Table of Contents [TOC]

{tocindex article="current"}

Guides

Menu

  • Pricing
  • Features
    • Regulation compliance
    • GDPR (EU)
    • CCPA (California)
    • PIPEDA (Canada)
    • LGPD (Brasil)
    • KVKK (Turkey)
    • POPIA (South Africa)
    • The basics
    • 42 languages
    • User consents recording
    • Third-party cookie blocking
    • Geo targeting
    • Cookie Banner
    • Google Consent Mode v2
    • Automation
    • Automatic monthly scans
    • Automatic script blocking
    • Advanced reporting
    • Cookie Banner sharing
    • IAB TCF 2.3 integration
    • Google-certified CMP
  • Resources
    • Cookie Scanner
    • Privacy Policy Generator
    • System status
    • Roadmap
    • Changelog
  • Blog
    • Guides
    • News
    • GDPR & CCPA
    • Privacy laws
    • Compare
    • Knowledge base
  • Support
    • Help Center
    • Integrations
    • Contact us
    • Feature request
  • For partners
    • Agencies
    • Affiliates
  • separator
  • Language switcher
    • Profile
    • Billing
    • My plan
  • Sign in
  • Try now
 
  • Guides
  • News
  • GDPR & CCPA
  • Privacy laws
  • Compare
  • Knowledge base
Details
10 September 2026

How Easy Must It Be to Withdraw Cookie Consent?

ON THIS PAGE

  • What Does GDPR Say About Withdrawing Consent?
  • Withdrawal Is Different From Rejecting Cookies
  • What Does “As Easy to Withdraw as to Give” Mean?
  • Does Cookie Consent Have to Be Withdrawable in One Click?
  • Must Visitors Be Able to Reach Cookie Settings From Every Page?
  • Can Visitors Withdraw Consent for Only Some Cookie Categories?
  • What Should Happen After Cookie Consent Is Withdrawn?
    • Withdrawal of Consent Is Not the Same as Deleting Personal Data
    • Should Existing Cookies Be Deleted?
    • What About Scripts That Have Already Loaded?
  • How Do the Rules Differ in the United Kingdom, California, and Canada?
    • UK GDPR and PECR
    • California: CCPA, Opt-Outs, and GPC
    • Canada: Consent Withdrawal Under PIPEDA
  • How to Test Your Cookie Consent Withdrawal Flow
  • Common Cookie Consent Withdrawal Mistakes
  • Making Cookie Consent Easy to Withdraw With CookieScript
  • Conclusion
  • Frequently Asked Questions

A visitor who accepts optional cookies should be able to change that decision without facing a substantially harder process. Under Article 7(3) of the General Data Protection Regulation (GDPR), consent may be withdrawn at any time and withdrawing it must be as easy as giving it. That does not create a universal one-click rule or require a floating cookie icon, but the relevant settings should be easy to find, understand and use without unnecessary friction.

Withdrawal must also work technically. Updating a preference in a Consent Management Platform (CMP) is not enough if consent-dependent tracking continues. The website must make the new choice effective, for example by updating relevant tags, vendors or tracker activity. Other privacy laws in the United Kingdom (UK), California and Canada address similar choices through different legal standards and mechanisms.

What Does GDPR Say About Withdrawing Consent?

GDPR Article 7(3) gives the data subject the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of consent-based processing before withdrawal; the person must be informed of the right before giving consent; and “it shall be as easy to withdraw as to give consent.”

For cookies, the GDPR is only part of the picture. Article 5(3) of the ePrivacy Directive addresses storing information on, or accessing information from, terminal equipment, subject to exemptions. Where the eprivacy framework requires consent, GDPR standards determine what valid consent means.

Withdrawal Is Different From Rejecting Cookies

Initial refusal means the visitor never gives the relevant consent. Withdrawal means they previously gave consent and later change that decision.

Withdrawal is also different from consent expiration, where fresh consent is requested after an appropriate period, and a reset, where stored choices are invalidated because purposes, vendors or configurations have materially changed.

These distinctions matter because the legal basis and technical response may differ. They also become important when comparing GDPR withdrawal with other privacy controls.

What Does “As Easy to Withdraw as to Give” Mean?

The GDPR does not reduce “ease” to one metric. Instead, compare the complete consent journey with the complete withdrawal journey.

Relevant factors include:

  • discoverability;
  • number of interactions;
  • wording and clarity;
  • navigation burden;
  • complexity;
  • confirmation screens;
  • authentication requirements;
  • requests for reasons;
  • mobile usability; and
  • whether the new choice actually takes effect.

If “Accept All” is prominent on the first layer but withdrawal requires footer → Privacy Policy → cookie section → separate preferences page → category toggle → confirmation, that difference is relevant even if every individual step technically works.

The European Data Protection Board (EDPB) Cookie Banner Taskforce emphasizes that withdrawal should remain readily accessible. Its findings do not prescribe one universal withdrawal interface.

EDPB consent guidance also requires withdrawal without detriment. Withdrawal should not impose costs, lower service levels or create other significant negative consequences for the person withdrawing consent. A consent mechanism should therefore provide a genuine choice rather than discourage withdrawal through penalties or avoidable disadvantages.

In 2025, the Commission nationale de l’informatique et des libertés (CNIL) fined the publisher of vanityfair.fr €750,000 for several cookie-law breaches, including an ineffective refusal and withdrawal mechanism: consent-required cookies were still placed and existing cookies continued to be read. The amount reflected the case as a whole, not a universal penalty for every difficult withdrawal flow.

Does Cookie Consent Have to Be Withdrawable in One Click?

No GDPR provision requires withdrawal to take exactly one click.

Article 7(3) requires withdrawal to be as easy as giving consent. Click count can therefore be useful evidence, but it is not the whole test.

A two-step withdrawal flow may be easier than a one-step control hidden deep inside a menu. Conversely, a five-step withdrawal process following a prominent one-click “Accept All” button may indicate disproportionate effort.

The EDPB’s consent guidance focuses on genuine, usable withdrawal rather than prescribing a fixed number of interactions.

Must Visitors Be Able to Reach Cookie Settings From Every Page?

Accessibility is part of an effective withdrawal mechanism. Current CNIL guidance, for example, recommends an easily accessible mechanism throughout navigation, such as a visible “manage cookies” link or cookie-settings icon.

Practical approaches can include:

  • Footer link: a clearly labeled Cookie Settings control;
  • Persistent control: a cookie badge or icon;
  • Preferences menu: a direct route from a privacy or preferences menu; or
  • Preference center: an accessible interface for reviewing and changing choices.

No single implementation is universally required by the GDPR.

A Cookie Policy can explain what cookies are used, why they are used and how choices can be changed. But merely mentioning withdrawal inside a long policy does not necessarily make the mechanism itself easy to find. The relevant test is whether a returning visitor can reach the settings without unnecessary searching.

Can Visitors Withdraw Consent for Only Some Cookie Categories?

Where consent was collected separately for different purposes, visitors should be able to revisit those choices appropriately.

A CMP may group technologies into categories such as analytics, functionality and marketing. Those are interface categories, not statutory GDPR categories, but they can help visitors manage separate purposes.

Where analytics and marketing were collected as separate consent choices, for example, the visitor should be able to revisit those choices separately. The withdrawal mechanism should reflect the level of granularity used when consent was collected.

At this point, the practical test has two sides: the choice must be easy to change, and the website must actually enforce the updated choice.

What Should Happen After Cookie Consent Is Withdrawn?

A preference center that displays “preferences updated” is not an effective implementation if consent-dependent processing continues.

Depending on the website architecture, withdrawal may require the site to:

  • Update CMP state: record the visitor’s current preference;
  • Control tags: prevent future consent-dependent tag firing;
  • Stop tracker activity: prevent relevant reads, writes and requests;
  • Update consent signals: change Google Consent Mode or Google Tag Manager (GTM) states;
  • Notify downstream systems: communicate the change to relevant vendors; and
  • Preserve preference evidence: retain the necessary record of the current choice.

The website should distinguish between evidence that consent was originally obtained, the visitor’s current consent state and a history showing that consent later changed.

Cookies are not the only technology involved. local storage, pixels, scripts, software development kits (SDKs), embedded services and other identifiers may continue processing even when particular browser cookies are removed. Technical testing should therefore look beyond the cookie list.

Withdrawal of Consent Is Not the Same as Deleting personal data

Withdrawing consent and exercising the right to erasure are legally distinct, but they can overlap.

Under the GDPR, withdrawal does not make earlier lawful processing retroactively unlawful. However, EDPB guidance states that controllers have an obligation to delete personal data processed on the basis of consent once that consent is withdrawn where no other purpose with its own lawful basis justifies continued retention, subject to applicable Article 17 of the GDPR exceptions.

A controller also cannot silently switch the same processing from consent to another lawful basis simply to continue it after consent has been withdrawn.

Article 17 erasure remains a separate right with its own conditions and exceptions. Withdrawal therefore does not automatically erase everything ever collected, but consent-based data may need to be deleted where no valid basis for continued retention remains.

Should Existing Cookies Be Deleted?

Deleting a browser cookie and erasing personal data are not the same technical or legal action. The exact response also depends on the applicable rules.

In the UK, current Information Commissioner’s Office (ICO) guidance says consent-dependent storage and access technologies that have already been set must be capable of being removed. CNIL guidance focuses on ensuring that relevant reading and writing operations stop and recognizes that deleting certain Third-Party Cookies may be outside the website publisher’s technical control.

Necessary cookies and the CMP preference itself may still need to remain. The CMP preference may be what remembers that the visitor withdrew or rejected optional tracking. Removing it blindly can cause the website to behave as though no preference exists.

The 2025 Orange injunction follow-up illustrates the third-party limitation: some cookies could remain in the browser where Orange lacked control over their deletion, but relevant reads and writes from the site had to stop.

What About Scripts That Have Already Loaded?

Changing a stored preference does not automatically unload JavaScript that is already executing.

Depending on the implementation, the site may need to use vendor consent application programming interfaces (APIs), GTM consent updates, Google Consent Mode, Transparency and Consent Framework (TCF) signals or direct integrations while preventing future consent-dependent requests.

A page reload can help in some architectures, but it is not a universal requirement or a substitute for correct consent logic.

The exact technical response also depends on the applicable law. Some regulators provide more explicit guidance on what should happen after withdrawal, as the UK example below illustrates.

How Do the Rules Differ in the United Kingdom, California, and Canada?

The practical principles above begin with the GDPR, but the legal mechanism changes outside the European Union (EU).

In the United Kingdom, the UK General Data Protection Regulation (UK GDPR) works alongside the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR). California and Canada use different statutory frameworks, discussed below.

These laws address consent and privacy choices differently, so websites should not treat every privacy preference as the same form of consent withdrawal.

UK GDPR and PECR

The UK GDPR contains the equivalent Article 7(3) withdrawal rule, while PECR governs storage and access technologies.

Published ICO consent guidance describes withdrawal as:

  • Easily accessible: it should not be hidden behind unnecessary barriers;
  • One step: the ICO describes an easily accessible one-step process; and
  • Consistent where possible: the same method used to give consent should be available for withdrawal where practical.

The “one-step process” wording is ICO guidance, rather than the literal wording of Article 7(3).

For cookies and similar technologies, the ICO’s final storage and access technology guidance says the consent mechanism must let users withdraw consent with the same ease that they gave it.

For non-exempt technologies, withdrawal means:

  • stopping the relevant storage and access technologies;
  • ceasing the related consent-based personal-data processing;
  • informing relevant third parties that consent has been withdrawn; and
  • treating the withdrawal as a request for erasure of information gathered under that consent.

The guidance also says storage and access technologies already set must be capable of being removed.

PECR now includes additional exceptions following the Data (Use and Access) Act 2025. Where consent is still required, withdrawal requirements remain relevant.

California: CCPA, Opt-Outs, and GPC

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), combines consent rules in certain circumstances with separate statutory opt-outs.

Under the CCPA Regulations effective January 1, 2026, where CCPA consent is required, consumers must be able to withdraw it at any time in the applicable circumstances. Relevant methods and choice architecture must be:

  • Easy to understand;
  • Easy to execute without unnecessary burden or friction; and
  • Symmetrical where required: privacy-protective choices should not be made unnecessarily harder than less privacy-protective choices.

California also gives consumers separate rights to opt out of the sale or sharing of Personal Information. “Sharing” includes cross-context behavioral advertising.

These opt-outs are not the same legal mechanism as withdrawing GDPR consent. A generic cookie preference therefore does not automatically implement a California sale/sharing opt-out; the underlying regulated activity must actually stop.

Qualifying opt-out preference signals such as Global Privacy Control (GPC) must be processed as sale/sharing opt-out requests by businesses subject to those requirements. GPC is an opt-out preference mechanism, not another term for withdrawing Cookie Consent.

Canada: Consent Withdrawal Under PIPEDA

The Personal Information Protection and Electronic Documents Act (PIPEDA) uses a different withdrawal standard.

PIPEDA Principle 4.3.8 says an individual may withdraw consent at any time, subject to:

  • Legal or contractual restrictions;
  • Reasonable notice; and
  • Explanation of consequences: the organization must inform the individual of the implications of withdrawal.

PIPEDA does not contain the GDPR phrase “as easy to withdraw as to give.”

Current Office of the Privacy Commissioner of Canada (OPC) consent guidance emphasizes user-friendly and understandable consent processes and meaningful choices. OPC behavioral-advertising guidance also treats clear notice and an effective, accessible opt-out as important where opt-out consent is appropriate.

PIPEDA is not a general Canadian “cookie law.” Cookies and similar trackers are relevant where they involve Personal Information, and withdrawal does not automatically require every previously collected record to be deleted immediately.

The key differences are:

RegimeMain privacy mechanismPractical standard
EU — GDPR/eprivacy Consent withdrawal Withdrawal must be as easy as giving consent
UK — GDPR/PECR Consent withdrawal Equivalent Article 7(3) rule, supplemented by ICO guidance
California — CCPA, as amended by the CPRA Consent withdrawal in relevant contexts, plus separate sale/sharing opt-outs and GPC Choices must be easy to execute without unnecessary friction; symmetry rules apply where relevant
Canada — PIPEDA Consent withdrawal Withdrawal is permitted subject to legal or contractual restrictions and reasonable notice; implications must be explained

The practical outcomes may sometimes look similar, but the legal mechanisms are different.

How to Test Your Cookie Consent Withdrawal Flow

A good audit should test the same two questions raised throughout the article: can the visitor change the choice easily, and does the website enforce it correctly?

  1. Findability: Can a returning visitor locate the relevant settings without searching through legal text?
  2. Access: Does the control directly open the preferences the visitor needs?
  3. Effort and clarity: Is changing the choice materially harder or more confusing than allowing tracking?
  4. Granularity: Can relevant purposes or categories be changed separately where appropriate?
  5. Technical effect: Do affected tags, reads, writes and network requests actually stop?
  6. Storage and persistence: Are applicable cookies and other storage handled correctly while the updated preference remains remembered?
  7. Downstream systems: Are GTM, vendors and consent APIs updated where needed?
  8. Navigation and mobile: Does the new state survive reloads and route changes, and is the control usable on smaller screens and with assistive technologies?
  9. Jurisdiction: Does the control implement the legal right actually being exercised rather than simply relabeling a generic cookie preference?

Use browser developer tools (DevTools) before changing the preference to inspect cookies, local storage, network requests and the CMP state. Repeat the checks afterward, then reload and navigate to another page.

DevTools cannot prove legal compliance on their own. They can, however, reveal a common implementation failure: the interface reports that a choice was saved while consent-dependent processing continues.

Common Cookie Consent Withdrawal Mistakes

Several failures appear repeatedly in real withdrawal journeys:

  • Buried controls: requiring visitors to search through a long policy or menu;
  • Disproportionate effort: making acceptance immediate while reversal involves unnecessary extra steps;
  • Mandatory reasons or authentication: requiring feedback, login or verification that was not needed for the original anonymous choice;
  • All-or-nothing changes: preventing purpose-level changes where consent was collected granularly;
  • UI-only withdrawal: saving a preference in the CMP while tracking continues;
  • Wrong deletion: removing the CMP preference and causing the website to forget that optional tracking was rejected; and
  • Legal-concept confusion: treating GDPR withdrawal, erasure, CCPA sale/sharing opt-outs and GPC as interchangeable.

The common thread is that a withdrawal control must be both usable and technically effective.

Making Cookie Consent Easy to Withdraw With CookieScript

CookieScript handles the consent-management side of the process: presenting the Cookie Banner, recording consent choices and helping websites apply those choices when visitors update their preferences.

CookieScript is a Consent Management Platform (CMP) that Google includes among the CMP partners available for Consent Mode setup. It is also a Google-certified CMP and has GOLD Tier status in Google’s CMP tiering system.

CookieScript supports consent withdrawal through several features that help visitors revisit their choices or communicate an updated consent state:

  • Cookie Banner, including Cookie Badge and Show cookie categories, gives visitors a way to return to their Cookie Consent settings after the original choice has been made. Cookie Badge can reopen the Cookie Banner, while cookie categories allow visitors to review and change individual category preferences where granular consent is used.
  • Consent events allow website or application logic to respond when a visitor changes a consent choice. CookieScript also supports GTM events when users change Cookie Consent, including changes to cookie categories and withdrawal of consent.
  • Google Consent Mode v2 communicates supported consent states to Google tags so their behavior can reflect the visitor’s updated choice. Consent Mode does not provide the withdrawal interface itself, but it can help Google services respond when the consent state changes.
  • IAB TCF 2.3 integration supports advertising environments using the IAB Europe Transparency & Consent Framework, including communicating updated consent choices to participating vendors when consent is granted, refused or revoked.

CookieScript also offers:

  • Cross-domain cookie consent sharing
  • Remember Consent for Subdomains
  • Cookie Scanner
  • User consents recording
  • Third-party cookie blocking
  • Geo targeting
  • SameSite consent-cookie configuration
  • 42 languages
  • Automatic monthly scans
  • Automatic script blocking
  • Advanced reporting
  • Google Tag Manager integration
  • Cookie Banner sharing
  • Privacy Policy Generator

A 14-day free trial of the Plus plan is also available without requiring a credit card.

Whichever CookieScript features are used, the withdrawal flow should still be tested against the website’s actual implementation. Visitors need to be able to revisit their Cookie Consent choices, and the relevant scripts, tags, storage and vendor states must respond appropriately when those choices change.

Conclusion

Audit both sides of the withdrawal journey: how easily visitors can change their choice and whether the website actually enforces it. A clear preference control is only effective when the technologies behind it respect the updated choice.

Register for free Show pricing plans

Frequently Asked Questions

Can users withdraw cookie consent at any time?

Under GDPR Article 7(3), consent may be withdrawn at any time, and the person must be informed of that right before giving consent. Withdrawal affects future processing based on that consent; it does not retroactively invalidate lawful earlier processing.

Does GDPR require one-click cookie consent withdrawal?

No. GDPR Article 7(3) requires withdrawal to be as easy as giving consent, not to use a fixed number of clicks. The overall journey matters, including findability, effort, wording and unnecessary friction.

Must Cookie Settings be available on every page?

GDPR does not literally require a floating icon on every page. However, withdrawal must remain sufficiently accessible. CNIL guidance recommends readily accessible mechanisms throughout navigation, which can include a badge, footer link or preferences menu.

Can visitors withdraw only some cookie categories?

Where consent was collected separately for different purposes, visitors should be able to revisit those choices appropriately. EDPB consent guidance addresses the need for granular consent. CMP categories such as analytics or marketing are interface groupings rather than statutory GDPR categories, but they can support granular preference changes.

Should cookies be deleted when consent is withdrawn?

Not necessarily every cookie. The exact response depends on the applicable rules and technology. Current ICO storage and access technology guidance addresses removal of consent-dependent storage and access technologies, while CNIL guidance emphasizes stopping relevant reads and writes. Necessary cookies and the CMP preference may still need to remain.

How is California’s CCPA different from GDPR withdrawal?

The California Consumer Privacy Act (CCPA) includes consent-withdrawal requirements where CCPA consent is required, but also provides separate sale/sharing opt-outs. Global Privacy Control (GPC) is an opt-out preference signal for those California rights. These mechanisms should not be described as GDPR cookie-consent withdrawal.

Can consent be withdrawn under PIPEDA?

Yes. PIPEDA Principle 4.3.8 permits withdrawal subject to legal or contractual restrictions and reasonable notice, and the organization must explain the implications. PIPEDA does not use GDPR’s “as easy to withdraw as to give” wording.

What happens to data collected before withdrawal?

Under GDPR Article 7(3), withdrawal does not make processing that was lawful before withdrawal retroactively unlawful. However, EDPB consent guidance explains that where personal data was processed on the basis of consent and no separate purpose with its own lawful basis supports continued retention, that data may need to be erased, subject to applicable legal exceptions.

 
  • About CookieScript
  • Terms of Service
  • Privacy Policy
  • Pricing
  • Resources
  • Cookie Scanner
  • Privacy Policy Generator
  • System status
  • Sitemap
  • Changelog
  • Alternatives
  • CookieBot
  • Termly
  • OneTrust
  • Iubenda
  • Cookie Information
  • CookieFirst
  • Illow
  • Blog
  • Guides
  • News
  • GDPR & CCPA
  • Privacy laws
  • Knowledge base
  • Support
  • Help center
  • Contact us
  • Integrations
  • Request a feature
  • Roadmap
  • For Partners
  • For agencies
  • For Affiliates

Copyright ©2026 CookieScript


main version