A persistent cookie is a small text file a website stores on a visitor’s device with a set expiry date, so it survives when the browser is closed and is still there next time they visit. That distinguishes it from a session cookie, which is deleted when the browser session ends.
How a persistent cookie works
When a server or a script sets a cookie, it can include an expiry date or a maximum age. If it does, the browser keeps the cookie until that moment and sends it back with requests to the same site. If it does not, the browser treats it as a session cookie.
Most analytics and advertising cookies are persistent because they exist to recognise a returning device. GA4’s _ga cookie lasts two years by default and is refreshed on each visit. Meta’s _fbp cookie lasts ninety days. A consent banner usually stores your choice in a persistent cookie so it does not ask again on every page.
Browsers also set their own limits. Chrome caps any cookie’s lifetime at 400 days, and Safari’s Intelligent Tracking Prevention limits cookies set by JavaScript to seven days, or less in some circumstances. A cookie’s stated expiry is therefore a maximum, not a promise.
Why it matters
In the UK, the Privacy and Electronic Communications Regulations (PECR) require consent before storing cookies that are not strictly necessary, whatever their duration, apart from a few narrow exemptions. The Data (Use and Access) Act 2025 added exemptions for some low-risk uses such as certain analytics, so check the ICO’s current guidance before relying on one. Duration does not decide whether consent is needed. What changes with duration is how proportionate your use looks, and the ICO expects expiry periods to fit the purpose. A cookie remembering a basket for a few days is easy to justify; a marketing cookie set for many years is not.
You also have to tell people. The ICO expects your cookie information to name each cookie, say what it does, who sets it and how long it lasts. A cookie policy without durations, or with durations copied from a generic list that do not match what the site actually sets, is a common gap on UK small business sites.
From a measurement point of view, persistent cookies are what allow returning visitors to be counted as returning. When consent is declined or a browser shortens cookie lifetimes, the same person starts to appear as several new users.
Common mistakes
- Listing cookies without durations. Visitors cannot make an informed choice without knowing how long a cookie stays.
- Copying a cookie list from another site. Your plugins, tags and embeds set their own cookies; only an audit of your site shows them.
- Setting persistent cookies before consent. Tags that fire on page load, before the visitor chooses, breach PECR regardless of how short the cookie is.
- Extending expiry without reason. Longer is not better if the purpose does not need it.
How to act on it
Run a cookie audit: open your site in a private window, decline all non-essential cookies, then look in the browser’s developer tools under Application and Cookies to see what is set and with what expiry. Repeat after accepting. Every cookie you find should appear in your cookie policy with its purpose, provider and duration, and the cookie policy on this site shows the kind of detail I mean.
Where you control the expiry, such as the GA4 cookie expiration setting in the tag configuration, set it to what the purpose genuinely needs. If your tracking set-up is fragile or fires before consent, fixing that properly is part of the measurement work I do under performance marketing.
