Skip to main content
Category: Consent Requirements

Ease of Withdrawal

Also known as: Ease of Withdrawing Consent, Right to Withdraw Consent
Simply put

Ease of Withdrawal is the data protection principle that a person who has agreed to let their personal data be used should be able to take back that agreement just as simply as they gave it. In practice, this means an organization cannot make it harder to say 'no later' than it was to say 'yes' in the first place. Once someone withdraws, the organization generally must stop the processing that relied on that agreement.

Formal definition

Under the GDPR, where consent is the Article 6(1)(a) lawful basis (or a condition for special category data under Article 9(2)(a)), the data subject has the right to withdraw consent at any time, and it must be as easy to withdraw as to give consent. This requirement is generally attributed to GDPR Article 7(3); practitioners should verify the precise article and wording against the current official text. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and controllers should inform data subjects of the right to withdraw before consent is given. Ease of withdrawal typically implies practical implementation duties, for example, avoiding disproportionate effort, extra steps, or friction that would deter withdrawal, though the specific technical measures required are subject to assessment and may be informed by regulator guidance (such as guidance from the European Data Protection Board). This concept applies to consent-based processing; where processing relies on another Article 6 basis (such as contract, legal obligation, or legitimate interests), the withdrawal-of-consent mechanism does not apply in the same way. Positions may differ under the UK GDPR and national implementing laws, and member state derogations can affect the detail.

Why it matters

Consent is only meaningful if it can be revoked. Where an organization relies on consent as its lawful basis under Article 6(1)(a) of the GDPR (or as a condition for special category data under Article 9(2)(a)), the ability of the data subject to change their mind is central to whether that consent is valid in the first place. If withdrawing is buried behind additional steps, logins, phone calls, or delays that were not required to give consent, regulators may take the view that the consent was never freely given and therefore never a sound basis for processing. Ease of withdrawal is thus not a cosmetic UX matter but a factor bearing on the lawfulness of the entire processing activity.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads should confirm that, wherever consent is the lawful basis, individuals are told of the right to withdraw before giving consent and are given a withdrawal route no harder to use than the original consent mechanism. They should also verify that a withdrawal is actioned, processing that relied on the consent generally stops, and that this is documented, while checking whether positions differ under the UK GDPR or national law.
Product and Engineering Teams
Teams that build consent capture flows, app permissions, cookie interfaces, sign-up forms, marketing preferences, are responsible for the practical implementation. They should aim to provide withdrawal controls that involve comparable effort to the consent step, avoiding added logins, delays, or extra steps that could deter withdrawal, recognizing that the specific measures expected are subject to assessment and may be shaped by regulator guidance.
Marketing and Customer Engagement Functions
Functions that rely on consent-based communications need to ensure that opting out or withdrawing is straightforward and that processing dependent on that consent ceases on withdrawal. They should also confirm whether a given activity actually relies on consent, since where another Article 6 basis applies the withdrawal-of-consent mechanism does not operate in the same way.
Legal Counsel Advising on Lawful Basis
Counsel assessing lawful basis should treat ease of withdrawal as a factor in whether consent is valid at all, distinguish consent from other Article 6 bases and Article 9 conditions, and verify the Article 7(3) citation and exact wording against the current official text before relying on it. They should flag divergence between EU, UK, and national implementing law and any relevant member state derogations.

Inside Ease of Withdrawal

Ease of Withdrawal Principle (Article 7(3) GDPR)
Where processing is based on consent, GDPR Article 7(3) provides that the data subject has the right to withdraw consent at any time, and that it must be as easy to withdraw as to give consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. This principle applies specifically to consent as an Article 6(1)(a) legal basis (and to the additional condition of explicit consent for special category data under Article 9), and does not extend to processing grounded on other legal bases.
Symmetry of Effort
Withdrawal should not require significantly more effort, steps, or friction than the act of giving consent. In practice, this generally means that if consent was obtained through a simple online action, withdrawal should be achievable through a comparably simple mechanism, though the precise implementation is subject to assessment against the specific service and how consent was collected.
Prior Information Requirement
Under Article 7(3), the data subject must be informed of the right to withdraw consent before giving it. This transparency obligation typically forms part of the information provided at the point of collection.
Prospective (Non-Retroactive) Effect
Withdrawal operates going forward. Processing that took place while consent was valid generally remains lawful; withdrawal removes the lawful basis for continued or future processing that relied on that consent.
Consequences of Withdrawal
Once consent is withdrawn, the controller generally must stop the processing that relied on it, unless another lawful basis genuinely applies to that processing. Continued processing may also trigger considerations under other GDPR provisions, such as erasure, but the availability and scope of those consequences depend on the circumstances.

Common questions

Answers to the questions practitioners most commonly ask about Ease of Withdrawal.

Does withdrawing consent make all previous processing unlawful?
No. Under GDPR Article 7(3), withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Withdrawal operates prospectively: it stops further processing based on that consent, but processing that occurred while valid consent was in place generally remains lawful. Note that a controller may need a separate justification to retain data after withdrawal (for example, a legal obligation), and if no lawful basis remains, the data should typically be deleted or otherwise handled in line with retention and erasure obligations.
Is it enough to let people withdraw consent by emailing us or calling customer service?
Generally this is unlikely to satisfy the standard. Article 7(3) requires that it be as easy to withdraw consent as to give it. If consent was collected through a simple online action such as a checkbox or toggle, requiring a phone call, a written letter, or navigating a burdensome process would typically create an imbalance regulators consider non-compliant. The withdrawal mechanism should generally match the ease of the original opt-in, and the data subject should be informed of the right to withdraw before giving consent.
Where should the withdrawal mechanism be placed so it meets the 'as easy to withdraw' standard?
There is no single mandated location, but the guiding principle from Article 7(3) is parity with the method of giving consent. In practice this often means offering withdrawal through the same interface or channel used to obtain consent, for example, an in-app toggle, an account privacy dashboard, or a clearly signposted preference centre. For consent given at sign-up, making withdrawal available within the user's ongoing account settings is a common approach. The suitability of any placement is subject to assessment based on how consent was originally collected.
How quickly must processing stop after a data subject withdraws consent?
The GDPR text does not specify a fixed deadline for ceasing processing after withdrawal. The general expectation is that processing based on that consent stops without undue delay once withdrawal is received. Organisations should typically design systems so that withdrawal takes effect promptly, propagates to any downstream systems or processors, and is logged. Where residual retention is claimed, it should rest on a separate, documented lawful basis rather than the withdrawn consent. Practices may vary, and readers should verify expectations against current regulatory guidance.
What records should we keep to demonstrate compliance with the ease-of-withdrawal requirement?
Consistent with the accountability principle, controllers should generally be able to evidence both that valid consent was obtained and that a compliant withdrawal facility exists. This typically includes records of how and when consent was given, the withdrawal method offered, and confirmation that withdrawal requests were actioned and communicated to relevant processors. Records should be sufficient to show parity between the giving and withdrawal of consent. The precise form of documentation is not prescribed and can be tailored to the organisation's processing, subject to assessment.
If we use consent-management tooling or third-party processors, who is responsible for enabling easy withdrawal?
The controller remains accountable for ensuring withdrawal is as easy as giving consent, even where a consent-management platform or a processor implements the mechanism. Processors generally act on the controller's documented instructions, so responsibilities should be reflected in the data processing arrangements between the parties. In practice this means the controller should confirm the tooling supports prompt withdrawal, propagates the change across systems, and does not introduce additional friction. Allocation of specific tasks is a matter for the parties' agreement, but ultimate compliance responsibility typically sits with the controller.

Common misconceptions

Withdrawing consent makes all past processing unlawful and requires it to be undone.
Article 7(3) expressly states that withdrawal does not affect the lawfulness of processing based on consent before its withdrawal. Its effect is generally prospective, meaning the controller must cease reliance on that consent going forward but need not retroactively invalidate earlier processing.
As long as a way to withdraw exists, the obligation is satisfied regardless of how difficult it is.
Article 7(3) requires that withdrawal be as easy as giving consent. A withdrawal route that is materially more burdensome than the original opt-in (for example, easy one-click consent but withdrawal only via a lengthy manual process) may fail this standard, subject to assessment of the specific mechanisms used.
The ease-of-withdrawal rule applies to all personal data processing.
The rule is specific to processing based on consent under Article 6(1)(a) (and explicit consent under Article 9). Where a controller relies on a different Article 6 legal basis, such as contract, legal obligation, or legitimate interests, the Article 7(3) withdrawal mechanism does not apply, although other data subject rights may.

Best practices

Inform data subjects of their right to withdraw consent before consent is given, and make this information clear and accessible at the point of collection, consistent with Article 7(3).
Design the withdrawal mechanism to require no more effort than the process used to obtain consent; where consent is collected via a simple digital action, provide a comparably simple withdrawal option.
Confirm that consent is the correct and genuine legal basis for the processing, since the ease-of-withdrawal obligation is tied specifically to consent-based processing and not to other Article 6 bases.
Establish internal processes to promptly cease consent-reliant processing once withdrawal is received, and check whether any other lawful basis genuinely and independently applies before continuing any related processing.
Document how consent was obtained and how withdrawal is offered so the symmetry-of-effort standard can be demonstrated, supporting accountability obligations.
Periodically review withdrawal mechanisms and consult current guidance from the relevant supervisory authority, as regulator expectations and interpretations in this area can evolve and may vary between jurisdictions (including divergence under the UK GDPR and national implementing law).