to take to ensure that your site remains compliant.
What is UK GDPR?
Launched in May 2018, the General Data Protection Regulation (GDPR) was a data privacy law that applied to all EU member states. The law aimed to strengthen data protection for individuals by increasing fines for non-compliance and standardizing data privacy rules across the EU.
Post-Brexit, the UK government brought many existing EU regulations into UK law – including GDPR, which became UK GDPR. It’s essentially the same law with some of the wording changed to reflect the new status as a UK Law. Moves are afoot to repeal some of the requirements (including Cookie Pop-ups), but so far, nothing has changed.
The GDPR replaced the 1995 Data Protection Directive (DPD) and applies to the processing of personal data in the EU. So if your customers are in the EU, then the processing of their data is still under the jurisdiction of EU law, and you will need to comply if you trade with people in the member states.
Why Is the Cookie Law Important?
The cookie law is an essential part of UK GDPR. It ensures that website owners obtain informed consent before storing or accessing cookies on a user’s device. The cookie law also limits the type of cookies allowed and the duration of their storage.
UK GDPR also stipulates that individuals have the right to access the data that companies store about them. Thus, website owners must also provide a way for users to access their data and request it be deleted if desired.
It’s important because it protects individuals by limiting the type and amount of data companies can store. It also offers individuals a set of rights and greater control over their personal data.

Post-Brexit UK companies need to comply with UK GDPR
Who Must Comply with the Cookie Law?
Any company that processes the personal data of UK residents are required to comply with UK GDPR. This still includes any eCommerce website that collects, processes, or stores the personal data of EU customers.
How to Comply With the Cookie Law
First, you must obtain informed consent to store or access cookies on a user’s device. You must clearly state the reason for storing or accessing cookies on their device and provide information about their functionality.
You must provide information about cookies on either your homepage or a separate page dedicated to cookie usage. The information provided must also be accessible to persons with disabilities. Next, you must limit the cookies you store and access only to those necessary to provide the services requested by the user.
You must also ensure that these cookies have an expiration date. For example, you cannot store persistent cookies that remain on a user’s device after they close the browser window. You must also obtain consent to store third-party cookies. This includes cookies used to track user behaviour and target advertisements.

Non-compliance with UK GDPR could result in costly legal action
Consequences of Non-Compliance
UK GDPR comes with hefty fines for failure to comply with the new rules. Non-compliant companies risk fines of up to £17.5 million or 4% of annual global revenue (whichever is greater).
With such high stakes, failing to comply with the cookie law is not an option. Doing so can put your eCommerce business at risk, cause brand damage, and lead to a loss of customer trust.
Summary
UK GDPR comes with requirements for companies that store and process the personal data of EU residents. One of these requirements is obtaining consent to store or access cookies on a user’s device.
By understanding what UK GDPR is and how it impacts your business, you can take the necessary steps to ensure that your site remains compliant.
To comply with the cookie law, you need to obtain informed consent, limit the types of cookies you store and access and obtain consent from third-party cookies.







