Privacy

Tracking cookies do not outstay the consent behind them

privacy.long-lived-cookies

Why this matters

A tracking cookie carries the permission it was set under, and permission does not last forever. Regulators across Europe have converged on around thirteen months as the point at which a site should ask again, on the reasoning that somebody who agreed to be measured last year has not agreed to be measured indefinitely. Several popular analytics tools still default to a two-year lifetime, so this is usually a setting nobody chose rather than a decision. Browsers now cap what they will store at a little over a year regardless, which hides the difference between a long setting and an absurd one.

Who fixes it

You can, usually

Roughly how long

20 minutes

Care needed

Low risk to change

How to fix it

Most tools expose this as a setting. In Google Analytics 4 it is Admin → Data Settings → Data Retention, and the cookie lifetime itself is the `cookie_expires` parameter on the config tag — set it to 34128000 seconds for thirteen months. Consent tools usually have their own re-ask interval, which should be set to match.

How we score it

Failing this check takes up to 8 points off your privacy score. It is a fact about your site rather than a measurement, so it reads the same on every scan until you change something.

Does your site pass this one?

This check runs on every scan, along with the other 106. Free, no account, and you see the evidence for each result.

Check my site

Other privacy checks

See all 107 checks