GDPR and PECR compliant lead tracking: the UK guide
28 July 2026 · Consent & privacy · Guides
Last updated: 13 July 2026. This article is general information for marketers, not legal advice. If you're making compliance decisions for your business, speak to a qualified adviser.
Tracking where your leads come from is legal in the UK. It always has been. What often is illegal is the way plenty of businesses end up doing it: identifiers dropped before anyone consents, form data joined to browsing history nobody mentioned, marketing emails sent on the back of a cookie banner click.
The frustrating part is that the fix isn't complicated. UK lead tracking sits under two laws, and each one asks a single question. PECR asks: what are you storing on the visitor's device? UK GDPR asks: what are you doing with the personal data once you have it? Answer both honestly and you can know which channel produced every lead without losing sleep over an ICO letter.
This guide walks through both laws in plain English, then gives you a checklist you can actually follow.
TL;DR: You can track which marketing produces your leads and stay fully compliant. The rules come from two places: PECR governs what you store on a visitor's device (consent for attribution cookies), and UK GDPR governs the personal data you keep (lawful basis, transparency, retention). This guide covers both, with a ten-step checklist at the end.
Which laws actually apply to lead tracking?
Two. The Privacy and Electronic Communications Regulations 2003, PECR for short, control what you store or access on a visitor's device (ICO Guide to PECR). The UK GDPR then controls how you handle their personal data afterwards. Lead tracking touches both, at different moments.
The shorthand we use internally: PECR is the cookie, GDPR is the lead record.
Think about what happens when someone clicks your Google ad and fills in your contact form. Before the form, they're an anonymous visitor, and the only question is whether you're allowed to put an identifier on their device to remember where they came from. That's PECR territory. After the form, you're holding a name, an email and a source. Now you've got personal data, and UK GDPR takes over: you need a lawful basis, you need to tell them what you're doing, and you can't keep it forever.
One trap worth naming early. PECR's storage and access rules don't just cover cookies. LocalStorage, tracking pixels, scripts and device fingerprinting all count, which the ICO made explicit when it finalised its storage and access technologies guidance in April 2026 (ICO). Swapping your cookie for a fingerprint doesn't get you out of anything.
Here's the split at a glance:
| What you're doing | Which law | What it requires |
|---|---|---|
| Dropping an attribution cookie or click ID on a visitor's device | PECR | Opt-in consent (it isn't strictly necessary) |
| Running first-party, aggregate analytics | PECR | Exempt since February 2026, with clear notice and a free way to object |
| Storing a lead's name, email and source in your CRM | UK GDPR | A lawful basis, a privacy notice, a retention limit |
| Sending that lead marketing emails later | PECR again, plus UK GDPR | Consent, or the soft opt-in for existing customers |
Everything in the rest of this guide hangs off that table.
The 2026 changes: DUAA and bigger fines
The Data (Use and Access) Act's main provisions came into force on 5 February 2026 (DLA Piper), and the headline for marketers is a new PECR exemption: first-party analytics cookies used purely for statistical purposes no longer need consent (Stevens & Bolton).
For lead tracking specifically, the change matters less than the headlines suggest. Counting visits is now easier. Connecting an individual lead to the ad they clicked is not, because that stopped being "statistical purposes" the moment you attached the data to one identifiable person. Per-lead attribution still needs consent.
The stakes moved too. PECR fines used to cap at £500,000; they now align with UK GDPR levels, up to £17.5m or 4% of global turnover (Mayer Brown). Cookie compliance stopped being a nuisance and became a board-level risk.
We've written a full breakdown of the DUAA changes, what qualifies for the exemption, and where the ICO's enforcement attention is heading in our guide to the UK cookie rules in 2026. If your question is "can I ditch my banner?", start there. This guide assumes the answer for lead tracking, which is no.
When do you need consent to track a lead?
You need consent before you store or read any attribution identifier on a visitor's device, because remembering which ad someone clicked is never "strictly necessary" under PECR (ICO storage and access guidance). That consent has to come before the identifier is set, not after.
Here's where most setups quietly go wrong. There isn't one consent in lead tracking. There are three, and they don't substitute for each other:
- Cookie consent. PECR's permission to store the attribution identifier on the device in the first place.
- Data processing consent. A UK GDPR lawful basis for holding the lead record. This one often isn't consent at all, as we'll get to in the next section.
- Email marketing consent. PECR has separate rules for electronic marketing messages, and a cookie banner click does not grant you permission to email anyone (ICO direct marketing guidance).
The moment of form submission is where the three meet. Up to that point you've got an anonymous visitor and, if they consented, a cookie holding a click ID. When they hit submit, they hand you personal data, and whatever's in that cookie can now be joined to a real person. That join is exactly what makes lead attribution useful, and exactly why it needs the consent layer to have been honest from the start.
A quick worked example. Visitor accepts your cookie banner, fills in your form, and you start sending them a weekly newsletter. Compliant? Not necessarily. The banner covered the cookie. It said nothing about email. Unless your form collected a separate, unbundled opt-in for marketing, or the soft opt-in applies because they became a customer, that newsletter is a PECR problem all of its own.
The soft opt-in, briefly: if someone bought from you (or negotiated a sale), you told them at the point of collection they could opt out, and you're marketing similar products with an opt-out in every message, you can email without explicit consent (ICO). Useful, but narrow. A lead who enquired and never bought usually doesn't qualify.
What's your lawful basis for the lead record itself?
For most businesses, legitimate interests. Someone who fills in your contact form plainly expects you to respond, and in our reading, holding their enquiry along with the source data you lawfully collected sits comfortably within that expectation. The ICO's guidance on legitimate interests is the reference point here (ICO).
Legitimate interests isn't a free pass, though. It comes with homework: a legitimate interests assessment, usually shortened to LIA. The ICO frames it as a three-part test (ICO). Is there a genuine interest? Is the processing necessary to achieve it? And does it hold up against the individual's rights and reasonable expectations? For "someone asked us a question, we recorded the enquiry and where it came from", that assessment tends to be short and comfortable. Write it down anyway. A dated, one-page LIA is the cheapest piece of compliance documentation you'll ever produce.
Two boundaries to respect.
First, legitimate interests can't rescue an unlawful cookie. If PECR required consent to set the attribution identifier and you didn't get it, you can't wave legitimate interests at the resulting data and call it fixed. The device-level consent requirement is PECR's, and GDPR lawful bases don't override it (ICO storage and access guidance).
Second, legitimate interests covers responding and basic source attribution. It stretches a lot less comfortably over enrichment, scoring against third-party data, or building a behavioural profile of everything the lead read before converting. The further you get from what the person would obviously expect, the harder the balancing test gets, and at some point the honest answer is: ask for consent, or don't do it.
Notice the pattern across this section and the last one. Consent governs the cookie. Legitimate interests usually governs the record. Consent again for the emails. Three different questions, three separate answers, and bundling them into one banner is how businesses end up non-compliant while feeling compliant.
How do you track lead sources compliantly in practice?
The pattern that works is consent-gated attribution: store nothing identifying before opt-in, capture the click ID or UTM at consent, join it to the lead at form submission, and fall back to aggregate numbers when consent is refused. Everything else in this section is detail on those four moves, and PECR's consent-first rule is why the order matters (ICO Guide to PECR).
Before consent, your site should set nothing and read nothing beyond the strictly necessary. Not a "we'll delete it if they refuse" placeholder. Nothing. The ICO's storage and access guidance treats storing anything on the device as the regulated act, so capturing first and asking later fails even if you never use the data (ICO).
When consent is refused, degrade gracefully. You lose the per-lead join, and that's the deal. What you keep is aggregate: how much traffic each channel sent, which the DUAA's analytics exemption now makes easier to count without consent, provided you give notice and a way to object (Stevens & Bolton). A report that says "60 leads, 41 attributed, 19 consented out" is honest. A report that quietly fingerprints the 19 is a fine waiting to happen.
Stay first-party. The moment a tag sends your visitors' data to an ad platform for the platform's own purposes, you've added a second data-sharing relationship to explain in your privacy notice and a second reason your banner can never shrink. First-party attribution, on your own domain, keeps the story simple: one controller, one purpose, one notice.
And minimise. Compliant attribution needs surprisingly little: the UTM parameters or click ID, the landing page, a timestamp. It does not need the visitor's full browsing history, their scroll depth on every page, or a session recording. Every extra field you store is something more to justify in the LIA, disclose in the notice, and delete on schedule. Store the answer to "which campaign produced this lead", not a surveillance diary.
This is the part where we mention our own product once, because it's the reason the product exists. We built Trackfully consent-first: it captures nothing about a visitor until they opt in, attributes the lead when consent allows, and reports refusals as aggregate rather than pretending they didn't happen. If you want to see the mechanics, the consent setup guide shows exactly what fires when, and what never fires at all.
How long can you keep lead data?
There's no fixed statutory period. UK GDPR's storage limitation principle says you can keep personal data no longer than you need it for the purpose you collected it for, and it puts the burden on you to decide, document and enforce that period (ICO).
That open-endedness makes people nervous, but it's genuinely workable. The question to ask of every lead record is: what's it still for? A live enquiry is obviously still for something. A lead who went quiet eighteen months ago and never bought is harder to defend, and "we might want to email them someday" isn't a purpose, it's a hope.
In our experience the defaults that agencies and small teams settle on look something like this. Leads that never convert get 12 to 24 months from last contact, long enough to cover slow B2B cycles, short enough to defend. Leads that become customers move into a different bucket with a different clock, because contracts, warranties and tax records carry their own timescales. Attribution data attached to the lead follows the lead: when the record goes, the click ID goes with it. Treat those as starting points to reason from, not rules to cite.
Deletion isn't the only exit. Anonymisation works too, and for attribution it's often the better move: strip the name and email, keep "one lead from that March campaign converted", and your historical channel reporting survives the cleanup. Once no individual can be identified, the record has left UK GDPR's scope.
Whatever you choose, write it down and automate it. A retention policy that relies on someone remembering to tidy the CRM every quarter is a policy that isn't happening.
Agencies: who's controller and who's processor?
In the typical setup, your client is the controller and you're the processor. The client decides why lead data is collected and what happens to it; you run the tracking on their instructions. That split matters because UK GDPR assigns each role different obligations, and it needs to be written into a contract with the processing terms Article 28 requires (ICO).
Getting the paperwork right is less painful than it sounds. Most agency-client agreements handle it with a data processing addendum: what data is processed, for what purpose, for how long, what happens on termination, and which sub-processors are involved. The tracking tool you deploy is one of those sub-processors, so its own terms need to line up. If your tool can't tell you clearly where data lives and under what terms, that's your answer about the tool.
Watch the role reversal, though. The moment you use a client's lead data for your own purposes, benchmarking across clients, training your own models, marketing your agency, you've become a controller for that use, with a controller's obligations. Plenty of agencies do this without realising it. Decide deliberately, and if you do it, say so in the contract.
Data residency is the quiet simplifier here. Keep the whole pipeline on UK soil and there's no international transfer analysis to run, no addendums for overseas processing, one less section in every client's due diligence questionnaire. It's worth asking every tool in your stack the question directly. For transparency, since we've mentioned our own tool once already: Trackfully's data is hosted in London.
One last agency-specific point. Consent collected on the client's website belongs to the client's relationship with the visitor. It doesn't transfer to your agency's newsletter, your other clients, or your prospecting list. Obvious when written down. Routinely violated in practice.
The compliance checklist
Ten steps, in the order we'd do them. Most small teams can get through the list in a week or two of focused work, and every item traces back to a requirement covered above.
- Map where lead data enters. Forms, phone calls, live chat, booking tools. You can't gate what you haven't listed.
- Audit every tag, script and pixel. Label each one: strictly necessary, first-party statistics, or attribution and advertising.
- Gate attribution behind consent. No identifier is stored or read before opt-in. Placeholder cookies count as storage, so no placeholders either.
- Test the refusal path. This is the step that catches the most problems, and the one almost nobody does. Open your own site in a private window, refuse consent, and watch the network tab to see what fires anyway. If anything attribution-related still runs, fix it before you move on to anything else.
- Update your privacy notice. Name lead source tracking as a purpose, state the lawful basis, list who the data is shared with.
- Write the LIA. One page: your interest, why the processing is necessary, why it doesn't override the lead's rights. Date it and file it.
- Unbundle email consent. A separate, unticked opt-in for marketing emails, or a documented soft opt-in position. Never inferred from the cookie banner.
- Set retention and automate it. Pick a period, write it into the notice, and schedule the deletion or anonymisation so it happens without a human.
- Sort the contracts (agencies especially). Roles documented, DPAs signed, data location confirmed.
- Diarise a review. The ICO's guidance moved twice in 2026 already. A quarterly half-hour catches drift before it becomes exposure.
Copy the list into your project tracker as is. Step 4 is the one people skip, and step 4 is the one that finds the problems.
FAQ
Is lead tracking illegal without consent?
No, but it's limited. Aggregate source tracking (how many leads each channel produced) can run without consent under the DUAA's first-party analytics exemption, with notice and an objection route (Stevens & Bolton). Tying an individual lead to their click needs opt-in consent first.
Can I see which Google ad a lead clicked without consent?
No, in our reading. Per-lead attribution means storing a click ID on the visitor's device and joining it to their form submission, and that storage needs PECR consent before it happens (ICO storage and access guidance). Without consent you get channel-level aggregates, not the individual join.
Do B2B leads count as personal data?
Yes. A named individual's work email, job title and enquiry are personal data under UK GDPR, because they relate to an identifiable person. PECR treats corporate subscribers (companies and LLPs) differently for email marketing, though sole traders and most partnerships still count as individuals (ICO). The lead record itself gets no B2B discount: lawful basis, notice and retention all still apply.
Does GA4 count as GDPR-compliant lead tracking?
Not by default, for two reasons. Stock GA4 configurations can share data with Google and feed advertising features, which takes them beyond the statistics-only exemption (Stevens & Bolton). And GA4 is an analytics tool, not a lead record: it won't manage per-lead consent, retention or subject access for you.
Do I need a DPO to track leads?
Usually not. UK GDPR only requires a data protection officer for public authorities and for organisations whose core activities involve large-scale, systematic monitoring or large-scale special category data (ICO). Ordinary lead tracking doesn't reach that bar, though someone still needs to own compliance internally.
Where that leaves you
Lead tracking and UK privacy law are not enemies. PECR asks you to get consent before you store an attribution identifier on someone's device. UK GDPR asks you to have a reason for the lead record, tell people about it, and not keep it forever. Both are entirely satisfiable while still knowing which campaign produced every consenting lead, and the aggregate picture for everyone else.
The businesses that get in trouble aren't the ones tracking leads. They're the ones tracking leads the pre-2018 way and hoping nobody looks, and with PECR fines now at GDPR levels, the hoping got expensive.
If you'd rather start from tooling that has the consent gating, the refusal path and the UK hosting built in, have a look at what Trackfully does or go straight to the getting started guide. And if you only do one thing today, do step 4 of the checklist: refuse consent on your own website and watch what happens.