Ban on Processing
A ban on processing is an enforcement action in which a data protection regulator orders an organisation to stop handling personal data, either temporarily or permanently. It is one of the strongest corrective measures a regulator can take, and it typically applies when an organisation's data practices are found to be unlawful or high-risk. The scope of a ban can vary, ranging from stopping a specific activity to halting all processing of certain data.
Under the GDPR, a ban on processing refers to a supervisory authority's corrective power to impose a temporary or definitive limitation, including a prohibition, on processing operations. This power is generally understood to fall among the corrective powers granted to supervisory authorities under Article 58(2) of the GDPR; practitioners should verify the precise sub-provision and wording against the current official text, as the exact scope and conditions can turn on the specific breach and the authority's assessment. A ban may be targeted (for example, ceasing a particular processing activity, transfer, or use of a specific dataset) or broad (suspending processing generally), and it is typically applied where processing is found to infringe the Regulation or presents unmitigated risk. The measure is subject to proportionality, must be reasoned, and its application can vary between EU member states and under the UK GDPR, where the equivalent enforcement powers sit within the national implementing framework. This definition addresses the GDPR/data protection concept only and does not cover unrelated administrative suspensions in other legal contexts.
Why it matters
A ban on processing represents one of the most consequential corrective measures a supervisory authority can impose, because it can require an organisation to stop handling personal data rather than simply pay a penalty and continue operating. For many businesses, personal data processing is integral to core operations, so a temporary or definitive limitation can disrupt services, product features, or entire business lines in a way that a fine alone may not. This makes the measure a significant operational and reputational risk, not merely a financial one.
For compliance leads and data protection officers, the possibility of a processing ban reframes how enforcement risk should be assessed. Because the measure is generally understood to sit among the corrective powers available to supervisory authorities under the GDPR (practitioners should verify the precise sub-provision against the current official text), and because it can be targeted at a specific activity or applied broadly, organisations cannot assume that non-compliance will be resolved through remediation timelines alone. In some cases a regulator may determine that continued processing should cease pending correction.
The practical stakes vary by jurisdiction. Enforcement powers, thresholds, and procedures can differ between EU member states owing to national implementing law and derogations, and the equivalent powers under the UK GDPR sit within the UK's national framework. Organisations operating across multiple jurisdictions should therefore treat the risk of a processing ban as context-dependent and confirm the applicable rules with the relevant authority or competent counsel.
Who it's relevant to
Inside Ban on Processing
Common questions
Answers to the questions practitioners most commonly ask about Ban on Processing.