Analytics and Tracking

Persistent Cookie

A cookie with a set expiry date, which stays on the visitor's device after the browser closes until it expires or is deleted.

Quick facts: Persistent Cookie

Category
Analytics and Tracking
Level
Beginner
Affects
Cookie consent, cookie policy, returning-user measurement, ad audiences
Where to see it
Browser developer tools, consent management platform, GA4 tag settings
In this article4
  1. How a persistent cookie works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

A persistent cookie is a small text file a website stores on a visitor’s device with a set expiry date, so it survives when the browser is closed and is still there next time they visit. That distinguishes it from a session cookie, which is deleted when the browser session ends.

When a server or a script sets a cookie, it can include an expiry date or a maximum age. If it does, the browser keeps the cookie until that moment and sends it back with requests to the same site. If it does not, the browser treats it as a session cookie.

Most analytics and advertising cookies are persistent because they exist to recognise a returning device. GA4’s _ga cookie lasts two years by default and is refreshed on each visit. Meta’s _fbp cookie lasts ninety days. A consent banner usually stores your choice in a persistent cookie so it does not ask again on every page.

Browsers also set their own limits. Chrome caps any cookie’s lifetime at 400 days, and Safari’s Intelligent Tracking Prevention limits cookies set by JavaScript to seven days, or less in some circumstances. A cookie’s stated expiry is therefore a maximum, not a promise.

Why it matters

In the UK, the Privacy and Electronic Communications Regulations (PECR) require consent before storing cookies that are not strictly necessary, whatever their duration, apart from a few narrow exemptions. The Data (Use and Access) Act 2025 added exemptions for some low-risk uses such as certain analytics, so check the ICO’s current guidance before relying on one. Duration does not decide whether consent is needed. What changes with duration is how proportionate your use looks, and the ICO expects expiry periods to fit the purpose. A cookie remembering a basket for a few days is easy to justify; a marketing cookie set for many years is not.

You also have to tell people. The ICO expects your cookie information to name each cookie, say what it does, who sets it and how long it lasts. A cookie policy without durations, or with durations copied from a generic list that do not match what the site actually sets, is a common gap on UK small business sites.

From a measurement point of view, persistent cookies are what allow returning visitors to be counted as returning. When consent is declined or a browser shortens cookie lifetimes, the same person starts to appear as several new users.

Common mistakes

  • Listing cookies without durations. Visitors cannot make an informed choice without knowing how long a cookie stays.
  • Copying a cookie list from another site. Your plugins, tags and embeds set their own cookies; only an audit of your site shows them.
  • Setting persistent cookies before consent. Tags that fire on page load, before the visitor chooses, breach PECR regardless of how short the cookie is.
  • Extending expiry without reason. Longer is not better if the purpose does not need it.

How to act on it

Run a cookie audit: open your site in a private window, decline all non-essential cookies, then look in the browser’s developer tools under Application and Cookies to see what is set and with what expiry. Repeat after accepting. Every cookie you find should appear in your cookie policy with its purpose, provider and duration, and the cookie policy on this site shows the kind of detail I mean.

Where you control the expiry, such as the GA4 cookie expiration setting in the tag configuration, set it to what the purpose genuinely needs. If your tracking set-up is fragile or fires before consent, fixing that properly is part of the measurement work I do under performance marketing.

Do and do not

Do

  • List every cookie's duration in your cookie policy
  • Set expiry periods proportionate to the purpose
  • Audit cookies before and after consent

Do not

  • Set non-essential persistent cookies before consent
  • Copy another site's cookie list
  • Assume a stated expiry is how long a browser will keep the cookie

Questions people ask about this

Are persistent cookies illegal in the UK?

No. They are lawful when used properly: strictly necessary ones can be set without consent, and most others need consent under PECR before they are stored. You must also explain what each one does and how long it lasts. The law regulates how you use them, not whether they exist.

How long can a cookie last in the UK?

No fixed legal maximum applies, but the ICO expects the duration to be proportionate to the purpose. In practice, browsers also cap lifetimes, with Chrome limiting cookies to 400 days. Choose the shortest duration that still does the job and state it in your cookie policy.

How do I see which persistent cookies my site sets?

Open your site in a private browser window, open the developer tools and look under Application, then Cookies, for your domain. The Expires column shows each cookie's expiry; "Session" means it is not persistent. Check before and after accepting your consent banner, because the two lists should be different.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.