Glossary

Consent withdrawal

A visitor revoking a permission they previously gave, which has to be as easy as giving it, and has to actually stop the technology it authorised.

Source
GDPR Art. 7(3); LGPD Art. 8 §5
Standard
As easy as giving consent
In StrongPrivacy
Preference centre, reopenable from any page

The standard

Article 7(3) of the GDPR says the data subject has the right to withdraw consent at any time, and that it must be as easy to withdraw as to give. Brazil’s LGPD says something close in Article 8 §5, requiring a facilitated and free procedure. In both cases the practical reading is that if acceptance took one click, withdrawal cannot take an email to support.

What withdrawal can and cannot undo

A runtime can stop future loading, remove the loaders it created, and send the revoke signal to vendors that publish one. What it cannot do is reach into a third party’s systems and delete what they already hold, stop a server-side integration it never controlled, or unring a bell that rang before the site was brought under management.

  • Managed loaders stop future loading; vendor revoke or teardown APIs and applicable cookie, browser-storage and server-side cleanup are still required because removing an element or reloading cannot undo every effect
  • Vendor revoke signals are sent where the vendor supports one, including to a script that finishes loading after the withdrawal
  • Server-side integrations such as a conversions API are outside the runtime’s reach and need their own handling
  • Cookies set on another party’s domain cannot be deleted from your page

Say so in the privacy notice

The honest version (we stop sending, and here is how to ask the vendor to delete) is both more accurate and easier to defend than implying a withdrawal erases history.

Common questions

Does withdrawing consent delete data already collected?

No. Withdrawal stops future processing based on that consent; it does not retroactively make earlier processing unlawful, and it does not by itself delete what a third party already holds. Deletion is a separate right, exercised through a data subject request.

How does a visitor withdraw in StrongPrivacy?

Through the preference centre, which can be reopened from any page. The new decision is recorded as its own consent record against the live configuration version, so the history shows both the grant and the withdrawal.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.