Skip to main content
Category: Data Subject Rights

Notification Obligation Regarding Rectification or Erasure

Also known as: Notification obligation regarding rectification or erasure of personal data or restriction of processing, Article 19 notification obligation
Simply put

This is a duty on an organisation that controls personal data to tell each third party it has shared that data with when it later corrects, deletes, or restricts the use of that data. In this way, corrections and deletions can flow through to others who also hold copies. The individual can also ask the organisation to identify who those recipients are.

Formal definition

Under Article 19 of the GDPR (and the corresponding provision of the UK GDPR), the controller shall communicate any rectification or erasure of personal data, or restriction of processing, carried out in accordance with Articles 16, 17(1) and 18, to each recipient to whom the personal data has been disclosed. Based on the evidence provided, this obligation applies unless doing so proves impossible or involves disproportionate effort; the precise wording of that limitation and any exceptions should be verified against the current official text. The Article also provides that the controller shall inform the data subject about those recipients if the data subject requests it. This provision operates as a downstream corollary to the rights of rectification (Article 16), erasure (Article 17), and restriction of processing (Article 18); the exact scope of what counts as 'impossible or disproportionate effort' is fact-specific and may be subject to regulatory guidance and assessment.

Why it matters

Article 19 addresses a practical gap that individual rights would otherwise leave open: when personal data has been shared with others, correcting or deleting it in one place does not automatically fix every copy that exists downstream. Without a duty to notify recipients, an individual could successfully exercise a right to rectification (Article 16), erasure (Article 17(1)), or restriction of processing (Article 18) against one controller, yet inaccurate or unlawfully retained data could continue circulating among the parties to whom it was disclosed. This provision is what makes those rights meaningful across a data-sharing chain rather than only at a single point.

For organisations, the obligation turns rights handling into a process that must extend beyond internal systems. When a controller rectifies, erases, or restricts data, it generally must communicate that change to each recipient to whom the data was disclosed, unless doing so proves impossible or involves disproportionate effort. The precise boundaries of that limitation are fact-specific and should be assessed case by case; the exact wording and any exceptions should be verified against the current official GDPR and UK GDPR text. In practice this means controllers need to know, and be able to reconstruct, who received particular data in order to satisfy the duty.

The Article also gives the individual a further lever: on request, the controller must inform the data subject about the recipients to whom these changes were communicated. This transparency element allows individuals to understand and, where relevant, pursue the propagation of a correction or deletion. Because what counts as 'impossible or disproportionate effort' may be subject to regulatory guidance and interpretation, organisations should document their reasoning where they rely on that limitation.

Who it's relevant to

Data Protection Officers and Privacy Teams
DPOs and privacy teams design the workflows that connect a data subject's rectification, erasure, or restriction request to the downstream notification of recipients. They should ensure the organisation can identify recipients of shared data and can assess, and document, any reliance on the 'impossible or disproportionate effort' limitation.
Controllers Sharing Data with Third Parties
Any controller that discloses personal data to recipients carries the Article 19 duty to communicate later rectifications, erasures, or restrictions to those recipients. Maintaining records of who received which data is generally necessary to meet this obligation reliably.
Individuals Exercising Their Rights
Data subjects benefit because corrections and deletions can flow through to others who hold their data. They can also request that the controller identify the recipients to whom the changes were communicated, supporting transparency over how their rights have propagated.
Compliance and Records Management Functions
Teams responsible for data mapping and records of processing help make Article 19 operable, since the ability to notify recipients depends on knowing who they are. Where a controller relies on the disproportionate-effort limitation, these functions support the fact-specific assessment and its documentation.

Inside Notification Obligation Regarding Rectification or Erasure

Communication to recipients
The controller must communicate any rectification, erasure, or restriction of processing to each recipient to whom the personal data have been disclosed, unless doing so proves impossible or involves disproportionate effort. This obligation is generally understood to arise under Article 19 GDPR; the reader should verify the article reference against the current official text.
Trigger events
The obligation is typically triggered by three underlying actions: rectification of inaccurate data (associated with the Article 16 right), erasure of data (associated with the Article 17 right), and restriction of processing (associated with the Article 18 right). Each triggering right has its own conditions that must be satisfied before the notification duty applies.
Definition of recipient
A recipient is generally the natural or legal person, public authority, agency, or other body to which personal data are disclosed, which may include third parties and, in many cases, processors. The precise treatment of processors versus other recipients can depend on the arrangement and should be assessed in context.
Impossibility or disproportionate effort exception
The duty to communicate is qualified: it does not apply where notification proves impossible or would involve disproportionate effort. Whether this threshold is met is fact-specific and subject to assessment rather than a fixed rule.
Duty to inform the data subject about recipients
On request from the data subject, the controller must generally inform them about the recipients to whom the data have been notified. This supports transparency and enables the individual to understand the downstream effect of exercising their rights.
Relationship to accountability
Discharging and documenting this obligation typically forms part of the controller's broader accountability posture, evidencing that downstream corrections or deletions have been propagated where required.

Common questions

Answers to the questions practitioners most commonly ask about Notification Obligation Regarding Rectification or Erasure.

Does the notification obligation require the controller to contact each recipient in every case, without exception?
No. Under Article 19 GDPR, the controller must communicate a rectification, erasure, or restriction of processing to each recipient to whom the personal data has been disclosed, but this duty is qualified: it does not apply where doing so proves impossible or would involve disproportionate effort. Whether an exception applies is a case-by-case assessment, and the controller should be able to justify any reliance on impossibility or disproportionate effort. The obligation is therefore not absolute.
Is this obligation the same as the data subject's right to information about recipients, so that satisfying one automatically satisfies the other?
Not exactly. Article 19 contains two distinct elements that should not be conflated. The first is the controller's own duty to notify recipients of a rectification, erasure, or restriction. The second is a separate, request-based element: the controller must inform the data subject about those recipients if the data subject asks. Notifying recipients does not by itself discharge the duty to inform the data subject on request, and vice versa. They are related but separate obligations within the same provision.
Who counts as a recipient that we need to notify?
A recipient is generally understood by reference to the GDPR's definition of recipient, meaning a party to whom the personal data has been disclosed. In practice, controllers typically identify recipients from their records of disclosures, which is one reason maintaining accurate processing and disclosure records is helpful. Where the scope of who qualifies as a recipient is uncertain in a particular arrangement, the position should be assessed against the definitions and current regulatory guidance rather than assumed.
How should we operationalize this obligation so notifications actually happen after a rectification or erasure?
Controllers commonly build the notification step into their data subject rights and data management workflows, so that when a rectification, erasure, or restriction is actioned, a downstream process identifies affected recipients and triggers the communication. Keeping records of disclosures and of the notifications sent typically supports both compliance and the ability to demonstrate accountability. The specific design should be tailored to the organization's systems and risk profile.
What should we do if notifying a recipient appears impossible or disproportionately burdensome?
The provision allows for exceptions where notification proves impossible or involves disproportionate effort. In such cases, a controller should typically document the reasoning behind that conclusion, including the factors making notification impossible or disproportionate, so the position can be justified if questioned. Because reliance on these exceptions is context-dependent and subject to assessment, controllers should avoid treating them as a blanket exemption.
How does this obligation interact with a data subject's request to know the recipients?
Alongside notifying recipients, the controller must inform the data subject about those recipients if the data subject requests it. Practically, organizations often prepare to respond to such requests as part of their broader rights-handling procedures, drawing on the same disclosure records used for the notification step. Handling the request-based element should be aligned with the organization's general approach to responding to data subject requests.

Common misconceptions

The controller can decide freely whether to notify recipients, since the exception for disproportionate effort is broad.
The exception is a qualified limitation, not a general discretion. Notification is the default expectation, and reliance on impossibility or disproportionate effort is subject to assessment and generally should be justified and documented rather than assumed.
This notification obligation is the same thing as the personal data breach notification duty owed to the supervisory authority or data subjects.
They are distinct. The obligation to communicate rectification, erasure, or restriction to recipients concerns propagating a data subject's exercised rights to downstream parties, and should not be conflated with breach notification duties, which arise from a security incident and follow their own separate requirements.
Once the controller corrects or deletes data in its own systems, its duties are complete.
In addition to actioning the right internally, the controller must generally communicate the change to relevant recipients unless the qualified exception applies, and must inform the data subject about those recipients on request. Internal action alone may not satisfy the full obligation.

Best practices

Maintain an accurate and current record of recipients to whom personal data have been disclosed, so that rectification, erasure, or restriction can be communicated to the correct parties when required.
Build workflows that automatically trigger downstream notification when a rectification, erasure, or restriction request is actioned, rather than treating notification as a manual afterthought.
Where relying on the impossibility or disproportionate effort exception, assess and document the specific reasoning on a case-by-case basis rather than applying it as a blanket policy.
Establish a clear process to inform data subjects, on request, about the recipients that were notified, and confirm timelines for responding to such requests.
Clarify in processor and third-party arrangements how corrections, deletions, and restrictions will be propagated, and verify these terms against the relevant contractual obligations.
Verify the applicable article references, and any UK GDPR or national implementing variations, against the current official text before relying on this obligation in a compliance program.