Preventing Data Subjects From Exercising a Right
This is one of the factors regulators use to decide whether a Data Protection Impact Assessment (DPIA) is needed before a processing activity begins. It refers to situations where the processing itself has the effect of blocking or limiting people from exercising a right they hold, or from accessing a service or entering into a contract. Where processing carries this feature, it is treated as an indicator of potential high risk that should be assessed rather than a guarantee that the activity is unlawful.
"Preventing data subjects from exercising a right or using a service or a contract" is one of the criteria identified in guidance (referenced as WP29 guidelines WP248) for determining when processing is likely to result in a high risk to individuals' rights and freedoms and therefore requires a DPIA. According to regulator guidance, this criterion is engaged where the processing in itself prevents data subjects from exercising a right or from accessing a service or a contract; the Irish Data Protection Commission links this scenario to Article 22 (automated individual decision-making) and Recital 91. Practitioners generally treat this as a screening indicator to be weighed alongside the other WP248 factors rather than a standalone determinant, and the presence of one or more such factors typically signals that a DPIA should be conducted. Readers should verify the current WP248 criteria and any national regulator lists against the applicable official text, as regulator guidance and supervisory authority lists can vary.
Why it matters
This criterion matters because it helps organisations identify, at the screening stage, processing activities that could have a significant practical impact on individuals before those activities begin. Where processing itself has the effect of blocking or limiting a person from exercising a right they hold, or from accessing a service or entering into a contract, regulators treat this as an indicator of potential high risk. Recognising this feature early allows an organisation to conduct a Data Protection Impact Assessment (DPIA) and address risks proactively rather than after harm has occurred.
The practical stakes are heightened where the processing is linked to automated individual decision-making. The Irish Data Protection Commission connects this scenario to Article 22 and Recital 91, which concern decisions producing legal or similarly significant effects on individuals. Where an automated process determines whether someone can access a service or conclude a contract, the consequences for the individual can be substantial, which is why this factor is flagged for careful assessment.
It is important to keep the boundaries of this criterion in mind. Its presence signals that a DPIA should generally be considered, not that the processing is unlawful or that a right has necessarily been infringed. It is one screening indicator among the WP248 factors, and the presence of one or more such factors typically points towards conducting a DPIA. Because supervisory authority lists and guidance can vary between member states and under the UK GDPR, readers should verify the current criteria against the applicable official text.
Who it's relevant to
Inside Preventing Data Subjects From Exercising a Right
Common questions
Answers to the questions practitioners most commonly ask about Preventing Data Subjects From Exercising a Right.