Cookie Policy Template (PECR + UK GDPR Marketing Consent)
UK cookie policy template aligned to PECR Regulation 6 and UK GDPR Article 7 consent rules. Includes ICO-aligned banner-design guidance and ePrivacy directive coverage.
Single policy template
£49.99
One-off purchase · lifetime access · no renewal
Or save with the ISO 27001 Core Set (16 policies for £400)
What is the Cookies, PECR & Marketing Consent Policy?
Quick answer. UK cookie policy template aligned to PECR Regulation 6 and UK GDPR Article 7 consent rules. Includes ICO-aligned banner-design guidance and ePrivacy directive coverage. Covers both the public cookie notice and the back-of-house PECR + GDPR marketing-consent register.
The Cookies, PECR & Marketing Consent Policy is one of 988 single-policy templates available on PolicySuite. Each is generated bespoke to your business from structured questions about your operations — not a generic word-doc template you have to rewrite. Buy this single policy at £49.99, or get the complete ISO 27001 Core Set (16 policies for £400) if you need the surrounding policies too.
What’s included in the template
- Strictly-necessary vs functional vs analytics vs marketing cookie classification
- Banner-design guidance to avoid ICO enforcement triggers
- PECR Regulation 6 first-cookie consent rules
- GDPR Article 7 consent capture, withdrawal and refresh cadence
- Marketing opt-in / soft opt-in (PECR Regulation 22)
- CNIL + EDPB guidance on dark patterns
- Cookie audit table (provider, purpose, retention, third-country)
- Periodic review process
Statutory and framework references
The template is drafted with explicit citations to the following anchors so your auditor, tribunal or ICO inspector can verify alignment. Every reference resolves to a primary-source link — legislation.gov.uk for UK statute, iso.org for ISO standards, ico.org.uk for ICO codes, acas.org.uk for ACAS Codes, and legislation.gov.uk for UK Acts and Regulations.
- PECR Regulation 6 (cookies)
- UK GDPR Article 7 (consent)
- UK GDPR Article 21 (objection / direct marketing)
- EU ePrivacy Directive 2002/58/EC
- ICO direct marketing code of practice
Why this policy matters
In 2024 alone, UK regulators and tribunals continued to test the documentation behind PECR Regulation 6 (cookies). The ICO issued over £56m in monetary penalties that year and the employment tribunals decided more than 12,800 cases where written policies were the controlling evidence. We see many UK SMEs lose disputes not because they lacked the policy entirely, but because the policy they had was generic, out of date, or unaccompanied by acknowledgement evidence. In our experience, a bespoke Cookies, PECR & Marketing Consent Policy sized to your business is the cheapest single line of defence against that outcome.
The three failures we see most often, for example across the 988 templates in the catalogue, are: (1) an unsigned, undated document with no version history; (2) a copy-paste template that names statutes the business does not actually engage (a tribunal will spot this in minutes); and (3) a policy never communicated to the people it binds. PolicySuite’s acknowledgement-tracking and version-stamping close the third gap by default. In our experience working with UK SMEs across UK statute and the ICO accountability framework, the policy that fails an audit is rarely the one that was missing — it is the one that was generic, undated, or never communicated. A bespoke policy generated from your own answers, version-stamped and distributed with acknowledgement tracking, is what stands up.
How PolicySuite generates this template for you
Buying the £49.99 single policy unlocks PolicySuite’s structured-question flow for the Cookies, PECR & Marketing Consent Policy. You answer ten to twenty questions about your business — sector, headcount, jurisdictions, processing categories, supplier dependencies — and the platform produces a bespoke policy in minutes. The output is fully editable, signed off in-app, and version-stamped so your audit trail is automatic.
Where the template references statute or framework controls, the citations are kept up to date as the regulations change. We track UK statute amendments, ISO revisions, and the periodic ICO, ACAS and HSE guidance updates so the policy you bought today does not silently rot in the back of your shared drive. When something material changes — a new statutory duty, a fresh ICO code of practice, an Annex A revision — you receive an in-app notification and a one-click re-generation prompt that retains all of your business-specific answers.
Single policy versus the full pack
A single £49.99 template is the right choice when you already have the surrounding policies and just need to plug a specific gap. If you need the complete framework set, the ISO 27001 Core Set (16 policies for £400) bundles the related policies at a lower per-policy cost, with a pack-level audit-mapping table included.
Further reading
Read the in-depth Cookie Policy library page for context on why the policy matters and what auditors and tribunals look for. The framework page UK GDPR explains how this policy fits the wider compliance picture.