Skip to main content
Category: Data Subject Rights

Restriction of Processing

Also known as: Right to restriction of processing, Right to restrict processing
Simply put

Restriction of processing is a data subject right that lets an individual limit how an organisation uses their personal data without requiring it to be deleted. When processing is restricted, the organisation may generally continue to store the data but is not permitted to otherwise use it, subject to certain exceptions. In practice this is often a temporary measure while an issue, such as a dispute about the data's accuracy, is being resolved.

Formal definition

Under the GDPR, the right to restriction of processing entitles a data subject to obtain from the controller a limitation on the processing of their personal data in defined circumstances, which per the evidence include where the accuracy of the data is contested and where the data is required for a legal claim. Where processing is restricted, the controller is generally permitted to store the personal data but not otherwise use it, absent an applicable exception. In practice, restriction is typically implemented as a temporary limitation, for example by flagging or isolating affected records; a request may be made verbally or in writing. The specific grounds and exceptions are set out in the Regulation text (Article 18, per Sources 2, 4 and 5), and readers should verify the current official wording, noting that the position may vary under the UK GDPR and national implementing law.

Why it matters

Restriction of processing gives individuals a middle path between allowing full use of their data and demanding its erasure. It matters because disputes about personal data are rarely resolved instantly. When an individual contests the accuracy of their data, or needs the data preserved for a legal claim, restriction allows the record to be effectively frozen while the underlying issue is worked out, rather than forcing an all-or-nothing outcome. This protects the individual's interests without destroying information that may still be needed.

For organisations, honouring restriction requests is a compliance obligation and a source of operational risk if mishandled. Because restricted data must generally continue to be stored but not otherwise used, controllers need reliable ways to identify, flag, and isolate affected records so that downstream systems and staff do not process them by default. A request can be made verbally or in writing, which means the trigger for restriction may arrive through any channel, not only a formal web form. Failing to act on such a request, or continuing to use restricted data outside the permitted exceptions, can expose an organisation to complaints and regulatory scrutiny.

The precise grounds for restriction, the exceptions that permit continued use, and how the right interacts with other data subject rights are set out in the Regulation text and associated regulator guidance. Because the position may vary under the UK GDPR and national implementing law, and because guidance evolves, organisations should treat restriction as a right whose operational detail must be verified against the current official sources rather than assumed.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads are responsible for ensuring the organisation can recognise and act on restriction requests, including those received verbally, and for confirming that restricted data is stored but not otherwise used except where an exception applies. They should map the defined grounds and exceptions against the current official text and account for possible divergence under the UK GDPR and national law.
Engineers and System Owners
Because restriction is typically implemented by flagging or isolating records, engineers and system owners need mechanisms to mark affected data so downstream systems and processes do not use it by default while it remains stored. This often needs to work as a temporary state that can be applied and later lifted once the underlying issue, such as an accuracy dispute, is resolved.
Compliance and Legal Teams
Legal and compliance teams handle situations where the accuracy of data is contested or where data is required for a legal claim, both of which can trigger restriction. They should confirm which specific grounds and exceptions apply in a given case against the current Regulation text and relevant national implementing law rather than relying on a general summary.
Individuals Exercising Their Rights
Data subjects can use restriction to limit how an organisation uses their personal data without requiring deletion, for example while a dispute is being resolved. A request can be made verbally or in writing, and in most cases the organisation may continue to store the data while being restricted from otherwise using it, subject to exceptions.

Inside Restriction of Processing

Right to Restriction
A data subject right under the GDPR (generally associated with Article 18) allowing individuals to require a controller to limit the processing of their personal data in specified circumstances, rather than having it erased or freely processed.
Triggering Grounds
Restriction typically applies where the accuracy of the data is contested (for a period allowing verification), where processing is unlawful but the individual opposes erasure, where the controller no longer needs the data but the individual requires it for legal claims, or where an objection to processing is pending verification. The precise conditions should be verified against the current official text.
Effect of Restriction
Where processing is restricted, the personal data may generally be stored but not otherwise processed, save with the data subject's consent, for the establishment, exercise or defence of legal claims, for the protection of another person's rights, or for reasons of important public interest, subject to assessment against the applicable provisions.
Marking and Technical Implementation
Controllers are generally expected to mark restricted data so that its restricted status is clear and to implement technical and organisational measures ensuring the data is not further processed while the restriction is in place.
Notification of Lifting
Where a restriction is to be lifted, the controller is typically required to inform the data subject before the restriction ceases to apply.
Downstream Notification Obligation
A controller that has disclosed the personal data to recipients is generally required to communicate any restriction to each recipient, unless this proves impossible or involves disproportionate effort, and to inform the data subject about those recipients if requested.
Scope Boundaries
The right concerns personal data of individuals and does not extend to anonymous data or, generally, to the data of deceased persons or legal entities. Member state derogations and national implementing law may vary aspects of the position, and the UK GDPR provides a broadly comparable but separate framework.

Common questions

Answers to the questions practitioners most commonly ask about Restriction of Processing.

Is restriction of processing the same as deleting or erasing the data?
No. Restriction of processing does not require erasure. It is a measure that limits how personal data may be used while continuing to store it. The data generally remains held but is effectively 'frozen' for most processing purposes. Erasure under the right to be forgotten is a separate right with its own conditions, and restriction is often used precisely as an alternative to deletion, for example where the data subject needs the data retained rather than removed. The two should not be conflated.
Does a restriction request mean the controller must stop all processing entirely?
Not entirely. Restriction limits processing but does not prohibit every activity. Storage of the restricted data generally continues, and further processing may still be permitted in defined circumstances, such as with the data subject's consent, for the establishment, exercise, or defence of legal claims, for the protection of another person's rights, or for reasons of important public interest. The precise permitted activities depend on the applicable provisions and the context, so this should be assessed case by case rather than treated as a blanket freeze.
How can restriction be implemented technically while still retaining the data?
Approaches typically include temporarily moving the data to a separate system, making it inaccessible to operational users, or applying flags or markers that prevent further processing. Guidance commonly refers to methods that make the restriction effective and auditable. The suitable method depends on the systems involved and the nature of the data, so controllers generally document the technical measures chosen and verify they actually prevent the restricted processing.
What should a controller do before lifting a restriction?
In most cases the controller is expected to inform the data subject before the restriction is lifted. Controllers should therefore have a process to record why a restriction was applied, track its status, and notify the individual ahead of resuming processing. The reader should verify the exact notification obligations against the current official text, as the wording governing when and how to inform the data subject is specific.
How does restriction interact with recipients the data was already shared with?
Where feasible, a controller that has disclosed the personal data to recipients may be expected to communicate the restriction to each recipient, unless doing so proves impossible or involves disproportionate effort. Controllers typically maintain records of disclosures to make such communication practicable. The precise scope of this obligation should be checked against the applicable provisions, and what counts as disproportionate effort will be a matter of assessment in each case.
How should teams handle a restriction that is only temporary pending verification?
Restriction is often invoked while a related matter is being resolved, such as verifying the accuracy of contested data or assessing a competing request. In these situations the restriction generally applies for the period needed to complete that assessment. It is good practice to log the trigger, the expected duration, the review point, and the outcome, so the restriction is not left in place indefinitely or lifted prematurely without the required notification. Specific timing and grounds should be confirmed against the current official text.

Common misconceptions

Restriction of processing is the same as erasure or the 'right to be forgotten'.
They are distinct rights. Restriction generally allows the data to continue to be stored while limiting other processing, whereas erasure concerns deletion of the data. Restriction is often a temporary or interim measure, for example while accuracy is verified or an objection is assessed.
Once processing is restricted, the controller can do nothing at all with the data.
Restricted data may generally still be stored, and further processing may be permissible in limited circumstances, such as with the data subject's consent, for the establishment, exercise or defence of legal claims, to protect another person's rights, or for reasons of important public interest, subject to assessment.
The right to restriction is unconditional and can be invoked in any situation.
Restriction typically applies only where specific grounds are met, such as contested accuracy, unlawful processing where the individual opposes erasure, the controller no longer needing the data but the individual requiring it for legal claims, or a pending objection. Whether a request qualifies depends on the facts and the applicable provisions.

Best practices

Establish an intake process that assesses each restriction request against the applicable grounds rather than treating restriction, erasure, and objection as interchangeable requests.
Implement technical and organisational measures to mark restricted personal data and prevent further processing while the restriction is in place, for example through flags, access controls, or moving data to a separately controlled store.
Maintain a record of restriction requests, the grounds relied on, the decision reached, and the date, so the controller can demonstrate accountability.
Where the data has been disclosed to recipients, notify each recipient of the restriction unless doing so is impossible or involves disproportionate effort, and be prepared to inform the data subject about those recipients on request.
Inform the data subject before any restriction is lifted, and document the reason and timing of lifting.
Verify the specific conditions, article references, and any national derogations against the current official text of the GDPR or UK GDPR, as the exact scope and implementing rules can vary.