This translation has not been editorially reviewed yet. The German version is authoritative. Deutsche Fassung →
How do you get back out?
Anyone who has once consented must be able to withdraw it just as easily. Art. 7(3) DSGVO explicitly requires this. The check therefore looks for a permanent way back — a link like "Cookie settings" in the footer that reopens the selection. This is only assessed if the page has a banner at all: with no consent, there's nothing to withdraw.
- The most common case isn't bad intent, it's a gap in the tool: the banner appears once, the visitor clicks, and after that the selection is no longer reachable. That makes consent practically irrevocable — and that's exactly what it must not be.
- The check specifically looks OUTSIDE the banner. The banner's own settings button disappears along with the banner, and helps nobody after that.
- The fix usually costs one line: every common banner tool comes with a link that reopens the selection. It just needs to sit somewhere permanently, usually in the footer next to the legal notice and privacy policy.
FAQ
Is it enough if you can delete cookies in the browser?
No. Withdrawal should be as easy as giving consent — giving consent was a click on the page. Pointing visitors to their browser settings is something else.
We don't have a banner at all. Does this point come back to bite us?
No. With no consent, there's nothing to withdraw — this point is then counted as met, and produces no finding.
Do you also check whether you can delete your account?
No, and deliberately so. Whether a page even runs accounts at all can't be reliably established from outside. Penalising a page with no login for this would be a false finding — and that costs more for an audit seal than a gap does.