Skip to main content
Category: Scope & Exemptions

Exemptions and Restrictions

Also known as: Exemptions, Restrictions, Derogations
Simply put

An exemption is a rule that frees a person or organization from an obligation or requirement that would otherwise apply to them. In a data protection setting, exemptions and restrictions describe situations where some of the usual duties or individual rights may be limited or set aside, though only under specific defined conditions. Whether any particular exemption applies depends heavily on the exact wording of the applicable law and the circumstances, so it should always be checked against the current official text.

Formal definition

Based on the general legal evidence available, an exemption is an immunity, exception, or freedom from a liability, duty, or other requirement that would otherwise apply. In the context of data protection frameworks, 'exemptions and restrictions' is a shorthand for provisions that narrow or disapply certain obligations or data subject rights in defined circumstances. The evidence packet provided does not contain GDPR-specific text, so no specific GDPR article number, scope, or condition should be inferred from it; practitioners should note that under the GDPR and UK GDPR many exemptions and restrictions are set at member state or national level through implementing law, meaning the position can diverge between jurisdictions. Any application of a particular exemption or restriction should be assessed on a case-by-case basis and verified against the current official Regulation text and applicable national law, as this entry's supporting sources address exemptions only in a general and non-EU legal sense.

Why it matters

Exemptions and restrictions determine where the ordinary duties of an organization and the rights of individuals can be lawfully limited, so they sit at the boundary between compliance and non-compliance. Misjudging an exemption can expose an organization to regulatory risk if it withholds information or declines to fulfil a request without a valid basis, and can equally harm individuals if a right is wrongly denied. Because the general evidence available here treats exemption only as an immunity, exception, or freedom from an otherwise applicable duty, practitioners should not read any specific data protection scope into it and should confirm the precise conditions against the applicable law.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads need to identify when an exemption or restriction may lawfully limit a duty or a data subject right, and to document the reasoning. Because many such provisions derive from national implementing law rather than the Regulation text alone, they should map the relevant exemptions for each jurisdiction in which they operate and avoid assuming uniformity across the EU or between the EU and UK.
Privacy and Data Protection Lawyers
Lawyers advising on exemptions must anchor any opinion in the precise statutory wording and applicable national law, distinguishing binding requirements from non-binding guidance. The general legal sources here treat exemption as an immunity or exception without GDPR-specific scope, so counsel should verify the exact conditions and note any divergence between regulators or uncertainty in the position.
Engineers and Product Teams
Engineers implementing rights-handling workflows, such as access or erasure request processing, should build in the possibility that a request may be lawfully restricted or exempt in defined circumstances, rather than assuming every obligation always applies in full. They should route the assessment of whether an exemption applies to legal or compliance colleagues, since that determination is context and law dependent.

Inside Exemptions and Restrictions

Restrictions under Article 23
The GDPR permits Union or member state law to restrict the scope of certain data subject rights and controller obligations (for example those in Articles 12 to 22 and Article 34, and corresponding principles in Article 5) where the restriction respects the essence of fundamental rights and freedoms and is a necessary and proportionate measure to safeguard specified objectives, such as national security, defence, public security, or the prevention and investigation of criminal offences. The precise list and conditions should be verified against the current official text.
National implementing derogations
Member states may provide exemptions and derogations in national law within the space the GDPR allows, meaning the position can vary between jurisdictions. In the UK, comparable provisions sit within the UK GDPR and the national implementing legislation, so practitioners should identify which regime and which national instrument applies before relying on an exemption.
Material and territorial scope limits
Some matters fall outside the GDPR's reach rather than being formal exemptions. The Regulation generally governs personal data of living individuals and does not apply to anonymous data, and typically not to the data of deceased persons or legal entities, though national law may address some of these. Purely personal or household activity is also generally excluded, subject to assessment of the facts.
Special processing contexts
Specific contexts, such as processing for journalistic, academic, artistic or literary expression, and processing for archiving, scientific or historical research, or statistical purposes, may attract tailored reconciliations or safeguards under the Regulation and national law. The availability and shape of these vary by member state derogation, so the applicable national provision should be confirmed.
Conditions attached to a restriction
A restriction is not open-ended. Legislative measures introducing restrictions must generally contain specific provisions about matters such as the purposes of processing, the categories of data, the scope of the restriction, safeguards against abuse, and the rights of data subjects to be informed, where relevant. The exact required elements should be checked against the current text.

Common questions

Answers to the questions practitioners most commonly ask about Exemptions and Restrictions.

Do exemptions and restrictions switch off the GDPR entirely for the activities they cover?
No. Exemptions and restrictions generally disapply or limit specific obligations or rights rather than removing the GDPR as a whole. Even where a restriction applies, core principles such as lawfulness, fairness, and security typically continue to bind the controller, and the restriction is usually confined to particular provisions (for example certain data subject rights or transparency duties). You should identify precisely which obligations are affected and treat everything else as fully applicable.
Can a controller rely on a restriction whenever complying with a request would be inconvenient or costly?
Generally no. Restrictions are not a general convenience mechanism. Under the GDPR framework, restrictions must have a legal basis, respect the essence of fundamental rights and freedoms, and be necessary and proportionate to a recognised objective. Many restrictions derive from member state law adopted under the Regulation's provisions for national derogations, so their availability and precise conditions can vary. Cost or inconvenience alone would typically not satisfy the necessity and proportionality test, and you should verify the specific legal grounding before relying on any restriction.
How do we determine whether a specific exemption or restriction is available to us?
Start by identifying the exact obligation or right you wish to limit, then locate the specific legal provision said to permit that limitation. Because many restrictions depend on member state implementing law, check the applicable national law and any UK GDPR position separately, as the two can diverge. Confirm that the restriction covers your intended purpose, applies to the particular provision at issue, and can meet the necessity and proportionality standard. Where the position is uncertain or regulators differ, treat the exemption as narrow and document your reasoning before relying on it.
What should we document when we decide to apply an exemption or restriction?
In most cases you should record the specific provision relied upon, the objective it serves, the particular obligation or right being limited, and your assessment of why the limitation is necessary and proportionate in the circumstances. Documenting the scope helps demonstrate that you have not disapplied more than the exemption permits and supports the accountability principle. Where a restriction is applied on a case-by-case basis, keep a contemporaneous note for each instance rather than a single blanket justification, and be prepared to review it if guidance or the underlying law changes.
How should exemptions affect the way we handle a data subject rights request?
Assess each right and, where relevant, each element of a request individually against the applicable exemption, rather than refusing a request wholesale. An exemption may apply to part of the personal data or to one right but not others, so partial disclosure or partial compliance is often appropriate. You should generally still acknowledge the request, apply the exemption only to the extent genuinely justified, and consider whether the individual can be informed of the restriction where doing so would not undermine its purpose. Where you are uncertain, resolve the boundary conservatively and record your rationale.
How often should we revisit our reliance on a particular exemption or restriction?
Reliance should be treated as context-dependent rather than permanent. The circumstances that justified a restriction can change, and the underlying national implementing law, regulatory guidance, or interpretation may evolve. As a practical matter you should re-examine whether the necessity and proportionality justification still holds when circumstances shift, when guidance is updated, or on a periodic review cycle. Verify the current position against the applicable official text and any relevant regulator guidance rather than assuming an earlier assessment remains valid.

Common misconceptions

An exemption switches off the GDPR entirely for a given activity.
Restrictions under Article 23 and national derogations are typically targeted, limiting specific rights or obligations rather than disapplying the Regulation wholesale. A restriction must generally respect the essence of the relevant rights and be necessary and proportionate, and other obligations usually continue to apply.
Exemptions apply uniformly across the EU and the UK.
Because the GDPR leaves room for member state derogations and the UK operates under its own UK GDPR and implementing law, the availability and detail of exemptions can diverge between jurisdictions. Practitioners should confirm the position under the specific applicable regime rather than assume consistency.
If data falls outside the GDPR's scope it is the same as an exemption.
Scope limits, such as anonymous data or purely household activity, mean the Regulation generally does not apply in the first place, which is conceptually distinct from an exemption or restriction operating within an otherwise applicable regime. The characterisation matters and is subject to assessment of the facts.

Best practices

Identify which regime applies (EU GDPR, UK GDPR, or relevant national implementing law) before relying on any exemption, and verify the specific provision and any conditions against the current official text.
Distinguish carefully between matters outside scope (for example anonymous data or household activity) and formal restrictions or derogations operating within the regime, and document which analysis you are applying.
Where relying on an Article 23 style restriction, record the objective being safeguarded and assess and document why the restriction is necessary and proportionate and respects the essence of the affected rights.
Check for member state derogations relevant to your processing context, such as journalism or research, since availability and safeguards can vary by jurisdiction.
Treat exemptions as targeted rather than blanket: continue to satisfy the obligations and rights that the restriction does not lawfully displace.
Monitor for updated guidance and legislative change, and re-verify any exemption you rely on rather than treating a past reading as permanently settled.