Skip to main content
Category: Consent Principles

Re-consent

Also known as: Reconsent, Ongoing consent, Re-consenting
Simply put

Re-consent is the process of asking someone to give their consent again, rather than relying on a consent they gave earlier. In the cookie and privacy context, it generally means prompting a user to make a fresh consent decision, for example after changes to how cookies or tracking technologies are used, after a set period of time, or when the original consent may no longer be valid. It is important to note that the evidence available here describes re-consent in the setting of human-subject research, and its application to cookie consent should be understood as an analogous practice rather than a directly documented one.

Formal definition

Re-consent refers to an action in which a data subject makes a consent decision again, replacing or renewing a prior consent record. In research contexts, from which the available evidence is drawn, re-consent is typically triggered when circumstances change, such as material amendments to the terms presented or the emergence of new information, and it may be performed as soon as possible or at a subsequent interaction point. Applied to cookie consent, re-consent would generally involve re-presenting the consent interface and capturing a new clear affirmative action where the original consent can no longer be relied upon, for instance following changes to the categories or purposes of cookies and similar technologies (pixels, local storage, SDKs), or where an organization applies a consent refresh interval. Under EU frameworks, any renewed consent would still need to be freely given, specific, informed, and unambiguous, and be logged as a distinct record; however, the specific circumstances requiring re-consent, and the intervals used, are not settled by uniform regulatory guidance and depend on data protection authority positions and the facts of each case. The evidence packet does not address cookie-specific re-consent triggers, timing, or record-keeping obligations, and those aspects fall outside the scope of what can be stated from these sources.

Why it matters

Re-consent addresses a core weakness in treating consent as a one-time event: a decision a user made at an earlier point may no longer accurately reflect what they are agreeing to. When the categories or purposes of cookies and similar technologies change, or when an organization applies a consent refresh interval, continuing to rely on a stale consent record risks processing personal data on a basis that is no longer specific or informed. Under EU frameworks, consent must be freely given, specific, informed, and unambiguous, and those qualities can erode as the underlying tracking practices evolve away from what the user originally saw.

For compliance teams, re-consent is therefore less about a fixed rule and more about maintaining a defensible link between what a user was told and what actually happens on the site. Where that link breaks, for example after material changes to how tracking technologies are used, prompting a fresh consent decision helps ensure the organization is not relying on a consent that can no longer support the processing. It is worth stressing that the evidence available here describes re-consent as an established practice in human-subject research rather than a directly documented cookie-consent requirement; its application to cookies should be understood as an analogous practice.

The specific circumstances that require re-consent, and any intervals used, are not settled by uniform regulatory guidance. They depend on the positions taken by individual data protection authorities and on the facts of each case, and they may differ between the EU, the UK, and jurisdictions such as US states that often rely on opt-out rather than opt-in models. Organizations should treat re-consent as a matter for legal judgment informed by current authority guidance rather than as a mechanically defined obligation.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for a consent program need to decide when a previously captured consent can no longer be relied upon and a fresh decision must be sought. This includes assessing material changes to tracking purposes and considering whether to apply a consent refresh interval, recognizing that the appropriate triggers and timing are not fixed by uniform guidance and depend on data protection authority positions and the facts.
Legal counsel and compliance teams
Counsel must exercise judgment on whether re-consent is required in a given situation and ensure any renewed consent still meets applicable standards, under EU frameworks, that consent is freely given, specific, informed, and unambiguous. They also need to account for differences in scope between the EU, the UK, and US state regimes, and should not assume a single approach is lawful everywhere.
Web developers and CMP implementers
Technical teams operationalize re-consent by re-presenting the consent interface, capturing a new clear affirmative action, and logging it as a distinct record. This is relevant when consent banners, categories, or the tracking technologies behind them change, so that captured consent continues to correspond to actual site behavior.
Marketing compliance teams
Teams deploying analytics, advertising, and functional cookies and similar technologies are directly affected when changes to those tools may require users to be prompted again. They should coordinate with privacy and legal colleagues before altering the purposes or categories of technologies that rely on user consent.

Inside Re-consent

Renewed affirmative action
Re-consent involves prompting a user to provide a fresh, clear affirmative action to confirm or renew their consent choices, rather than relying on a previously stored preference. This is intended to maintain consent that remains freely given, specific, informed, and unambiguous under the GDPR standard.
Consent expiry or refresh cycles
Many organizations re-prompt users after a defined period so that stored consent does not persist indefinitely. There is no single universally mandated interval; expectations vary and some data protection authorities in EU jurisdictions have offered guidance suggesting periodic renewal, but practitioners should treat any specific duration as a matter of local guidance and risk assessment rather than a fixed rule.
Triggering events for re-consent
Circumstances that may warrant seeking consent again include material changes to the purposes of processing, the addition of new cookies, vendors, or tracking technologies (including pixels, SDKs, or local storage), changes to the CMP configuration, or significant updates to the privacy or cookie notice that alter what a user was originally informed about.
Re-consent versus withdrawal
Re-consent concerns actively re-seeking permission, which is distinct from a user's right to withdraw consent at any time. Withdrawal must be as easy as giving consent, whereas re-consent is initiated by the controller to keep permissions current.
Record-keeping and logging
Each re-consent event should be logged as a new consent record, typically capturing what the user was shown, the choices made, and the timestamp. This supports demonstrating ongoing compliance, though such records evidence rather than guarantee lawful processing.
Scope limitations
Re-consent primarily addresses consent obtained under the ePrivacy rules for placing or accessing information on a device and any linked GDPR consent for subsequent processing. It does not necessarily apply where processing relies on a different lawful basis, and its relevance differs under opt-out frameworks such as certain US state privacy laws where periodic opt-in renewal is generally not the operative model.

Common questions

Answers to the questions practitioners most commonly ask about Re-consent.

Does re-consent need to be collected on a fixed schedule, such as every 12 months?
No. Contrary to a common misconception, there is no universal fixed expiry period that mandates re-consent at a set interval. Some data protection authorities in the EU have suggested that periodically refreshing consent is good practice, and certain national guidance references indicative timeframes, but these are generally recommendations rather than a harmonised legal rule. The appropriate interval depends on factors such as the nature of the processing, how the cookies are used, and whether the original consent remains valid, specific, and informed. You should treat any single duration as a guideline to be assessed against applicable guidance in your jurisdiction, not as a definitive legal deadline.
If we re-consent users, does that automatically make our prior data processing lawful?
No. Re-consent operates prospectively and does not retroactively cure consent that was invalidly obtained. If earlier consent failed to meet the applicable standard, for example, if it relied on pre-ticked boxes, implied consent from continued browsing, or a non-compliant cookie wall, then re-consent going forward does not remedy the earlier placing of or access to information on the device, nor any personal data processing that followed under the GDPR. Re-consent addresses the validity of consent from the point it is properly collected; the lawfulness of past activity is a separate question that depends on the facts and applicable law.
What events, other than the passage of time, should trigger a re-consent prompt?
Re-consent may be appropriate whenever the original consent can no longer be relied upon as freely given, specific, informed, and unambiguous. Common triggers include material changes to the purposes of processing, the introduction of new categories of cookies or similar technologies (such as new pixels, SDKs, or tracking scripts), the addition of new third-party vendors or recipients, and significant changes to how data is shared. Changes to your consent management platform configuration or to the legal basis relied upon may also warrant a fresh consent flow. Whether a given change requires re-consent depends on its significance and on applicable guidance, so this should be assessed case by case rather than treated as automatic.
How should a re-consent request be presented to users so it remains valid?
A re-consent request should generally meet the same standard as an initial consent request under EU law: it must be based on a clear affirmative action, be specific to the relevant purposes and technologies, and be accompanied by the information users need to make an informed choice, including what has changed. Withdrawing consent should be as easy as giving it. Re-presenting the request should not degrade into a pattern that pressures users into agreeing, and the ability to decline should remain genuine. Requirements differ across the EU, the UK, and US state regimes, so the exact presentation should be aligned with the framework or frameworks that apply to your users.
How should we record and log re-consent for accountability purposes?
Consistent with record-keeping expectations under the GDPR's accountability principle, organisations generally maintain records demonstrating that valid consent was obtained, typically including what the user was shown, which purposes and technologies they consented to, the timestamp, and the mechanism used. The same approach applies to re-consent: a new consent record is usually created reflecting the refreshed choice, while retaining prior records where relevant. A consent management platform can support this logging, but it does not by itself establish compliance; the underlying consent flow and its documentation must satisfy the applicable legal standard. Retention of consent logs should be considered against data minimisation and applicable retention obligations.
Should we block cookies until re-consent is obtained, and what happens to users who do not respond?
In most EU jurisdictions, non-essential cookies and similar technologies should not be placed or accessed before valid consent is given, so where existing consent is no longer relied upon, the associated technologies should generally be suspended until fresh consent is obtained. Strictly necessary or essential cookies typically remain exempt and need not be blocked. For users who do not respond to a re-consent prompt, the safer default in an opt-in regime is to treat the non-essential technologies as not consented and refrain from deploying them, rather than assuming continued agreement. Under opt-out frameworks such as certain US state laws, the analysis differs and continued processing may be permissible absent an opt-out signal. The correct handling depends on the applicable regime and should not be assumed uniform.

Common misconceptions

Once a user consents, that consent is valid forever and never needs to be sought again.
Consent is not necessarily permanent. In most EU jurisdictions, guidance and enforcement practice suggest that consent can become stale, particularly after long periods or when the processing changes materially, in which case re-consent may be advisable. The absence of a single fixed expiry period means this is a risk-based decision informed by local data protection authority guidance rather than a universal rule.
Re-consent is a legal obligation with a fixed, universally mandated time limit.
There is no single duration that applies everywhere. Some authorities in EU jurisdictions have suggested periodic renewal, but intervals differ and depend on context. Practitioners should not treat any particular number of months as definitively required, and requirements differ again under UK and various US state frameworks.
Re-prompting users through a CMP automatically makes ongoing tracking compliant.
A CMP can facilitate and log re-consent, but the tool does not itself guarantee compliance. Whether renewed consent is valid still depends on it being freely given, specific, informed, and unambiguous, on accurate disclosure of purposes and technologies, and on legal judgment applied to the specific facts and jurisdiction.

Best practices

Define and document a re-consent policy that sets out when consent will be refreshed, tying triggers to material changes in purposes, new cookies, vendors, or tracking technologies, and to any renewal intervals informed by applicable data protection authority guidance.
Treat each re-consent as a fresh consent event: present clear, updated information and require a new affirmative action rather than relying on pre-ticked boxes, implied consent, or continued browsing, which are generally considered non-compliant in the EU.
Log every re-consent interaction as a distinct record capturing what was shown, the choices made, and the timestamp, to support demonstrating ongoing compliance without overstating that logs alone establish lawfulness.
Re-prompt users when the cookie or privacy notice changes materially or when new pixels, SDKs, local storage, or fingerprinting techniques are introduced, since these fall within the same consent rules even though they are not literally cookies.
Ensure withdrawing consent remains as easy as granting or renewing it, and keep the two flows distinct so that re-consent prompts do not undermine a user's ability to decline or opt out.
Adapt the approach to the relevant jurisdiction, recognizing that opt-in re-consent reflects EU and UK expectations while US state laws such as the CCPA and CPRA typically operate on an opt-out model, and seek legal input where interpretations are contested or facts fall outside the definition.