A session cookie is a small file a website stores in the browser without an expiry date, so the browser deletes it when the browsing session ends. Websites use session cookies to remember things for the length of a visit, such as a login or the contents of a basket.
How a session cookie works
Every cookie is set by the site with a name, a value and some attributes. If the site gives no expiry date or maximum age, the browser treats it as a session cookie and keeps it only in its current session. A cookie with an expiry date is a persistent cookie and survives until that date, even after the computer is switched off.
Typical session cookies have names like PHPSESSID, JSESSIONID or ASP.NET_SessionId. They hold a random reference that links the browser to information the server keeps, such as “this visitor is logged in” or “this basket holds two items”.
“Ends when the browser closes” is less reliable than it sounds. Many people never fully close their browser, and browsers with a “continue where you left off” setting restore session cookies on restart, so a session cookie can last days.
Do not confuse session cookies with sessions in analytics. GA4 tracks sessions using its own cookies, and those are persistent: the _ga cookie and the one that stores session state last up to two years by default.
Why it matters
In the UK, PECR’s consent rule covers storing or reading information on a visitor’s device, whatever the lifespan. Session cookies are not automatically exempt. The exemption depends on purpose: a cookie that is strictly necessary for something the visitor asked for, such as keeping a basket or a secure login working, does not need consent. A session cookie used for analytics or advertising generally does, even though it disappears at the end of the visit.
At the time of writing (October 2026), the Data (Use and Access) Act 2025 relaxes the consent rule for a few low-risk purposes, including some analytics used only to improve your own site, provided visitors are told and can object easily. Check the ICO’s current guidance on which exemptions are in force before relying on one.
Common mistakes
- Assuming every session cookie is “essential” because it is short-lived, and loading it before consent.
- Listing cookies in a cookie policy without stating their purpose and duration, which visitors need to make a choice.
- Copying a cookie list from a template rather than auditing what the site actually sets.
- Putting personal data, such as an email address, directly in a cookie value rather than a random reference.
- Forgetting security attributes. Login session cookies should be marked Secure and HttpOnly so they are sent only over HTTPS and cannot be read by page scripts.
How to act on it
Run a cookie audit: open your site in a private window, decline all non-essential cookies, then list everything that is still set using the browser’s developer tools. Every remaining cookie, session or persistent, should be strictly necessary. Then accept cookies and check that analytics and advertising cookies appear only afterwards.
Record each cookie’s name, provider, purpose and duration in your cookie policy, and keep it updated when you add plugins or tools. Making sure tracking respects consent while still giving ad platforms usable data is part of my performance marketing work.
