Re-consent
Re-consent is the process of asking someone to give their consent again, rather than relying on a consent they gave earlier. In the cookie and privacy context, it generally means prompting a user to make a fresh consent decision, for example after changes to how cookies or tracking technologies are used, after a set period of time, or when the original consent may no longer be valid. It is important to note that the evidence available here describes re-consent in the setting of human-subject research, and its application to cookie consent should be understood as an analogous practice rather than a directly documented one.
Re-consent refers to an action in which a data subject makes a consent decision again, replacing or renewing a prior consent record. In research contexts, from which the available evidence is drawn, re-consent is typically triggered when circumstances change, such as material amendments to the terms presented or the emergence of new information, and it may be performed as soon as possible or at a subsequent interaction point. Applied to cookie consent, re-consent would generally involve re-presenting the consent interface and capturing a new clear affirmative action where the original consent can no longer be relied upon, for instance following changes to the categories or purposes of cookies and similar technologies (pixels, local storage, SDKs), or where an organization applies a consent refresh interval. Under EU frameworks, any renewed consent would still need to be freely given, specific, informed, and unambiguous, and be logged as a distinct record; however, the specific circumstances requiring re-consent, and the intervals used, are not settled by uniform regulatory guidance and depend on data protection authority positions and the facts of each case. The evidence packet does not address cookie-specific re-consent triggers, timing, or record-keeping obligations, and those aspects fall outside the scope of what can be stated from these sources.
Why it matters
Re-consent addresses a core weakness in treating consent as a one-time event: a decision a user made at an earlier point may no longer accurately reflect what they are agreeing to. When the categories or purposes of cookies and similar technologies change, or when an organization applies a consent refresh interval, continuing to rely on a stale consent record risks processing personal data on a basis that is no longer specific or informed. Under EU frameworks, consent must be freely given, specific, informed, and unambiguous, and those qualities can erode as the underlying tracking practices evolve away from what the user originally saw.
For compliance teams, re-consent is therefore less about a fixed rule and more about maintaining a defensible link between what a user was told and what actually happens on the site. Where that link breaks, for example after material changes to how tracking technologies are used, prompting a fresh consent decision helps ensure the organization is not relying on a consent that can no longer support the processing. It is worth stressing that the evidence available here describes re-consent as an established practice in human-subject research rather than a directly documented cookie-consent requirement; its application to cookies should be understood as an analogous practice.
The specific circumstances that require re-consent, and any intervals used, are not settled by uniform regulatory guidance. They depend on the positions taken by individual data protection authorities and on the facts of each case, and they may differ between the EU, the UK, and jurisdictions such as US states that often rely on opt-out rather than opt-in models. Organizations should treat re-consent as a matter for legal judgment informed by current authority guidance rather than as a mechanically defined obligation.
Who it's relevant to
Inside Re-consent
Common questions
Answers to the questions practitioners most commonly ask about Re-consent.