You may have noticed something missing from this website. There is no cookie wall. Nothing slides up from the bottom asking you to accept, reject, or manage 47 categories of tracking before you can read a sentence.
That is not an oversight. It is the law working the way it was meant to. This post explains when a cookie banner is legally required, when it is not, what changed in February 2026, and how to work out which side of the line your own site is on.
Cookie consent has one legal job: to get your permission before a website stores something on your device that it does not strictly need. That is it. The rule comes from the Privacy and Electronic Communications Regulations (PECR), not from GDPR directly, and it has always had a large exception built in: cookies that are strictly necessary for the service you asked for do not need consent. Ever.
A login cookie is strictly necessary. A shopping basket is strictly necessary. The banner asking permission for those cookies? Not required. Worse, asking consent for things that do not need it trains people to click "accept all" without reading, which defeats the entire point. The ICO has said as much.
So when a site shows you a banner, it is usually telling you one of two things. Either it runs advertising and tracking cookies that genuinely need your permission, or somebody installed a consent tool because everyone else has one. The second group is bigger than you would think.
Here is our complete inventory. Two authentication cookies from Supabase that keep you logged in. A one-byte note that you saw our cookie notice. Two preferences in local storage: your theme and whether the sidebar is collapsed. All strictly necessary or set at your request.
No Google Analytics. No Meta Pixel. No fingerprinting. No third-party anything. We build GDPR compliance software; running surveillance on our own visitors would be a strange way to sell it.
The Data (Use and Access) Act 2025 amended PECR, and one change matters here: websites may now run analytics without consent, provided the analytics are used solely for aggregate statistics, the data stays with the website operator, individuals cannot be identified from it, the use is clearly explained, and visitors get a free opt-out.
This is a sensible change. Counting readers was never the problem; following them around the internet was. If your only sin is wanting to know which pages get read, you no longer need a banner for it. Advertising and anything shared with third parties still needs consent, as it should.
We recently added page counting to this site. Here is everything it records: the page path, the domain the visitor came from, and the date. No cookies set or read. No IP address stored. No identifier of any kind. Two visits from you look identical to two visits from strangers.
Technically that does not even reach the threshold where the new DUAA exception is needed, because nothing is stored on your device at all. We honour the exception's conditions anyway: the full explanation lives on our cookie policy page, along with a one-click opt-out. Maybe honouring conditions we are not subject to is overkill. We are a compliance company. It comes with the territory.
Work through this honestly:
The uncomfortable version: if you have a banner and you also fire your Meta Pixel before anyone clicks accept, you have the worst of both worlds. The banner does not protect you; the firing order is the whole game.
Rowpa scans your website, finds the tools quietly collecting data (including the pixels you forgot about), and tells you which ones need consent, which need a data processing agreement, and which make you a joint controller. It takes seconds and the first scan is free.
Run your free scan and find out which side of the line you are on.