Collecting consent once and treating it as permanent is one of the most common misunderstandings in cookie compliance. In reality, consent has a lifecycle. It can become invalid — legally or practically — as time passes, as your website changes, or as the purposes for which data is processed evolve. Managing this lifecycle is not optional; it is a core part of a defensible compliance posture.
When Consent Needs to Be Refreshed
Regulators and data protection authorities broadly agree that consent should be re-sought when the purposes for processing change materially, when the list of third-party recipients changes, or when a significant period of time has passed. While GDPR does not specify a precise expiry period, guidance from several European DPAs suggests that consent collected more than twelve months ago should be revisited. Consent Management Platforms that never prompt returning users to review their preferences are likely operating on stale records.
The Technical Dimension
Beyond the legal question, there is a practical one: consent records must be stored accurately and be retrievable. If a user accepted cookies eighteen months ago and your CMP cannot produce a timestamped record of that consent — including which version of your privacy notice was in place at the time — that consent is difficult to rely on in a regulatory review. Consent records should be treated with the same rigour as any other compliance documentation.

Handling Consent After a Website Redesign or Platform Change
A significant change to your website, data infrastructure, or cookie inventory can invalidate previously collected consent if the processing has materially changed from what users originally agreed to. A website migration, a new analytics platform, or a changed advertising stack may all trigger an obligation to re-present the consent experience to existing visitors.
How Digital Analytics Lab Helps
Digital Analytics Lab helps you assess whether your current consent records remain valid, identify triggering events that require re-consent, and configure your CMP to handle re-consent flows correctly. We ensure your compliance records are timestamped, version-controlled, and auditable — so that if your practices are ever scrutinised, your documentation holds up.


