Skip to content

This translation has not been editorially reviewed yet. The German version is authoritative. Deutsche Fassung →

Data protection

How can visitors permanently revoke cookie consent?

Via a permanently reachable route that reopens the consent choice at any time — a link like "Cookie settings" in the footer of every page is typical. Article 7(3) DSGVO (GDPR) requires that revoking consent be just as easy as giving it. A banner that disappears after the first click and never comes back doesn't meet that: someone who consented yesterday finds no way back today. Our check searches your website for this route and states the result in the report.

Consent isn't a one-way street

A cookie banner captures the visitor's decision on their first visit. After that, it disappears — and on many websites, so does any way to change that decision. This exact state is the problem: consent stays stored, often for months, and the visitor has no visible lever left. The regulation frames it as a balance: revoking consent must be just as easy as giving it. If giving consent was one click in the banner, revoking it must not require deleting all browser data or emailing the operator.

What a permanent revocation route looks like

A proven approach is a permanently visible entry point that reopens the consent window — with the same choices as on the first visit. Most consent tools already include this: as a footer link, as a small floating icon at the edge of the page, or as a menu item in the privacy policy. What matters is findability from every page and a clear label like "Cookie settings" or "Revoke consent". A route only insiders know about isn't one at all.

What the check exactly measures

The check first establishes whether your website shows a cookie banner at all. If it does, it looks outside the banner for a permanent revocation entry point — for links like "Cookie settings", "Revoke consent", or the familiar buttons of common consent tools. If it finds one, the report names where it was found. If it finds none, the finding appears with the corresponding recommendation. The check is a technical examination, not legal advice; it establishes the facts that a legal assessment needs.

  • Check for yourself: can you reopen the consent choice on your website after giving consent, without deleting browser data?
  • Activate the reopen link or floating icon your consent tool already includes.
  • Put the "Cookie settings" link in the footer, so it's reachable from every page.
  • Also mention this route in the privacy policy — that's where visitors look first.

FAQ

Is it enough that visitors can delete their cookies in the browser?

Deleting browser data is considerably more cumbersome than the original one-click consent — that doesn't achieve the balance required by Article 7(3) DSGVO (GDPR), revocation as easy as giving consent. The website itself has to provide the route.

Does the revocation link have to appear on every page?

It has to be permanently and easily reachable. The footer meets that, since it appears on every page. An entry point hidden on just a single subpage doesn't meet the requirement.

What happens to already-set cookies after revocation?

The consent tool should remove or expire the affected cookies and stop loading the associated services on the next page build. Whether that actually happens depends on the integration — something our functional rejection test makes visible.

Deutsche Fassung dieser Seite