CookieScan

How long does cookie consent last?

Neither GDPR nor the ePrivacy directive set a fixed duration — in practice, many CMP vendors across Europe have adopted a reference point of around 13 months, after which the choice must be asked again.

The practice

There is no duration set in the text of GDPR or the ePrivacy directive itself. In practice, however, many CMP vendors across Europe have adopted a reference point of a maximum of 13 months for storing a user’s expressed consent (or rejection). Past that point, the banner should reappear to collect a fresh choice.

On Shopify

Most CMPs on the market (OneTrust, Axeptio, Didomi, Cookiebot, CookieFirst, Osano) let you configure this duration. The watch-out: some plugins’ default configuration doesn’t always enforce this limit, or stores consent in a longer-lived cookie (12 months, 24 months) without automatic re-evaluation.

What it doesn’t change

This duration only concerns the validity of the stored consent, not the site’s behaviour in the meantime: as long as valid consent hasn’t been given, non-essential trackers shouldn’t run, regardless of how much time has passed since the last visit.

Does your store follow these rules?

Our free scanner technically checks what fires before consent on your Shopify store, in ~30 seconds.

Scan my store for free

Sources

Other articles

Independent informational content, not affiliated with Shopify. Not legal advice; for an assessment of your situation, consult a lawyer or your DPO.