Skip to main content
Category: Supervisory Authorities & Enforcement

Ban on Processing

Also known as: Processing Ban, Limitation on Processing, Prohibition on Processing
Simply put

A ban on processing is an enforcement action in which a data protection regulator orders an organisation to stop handling personal data, either temporarily or permanently. It is one of the strongest corrective measures a regulator can take, and it typically applies when an organisation's data practices are found to be unlawful or high-risk. The scope of a ban can vary, ranging from stopping a specific activity to halting all processing of certain data.

Formal definition

Under the GDPR, a ban on processing refers to a supervisory authority's corrective power to impose a temporary or definitive limitation, including a prohibition, on processing operations. This power is generally understood to fall among the corrective powers granted to supervisory authorities under Article 58(2) of the GDPR; practitioners should verify the precise sub-provision and wording against the current official text, as the exact scope and conditions can turn on the specific breach and the authority's assessment. A ban may be targeted (for example, ceasing a particular processing activity, transfer, or use of a specific dataset) or broad (suspending processing generally), and it is typically applied where processing is found to infringe the Regulation or presents unmitigated risk. The measure is subject to proportionality, must be reasoned, and its application can vary between EU member states and under the UK GDPR, where the equivalent enforcement powers sit within the national implementing framework. This definition addresses the GDPR/data protection concept only and does not cover unrelated administrative suspensions in other legal contexts.

Why it matters

A ban on processing represents one of the most consequential corrective measures a supervisory authority can impose, because it can require an organisation to stop handling personal data rather than simply pay a penalty and continue operating. For many businesses, personal data processing is integral to core operations, so a temporary or definitive limitation can disrupt services, product features, or entire business lines in a way that a fine alone may not. This makes the measure a significant operational and reputational risk, not merely a financial one.

For compliance leads and data protection officers, the possibility of a processing ban reframes how enforcement risk should be assessed. Because the measure is generally understood to sit among the corrective powers available to supervisory authorities under the GDPR (practitioners should verify the precise sub-provision against the current official text), and because it can be targeted at a specific activity or applied broadly, organisations cannot assume that non-compliance will be resolved through remediation timelines alone. In some cases a regulator may determine that continued processing should cease pending correction.

The practical stakes vary by jurisdiction. Enforcement powers, thresholds, and procedures can differ between EU member states owing to national implementing law and derogations, and the equivalent powers under the UK GDPR sit within the UK's national framework. Organisations operating across multiple jurisdictions should therefore treat the risk of a processing ban as context-dependent and confirm the applicable rules with the relevant authority or competent counsel.

Who it's relevant to

Data Protection Officers
DPOs need to understand that a processing ban is among the strongest corrective measures a supervisory authority can take, and that it can be targeted or broad. When advising on enforcement risk, they should factor in the possibility that a regulator may require processing to stop, subject to proportionality and the authority's reasoned assessment, rather than assuming remediation over time will always suffice.
Compliance and Legal Leads
Those responsible for compliance programs should treat a processing ban as an operational and reputational risk, not solely a financial one, because it can halt activities that depend on personal data. They should confirm how the relevant power operates in the applicable jurisdiction, noting that EU member states can vary and that the UK GDPR places equivalent powers within the national implementing framework.
Organisations Operating Across Jurisdictions
Businesses processing personal data in multiple EU member states or under the UK GDPR should recognise that the scope, thresholds, and procedures around a ban on processing can differ, and that a snapshot of the position may change. They should verify the applicable powers and any appeal routes against the current official text and with competent authorities or counsel.
Engineering and Product Teams
Technical teams whose systems rely on personal data should be aware that a targeted ban could require ceasing a specific processing activity, transfer, or use of a particular dataset. Building the ability to isolate and suspend defined processing operations can help an organisation respond if such a measure is imposed.

Inside Ban on Processing

General prohibition on processing special category data
Under Article 9(1) GDPR, processing of special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and the processing of genetic data, biometric data for uniquely identifying a person, data concerning health, or data concerning a person's sex life or sexual orientation) is generally prohibited unless one of the specific conditions in Article 9(2) applies. This is often described as a 'ban on processing' in the sense of a default prohibition that must be lifted by a qualifying condition.
Supervisory authority power to impose a ban
Distinct from the Article 9(1) prohibition, supervisory authorities have corrective powers under Article 58(2)(f) to impose a temporary or definitive limitation, including a ban, on processing. This is an enforcement measure directed at a controller or processor rather than a category-level default prohibition.
Article 9(2) lifting conditions
The general prohibition can be lifted where a condition in Article 9(2) is met, for example explicit consent, processing necessary for employment or social security law obligations, protection of vital interests, or reasons of substantial public interest, among others. Member state law may further specify or restrict these conditions, so the position can vary by jurisdiction.
Interaction with an Article 6 legal basis
Meeting an Article 9(2) condition does not, on its own, make processing lawful. In most cases an Article 6 legal basis is also required, so both an Article 6 basis and an Article 9(2) condition are typically needed for special category data. Practitioners should verify this two-layer requirement for the specific processing.
Scope boundary
The prohibition concerns personal data of identified or identifiable living individuals. It does not generally apply to anonymous data, and the treatment of deceased persons' data or legal entities is outside the core scope and may be addressed differently under national law.

Common questions

Answers to the questions practitioners most commonly ask about Ban on Processing.

Is a "ban on processing" the same thing as a fine issued by a supervisory authority?
No. A ban on processing is a corrective power that restricts or stops processing activity, generally exercised by a supervisory authority under Article 58(2) GDPR (including the power to impose a temporary or definitive limitation on processing, such as a ban). An administrative fine is a separate corrective measure under a different provision. The two can be applied together or independently, and the presence of one does not imply the other. You should verify the specific measure and its legal basis in the authority's decision rather than assume it is monetary.
Does a ban on processing mean a controller must permanently delete all the affected personal data?
Not necessarily. A ban or limitation on processing restricts the operations that may be carried out on the data; it is conceptually distinct from erasure. A limitation may be temporary or definitive, and it may cover specific processing operations rather than all of them. Erasure is a separate concept with its own conditions. Whether deletion is required depends on the terms of the specific order and any accompanying instructions, so the scope should be read carefully against the actual decision.
How should a controller respond operationally when a supervisory authority imposes a ban on processing?
In most cases, the immediate steps are to identify the precise processing operations covered, confirm whether the measure is temporary or definitive, and halt or restrict those operations accordingly while preserving the data in a manner consistent with the order. It is generally advisable to document the actions taken, involve the data protection officer and legal counsel, and clarify any ambiguity with the authority. The exact response depends on the wording and scope of the decision, so this should be treated as a general framework rather than a fixed checklist.
Can a ban on processing apply to only part of an organisation's activities?
Yes, in principle a limitation or ban can be scoped to particular processing operations, categories of data, purposes, or systems rather than the whole organisation. The scope is defined by the supervisory authority's decision. Because the boundary can vary, controllers should map the order to their specific processing inventory to determine which activities are affected and which may continue, subject to assessment of the decision's terms.
What is the relationship between a ban on processing and the right to restriction of processing exercised by a data subject?
They arise from different mechanisms. A ban or limitation imposed by an authority is a corrective power exercised by a regulator, whereas restriction of processing at the request of a data subject is a data subject right with its own conditions and consequences. Both limit processing, but the trigger, the actor, and the governing provisions differ. Controllers should not treat one as interchangeable with the other and should confirm which mechanism applies in a given case.
Can a controller challenge or seek to lift a ban on processing?
Generally, decisions of a supervisory authority are subject to procedural and remedial routes, and affected parties typically have a right to an effective judicial remedy against a legally binding decision of an authority. The availability, timing, and forum for any challenge depend on the applicable procedural rules, which can vary between EU member states and under the UK GDPR framework. Because these procedures differ by jurisdiction, the specific avenues and deadlines should be verified against the applicable national law and the decision itself.

Common misconceptions

The 'ban on processing' means special category data can never lawfully be processed.
It is a default prohibition, not an absolute bar. Processing is generally permitted where a condition in Article 9(2) applies and, in most cases, a separate Article 6 legal basis is also satisfied. The lawful path is context and jurisdiction dependent.
Any reference to a 'ban on processing' refers to the same thing.
There are at least two distinct concepts: the general prohibition on special category data under Article 9(1), and the corrective power of a supervisory authority to impose a limitation or ban on processing under Article 58(2)(f). These operate differently and should not be conflated.
Satisfying an Article 9(2) condition alone makes the processing lawful.
An Article 9(2) condition lifts the specific prohibition on special category data, but a valid Article 6 legal basis is typically still required. Both layers generally need to be documented for the processing to be lawful.

Best practices

Before processing special category data, identify and document both an applicable Article 9(2) condition and a corresponding Article 6 legal basis, treating them as separate requirements.
Distinguish clearly in your records whether you are addressing the Article 9(1) default prohibition or a supervisory authority's Article 58(2)(f) corrective power, as the response differs.
Check the relevant national implementing law and any member state derogations, since conditions and safeguards for special category data can vary by jurisdiction and should be verified against current official texts.
Assess at the outset whether the data truly falls within a special category and whether it concerns living identifiable individuals, to confirm the prohibition applies before building your lawful basis analysis.
Where relying on explicit consent as the Article 9(2) condition, verify that it meets the heightened explicit consent standard and remains freely given, specific, informed, and withdrawable.
Maintain up-to-date processing records and be prepared to demonstrate the basis to a supervisory authority, given its power to impose a temporary or definitive limitation on processing.