Earlier quoted context omitted.
Per European Privacy Law, you only own the data for the specific use-cases that you asked it for in your terms of use / privacy policy. I agreed to that when signing up. If you change that in the future, you have to ask for my consent again. If I deny, then you cannot use my data for your new use-case.
Is the revision opt in (express permission required, by default you do not agree)? Or is it opt out (by default you agree, unless you expressly refuse)? In the U.S. terms of service are usually the latter. You'll get a notification of revised terms, and you can refuse. But as a consequence every company I'm aware of will then terminate service. Examples include insurance, banks, and (perhaps infamously) iTunes which…
(32) Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject's agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement. This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject's acceptance of the proposed processing of his or her personal data. Silence, pre-ticked boxes or inactivity should not therefore constitute consent. Consent should cover all processing activities carried out for the same purpose or purposes. When the processing has multiple purposes, consent should be given for all of them. If the data subject's consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided.
(42) Where processing is based on the data subject's consent, the controller should be able to demonstrate that the data subject has given consent to the processing operation.