Skip to main content
Category: Consent Principles

Device Storage Duration Disclosure

Also known as: Device Storage Duration & Access Disclosure, Device Storage and Operational Disclosures
Simply put

Device Storage Duration Disclosure is a requirement, developed within the IAB's Transparency and Consent Framework (TCF), for vendors to tell users how long the cookies or other data they place on a device will remain stored. It also covers whether that storage period can be refreshed or renewed. The aim is to give users clearer information about how long tracking or storage technologies operate on their devices.

Formal definition

Device Storage Duration Disclosure refers to a set of TCF specifications and policies under which participating vendors must declare, in a structured format, the maximum duration for which information is stored on a user's device and whether that duration may be refreshed. Under the IAB Europe TCF policies, a vendor is required to indicate on the Global Vendor List (GVL) the maximum storage duration, and, per the finalized Device Storage Duration & Access Disclosure specification, vendors must maintain a corresponding JSON disclosure file reflecting these requirements. According to the evidence, all vendors were directed to update their Device Storage Duration & Access Disclosure JSON file to reflect new requirements by May 31, 2026. These disclosures support transparency about the duration of operation of cookies and analogous device-storage or access technologies within the TCF, but as an industry framework the TCF is a self-regulatory mechanism and adherence to it does not by itself establish compliance with the ePrivacy rules governing device storage and access or with the GDPR's requirements for valid consent and lawful processing; legal assessment of those obligations is outside the scope of this specification. Practitioners should note that the scope of the disclosure covers stored information and its refresh characteristics as declared by the vendor, and does not independently verify the accuracy of vendor declarations.

Why it matters

Duration is a core element of transparency about tracking technologies. Users can only make informed choices about cookies and analogous device-storage mechanisms if they understand not just what data is placed on their devices, but how long it persists and whether that period can be quietly extended through refreshing. Device Storage Duration Disclosure formalizes this within the IAB's Transparency and Consent Framework, requiring participating vendors to declare maximum storage durations and refresh characteristics in a structured, machine-readable way. This structured approach allows consent management platforms and downstream systems to surface consistent information rather than relying on ad hoc or absent disclosures.

Who it's relevant to

TCF-participating vendors
Vendors registered on the Global Vendor List are directly responsible for declaring maximum storage durations and refresh characteristics, and for maintaining an accurate Device Storage Duration & Access Disclosure JSON file. Per the evidence, vendors were directed to update this file to reflect the new requirements by May 31, 2026, making this an operational obligation for teams managing GVL registrations.
Consent management platform (CMP) providers
CMPs consume the structured disclosures produced under the TCF and may surface storage duration information to users. Providers should account for the finalized specification and the associated JSON file requirements in how they read and present vendor declarations, while recognizing that the framework supports transparency but does not itself establish legal compliance.
Privacy officers and data protection professionals
Those overseeing cookie and tracking governance can use these disclosures as an input to transparency assessments, since storage duration is relevant information for users. However, the TCF is a self-regulatory industry mechanism; adherence to it does not by itself establish compliance with the ePrivacy rules governing device storage and access or with the GDPR's requirements for valid consent, so independent legal assessment remains necessary.
Web developers and technical implementation teams
Teams integrating vendor tags, SDKs, and CMP logic may need to align their handling of the JSON disclosure file with the finalized specification. Because similar technologies such as pixels, local storage, and other device-access mechanisms can fall within the same transparency concerns, developers should confirm which of their storage and access practices are covered by the vendor declarations.

Inside Device Storage Duration Disclosure

Storage Duration Statement
The specific period for which each cookie or similar technology remains stored on the user's device, typically expressed in a concrete unit (for example seconds, days, months, or years) rather than a vague reference such as 'as needed'. Under EU guidance interpreting the ePrivacy Directive and the GDPR's transparency principle, this information is generally expected to be disclosed to the user before or at the time consent is sought.
Per-Technology Granularity
Duration disclosures are generally expected at the level of individual cookies or trackers, not only in aggregate. This includes non-cookie technologies such as pixels, local storage, and SDKs, which fall within the same rules even though they are not literally cookies. Some storage mechanisms (for example certain local storage entries) may persist until manually cleared, and this should be stated where relevant.
Persistent vs. Session Distinction
A distinction between session storage, which typically expires when the browser session ends, and persistent storage, which remains for a defined retention period or until deletion. This distinction helps users understand the practical duration of each technology on their device.
First-Party vs. Third-Party Context
An indication of whether the storage is set by the site operator (first-party) or by a third party, since the durations set by third parties may differ and may be outside the direct control of the site operator. The disclosure should reflect the actual behaviour of both where third-party technologies are present.
Legal Basis for the Disclosure Requirement
In most EU jurisdictions the expectation to disclose storage duration derives from the transparency and 'informed' elements of valid consent under the GDPR, read together with the ePrivacy Directive's rules on storing and accessing information on a device. The two regimes are distinct: the ePrivacy rules govern the storage itself, while the GDPR governs any resulting personal data processing and its transparency obligations.

Common questions

Answers to the questions practitioners most commonly ask about Device Storage Duration Disclosure.

Does disclosing cookie storage duration satisfy my consent obligations on its own?
No. Disclosing how long cookies or similar technologies persist on a device is one element of providing informed consent, but it does not by itself make consent valid. Under the GDPR, consent must still be freely given, specific, informed, and unambiguous, which generally requires a clear affirmative action alongside broader disclosures such as the purposes of processing and the identity of parties involved. Storage duration disclosure supports the transparency requirement but does not replace the full set of conditions for valid consent, and it does not substitute for a lawful basis where one is required.
Is storage duration disclosure only relevant to cookies?
No. Although the term references cookies, similar technologies such as pixels, local storage, software development kits (SDKs), and device fingerprinting techniques can also store or retain information on or about a user's device. In most EU jurisdictions the ePrivacy rules governing access to and storage of information on a device apply to these technologies as well, so duration-related transparency may be relevant to them even though they are not literally cookies. The precise treatment can depend on how a given technology functions and how national authorities interpret it.
Where should storage duration information typically be presented to users?
Storage duration information is commonly presented within a cookie policy or notice and, in more granular form, within a consent management platform (CMP) interface, often at the level of individual cookies or categories. Placement should support the informed element of consent, meaning the information should be reasonably accessible before or at the point a user makes a choice. There is no single mandated format, and expectations can vary between the EU, the UK, and other regimes, so the appropriate presentation depends on the applicable framework and any relevant guidance from the competent authority.
How specific should the disclosed duration be?
Practice varies, but many organizations disclose a defined retention period for each cookie or a representative period per category, expressed in a unit such as days, months, or years, and distinguish session cookies from persistent ones. The level of granularity that is expected can differ by jurisdiction and by the guidance of the relevant data protection authority. Where a duration cannot be stated as a fixed figure, describing the basis on which it is determined may be appropriate. This entry does not prescribe a specific required duration, as that is not something that can be stated uniformly across regimes.
How should third-party cookie durations be handled in disclosures?
Third-party cookies and similar technologies are often set by parties other than the site operator, and their durations may be determined by those third parties. Organizations frequently rely on information provided by vendors or captured through a CMP to disclose these durations, and keeping that information accurate typically requires periodic review as third-party behavior changes. Where a third party controls the storage period, the disclosure should reflect that reality rather than imply the site operator sets it. The allocation of responsibility between parties can raise questions that depend on facts outside the scope of this definition.
How can storage duration disclosures be kept accurate over time?
Because the cookies and technologies deployed on a site can change as scripts, vendors, and third-party services are updated, disclosed durations can become outdated. Many organizations use periodic scanning or auditing, combined with CMP records, to detect discrepancies between disclosed and actual durations. A CMP or scanning tool can support this process but does not guarantee accuracy or compliance, and maintaining reliable disclosures generally involves ongoing review rather than a one-time exercise. The appropriate cadence and controls depend on the organization's specific deployment and applicable obligations.

Common misconceptions

Stating a single overall duration for the whole cookie banner or website satisfies the disclosure obligation.
Guidance from EU data protection authorities generally indicates that duration should be disclosed at a per-technology level, because different cookies and trackers persist for very different periods. A single blanket figure typically does not give users the specific, informed picture that valid consent is generally expected to require, though the precise level of detail expected can vary between authorities and remains subject to evolving guidance.
Duration disclosure requirements are identical everywhere, so one statement works for all users.
Obligations vary by jurisdiction. In most EU jurisdictions and the UK, duration disclosure is tied to the informed-consent standard and the ePrivacy rules. Under US state privacy laws such as the CCPA and CPRA in California, the framework often relies on opt-out rather than opt-in, and the emphasis and required content of disclosures may differ. The geographic scope of any specific requirement should always be identified.
Publishing accurate durations in a cookie policy makes the site compliant.
Accurate duration disclosure is one component of transparency, but it does not by itself establish compliance. Consent must still be freely given, specific, informed, and unambiguous, and other obligations (such as consent logging and honouring withdrawal) also apply. A consent management platform can support these disclosures but does not replace legal judgment or guarantee compliance, and stated durations must also match the technologies' actual behaviour.

Best practices

Document the actual storage duration of each cookie and similar technology (including pixels, local storage, and SDKs) and disclose it at a per-technology level rather than as a single aggregate figure.
Distinguish clearly between session and persistent storage, and flag technologies such as certain local storage entries that may persist until the user manually clears them.
Indicate whether each technology is first-party or third-party, and verify third-party durations against the providers' actual behaviour rather than assuming a default.
Reconcile disclosed durations with the technologies' real behaviour on a recurring basis, since scripts and third-party tags can change; periodically re-scan and update the disclosure.
Tailor the scope and presentation of duration disclosures to the applicable jurisdictions (for example EU/UK informed-consent expectations versus US state opt-out frameworks), and state which users or regions each disclosure applies to.
Treat duration disclosure as one element of a broader transparency and consent programme, retaining supporting records and seeking legal review rather than relying on a CMP alone to establish compliance.