skip to content

Under GDPR Art. 7(3), how easy must withdrawing consent be, and what happens to data processed before withdrawal?

level: middleimportance: must knowfreq 56%

answer

  1. as easy as giving
  2. same interface, no detriment
  3. past processing stays lawful
  4. stop, then delete or re-base openly

basics

~20 s

Under GDPR Art. 7(3), withdrawing consent must be as easy as giving it, at any time. Processing before withdrawal stays lawful, but processing based on that consent must stop, and data with no other lawful basis should be deleted.

solid answer

~50 s

Under GDPR `Art. 7(3)`, the data subject may **withdraw consent at any time**, must be **told of that right before consenting**, and withdrawing must be **as easy as giving** consent. EDPB Guidelines 05/2020 read this practically: consent given with one click must be withdrawable with comparable ease, through the same interface, free of charge and without lowering service levels (paras. 113-114); a phone line open on business days to withdraw a consent given online fails (Example 22). On the effect, `Art. 7(3)` says withdrawal *does not affect the lawfulness of processing based on consent before* it. Afterwards, the processing that relied on consent must **stop**, and data with no other lawful basis should be **deleted** (para. 117). The controller cannot **silently migrate** to another basis; any change must be communicated to the person (para. 120).

go deeper

for a junior

Recall that consent can be withdrawn at any time, as easily as it was given, and that past processing stays lawful.

for a middle

Explain the EDPB's reading of as easy as giving (same interface, no fee, no detriment) and what must stop or be deleted after withdrawal.

for a senior

Design withdrawal to propagate across systems, separate data held on other bases, and avoid silent migration to a new lawful basis.

for a principal

Treat withdrawal as a first-class product flow with parity metrics against the consent flow, because a weak withdrawal path invalidates the consent itself.

## What Art. 7(3) says `Art. 7(3)` of the GDPR (Regulation (EU) 2016/679) contains four rules in four sentences: 1. The data subject has the **right to withdraw** consent **at any time**. 2. Withdrawal **does not affect the lawfulness** of processing based on consent **before** its withdrawal. 3. The data subject must be **informed of this right before** giving consent. 4. It shall be **as easy to withdraw as to give** consent. EDPB Guidelines 05/2020 on consent describe easy withdrawal as a **necessary aspect of valid consent**: if the withdrawal mechanism does not meet the GDPR's requirements, the consent mechanism itself does not comply (para. 116). ## How easy is "as easy" The Regulation does not say withdrawal must use the same action as consent (para. 113), but the EDPB sets a practical standard: - **Comparable effort.** Where consent was given by one mouse-click, swipe or keystroke, the person must *in practice* be able to withdraw equally easily (para. 114). - **Same interface.** Consent given through a website, an app, an account or a device interface must be withdrawable through the same interface; switching channels only to withdraw is undue effort (para. 114). - **Without detriment.** Withdrawal must be free of charge and must not lower service levels (para. 114). - **Available any time.** Example 22 describes consent given online with a one-click choice, withdrawable only by calling a call centre on business days between 8am and 5pm. The EDPB concludes this does not comply with `Art. 7(3)`. | Consent given by... | Compliant withdrawal | Non-compliant withdrawal | |---|---|---| | One click in an app | A toggle in the same app's settings | Emailing support and waiting for a reply | | Ticking a box on a web form | A link or control on the site, or in each message | A letter by post | | An account preference | The same preference page | A phone call during office hours | ## What happens to past processing `Art. 7(3)` answers the question directly: withdrawal *does not affect the lawfulness of processing based on consent before its withdrawal*. So: - **Past processing stays lawful**, provided it met the GDPR at the time. Emails already sent and analyses already run are not retroactively unlawful. - **Processing based on that consent must stop.** The EDPB says the controller must stop the processing actions concerned (para. 117). - **Delete what has no other basis.** If no other lawful basis justifies continued processing, including storage, the data *should be deleted* (para. 117; see also `Art. 17(1)(b)`, the erasure ground for withdrawn consent). - **Other purposes are unaffected.** Data processed for a different purpose on another basis, such as performing a contract, need not be erased because marketing consent was withdrawn (para. 118). ## No silent switching A tempting shortcut is to keep processing after withdrawal by relabelling the basis as legitimate interests. The EDPB closes it: - A controller *cannot silently migrate* from withdrawn consent to another basis; any change must be notified under the information duties of `Arts. 13` and `14` (para. 120). - More broadly, a controller that chose consent cannot swap to another basis retrospectively to rescue processing when consent is found invalid (para. 123). This is why the purpose and basis of each data element should be clear from the outset (para. 118). ## Designing for withdrawal 1. **Tell people before they consent** that they can withdraw and how (`Art. 7(3)`). 2. **Put the control where consent was given**, with the same number of steps or fewer. 3. **Propagate the change** to every system acting on that consent. 4. **Record the withdrawal** with its time, so the controller can show when processing had to stop. 5. **Decide in advance** which data are deleted and which remain on another basis. ## Common mistakes - Treating withdrawal as retroactive and deleting records needed for another purpose. - Treating withdrawal as prospective only for new data while continuing to use what was already collected for the same purpose. - Requiring a login, a phone call or a reason to withdraw a consent that took one click to give. - Continuing processing under a new basis without telling the person.

  • Under the GDPR, must a controller delete all of a user's data when the user withdraws marketing consent?
    No. EDPB Guidelines 05/2020 (paras. 117-118) say processing based on the withdrawn consent must stop and data with no other lawful basis should be deleted, but data processed for another purpose on another basis, such as performing a contract, need not be erased. The controller should know from the outset which basis covers each data element.
  • Under EDPB Guidelines 05/2020, may a controller charge a fee or reduce service for withdrawing consent?
    No. Para. 114 says the data subject should be able to withdraw without detriment, which means withdrawal must be free of charge and must not lower service levels. A penalty for withdrawing would also call into question whether the consent was freely given in the first place.
  • Under the GDPR, can a controller continue processing on legitimate interests after a user withdraws consent?
    Not silently. EDPB para. 120 says the controller cannot silently migrate from withdrawn consent to another basis; any change must be communicated under `Arts. 13` and `14`. Para. 123 adds that a controller cannot swap bases retrospectively to rescue processing. A new basis would need to genuinely fit and be disclosed.

saying these in an interview costs you the question

  • Withdrawing consent makes all earlier processing unlawful retroactively.
  • Offering withdrawal only by phone is fine if the phone line is free.
  • After withdrawal, the controller may keep processing under legitimate interests quietly.
  • Withdrawal of marketing consent requires deleting the user's order records too.
  • Users need only be told about withdrawal after they have consented.