Overview
This check reviews the expiration duration configured on every cookie set by the property and flags any cookie whose lifetime exceeds either your documented retention period for that data category or the commonly referenced 13-month+ ceiling that major browsers now enforce for first-party cookies as an industry practice benchmark.
Note: This guide is provided for informational purposes only and does not constitute legal advice. Consult qualified legal counsel regarding your organization's specific CCPA/CPRA compliance obligations.
Why is it important
CCPA requires disclosure of retention periods for each category of personal information collected, and a cookie with an unexpectedly long expiration (a "session" cookie configured to persist for two years, for example) directly contradicts those disclosures and extends the window during which that consumer's data remains exposed to processing. This check, like the categorization check above, can be partially but not fully automated: ObservePoint reliably reports the configured expiration on every observed cookie, but confirming that duration against your specific documented retention commitment for that data category requires cross-referencing your privacy program's records.
Implementation
Run a full-site Audit and pull the Cookies report sorted by expiration duration.
Check the pre-built ObservePoint report for Cookies Exceeding Retention Threshold (13 months+).
Cross-reference each flagged cookie against your Cookie & Tag Inventory's documented retention commitment for that category; the 13-month+ figure is a ceiling, not the target for every category.
Why manual review is required: the 13-month+ portion is fully automated; that's a fixed, universal ceiling (the same limit major browsers now enforce on first-party cookies), so ObservePoint can flag any cookie crossing it with no judgment call needed.
What can't be automated is checking against your documented retention period, since that number isn't universal (it's specific to your Privacy Policy's disclosures and varies by data category). A cookie can pass the 400-day check easily (say, 200 days) while still violating your own disclosed 90-day limit for that category, and only a human cross-referencing the flagged cookie against your Cookie & Tag Inventory would catch that.
Remediation
For remediation, check the following steps:
For each over-retention cookie, first confirm whether the long expiration is a vendor default that was never explicitly configured (common with third-party advertising and analytics scripts) or a deliberate first-party setting that no longer matches your documented policy.
Where possible, reconfigure the cookies' expiration directly (first-party cookies you control) or contact the vendor to request a shorter default (third-party cookies), and update your Privacy Policy and Cookie & Tag Inventory if the actual retention period needs to be revised to match reality rather than the other way around.
Re-run the Cookies report after the change and confirm the cookie's observed expiration now falls within the documented threshold.
Conclusion
Retention-period accuracy protects both the consumer and the business. An inflated cookie lifetime extends your own exposure window unnecessarily, so treating this as a routine reconciliation rather than a one-time fix keeps your actual practice aligned with what your Privacy Policy discloses.
