Rights & provenance
What happens when consent is withdrawn
Last updated 2026-07-22
Consent-based data has a property every licence has to plan for: the person can change their mind. Under GDPR Article 7(3), a data subject can withdraw consent at any time, withdrawal must be as easy as giving consent was, and — the clause both sides misread — withdrawal does not affect the lawfulness of processing that already happened. Article 17(1)(b) then gives a right to erasure of the personal data where consent was the legal basis and no other ground applies. Illinois’ BIPA approaches the same idea from the collection side: a voiceprint requires informed written release before collection, and Section 15(a) requires destruction when the collection purpose is satisfied or within three years of the person’s last interaction, whichever comes first. What none of these instruments cleanly answers is the question AI created: when data has already shaped the weights of a trained model, what exactly does withdrawal reach — the future, the dataset, or the model itself? The emerging regulatory answer treats those as three different questions.
Why it matters to a buyer
The fear version — one withdrawal means deleting the model — is not what European regulators have said. The EDPB’s Opinion 28/2024 on AI models starts a step earlier: if a model is genuinely anonymous, meaning the probability of extracting personal data about any individual is negligible, the GDPR does not apply to the model itself, and rights run against the training dataset but not the weights. Where a model does memorize personal data — the EDPB and CNIL note large language models often do — data-subject rights apply to the model, with the practical difficulties acknowledged. The CNIL’s guidance, updated January 2026, is the most operational statement so far: retraining is the most effective response and can be batched periodically; where retraining is disproportionate, sufficiently effective and robust output filters are an acceptable answer; and an erasure request can in principle be refused where compliance would be disproportionate — its example is a public figure asking a general LLM provider to retrain — though the CNIL warns that requests refusable today may have to be honored tomorrow as unlearning techniques mature. The hard edge sits elsewhere: where the underlying processing was unlawful from the start, the EDPB confirms supervisory authorities can order deletion of the unlawfully processed data and, in serious cases, of the model trained on it. So the buyer’s real exposure is not the occasional withdrawal — it is a corpus whose consent was defective from day one. Segment training data by legal basis, keep the provenance to prove which consent covers what, and preserve a retraining path.
Why it matters to a data owner
The supplier’s job is to make withdrawal a defined event instead of a dispute. State in the consent and in the licence what withdrawal reaches — future collection stops, the material comes off the market for new licensing, delivered datasets get deleted or flagged downstream — and what it does not reach: models already trained during the licence term. That candor is not a loophole. The CNIL expressly contemplates telling people at consent time that erasure of data already learned by a model may not be possible, and treats that disclosure as part of valid, informed consent. The contract mechanics that implement this are familiar: sunset clauses that time-box training rights; no-retroactive-effect language for completed training runs; and pass-through obligations in dataset licences requiring re-users to honor erasure and rectification requests, which the CNIL identifies as good practice alongside GDPR Article 19’s notification duty. Suppliers handling Illinois-touching audio should also build the destruction schedule into operations, because BIPA’s Section 15(a) clock runs whether or not anyone asks. A supplier who can show this machinery is more licensable, not less — buyers pay for consent that will not become a crisis.
Current legal status
GDPR: Article 7(3) grants withdrawal at any time without retroactive effect on prior processing; Article 17(1)(b) requires erasure where consent was the basis and no other legal ground applies; Article 19 requires notifying recipients of erasure unless impossible or disproportionate. EDPB Opinion 28/2024, adopted December 2024, holds that a truly anonymous model falls outside the GDPR, that non-anonymous models carry data-subject rights, and that supervisory authorities may order deletion of unlawfully processed data and in some cases of the model built on it. The CNIL’s AI guidance, updated January 5, 2026, operationalizes this: rights run against training datasets and against non-anonymous models; retraining is the most effective remedy and may be periodic; robust output filtering is an accepted alternative where retraining is disproportionate; disproportionate complexity and cost are legitimate factors, but the threshold will tighten as unlearning matures; and providers should prefer anonymous models by design. In the US there is no general withdrawal right; the closest analogues are statutory. BIPA conditions collection on informed written release — electronic signatures suffice after Public Act 103-0769 (August 2024), which also limited recovery to one per person for repeated identical collection — and requires destruction on the Section 15(a) schedule. The May 2026 Illinois voiceprint class actions against major AI companies show the collection-side theory in active litigation. Contractual sunset and no-retroactive-effect terms are common practice, not statutory requirements.
What fiund does about it
fiund treats withdrawal as a term to be drafted, not discovered: consent artifacts state scope and duration up front, the paperwork sits in the provenance record, and buyers know at licensing time exactly which material rests on consent and what happens if it is pulled.
Sources
- EUR-Lex — Regulation (EU) 2016/679 (GDPR), Articles 7, 17, and 19
- EDPB — Opinion 28/2024 on data protection aspects of AI models
- CNIL — Ensuring and facilitating the exercise of data subjects’ rights in AI (updated Jan 2026)
- King & Spalding — Illinois BIPA reform takes effect (Public Act 103-0769)
- Biometric Update — Tech giants sued under BIPA over voiceprints used to train AI (May 2026)
More on rights & provenance
Want data that clears this in diligence?
Whether you're building a model or sitting on an archive, the first conversation is short and specific.
Send a brief