← All posts
cookie consentSep 30, 20266 min read

How long does cookie consent last? Rules by country

No law fixes how long cookie consent lasts. What the CNIL, ICO, Garante and AEPD recommend, when to ask again, and how it differs from cookie lifetimes.

Katla Team

No EU or UK law sets a fixed lifetime for cookie consent. Regulators fill the gap with guidance: France's CNIL treats keeping a visitor's choice for six months as good practice, the UK's ICO and Italy's Garante say not to ask again for six months after a refusal, and Spain's AEPD says consent should not last longer than 24 months. Whatever period you choose, you have to ask again as soon as you add a purpose or a third party the original consent did not cover.

What the law says

The GDPR has no expiry date for consent. The EDPB's guidelines on consent put it directly: "There is no specific time limit in the GDPR for how long consent will last. How long consent lasts will depend on the context, the scope of the original consent and the expectations of the data subject." The EDPB then recommends, as a best practice, "that consent should be refreshed at appropriate intervals".

Two fixed points hold in every country. A visitor can withdraw at any time, and under Article 7(3) of the GDPR "it shall be as easy to withdraw as to give consent". And under Article 7(1) you have to be able to demonstrate that consent was given, which in practice means recording when. Our GDPR page covers the rest of what valid consent needs.

What regulators recommend

RegulatorGuidanceApplies to
CNIL (France)Keeping a visitor's choice, consent and refusal alike, for six months is good practice, judged case by caseConsent and refusal
ICO (UK)After a refusal, wait "a reasonable amount of time"; six months is "a suitable timeframe to request fresh consent"Refusal
Garante (Italy)Do not show the banner again unless conditions change significantly, the site cannot tell whether a choice was stored, or at least six months have passedRefusal or partial acceptance
AEPD (Spain)Good practice that consent lasts no more than 24 months, with the choice kept in the meantimeConsent

Sources: the CNIL's recommendation, the ICO's guidance on managing consent, the Garante's 2021 cookie guidelines and the AEPD's cookie guide.

Read together, six months is the European benchmark: the minimum time to respect a "no" in the UK and Italy, and in France the period the CNIL treats as good practice for keeping a choice at all. Spain's 24 months is an outer limit for a "yes", not a target. The ICO also warns against the opposite habit: "You should not repeatedly ask or prompt people to specify their preferences as a matter of course."

The CNIL and the ICO both frame their figures as general guides, with the right period depending on the site and its audience. Details by country are on our pages for France and the UK.

In the US

California runs an opt-out model, so the clock works the other way. When a consumer opts out of the sale or sharing of their personal information, a business has to respect it and "wait for at least 12 months before requesting that the consumer authorize the sale or sharing", under section 1798.135(c)(4) of the California Civil Code. More on our CCPA page.

When you have to ask again sooner

You add a purpose or a partner. The EDPB: "If the processing operations change or evolve considerably then the original consent is no longer valid." The ICO is specific: "if you introduce new tags or cookies for a different purpose to what you originally stated when consent was granted, you must obtain fresh consent for the new purpose." Its own example is a site that adds a social media plugin and has to ask again. The AEPD and the Garante say the same about new third parties.

The stored choice is gone. If a visitor clears their cookies, the site has no record of the choice, and the Garante accepts asking again in that case. Browsers can remove it too: Safari's tracking prevention deletes cookies created in JavaScript after seven days without interaction with the site, and a banner that stores the choice in such a cookie loses it with them.

The visitor asks. Withdrawal is always open, so keep a link or icon that reopens the choice on every page.

Info

A change may be coming. The European Commission's Digital Omnibus proposal of November 2025 would add a rule to the GDPR: after a refusal, no new request for the same purpose "for a period of at least six months", and after consent, no new request while the consent can still be relied on. It is a proposal, and the European Parliament's legislative train still showed it in the legislative process in August 2026.

Consent lifetime is not cookie lifetime

Two clocks run side by side, and they are easy to confuse.

ClockWhat sets itGuidance
How long the choice is rememberedThe expiry of the consent cookie, or your server-side recordThe regulator periods above
How long each cookie lives once allowedThat cookie's own expiryShould match its purpose

The Article 29 Working Party said an exempt cookie should have "a lifespan that is in direct relation to the purpose it is used for" in its 2012 opinion. For the audience measurement it exempts from consent, the CNIL recommends a tracker lifetime such as 13 months, not extended automatically on each visit, and keeping the data for at most 25 months.

The clocks also interact. An analytics cookie that lives two years does not stretch a consent that has lapsed or been withdrawn. The CNIL notes that for a withdrawal to take effect, a site may need specific measures to make sure trackers set earlier are no longer read or written.

Setting your own period

  1. Pick a period and write down why. Six months matches the CNIL's good practice; a longer period is easier to defend with a reason tied to your site and audience.
  2. Treat a "no" as at least as durable as a "yes". Re-asking a refusal sooner than six months runs against the ICO and Garante guidance.
  3. Ask again when your purposes or partners change, whatever the period says.
  4. Record the time of every choice, so you can show when consent was given.
  5. Keep the choice reachable, so a visitor never has to wait for it to expire to change their mind.

Most of this is the consent tool's job; what a consent management platform should handle is covered separately.

What Katla does

Katla stores a visitor's choice for 12 months, in a cookie on your own domain. For a refusal, that means asking again less often than any of the six-month rules above require. For an acceptance, it is inside the AEPD's 24-month ceiling but twice the six months the CNIL describes as good practice, and there is no setting to shorten it today. Like any cookie written by a script, Safari may clear it sooner.

Each decision is recorded with its categories, its time and a truncated IP address, and Katla keeps the latest decision per visitor. A floating settings icon, or your own "Cookie settings" link calling katla.open(), reopens the choice on any page.


This post summarises regulator guidance and is not legal advice. Recommended periods differ by country, so check the regulator's own text for the markets you serve.