Skip to main content
Category: Consent Principles

Withdrawal of Consent

Also known as: Consent Withdrawal, Revocation of Consent, Right to Withdraw Consent
Simply put

Withdrawal of consent is when a person tells an organisation that they no longer agree to a use of their data that was previously based on their permission, such as tracking through cookies. Under EU law, it must be as easy to withdraw consent as it was to give it, and the organisation must stop the relevant processing once consent is withdrawn. In practice, this often means a website provides a way to change or reject cookie choices at any time.

Formal definition

In the cookie and tracking context, withdrawal of consent refers to a data subject's revocation of previously granted consent that served as the legal basis for processing personal data and, where applicable, for the placing of or access to information on the user's device. Under the GDPR, the right to withdraw consent is provided for in Article 7(3): withdrawal must be as easy to effect as giving consent, does not affect the lawfulness of processing carried out before withdrawal, and the controller must cease the relevant processing without undue delay once consent is withdrawn. Where a cookie or similar technology (including pixels, SDKs, local storage, or fingerprinting) relied on consent both to be set and to process resulting personal data, withdrawal should generally trigger cessation of the associated tracking and processing, though the technical mechanics (for example, updating consent state via a CMP and honouring it downstream) are implementation-dependent. This entry addresses the EU/GDPR framing; obligations may differ under other regimes, and consent-based approaches (typical of the EU and UK) differ from opt-out models used under certain US state privacy laws, where the analogous mechanism may be an opt-out of sale or sharing rather than withdrawal of prior consent. Detailed record-keeping and CMP-specific behaviours are out of scope of this definition.

Why it matters

Withdrawal of consent is a cornerstone of the consent model that underpins cookie compliance in the EU and UK. Because consent under the GDPR must be freely given, the ability to take it back is what keeps that consent meaningful over time. Article 7(3) makes withdrawal an ongoing right: a data subject can revoke their permission at any point, and the organisation must stop the relevant processing without undue delay. For any tracking that relies on consent as its legal basis, a failure to offer a genuine, workable withdrawal route can undermine the validity of the original consent itself, exposing the organisation to compliance risk.

Who it's relevant to

Privacy and Data Protection Officers
DPOs and privacy officers need to ensure that withdrawal mechanisms genuinely meet the Article 7(3) standard that withdrawal is as easy as giving consent. This includes assessing whether the withdrawal route is accessible on an ongoing basis and whether processing actually stops once a user revokes permission, rather than treating withdrawal as a formality that has no downstream effect.
Legal and Compliance Counsel
Counsel advising on cookie compliance must map how withdrawal obligations apply across the different regimes an organisation operates in. The consent-and-withdrawal model of the EU and UK differs from opt-out mechanisms under certain US state privacy laws, so counsel should avoid assuming one control satisfies all frameworks and should flag areas where regulatory expectations remain unsettled.
Web Developers and Engineering Teams
Developers are responsible for the technical implementation that makes withdrawal effective. This typically involves updating the consent state through a CMP and ensuring that downstream tags, scripts, pixels, SDKs, and other tracking technologies honour that change so the relevant processing actually ceases. Because these mechanics are implementation-dependent, testing that a withdrawal produces the intended effect is important.
Marketing and Analytics Compliance Teams
Teams relying on cookies for analytics or advertising need to understand that consent can be withdrawn at any time and that the associated tracking must then stop. They should design campaigns and measurement approaches on the assumption that a segment of users may revoke consent, and coordinate with privacy and engineering colleagues so that withdrawal is respected in practice.

Inside Withdrawal of Consent

Right to Withdraw
Under the GDPR, where consent is the legal basis for processing, the data subject has the right to withdraw that consent at any time. In the cookie context, this typically applies to consent obtained under the ePrivacy Directive's national implementations for non-essential cookies and similar technologies (such as pixels, local storage, and SDKs).
Ease of Withdrawal
The GDPR requires that withdrawing consent be as easy as giving it. In practice, this generally means users should be able to change or revoke their cookie choices through a mechanism that is at least as accessible as the original consent interface, rather than through a more burdensome process.
Prospective Effect
Withdrawal generally operates going forward and does not, by itself, affect the lawfulness of processing carried out before the withdrawal. It also does not automatically erase data already collected; separate rights and obligations (such as erasure) may apply to that data.
Post-Withdrawal Actions
Following withdrawal, non-essential cookies and similar technologies should generally cease to be placed or read, and associated processing that relied on consent should stop. Strictly necessary or essential cookies, which are typically exempt from consent, are generally unaffected.
Record-Keeping
Organizations are generally expected to be able to demonstrate the state of a user's consent, which includes logging withdrawals. Consent management platforms (CMPs) commonly support this, but such tools support compliance rather than guarantee it.
Jurisdictional Scope
The withdrawal right described here reflects EU (and broadly UK) opt-in frameworks. Several US state regimes, such as the CCPA/CPRA in California, rely more on opt-out mechanisms, so the concept of 'withdrawal' maps differently across jurisdictions.

Common questions

Answers to the questions practitioners most commonly ask about Withdrawal of Consent.

Is withdrawing consent the same as opting out under US state privacy laws?
Not exactly. Withdrawal of consent is a concept most directly associated with opt-in regimes such as the GDPR and the ePrivacy Directive, where consent must be obtained before non-essential cookies are placed and the user retains the right to take that consent back. Several US state frameworks, such as California's CCPA/CPRA, generally rely on an opt-out model rather than prior opt-in consent, so the mechanisms differ. In practice, tools like Global Privacy Control signals are often used to communicate opt-out preferences in the US context. The underlying goal of letting a user stop a given processing activity is similar, but the legal framing, timing, and defaults are not identical, so you should map obligations to the specific jurisdiction rather than treating the two as interchangeable.
Does withdrawing consent make prior processing unlawful or require us to delete everything we already collected?
Generally, no. Under the GDPR, withdrawing consent does not retroactively affect the lawfulness of processing carried out before the withdrawal. It means the processing that relied on that consent must stop going forward. Whether previously collected data must be deleted depends on separate considerations, including whether another lawful basis or a legal retention obligation applies, and on any data subject request the user may separately make. Withdrawal and erasure are related but distinct concepts, so the practical outcome for existing data depends on facts not resolved by the act of withdrawal alone.
How easy does the withdrawal mechanism need to be for users to find and use?
Under the GDPR, it must be as easy to withdraw consent as it was to give it. In practice this often means offering a persistent and accessible way to change cookie preferences, such as a link or icon that reopens the consent management platform's settings, rather than requiring users to hunt through a privacy policy or contact support. What counts as sufficiently easy can depend on the design of your original consent flow and on guidance from the relevant data protection authority, so approaches vary and expectations may evolve.
What should technically happen when a user withdraws consent for analytics or advertising cookies?
The withdrawal should stop the further placing of, and access to, the relevant non-essential cookies and similar technologies, such as pixels, local storage, SDKs, or fingerprinting, that were relying on that consent. This typically involves ceasing the associated tracking, and many organizations also clear or expire the affected client-side identifiers where feasible. The precise steps depend on your tag management and CMP configuration, and coordinating downstream vendors so they honor the change can be non-trivial. What is out of scope here is any separate deletion of server-side data already processed, which is governed by other rules.
Do we need to keep records when a user withdraws consent?
Maintaining records that demonstrate the state of a user's consent is generally consistent with accountability expectations under the GDPR, and many organizations log withdrawals alongside the original consent to show what was permitted and when it changed. Consent logging is often handled by a CMP, but the tool supports rather than guarantees compliance, and you should confirm that the logs capture what your legal and record-keeping needs require. The specific retention period and content of such records depend on facts and guidance beyond this definition.
Can we ask the user to reconfirm their choices or show the banner again after they withdraw consent?
You can generally provide a clear way for users to change or re-grant preferences later, but re-prompting should not be used in a way that pressures users into reinstating consent or makes withdrawal feel penalized, which could undermine the requirement that consent be freely given. Repeatedly displaying banners to nudge a user back toward acceptance may attract scrutiny in EU jurisdictions. Where the line falls between offering a legitimate re-consent option and applying undue pressure can be a contested and fact-specific question, so approaches differ and DPA expectations may evolve.

Common misconceptions

Withdrawing consent retroactively invalidates all prior processing and requires deletion of previously collected data.
Withdrawal generally takes effect prospectively and does not, on its own, render prior consent-based processing unlawful. It also does not automatically trigger deletion; erasure of already-collected data is a separate matter governed by other rights and obligations.
As long as a privacy policy explains that users can email to withdraw consent, the requirement is satisfied.
The GDPR requires that withdrawal be as easy as giving consent. Where consent was given through a simple banner interaction, requiring a more burdensome route (such as sending an email) may be considered non-compliant in many EU jurisdictions.
Using a CMP with a withdrawal option guarantees compliance with withdrawal obligations.
CMPs and similar tools support compliance but do not replace legal judgment. Whether withdrawal is properly honored depends on factors such as whether non-essential technologies actually stop firing and whether records are adequately kept.

Best practices

Provide a persistent, easily accessible mechanism (such as a settings link or icon) that lets users revisit and revoke their cookie choices without more friction than the original consent step.
Ensure that, upon withdrawal, non-essential cookies and similar technologies (pixels, local storage, SDKs) actually stop being placed or read, and that dependent processing ceases.
Log withdrawals alongside consent so the organization can demonstrate the current and historical state of each user's choices, while recognizing that logging tools support rather than guarantee compliance.
Treat withdrawal as prospective and separately assess whether erasure or other data subject rights apply to data already collected, rather than assuming withdrawal alone deletes past data.
Distinguish essential from non-essential technologies so that withdrawal affects only consent-based processing and does not disrupt strictly necessary cookies.
Map the withdrawal experience to the relevant jurisdiction, recognizing that EU/UK opt-in withdrawal differs from opt-out models under US state laws such as the CCPA/CPRA, and adjust interfaces accordingly.