Restriction of Processing
Restriction of processing is a data subject right that lets an individual limit how an organisation uses their personal data without requiring it to be deleted. When processing is restricted, the organisation may generally continue to store the data but is not permitted to otherwise use it, subject to certain exceptions. In practice this is often a temporary measure while an issue, such as a dispute about the data's accuracy, is being resolved.
Under the GDPR, the right to restriction of processing entitles a data subject to obtain from the controller a limitation on the processing of their personal data in defined circumstances, which per the evidence include where the accuracy of the data is contested and where the data is required for a legal claim. Where processing is restricted, the controller is generally permitted to store the personal data but not otherwise use it, absent an applicable exception. In practice, restriction is typically implemented as a temporary limitation, for example by flagging or isolating affected records; a request may be made verbally or in writing. The specific grounds and exceptions are set out in the Regulation text (Article 18, per Sources 2, 4 and 5), and readers should verify the current official wording, noting that the position may vary under the UK GDPR and national implementing law.
Why it matters
Restriction of processing gives individuals a middle path between allowing full use of their data and demanding its erasure. It matters because disputes about personal data are rarely resolved instantly. When an individual contests the accuracy of their data, or needs the data preserved for a legal claim, restriction allows the record to be effectively frozen while the underlying issue is worked out, rather than forcing an all-or-nothing outcome. This protects the individual's interests without destroying information that may still be needed.
For organisations, honouring restriction requests is a compliance obligation and a source of operational risk if mishandled. Because restricted data must generally continue to be stored but not otherwise used, controllers need reliable ways to identify, flag, and isolate affected records so that downstream systems and staff do not process them by default. A request can be made verbally or in writing, which means the trigger for restriction may arrive through any channel, not only a formal web form. Failing to act on such a request, or continuing to use restricted data outside the permitted exceptions, can expose an organisation to complaints and regulatory scrutiny.
The precise grounds for restriction, the exceptions that permit continued use, and how the right interacts with other data subject rights are set out in the Regulation text and associated regulator guidance. Because the position may vary under the UK GDPR and national implementing law, and because guidance evolves, organisations should treat restriction as a right whose operational detail must be verified against the current official sources rather than assumed.
Who it's relevant to
Inside Restriction of Processing
Common questions
Answers to the questions practitioners most commonly ask about Restriction of Processing.