Analytics and Tracking

Session Cookie

A cookie with no expiry date, deleted when the browsing session ends, used to remember things such as a login or basket during a visit.

Quick facts: Session Cookie

Category
Analytics and Tracking
Level
Beginner
Affects
Cookie consent set-up, cookie policy, logins and baskets, analytics data
Where to see it
Browser developer tools (Application or Storage tab), cookie scanners, consent management platforms
In this article4
  1. How a session cookie works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

A session cookie is a small file a website stores in the browser without an expiry date, so the browser deletes it when the browsing session ends. Websites use session cookies to remember things for the length of a visit, such as a login or the contents of a basket.

Every cookie is set by the site with a name, a value and some attributes. If the site gives no expiry date or maximum age, the browser treats it as a session cookie and keeps it only in its current session. A cookie with an expiry date is a persistent cookie and survives until that date, even after the computer is switched off.

Typical session cookies have names like PHPSESSID, JSESSIONID or ASP.NET_SessionId. They hold a random reference that links the browser to information the server keeps, such as “this visitor is logged in” or “this basket holds two items”.

“Ends when the browser closes” is less reliable than it sounds. Many people never fully close their browser, and browsers with a “continue where you left off” setting restore session cookies on restart, so a session cookie can last days.

Do not confuse session cookies with sessions in analytics. GA4 tracks sessions using its own cookies, and those are persistent: the _ga cookie and the one that stores session state last up to two years by default.

Why it matters

In the UK, PECR’s consent rule covers storing or reading information on a visitor’s device, whatever the lifespan. Session cookies are not automatically exempt. The exemption depends on purpose: a cookie that is strictly necessary for something the visitor asked for, such as keeping a basket or a secure login working, does not need consent. A session cookie used for analytics or advertising generally does, even though it disappears at the end of the visit.

At the time of writing (October 2026), the Data (Use and Access) Act 2025 relaxes the consent rule for a few low-risk purposes, including some analytics used only to improve your own site, provided visitors are told and can object easily. Check the ICO’s current guidance on which exemptions are in force before relying on one.

Common mistakes

  • Assuming every session cookie is “essential” because it is short-lived, and loading it before consent.
  • Listing cookies in a cookie policy without stating their purpose and duration, which visitors need to make a choice.
  • Copying a cookie list from a template rather than auditing what the site actually sets.
  • Putting personal data, such as an email address, directly in a cookie value rather than a random reference.
  • Forgetting security attributes. Login session cookies should be marked Secure and HttpOnly so they are sent only over HTTPS and cannot be read by page scripts.

How to act on it

Run a cookie audit: open your site in a private window, decline all non-essential cookies, then list everything that is still set using the browser’s developer tools. Every remaining cookie, session or persistent, should be strictly necessary. Then accept cookies and check that analytics and advertising cookies appear only afterwards.

Record each cookie’s name, provider, purpose and duration in your cookie policy, and keep it updated when you add plugins or tools. Making sure tracking respects consent while still giving ad platforms usable data is part of my performance marketing work.

Do and do not

Do

  • Judge consent needs by a cookie's purpose, not its lifespan
  • Audit what your site sets before and after consent
  • Mark login cookies Secure and HttpOnly

Do not

  • Assume short-lived cookies are exempt from PECR
  • Copy a cookie list from a template
  • Store personal data directly in cookie values

Questions people ask about this

Do session cookies need consent in the UK?

It depends on what they do, not how long they last. Session cookies that are strictly necessary for a service the visitor requested, such as a basket or a secure login, are exempt. Session cookies used for analytics or advertising generally need consent under PECR, subject to any exemptions now in force, so check the ICO's current guidance.

What is the difference between a session cookie and a persistent cookie?

A session cookie has no expiry date and is deleted when the browsing session ends. A persistent cookie has an expiry date and stays on the device until then, even if the browser is closed. Both are covered by PECR; the difference is lifespan, not legal status.

Is a GA4 session tracked with a session cookie?

No. GA4 groups activity into sessions, but it uses persistent first-party cookies to do it, which last up to two years by default. That is why GA4 cookies sit in the analytics category of a UK cookie banner, even though the word session appears in its reports.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.