Skip to main content
Category: Impact Assessments & Documentation

Preventing Data Subjects From Exercising a Right

Also known as: Preventing data subjects from exercising a right or using a service or contract
Simply put

This is one of the factors regulators use to decide whether a Data Protection Impact Assessment (DPIA) is needed before a processing activity begins. It refers to situations where the processing itself has the effect of blocking or limiting people from exercising a right they hold, or from accessing a service or entering into a contract. Where processing carries this feature, it is treated as an indicator of potential high risk that should be assessed rather than a guarantee that the activity is unlawful.

Formal definition

"Preventing data subjects from exercising a right or using a service or a contract" is one of the criteria identified in guidance (referenced as WP29 guidelines WP248) for determining when processing is likely to result in a high risk to individuals' rights and freedoms and therefore requires a DPIA. According to regulator guidance, this criterion is engaged where the processing in itself prevents data subjects from exercising a right or from accessing a service or a contract; the Irish Data Protection Commission links this scenario to Article 22 (automated individual decision-making) and Recital 91. Practitioners generally treat this as a screening indicator to be weighed alongside the other WP248 factors rather than a standalone determinant, and the presence of one or more such factors typically signals that a DPIA should be conducted. Readers should verify the current WP248 criteria and any national regulator lists against the applicable official text, as regulator guidance and supervisory authority lists can vary.

Why it matters

This criterion matters because it helps organisations identify, at the screening stage, processing activities that could have a significant practical impact on individuals before those activities begin. Where processing itself has the effect of blocking or limiting a person from exercising a right they hold, or from accessing a service or entering into a contract, regulators treat this as an indicator of potential high risk. Recognising this feature early allows an organisation to conduct a Data Protection Impact Assessment (DPIA) and address risks proactively rather than after harm has occurred.

The practical stakes are heightened where the processing is linked to automated individual decision-making. The Irish Data Protection Commission connects this scenario to Article 22 and Recital 91, which concern decisions producing legal or similarly significant effects on individuals. Where an automated process determines whether someone can access a service or conclude a contract, the consequences for the individual can be substantial, which is why this factor is flagged for careful assessment.

It is important to keep the boundaries of this criterion in mind. Its presence signals that a DPIA should generally be considered, not that the processing is unlawful or that a right has necessarily been infringed. It is one screening indicator among the WP248 factors, and the presence of one or more such factors typically points towards conducting a DPIA. Because supervisory authority lists and guidance can vary between member states and under the UK GDPR, readers should verify the current criteria against the applicable official text.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads use this criterion as part of the DPIA screening process to decide whether a full assessment is required before processing begins. They are typically responsible for documenting how the WP248 factors were considered and for verifying the applicable supervisory authority's current list, given that guidance and national lists can vary.
Compliance and Legal Teams
Compliance and legal professionals assess whether a processing activity has the effect of preventing individuals from exercising a right or accessing a service or contract, and how that interacts with related obligations such as those under Article 22 and Recital 91 concerning automated individual decision-making. They advise on the risk position, which is context dependent, rather than treating the factor as a determination of unlawfulness.
Product and Engineering Teams
Teams designing systems that gate access to services, contracts, or user rights need to recognise when their processing may engage this screening indicator, particularly where automated decisions are involved. Early identification allows them to flag activities for a DPIA and to build in appropriate safeguards and assessment before deployment.
Controllers Deploying Automated Decision-Making
Controllers operating processes that automatically determine eligibility for a service or the ability to enter a contract are especially likely to encounter this factor, given its link to Article 22 and Recital 91. They should generally treat its presence as a prompt to assess high-risk potential rather than assume the processing is either compliant or prohibited.

Inside Preventing Data Subjects From Exercising a Right

Data Subject Rights
The rights conferred on individuals under the GDPR, which generally include the right of access, rectification, erasure, restriction of processing, data portability, objection, and rights related to automated decision-making. Preventing a data subject from exercising any of these can constitute a compliance failure. The specific rights available and their conditions vary by article and are subject to exemptions and derogations.
Facilitation Obligation
Controllers are generally expected to facilitate the exercise of data subject rights and cannot make it unreasonably difficult for individuals to submit or pursue a request. Practices that obstruct, delay without lawful basis, or discourage requests may amount to preventing the exercise of a right. The precise scope of what constitutes obstruction is assessed on the facts.
Barriers to Exercise
Mechanisms or practices that impede a data subject, such as excessive identity verification demands, unjustified fees, opaque or non-functional request channels, misleading information about available rights, or failure to respond within the applicable timeframe. Whether a given barrier is lawful depends on context and any applicable exemption.
Permissible Limitations
Not every restriction on a right is unlawful. Rights may be qualified by conditions, exemptions, and member state derogations, and controllers may refuse manifestly unfounded or excessive requests in defined circumstances. Distinguishing a lawful limitation from unlawful prevention requires a case-by-case assessment against the relevant provisions.
Response Timeframes
Controllers are generally required to respond to rights requests within a defined period, with a possible extension in certain complex cases. Failing to respond, or responding outside the applicable timeframe without justification, can be treated as preventing exercise of the right. Verify the exact periods against the current official text.

Common questions

Answers to the questions practitioners most commonly ask about Preventing Data Subjects From Exercising a Right.

Does a data subject right mean an organisation must comply with every request without exception?
No. Data subject rights are not, in most cases, absolute. The rights under the GDPR are typically subject to conditions, exemptions, and balancing tests, and certain requests may be refused or limited where a recognised ground applies. However, this is distinct from actively preventing or obstructing a data subject from exercising a right, which is treated differently. An organisation should assess each request against the applicable legal grounds rather than assume either automatic compliance or a general power to decline. The precise scope of exemptions can also vary under national implementing law and member state derogations, so the position should be verified against the current official text and relevant guidance.
Is refusing or restricting a request the same as preventing a data subject from exercising a right?
Not necessarily. Lawfully declining a request on a recognised basis, or applying an available exemption, is generally different from preventing, deterring, or obstructing the exercise of a right itself. The distinction typically turns on whether the organisation is engaging with the request and applying legitimate grounds transparently, versus creating barriers, discouragement, or non-response that undermine the ability to exercise the right at all. Because this boundary can be fact-sensitive and interpreted differently by different regulators, organisations should document their reasoning and treat the line between lawful limitation and improper obstruction as a matter for case-by-case assessment.
How should an organisation handle a request where it believes an exemption or ground for refusal may apply?
In most cases the organisation should still acknowledge and engage with the request rather than ignore it. Good practice generally involves assessing whether a recognised exemption or ground applies, documenting the assessment, and communicating the outcome and reasoning to the data subject where required. Providing a clear explanation, and where relevant information about avenues to challenge the decision, helps distinguish a lawful limitation from obstruction. Because the availability and scope of exemptions can depend on national implementing law, the specific requirements should be checked against the applicable legal framework.
What practical steps help avoid inadvertently obstructing the exercise of a right?
Organisations typically reduce this risk by making request channels accessible, responding within applicable timeframes, avoiding unnecessary friction or excessive identity verification demands, and not imposing conditions that discourage legitimate requests. Staff handling requests should generally be trained to recognise a rights request even when it is not framed in formal terms. Where a request is limited or declined, transparency about the reasons is usually important. What counts as an acceptable process can be interpreted differently by regulators, so organisations should align their approach with current guidance and monitor for updates.
How can an organisation demonstrate that it did not prevent a data subject from exercising a right?
Demonstrating this generally depends on maintaining records of how requests are received, assessed, and answered, including the grounds relied upon for any limitation and the communications sent to the data subject. Documented policies, response timelines, and evidence of engagement typically support an accountability position. Because expectations around evidence and record-keeping can vary and evolve, organisations should treat documentation as an ongoing practice and verify the specific accountability requirements against the current official text and applicable regulatory guidance.
How should this issue be addressed when a processor, rather than the controller, receives or handles a request?
Responsibility for responding to data subject rights generally rests with the controller, while a processor typically acts on the controller's documented instructions and assists the controller in fulfilling requests. The allocation of these responsibilities is usually set out in the data processing arrangement between the parties. To avoid a situation where a request is effectively obstructed through unclear handling, organisations often define escalation and forwarding procedures so that requests reaching a processor are routed to the controller promptly. The precise obligations should be confirmed against the relevant contractual terms and applicable legal provisions.

Common misconceptions

Any refusal to comply with a data subject request unlawfully prevents them from exercising a right.
Rights under the GDPR are not absolute. Certain requests may be lawfully refused or limited where an exemption, derogation, or condition applies, or where a request is manifestly unfounded or excessive. Prevention of a right generally refers to obstructing lawful exercise, not to legitimately applying a permitted limitation, and each case should be assessed on its facts.
Requiring identity verification always amounts to obstructing a data subject.
Controllers may generally take reasonable steps to confirm the identity of a requester, particularly to avoid disclosing data to the wrong person. The concern arises where verification demands are excessive or disproportionate and function as a barrier. The line between reasonable verification and obstruction is a matter of assessment.
Prevention of a right only occurs through an outright, explicit denial.
Prevention can arise through indirect means as well, such as unjustified delay, non-functional channels, misleading information, or unreasonable fees, even absent a formal refusal. The focus is on the practical effect on the data subject's ability to exercise the right.

Best practices

Establish clear, accessible, and functioning channels through which data subjects can submit rights requests, and communicate these transparently.
Limit identity verification to what is reasonable and proportionate for the request, avoiding demands that operate as barriers to exercise.
Track and meet the applicable response timeframes, documenting any lawful basis for an extension or for refusing a manifestly unfounded or excessive request.
Where a right is limited or refused, record the specific exemption, condition, or derogation relied upon and assess each request on its individual facts rather than applying blanket policies.
Train staff handling requests to distinguish lawful limitations from practices that obstruct, delay, or discourage the exercise of a right.
Periodically review request-handling processes to identify and remove unjustified fees, unclear information, or friction that could impede data subjects, and verify approaches against the current official text and applicable guidance.