UK ICO Compliance

Best Practices for UK ICO Consent Compliance

The UK Information Commissioner’s Office (ICO) outlines how organizations must approach cookie consent within the scope of the Privacy and Electronic Communications Regulations (PECR). These requirements go beyond legal compliance, they are designed to ensure that users are given clear, fair, and transparent choices about how their data is used. 

In this topic, we highlight the essential principles of an ICO-aligned consent framework and show how Inmobi CMP can be applied to put these principles into practice. 

Requirements for Valid Consent 

In alignment with GDPR principles, the ICO requires that consent is more than a simple acknowledgment. It must reflect a user’s clear and deliberate choice. For a consent banner to be considered compliant, it needs to embody four core qualities: freely given, specific, informed, and unambiguous.

Standard  Explanation 
Freely given  Consent should be offered without pressure. Users must be able to decline cookies without losing access to the main content or service. 
Unambiguous  Consent must come from a deliberate action. Assumptions such as “continuing to browse means you agree” do not qualify as valid under ICO rules. 
Specific and informed  Users need clear, plain-language details on what data is collected, why it is used, and how cookies support those purposes, so they can make an informed decision. 

 The Inmobi CMP platform provides the functionality to implement these standards effectively and helps ensure your consent messaging is consistent with ICO requirements. 

Right to Decline and Withdraw Consent

Standard  Explanation 
Balanced acceptance and rejection  The consent interface should not favor acceptance over refusal. If a single-click “Accept All” option is offered, an equivalent “Reject All” or “Continue without accepting” option should appear with equal prominence on the first layer
Simple withdrawal   Users must have ongoing access to review and change their preferences. This is typically achieved through a persistent element, such as a footer link or a privacy icon, that reopens the consent banner at any time.  

InMobi CMP supports these requirements through an option in the Themes settings, which provides the necessary setup required to be compliant with the UK ICO.  

Record-Keeping and Accountability

Accountability is a central principle of the ICO’s guidance. Organizations must be able to show that consent was collected properly and that reliable records are maintained over time. A Consent Management Platform (CMP) plays a key role in enabling this transparency. 

Standard  Explanation 
Documented proof of consent  Every user decision should be logged securely, with details such as the date, time, and specific preferences selected. Within the Inmobi CMP platform, these records are generated automatically to ensure accuracy and consistency. 
Comprehensive audit trail  Maintaining this information creates a verifiable trail of evidence. Such records can be critical if the ICO requests confirmation of your consent practices during an investigation or complaint process. 

Further Guidance 

For official examples and deeper advice, see the ICO’s resource: How do we manage consent in practice

By following these practices, you ensure your consent experience is both compliant and user-centric—protecting your business while respecting user rights. 

On This Page

Last Updated on: 23 Sep, 2025