Email Marketing

Ending the Banner Fatigue: The Data & Marketing Association’s Push to Overhaul Low-Risk Cookie and Tracking Regulations in the UK

LONDON — The landscape of digital marketing, consumer privacy, and regulatory compliance in the United Kingdom could be on the verge of a radical transformation. In a move that has reignited the perennial debate between seamless digital user experiences and stringent data protection, the Data & Marketing Association (DMA) has formally petitioned the UK Government to scrap mandatory consent requirements for low-risk cookies and comparable tracking technologies.

Published on September 24, the DMA’s strategic policy proposal has been delivered directly to key government officials. While the proposal’s immediate visibility has centered on web-based cookies—the ubiquitous and often maligned banners that interrupt virtually every browsing session—its implications reach far deeper into the digital ecosystem, quietly encompassing marketing emails, tracking pixels, customer relationship management (CRM) systems, and loyalty platforms.

As government departments weigh their newly granted legislative powers under the Data (Use and Access) Act 2025, industry stakeholders, privacy advocates, and legal experts are closely monitoring what could become the most significant adjustment to the UK’s digital regulatory framework since the implementation of the General Data Protection Regulation (GDPR) and the Privacy and Electronic Communications Regulations (PECR).


Main Facts

At the core of the DMA’s intervention is a call to eliminate what it describes as "consent fatigue"—the phenomenon where web users mechanically click "Accept All" on countless pop-up banners simply to access content, rendering the foundational legal principle of "informed consent" functionally meaningless.

The primary elements of the DMA’s lobbying effort and the surrounding regulatory framework include:

  • The Core Proposal: The DMA is asking the UK Government to remove the mandatory consent requirement for low-risk cookies and similar storage and access technologies under PECR.
  • Scope Expansion: The organization wants these exemptions to explicitly cover consumer loyalty schemes, CRM databases, and routine marketing measurements where identical tracking methods are deployed under robust safeguards.
  • The Legislative Vehicle: The Data (Use and Access) Act 2025 has empowered government ministers to introduce exemptions to the consent rule outlined in Regulation 6 of PECR without requiring an entirely new Act of Parliament.
  • The Email Blindspot: While the DMA’s public-facing announcement did not explicitly reference email marketing, the underlying legal mechanics mean that tracking pixels, link-decoration tools, and open-rate analytics used in commercial emails fall under the exact same regulatory framework (PECR Regulation 6). Any legislative carve-out for website cookies will inevitably apply to email tracking technologies.
  • The AI Complication: The DMA’s policy paper introduces a forward-looking concern regarding artificial intelligence: as autonomous AI agents begin browsing the web on behalf of human users, empirical research shows that these agents routinely accept every consent banner by default, fundamentally undermining the human-centric consent model.
  • Current Status: No laws have changed yet. The policy paper remains confidential to government officials, and current regulations remain fully enforceable. The DMA is actively gathering case studies from its members to demonstrate the financial and operational costs of current banner mandates.

Chronology of Events

To understand how the UK arrived at this regulatory crossroads, it is necessary to trace the convergence of privacy law, technological evolution, and digital marketing advocacy over recent years.

April 29: The ICO Clarifies the Boundaries

The Information Commissioner’s Office (ICO) published its final, comprehensive guidance on the use of storage and access technologies. This updated guidance definitively clarified that tracking pixels embedded in marketing emails—which record when, where, and on what device an email is opened—must comply with the strict consent rules of PECR Regulation 6, mirroring the legal treatment of website cookies. Furthermore, the guidance brought "link decoration" (appending tags to newsletter links to track sources) under the same regulatory microscope.

Throughout Summer 2025: Legislative Realignment

As the UK Parliament debated and ultimately passed the Data (Use and Access) Act 2025, lawmakers recognized the need for regulatory flexibility. The Act granted ministers the discretionary power to amend or introduce exemptions to PECR Regulation 6. This legislative mechanism transformed what was previously an intractable European-derived rule into a dynamic policy tool that domestic ministers could adjust.

September 24: The DMA Submits Its Proposal

The DMA published its official announcement detailing its outreach to the government. The organization formally requested that ministers utilize their new powers under the Data (Use and Access) Act 2025 to end cookie banners for low-risk uses. The comprehensive policy paper was submitted directly to relevant government departments, bypassing immediate public release while initiating high-level consultations.

Present Day: Evidence Gathering and Inter-Departmental Deliberation

Civil servants across multiple government bodies are evaluating how to draft potential exemptions. Simultaneously, the DMA has mobilized its corporate membership base, collecting concrete examples of how redundant consent banners inflate business costs without providing tangible privacy benefits to consumers.


Supporting Data and Regulatory Mechanics

To fully grasp why the DMA’s proposal carries such weight, one must examine the legal interplay between the Data (Use and Access) Act 2025, PECR, and the Information Commissioner’s Office (ICO) guidelines.

The PECR Puzzle: Regulation 22 vs. Regulation 6

In the realm of direct marketing, email communication is primarily governed by Regulation 22 of PECR. Under this regulation, marketers often rely on the "soft opt-in" exemption, which allows businesses to send marketing emails to existing customers who purchased a product or service, provided they were given a clear opportunity to opt out at the point of collection.

However, the technology inside the email is subject to a completely different legal standard. When a marketer embeds a tracking pixel or utilizes link decoration, that technology reads or stores information on the recipient’s device. This triggers Regulation 6 of PECR.

Crucially, while the soft opt-in covers the delivery of the email message, it provides no equivalent permission for the tracking pixel embedded within it. Consequently, under current ICO guidance finalized in April, marketers theoretically require distinct, affirmative consent for the pixel itself, creating a fractured compliance burden where the email may be legally sent, but the measurement of its success violates tracking laws.

The AI Factor and Autonomous Browsing

The DMA’s submission also introduces a fascinating technological critique of the modern consent paradigm: the rise of AI agents. As consumers increasingly deploy personal AI assistants to manage their digital lives, surf the web, and compare products, these automated agents encounter thousands of cookie banners daily.

Early research cited in the DMA’s paper reveals a critical flaw in automated compliance: AI agents, programmed to optimize for task completion and speed, overwhelmingly accept every cookie banner and privacy prompt by default. This empirical reality dismantles the legal fiction that consent banners ensure meaningful human autonomy and informed choice. If an algorithm accepts a tracking cookie on behalf of a human without reading or weighing the privacy trade-offs, the consent mechanism has failed its statutory purpose.


Official Responses and Industry Perspectives

The debate over cookie banners exposes a fundamental philosophical split in the digital economy: the tension between administrative burden and user privacy rights.

The Marketing Sector’s View: Banner Fatigue and Economic Waste

Rachel Aldighieri, Chief Executive of the DMA, did not mince words when assessing the current state of digital compliance. In statements accompanying the policy release, Aldighieri pointed out an undeniable empirical truth: almost nobody reads cookie banners.

"The law treats a click on ‘accept’ as informed consent when it is no such thing," Aldighieri stated. Consumers, exhausted by constant interruptions, engage in reflexive clicking—treating banners as digital obstacles to be cleared rather than genuine notifications of data processing.

For businesses, particularly small and medium-sized enterprises (SMEs), designing, implementing, and maintaining complex Consent Management Platforms (CMPs) represents a substantial financial drain. The DMA argues that forcing organizations to collect explicit consent for low-risk, non-intrusive analytical processes—such as measuring aggregate website traffic or monitoring whether a customer opened a transactional receipt—adds regulatory friction without enhancing personal data safety.

The Regulatory Position: The ICO’s Guardrails

While the government holds the pen on legislative exemptions, the ICO remains the ultimate watchdog tasked with enforcing compliance and protecting consumer data rights.

The ICO’s stance, reinforced in its April guidance, has been that tracking technologies—whether placed via a browser or delivered via an HTML email—represent an intrusion into the terminal equipment of the user. The regulator has consistently maintained that transparency and user control are paramount.

However, the ICO operates within boundaries established by Parliament. If ministers use the powers granted by the Data (Use and Access) Act 2025 to carve out specific exemptions for low-risk measurement, CRM operations, or loyalty schemes, the ICO will be legally bound to adapt its enforcement guidance accordingly.


Implications for Businesses, Marketers, and Consumers

If the UK Government accepts the DMA’s recommendations and drafts legislation to exempt low-risk technologies from PECR Regulation 6, the ripple effects will transform multiple sectors.

1. The Transformation of Email Marketing and Analytics

If ministers craft an exemption covering routine measurement or marketing communications within an existing customer relationship, the operational reality of email marketing will shift dramatically.

  • Streamlined Tracking: Standard open-rate tracking, device identification, and click-through analytics could become frictionless, sparing marketers from attempting to secure explicit, granular consent for every pixel embedded in an email campaign.
  • Legal Harmonization: Such an exemption would bridge the historical disconnect between PECR Regulation 22 (the soft opt-in for emails) and Regulation 6 (the device-access rule for pixels), aligning the law with commercial reality.

2. Website User Experience: The Death of the Banner?

For ordinary web users, the most visible impact would be the potential disappearance of annoying cookie banners for sites that rely exclusively on low-risk, first-party analytics or functional performance tracking. Browsing the web could become noticeably smoother and less obstructed. However, high-risk tracking—such as cross-site behavioural profiling, third-party advertising trackers, and sensitive data collection—would remain strictly subject to consent rules.

3. The Drafting Challenge: Ambiguity and Enforcement

Everything hinges on the precise statutory drafting of the forthcoming exemptions—a text that, as of publication, remains confidential within government offices.

  • If the definitions of "low-risk" or "measurement" are drawn too broadly, consumer privacy advocates may sound the alarm over potential loopholes that allow unmonitored profiling.
  • If the definitions are drawn too narrowly, businesses may find themselves locked into the exact same compliance burdens they are currently fighting to escape.

4. A Divergence from EU Standards?

By potentially relaxing rules on low-risk cookies and tracking pixels, the UK government is flirting with a regulatory divergence from the European Union’s General Data Protection Regulation (GDPR) and ePrivacy directives. While businesses operating solely within the UK could benefit from reduced red tape, multinational corporations operating across both the UK and the EU will still need to comply with Brussels’ stricter, unyielding consent frameworks for European audiences.


What Happens Next?

For now, the status quo remains firmly in place. Current legislation and ICO guidelines are fully active, and businesses must maintain their existing compliance structures or risk severe financial penalties.

The DMA has not provided a definitive timetable for government action. Instead, the association is actively engaged in an evidence-gathering campaign, collecting case studies and financial data from its corporate members to illustrate the exact costs associated with redundant consent banners. This data will be used to lobby civil servants during the crucial drafting phase of the new exemptions.

As the Department for Culture, Media and Sport (DCMS), the Department for Business, Innovation, Science and Trade (DBIST), and the Cabinet Office review the DMA’s proposals, the digital marketing industry stands at a critical juncture. Whether the government chooses to dismantle the ubiquitous cookie banner and modernize email tracking laws will depend on its ability to strike a delicate balance: alleviating the administrative fatigue weighing down the digital economy while preserving essential safeguards for consumer privacy in an increasingly automated world.