ICO Storage and Access Technologies Guidance: Visitor ID in 2026
What the ICO's final cookie guidance of 29 April 2026 means for B2B visitor-identification scripts
The ICO's final storage and access technologies guidance, published 29 April 2026, explains how PECR and UK GDPR apply to cookies, pixels, scripts and fingerprinting. A visitor-identification script needs consent if it stores or reads anything on the device for identification, because the ICO says the statistical exception is not for identifying who uses a service.
In short
- The ICO finalised its storage and access technologies guidance on 29 April 2026, reflecting the Data (Use and Access) Act.
- PECR regulation 6 applies whenever a script stores or reads information on a device, including sessionStorage and fingerprinting.
- The statistical purposes exception, in force since 5 February 2026, is 'not for identifying, tracking or monitoring people or groups of people', in the ICO's words.
- PECR fines can now reach £17.5 million or 4% of global turnover.
- Ask every vendor exactly what its script stores and reads, and check your privacy notice names visitor identification.
The ICO storage and access technologies guidance, finalised on 29 April 2026, is the regulator's main statement on how cookie law applies to cookies, pixels, scripts and fingerprinting. If you run a B2B visitor-identification tool, the useful question is narrow: does the guidance cover it, and what do you need to do? This explainer answers that, quoting the ICO directly. It is general information, not legal advice.
What did the ICO publish on 29 April 2026?
On 29 April 2026 the Information Commissioner's Office published its finalised guidance on storage and access technologies. The ICO says it covers "how the Privacy and Electronic Communications Regulations (PECR) (and where relevant, the UK GDPR) apply to cookies, tracking pixels, device fingerprinting and similar technologies"1. It incorporates two consultations and the changes made by the Data (Use and Access) Act 20251.
The guidance itself has a short history. It was first published as a draft on 20 December 2024, updated on 7 July 2025 with a new chapter on exceptions following the Data (Use and Access) Act, and finalised on 29 April 2026 with two new sub-chapters, including one on what "a simple means of objecting" means2.
Two points from the announcement matter for marketers. First, the ICO says the guidance "reflects the law as it currently stands" and sits separately from its review of regulation 6 of PECR for online advertising1. Second, it restated its enforcement message, covered below.
Does a visitor-identification script count as "storage and access"?
It depends on what the script does on the visitor's device.
PECR's rule on storage and access applies "to any technology that stores information, or accesses information stored, on a subscriber's or user's 'terminal equipment'", which the ICO says includes cookies, tracking pixels, link decoration, web storage, fingerprinting techniques, and scripts and tags3. On scripts specifically, it says: "Regulation 6 of PECR applies whenever the use of scripts and tags accesses or stores information on a user's device"3. Web storage explicitly includes both localStorage and sessionStorage3.
So a practical test for any visitor-identification snippet:
- If it stores or reads anything on the device (a cookie, a value in localStorage or sessionStorage, or a device fingerprint), regulation 6 applies, and you need consent unless an exception fits.
- If a third-party script it loads sets its own cookies or storage, that is also storage and access on your site, and you are responsible for getting any consent needed.
- Identifying the organisation from the network address raises a UK GDPR question as well as any PECR one. The ICO notes that the UK GDPR "refers to cookies and IP addresses as types of" online identifier, so where an IP address relates to a person, it is personal data4.
Be careful with fingerprinting. The ICO says organisations sometimes use it "in the belief that regulation 6 does not apply", but that it does apply where fingerprinting stores or accesses information on a device, and it lists HTTP header information among the elements such techniques can use3. Ask your vendor exactly what its script reads and writes, not just whether it uses cookies.
For our own product, Scout's privacy notice sets out what the snippet stores and states that website owners are responsible for getting any consent their visitors need before the snippet loads, for example through their cookie banner. Our guide to visitor identification and GDPR covers the lawful-basis side in more depth.
What are the new exemptions?
Section 112 of the Data (Use and Access) Act 2025, which amends PECR's storage rule, came into force on 5 February 2026 under SI 2026/825. It added new exceptions to the consent requirement, which the ICO guidance explains6. Two matter most for marketing sites.
Statistical purposes. This applies where the sole purpose is collecting information "for statistical purposes about how the service is used with a view to making improvements to the service"6. You must give clear and comprehensive information and "a 'simple and free' means to object"6. The ICO describes it as "essentially for analytics purposes" and then draws a firm line: "It is about how your service is used, not about who uses it. It is not for identifying, tracking or monitoring people or groups of people who use your service. It also doesn't apply to things like online advertising."6
The ICO's own examples are directly relevant. It says you must obtain consent for "tracking or profiling individual visitors or categories of visitors (eg based on their IP address or the pages they visited on your website)"6. Company-level visitor identification is, by design, about who visited. Do not assume the statistical exception covers any storage a visitor-identification tool uses.
Appearance and functionality. This covers storage whose sole purpose is to adapt how the service "appears or functions in line with the subscriber's or user's preference", such as remembering a chosen language6. The ICO says it "is not about adapting the content to display to a user on your service based on known or inferred interests or behaviours about them"6.
For both exceptions, an opt-out is not optional. The ICO says: "If you don't offer this, what you're doing isn't in line with either exception."6 Law firm DLA Piper's view is that "the cookie consent exemptions are relatively narrow and will likely be challenging for clients to adopt"7.
What about "consent or pay"?
The ICO's consent or pay guidance, published on 23 January 2025, covers models where people either consent to personalised advertising or pay for access without it8. The ICO's position is that "data protection law does not prohibit 'consent or pay' business models", but organisations must be able to show consent was freely given8. It sets out four factors to assess: power imbalance, an appropriate fee, equivalence between the options, and privacy by design8.
The storage and access guidance takes the same line on cookie walls. It says that in most cases a "take it or leave it" approach "does not comply with the requirement for consent to be freely given", and points to the consent or pay guidance for the newer model9. For most B2B sites this is academic: few gate their content behind tracking. It matters if you run a paid research portal or a gated content library.
What did enforcement look like?
The ICO's announcement quoted William Malcolm, its Executive Director of Regulatory Risk and Innovation: "99% of the UK's top 1,000 websites now meet compliance standards for cookie banners owing to focused ICO work with industry."1 He added that "there is still more to do"1.
Fines have also changed. When most of the Act commenced on 5 February 2026, the ICO said it gained the ability to "issue fines of up to £17.5 million or 4% of global turnover under the Privacy and Electronic Communications Regulations (PECR)"10. DLA Piper notes that the ICO "has indicated that cookie compliance will be a renewed area of enforcement, particularly where organisations fail to offer meaningful opt-outs or rely on ambiguous statistical purposes"7.
More change may follow for advertising. On 18 May 2026 the ICO published advice to government on how regulation 6 could be amended through secondary legislation so that some lower-risk forms of online advertising could run without consent11. That is advice, not law. Until the government legislates, the current rules apply.
A checklist for B2B sites running visitor identification
| Step | What to check |
|---|---|
| Inventory | Which cookies, web storage, pixels and fingerprinting does each script use, including third-party scripts it loads? |
| Consent | Anything stored or read on the device for identification should sit behind your consent tool unless a named exception clearly fits. |
| Exceptions | If you rely on statistical or appearance exceptions, is there clear information and a simple, free opt-out? |
| Privacy notice | Does it name visitor identification, the provider, what is collected and your lawful basis? |
| Vendor questions | Where is data hosted, are raw IP addresses stored, is the vendor your processor, and what does its script store? |
On the vendor questions, it is fair to expect specific answers. Scout, for example, identifies companies rather than individuals, hosts data in the UK and EEA, and never stores raw IP addresses, keeping only salted hashes. It also shows a confidence score for each match so you are not acting on weak ones. Details are in the privacy notice.
For the wider legal changes behind all this, see what the Data (Use and Access) Act changed for B2B marketing.
The short version
The ICO's final guidance does not create a special category for visitor identification. It asks the same question of every script: does it store or read anything on the device, and for what purpose? Answer that honestly for each tool on your site, and the rest follows. If you are unsure, take advice from a solicitor or your data protection officer.
To go further, read how Scout approaches storage and IP addresses in our visitor identification GDPR guide, then try Scout free for 14 days, no card needed.
Frequently asked questions
Do I need a cookie banner for B2B visitor tracking?
If the tracking stores or reads anything on the visitor's device for identification, you will generally need consent under PECR, and a consent tool is the usual way to collect it. The ICO says the statistical purposes exception does not cover identifying or tracking visitors. This is general information, not legal advice.
Is IP-based identification a cookie?
No, an IP address arrives with every web request and is not stored on the device like a cookie. But the UK GDPR treats IP addresses as online identifiers, so it can be personal data, and a script that does IP lookups may also use cookies, web storage or fingerprinting that PECR covers. Check what the whole script does.
What is PECR's maximum fine now?
Since 5 February 2026 the ICO can issue PECR fines of up to £17.5 million or 4% of global turnover, the same level as UK GDPR. The ICO has said it reserves monetary penalties for the most serious infringements.
Does the statistical purposes exception cover Google Analytics?
It can cover analytics that produce aggregate statistics to improve your site, provided you give clear information and a simple, free way to object. It does not cover tracking or profiling individual visitors, advertising uses, or keeping individual-level data after aggregation. How a specific tool is configured matters.
Sources
- ICO: Final storage and access technologies guidance published ico.org.uk
- ICO: Guidance on the use of storage and access technologies ico.org.uk
- ICO: What are storage and access technologies? ico.org.uk
- ICO: How do the PECR rules relate to the UK GDPR? ico.org.uk
- legislation.gov.uk: The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82) legislation.gov.uk
- ICO: What are the exceptions? ico.org.uk
- DLA Piper Privacy Matters: UK: Commencement of the data protection provisions in the Data (Use and Access) Act privacymatters.dlapiper.com
- ICO: Consent or pay, about this guidance ico.org.uk
- ICO: How do the rules apply to online advertising? ico.org.uk
- ICO: Statement on the commencement of the Data (Use and Access) Act (DUAA) ico.org.uk
- ICO: Our advice to government on potential changes to online advertising rules ico.org.uk