Cookie
When Should You Re-Ask for Cookie Consent? (Consent Expiry, Explained)
20
August
2026
02
September
2026
.jpg)
TL;DR:
No law sets an exact expiry date for cookie consent, but the practical answer is clear. Re-ask roughly every 6 to 12 months (France's CNIL recommends no longer than 6 months, and the UK's ICO uses 6 months in its own example), and re-ask immediately whenever something material changes: a new cookie, a new purpose, a new third-party vendor, or an updated privacy policy. Store each visitor's choice, expire it on your chosen interval, and re-prompt. Do not ask on every visit, that is banner fatigue, not compliance.
Note: This is general information, not legal advice. Confirm the requirements for your jurisdiction with qualified counsel.
"How long does cookie consent last, and when do I have to ask again?" is one of the most common questions site owners have, and one of the worst-answered. The usual reply is a shrug and "it depends." Here is the actual, practical answer.
Does cookie consent expire?
Yes, in practice, even though the law is not precise about it. Neither the GDPR nor the ePrivacy rules set a specific number of days after which consent stops being valid. But consent is not treated as permanent either. It reflects a decision a person made at a moment in time, and after long enough, or after things change, that decision no longer reliably represents their choice.
So the real question is not "does it expire" but "on what schedule should I refresh it, and what events force an earlier refresh?"
What regulators actually recommend
There is no single EU-wide expiry number, but the main guidance points the same direction:
- France (CNIL): recommends that consent be re-obtained after no longer than six months.
- UK (ICO): in its own example mechanism, the user's choice is stored for six months, after which it expires and the person is asked again. The ICO's broader guidance is to refresh consent at "appropriate intervals."
- Common practice: many organizations expire consent somewhere between 6 and 12 months, and some go up to 24, depending on their risk appetite and audience.
One important clarification, because it gets confused constantly: the often-cited 13 months figure is about how long an analytics cookie itself may live under CNIL's guidance, not how often you re-ask for consent. Those are two different clocks. The re-ask interval is the 6-month recommendation above.
The two triggers to re-ask
Think of it as two separate triggers. Either one means you re-ask.
1. Time-based: your interval expires
Pick an interval (6 to 12 months is the sensible range), store each visitor's choice with that expiry, and when it lapses, ask again. This handles the "how long is this decision good for" question.
2. Change-based: something material changes
This one matters more than most people realize, and it overrides the clock. Re-ask right away, regardless of when you last asked, if you:
- Add new cookies or tracking technologies
- Add a new purpose (for example, you start using data for advertising when you did not before)
- Add a new third-party vendor that processes data
- Change your privacy or cookie policy in a way that affects what people agreed to
Consent is tied to the specific purposes and parties a person agreed to. If those change, the old consent no longer covers the new reality, so you need a fresh one.
How to choose your interval
A simple way to decide:
- Lean toward 6 months if you have a lot of EU or French traffic, handle sensitive data, or want to be conservative.
- 12 months is a common, defensible middle ground for many businesses.
- Whatever you choose, document your reasoning, and be consistent. An arbitrary interval you cannot explain is weaker than a considered one you can.
There is also a third, quieter trigger: if you cannot actually prove a visitor's prior consent (because it was not recorded properly), you should treat it as if you do not have it, and ask again. Which is why keeping consent records matters as much as collecting consent in the first place.
Do not over-ask
There is a real failure mode in the other direction. Prompting for consent on every visit, or every few days, is not extra compliance, it is banner fatigue. It annoys users, trains them to click "accept" reflexively (which undermines the validity of the consent), and hurts your experience.
The goal is to ask at the right moments: when consent genuinely expires, and when something changes. Not constantly.
How to set this up
In practice, this is a configuration job, not a manual one:
- Store each visitor's choice in a consent record or cookie with a defined expiry (your chosen interval).
- Auto-expire and re-prompt when the interval lapses, so you are not tracking this by hand.
- Log every consent with a timestamp and what was agreed to, so you can prove it.
- Re-trigger the banner automatically when you change your cookie configuration or add a vendor, so a change never slips out without fresh consent.
A consent management platform does all of this for you, which is the point of using one.
Where ConsentBit fits
Getting consent expiry right by hand is fiddly and easy to forget. ConsentBit handles it: you set your renewal interval, and it stores each visitor's choice, expires it on schedule, re-prompts automatically, and logs every consent event so you can demonstrate it. When you add or change cookies, it re-asks so your consent always matches what your site actually does. You decide the policy, and the tool keeps you to it.
Frequently asked questions
1. How long does cookie consent last?
There is no exact legal duration, but the practical answer is to refresh it every 6 to 12 months. France's CNIL recommends re-obtaining consent after no longer than six months, and the UK's ICO uses six months in its own example.
2. Do I have to ask for cookie consent on every visit?
No, and you should not. Re-asking too often is banner fatigue, which annoys users and weakens the quality of consent. Ask again when your chosen interval expires or when something material changes, not on every visit.
3. When do I need to re-ask for consent immediately?
Whenever what people agreed to changes: you add new cookies or trackers, add a new purpose (such as advertising), add a new third-party vendor, or update your cookie or privacy policy in a way that affects their choice.
4. Is cookie consent valid for 13 months?
The 13-month figure refers to how long certain analytics cookies may live under CNIL guidance, not how often you re-ask for consent. The re-ask recommendation is closer to six months. They are two different clocks.
5. What happens if I cannot prove someone consented?
Treat it as though you do not have consent, and ask again. This is why recording every consent with a timestamp matters, without proof, consent is hard to rely on.
Want consent expiry handled automatically?
Set your renewal interval once, and let it run. ConsentBit stores each visitor's choice, expires and refreshes it on schedule, re-prompts when your cookies change, and logs every consent so you can prove it.