Duration
|
Applies to: All users This article explains a concept that applies regardless of which interface you use. |
What it is
Controls how long a visitor’s consent cookie remains valid in their browser. Two separate duration fields exist: one for accepted consent and one for rejected consent. Both draw from the same set of options.
How it works (end-to-end)
- On first decision, the visitor selects a Duration in the banner (if the duration selector is shown).
- When they click Save my preferences (or your custom label), Cookie Compliance writes a consent cookie with that expiry.
- Until expiry, the banner, autoblocking rules, and integrations (e.g., Google/Microsoft/Facebook consent modes) honor the stored choices.
- After expiry, the banner re-prompts. A new consent cookie is set when the visitor interacts again and saves.
Editing the options
- You can add/remove Duration values in the field: click the “x” to remove a value, then click in the field to open the dropdown and pick a replacement.
- Changes take effect immediately for new consents. Existing visitors keep their current expiry until they re-consent.
All available values
- An hour – consent re-confirmed each session; suitable for high-sensitivity contexts.
- 1 day – daily re-prompt.
- 1 week – weekly re-prompt.
- 1 month – monthly renewal.
- 3 months – quarterly renewal.
- 6 months – CNIL guidance commonly cites this as a prudent upper bound for cookie consent validity.
- 1 year – annual renewal.
- Infinity – consent never expires; the banner never re-prompts this visitor unless they revoke consent manually.
Accepted expiry vs. Rejected expiry
The plugin provides two independent duration fields:
- Accepted expiry – how long a positive consent choice is remembered.
- Rejected expiry – how long a rejection (Private / refuse) is remembered before the banner asks again.
You may set shorter rejected expiry periods to give visitors a periodic opportunity to reconsider.
Defaults & guidance
- Both GDPR-style and U.S. consumer privacy regimes favor periodic renewal so people can make an informed choice again.
- If you serve the EU/EEA (or align globally), set 6 months as your accepted default and a shorter value (e.g., 1 month) for rejected expiry.
- Use Infinity only where your legal basis supports indefinite consent storage and you offer a visible Revoke Consent control.