Withdrawal cannot necessarily reverse prior processing outcomes
Aliases: prospective withdrawal · non-retroactivity · irreversible processing outcome
What it is
The prospective effect of consent withdrawal means revocation stops future processing that depends on consent but does not automatically restore a world in which earlier lawful disclosure, inference, decision, or external action never occurred. Stopping, deletion, correction, and remediation are related but distinct operations. A control presented as undoing every consequence creates false control.
Why it happens
Processing outcomes cross reversibility boundaries. Data reach recipients, profiles affect ranking, reports are read, and decisions trigger transactions or notices. Withdrawal can cut new inputs and jobs but cannot erase another person's knowledge or compensate an old decision automatically. A system that fails to separate source data, derived state, and executed consequence may stop collection while continuing to use a score or audience list.
Studying it
Researchers can model processing states from the withdrawal event through new collection, queued jobs, derived features, published outputs, and external actions, measuring stop latency and residual effect. Counterfactual tests run comparable tasks before and after withdrawal to detect old-feature reads. Whether earlier processing was lawful must be separated from whether an outcome should remain; deletion, correction, contract, or another rule may govern the latter.
Where it stops holding
Prospective effect is not permission to retain everything. Pending jobs, future reuse, and removable profiles without another basis should stop or clear, and unlawful processing is not protected because it preceded withdrawal. Some effects can be partially reversed through recomputation, recipient notice, or human review. Exact legal consequences vary by jurisdiction and basis, so product promises should avoid absolutes.
Applying it
- Separate future stopping, historical deletion, outcome correction, and recipient contact in the interface, stating each scope.
- Have withdrawal block collection, cancel unexecuted queues, and invalidate dependent features rather than toggling the front end alone.
- Identify irreversible external consequences and provide appeal, human review, or recipient notification instead of claiming automatic restoration.
- Withdraw accounts containing old profiles and pending tasks, then retest ranking, scoring, export, and notices; repair every unsupported read of residual state.
Related
- Same group: O1.10.1 One master switch cannot express different preferences by purpose · O1.10.2 Withdrawal should be no harder than giving consent · O1.10.4 Granularity adds interface complexity that needs careful presentation
- Adjacent: O1.07 Right to erasure and data deletion · O1.03 Purpose limitation
- Search terms:
prospective withdrawal·consent revocation·residual processing