At page load, before any consent interaction, a cookie is placed with a lifetime at or near the ceiling the browser permits, currently 399 days in Chromium-based browsers.
Why it is a separate entry
The visitor is recognisable for over a year on the basis of a decision they were never given. Storage limitation requires a term tied to the purpose, not to the technical maximum.
How it arises
default retention of the measurement setup left untouched
cookie placed outside the consent gate, so the term was never considered
Not to be confused with
If the cookie is set only after consent, this is a retention question and not this entry. The pre-consent placement is what makes it a fault here.
How to establish it
A Set-Cookie with max-age at or above 34128000 seconds (399 days), or an equivalent Expires, issued before the consent event.
method network-with-identifierQoD 95
Requirements on the measurement
clean profile
no interaction
read Set-Cookie headers, not only the cookie jar
What would refute it
by handThe cookie is strictly necessary for a service the visitor requested.finding falls
automatedThe lifetime is set by the browser, not by the server.finding falls
Where this plugs into existing processes
The one question that surfaces itWhat is the longest-lived cookie you set before anyone has chosen anything?
In a DPIA, verify this
Verify the actual lifetime of identifiers set before consent, rather than the retention table in the document.
As a procurement clause
No identifier is stored with a lifetime beyond what the stated purpose requires, and none before consent.
With a complaint, hand over
The Set-Cookie headers from the pre-consent capture, with lifetimes.
DPE Catalogue. DPE-2026-0004: Maximum cookie lifetime. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0004
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0004, established under DPE Measurement Method 1.0”
Identifiers are permanent and are never
reused. An entry that is deprecated keeps its number and its address, with the reason attached, because
references to it exist elsewhere.