Cookie Lifespan
Cookie lifespan is the length of time a cookie remains stored and valid on a user's browser before it expires. Once a cookie reaches its expiration point, the data it stored is no longer accessible. Depending on the cookie's purpose, this duration can range from a very short period, such as minutes, up to several years.
Cookie lifespan refers to the period during which a browser retains a cookie before it expires and its stored data becomes inaccessible. The duration is typically governed by an expiration attribute (for example, an Expires date or Max-Age value) set when the cookie is written; session cookies persist only until the browser session ends, while persistent cookies remain until their defined expiry. Durations vary by purpose and may span from minutes to years. Note that cookie lifespan is a technical property distinct from, though related to, the separate question of how long consent for setting a cookie remains valid before it should be re-obtained. In most EU jurisdictions, the appropriate lifespan of non-essential cookies is treated as part of the transparency and data-minimization considerations under the ePrivacy and data protection frameworks, though the evidence provided here does not establish specific maximum durations, which vary by regime and regulatory guidance.
Why it matters
Cookie lifespan is a practical dimension of both transparency and data minimization. Because cookies can persist anywhere from minutes to several years, the duration a cookie is set to remain on a user's device directly affects how long tracking or identification can continue. In most EU jurisdictions, disclosing the duration of non-essential cookies is treated as part of the information users should receive before consenting, so that consent can be considered informed. An excessively long lifespan for a purpose that does not require it can sit uncomfortably with data-minimization expectations under the ePrivacy and data protection frameworks, though the evidence here does not establish any specific maximum duration, which varies by regime and regulatory guidance.
Cookie lifespan is also distinct from, though related to, the separate question of how long consent for a cookie remains valid before it should be refreshed. A cookie may technically persist for a long period while the legal basis for setting it is a separate matter governed by the applicable consent standard. Conflating the two can lead organizations to assume that a long-lived cookie carries an equally long-lived consent, which does not follow. Treating expiration as purely a technical setting, without considering the transparency and consent implications, is a common source of compliance gaps.
For readers making compliance decisions, lifespan matters because it is something a user reasonably expects to be told and something a data protection authority may scrutinize when assessing proportionality. The appropriate duration depends on the cookie's purpose and cannot be stated as a single figure that applies everywhere.
Who it's relevant to
Inside Cookie Lifespan
Common questions
Answers to the questions practitioners most commonly ask about Cookie Lifespan.