Short answer: treat data consent revocation and active session revocation as separate controls, then connect them with an explicit policy: stop newly forbidden data operations immediately, but terminate the whole session only when identity risk, account recovery, or regulation requires it.

Decision

Existing session

Protected data operations

Best fit