In September 2025, France’s data protection authority, the CNIL, fined a global search and advertising company 325 million euros and a global fast-fashion retailer 150 million euros on the same day.
Among the findings in both cases: when users clicked refuse, or later withdrew consent, advertising cookies continued to be placed and read regardless.
For marketers, the lesson is uncomfortable. Collecting consent is a largely solved problem, with mature tooling and familiar banner patterns. Making a withdrawal actually take effect across the marketing stack is where consent management now fails in practice, and where regulators are concentrating enforcement.
Consent management is the discipline of capturing, storing, and enforcing individuals’ choices about their personal data across every system that processes it. “Enforcing” is becoming the most important word in that definition.
Withdrawal Is a Legal Requirement, Not a Courtesy
Under Article 7(3) of the General Data Protection Regulation (GDPR), withdrawing consent must be as easy as giving it. The obligation goes well beyond the interface: once consent is withdrawn, processing based on that consent must stop.
European regulators read the requirement strictly. If accepting cookies takes one click, refusing or withdrawing should take no more, and the link to change a choice must be as accessible as the banner that collected it.
That second half is the hard part.
A consent management platform can log a withdrawal in milliseconds, but the data collected under the original consent has typically spread to the customer relationship management (CRM) system, the customer data platform (CDP), analytics tools, marketing automation, advertising audiences, and external processors.
Each of those systems keeps working unless something tells it to stop.
Regulators Now Test Consent Management After the Click
The CNIL’s recent decisions show how precisely regulators probe this gap.
In November 2025, it fined the French card-issuing subsidiary of a global payment services company 1.5 million euros, partly because trackers already placed on users’ devices continued to be read after those users withdrew their consent.
The CNIL’s September decisions carried the same operational sting. Beyond the headline fines, the CNIL ordered corrective measures within six months, putting the burden on both companies to demonstrate that refusals and withdrawals now actually stop the processing.
The technical bar has also risen. In its 2025 decisions, the CNIL indicated that ceasing to read a marketing cookie after withdrawal is no longer sufficient, and that the cookie should be removed from the user’s device.
In fact, among the CNIL’s 143 compliance orders in 2025, several targeted websites that failed to take account of users’ withdrawal of consent. Withdrawal has moved from a footnote in consent guidance to a primary enforcement theater.
Why Marketing Stacks Fail at Withdrawal
The failure is structural rather than negligent. Most enterprises capture consent at the edge, in a banner or a signup form, and store it in whichever tool captured it. Withdrawal signals then face a one-way street: data flows outward into activation platforms easily, while control signals may not flow back.
Consider a typical sequence.
- A customer withdraws marketing consent through an email unsubscribe link.
- The email platform suppresses them, but the CDP still holds their profile, the advertising platform still includes them in a custom audience, and a processor is still enriching their record.
- Marketing to that person has only partially stopped, and legally a partial stop is a failure.
Withdrawal also has a time dimension. Suppression lists sync on schedules, audiences refresh daily or weekly, and every delay is a period of processing without a lawful basis.
The processor chain deepens the problem. Under Article 28 of the GDPR, controllers remain responsible for processing carried out on their behalf, so a withdrawal that never reaches an agency, an enrichment vendor, or an outsourced call center is still the controller’s failure.
What Effective Consent Withdrawal Looks Like
Effective consent compliance treats withdrawal as an event to propagate rather than a record to file.
When consent status changes, that change should push automatically to every connected system:
- Suppression in email and SMS
- Removal from advertising audiences
- Notification to processors
- Deletion or restriction of the underlying data where required
Marketers should be able to answer three questions about their own operation.
- How quickly does a withdrawal reach every activation channel?
- Which systems rely on manual exports to stay in sync?
- Could the organization demonstrate the full journey of a single withdrawal, from click to final system, if a regulator asked?
Where any answer involves a spreadsheet, a quarterly job, or a shrug, the organization has a withdrawal gap of exactly the kind the CNIL has been fining.
The Commercial Case for Better Consent Management
Withdrawal handled well is retention infrastructure. When customers can reduce frequency or switch channels in a preference center instead of facing an all-or-nothing unsubscribe, many choose to stay partially engaged, and the organization retains permissioned reach it would otherwise lose entirely.
Regulators have made the direction unmistakable: the consent lifecycle is judged end to end, and the withdrawal leg is where organizations are getting caught.
A useful first step costs nothing. Withdraw consent from your own brand today, across every channel you can find, and watch how long each system takes to notice.