O1.10.3Prospective effect of consent withdrawaldesignresearch

Withdrawal cannot necessarily reverse prior processing outcomes

Aliases: prospective withdrawal · non-retroactivity · irreversible processing outcome

What it is

The prospective effect of consent withdrawal means revocation stops future processing that depends on consent but does not automatically restore a world in which earlier lawful disclosure, inference, decision, or external action never occurred. Stopping, deletion, correction, and remediation are related but distinct operations. A control presented as undoing every consequence creates false control.

Why it happens

Processing outcomes cross reversibility boundaries. Data reach recipients, profiles affect ranking, reports are read, and decisions trigger transactions or notices. Withdrawal can cut new inputs and jobs but cannot erase another person's knowledge or compensate an old decision automatically. A system that fails to separate source data, derived state, and executed consequence may stop collection while continuing to use a score or audience list.

Studying it

Researchers can model processing states from the withdrawal event through new collection, queued jobs, derived features, published outputs, and external actions, measuring stop latency and residual effect. Counterfactual tests run comparable tasks before and after withdrawal to detect old-feature reads. Whether earlier processing was lawful must be separated from whether an outcome should remain; deletion, correction, contract, or another rule may govern the latter.

Where it stops holding

Prospective effect is not permission to retain everything. Pending jobs, future reuse, and removable profiles without another basis should stop or clear, and unlawful processing is not protected because it preceded withdrawal. Some effects can be partially reversed through recomputation, recipient notice, or human review. Exact legal consequences vary by jurisdiction and basis, so product promises should avoid absolutes.

Applying it

  • Separate future stopping, historical deletion, outcome correction, and recipient contact in the interface, stating each scope.
  • Have withdrawal block collection, cancel unexecuted queues, and invalidate dependent features rather than toggling the front end alone.
  • Identify irreversible external consequences and provide appeal, human review, or recipient notification instead of claiming automatic restoration.
  • Withdraw accounts containing old profiles and pending tasks, then retest ranking, scoring, export, and notices; repair every unsupported read of residual state.

Related

  • Same group: O1.10.1 One master switch cannot express different preferences by purpose · O1.10.2 Withdrawal should be no harder than giving consent · O1.10.4 Granularity adds interface complexity that needs careful presentation
  • Adjacent: O1.07 Right to erasure and data deletion · O1.03 Purpose limitation
  • Search terms: prospective withdrawal · consent revocation · residual processing

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/O1.10.3