Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Data Subject Rights

Right to Restriction of Processing

Also known as: Right to Restrict Processing, Restriction of Processing
Simply put

The right to restriction of processing lets an individual ask an organisation to limit how it uses their personal data, rather than deleting it, in certain circumstances. When this right applies, the organisation may generally continue to store the data but is limited in what else it can do with it. It typically arises in situations such as when the person disputes whether their data is accurate or objects to certain processing.

Formal definition

A data subject right, provided under Article 18 of the EU GDPR and the UK GDPR, entitling an individual to obtain from the controller the restriction of processing of their personal data where one of the specified grounds applies. Recognised grounds generally include where the data subject contests the accuracy of the personal data, where the processing is unlawful but the data subject opposes erasure and requests restriction instead, and related circumstances set out in the applicable text. Restriction is defined as the marking of stored personal data with the aim of limiting future processing; it is distinct from erasure in that the data is retained but its further use is constrained. The right is exercisable against the controller (not the processor directly) and applies within the territorial and material scope of the EU GDPR and the UK GDPR respectively; note that these are separate legal instruments applying to different jurisdictions since the UK's departure from the EU. This entry does not address the full list of qualifying conditions, applicable exemptions, or procedural time limits, which vary and should be verified against the current authoritative text and regulator guidance.

Why it matters

The right to restriction of processing gives individuals a middle path between leaving their data fully in use and having it erased. When a person disputes the accuracy of their data or contests the lawfulness of its processing, restriction allows the disagreement to be resolved without the data being deleted in the meantime or continuing to be used freely. This protects the individual from potential harm caused by ongoing processing while a dispute is unresolved, and it preserves the data for cases where retention is preferable to erasure — for example, where the individual wants the data kept to support a legal claim rather than removed.

For organisations, honouring this right requires operational readiness that goes beyond simply acknowledging a request. Because restriction generally permits continued storage but limits other processing, controllers must be able to mark affected records and technically prevent further use across their systems. Failing to do so can mean processing data unlawfully in the very circumstances where an individual has asked for restraint, exposing the organisation to complaints and regulatory scrutiny under the applicable GDPR regime.

The right also illustrates why data subject rights cannot be treated as interchangeable. Restriction is distinct from erasure: the data survives but its use is constrained. Treating a restriction request as a deletion request, or vice versa, can defeat the individual's intended outcome and create compliance failures. Organisations should verify the specific qualifying grounds, exemptions, and time limits against the current authoritative text and regulator guidance, as these are not addressed in full here.

Who it's relevant to

Data protection officers and privacy teams
Those responsible for handling data subject requests must be able to recognise a restriction request, distinguish it from an erasure request, and confirm whether a qualifying ground applies. They should ensure the organisation can respond within applicable time limits and document the basis for its decision, verifying the specific requirements against the relevant EU or UK GDPR text and regulator guidance.
Controllers processing personal data
Because this right is exercisable against the controller rather than the processor directly, organisations acting as controllers bear primary responsibility for implementing restriction. They need processes to mark affected records and technically limit further processing across their systems while continuing to store the data, and to identify which of the EU GDPR or UK GDPR applies to a given activity.
Information security and IT teams
Since restriction is defined as the marking of stored personal data to limit its future processing, technical teams must be able to flag records and enforce constraints on how that data is used without deleting it. This requires system capabilities that separate storage from active processing, which may not be straightforward in environments not designed with this distinction in mind.
Individuals exercising their rights
Data subjects who dispute the accuracy of their data or contest the lawfulness of its processing may use this right to limit an organisation's use of their information without having it erased. This can be valuable where the individual prefers the data to be retained — for instance while a dispute is resolved — rather than deleted outright.

Inside Right to Restriction of Processing

Definition and legal basis
The right to restriction of processing is a data subject right under the EU General Data Protection Regulation (GDPR), which is binding law within the EU/EEA. It permits an individual, in certain circumstances, to require that a controller limit its processing of their personal data rather than erase it. Broadly analogous rights may exist under other frameworks such as the UK GDPR, but scope and wording differ across jurisdictions; readers should verify against the applicable text.
Grounds for invoking restriction
The GDPR generally makes restriction available in specific situations, such as where the data subject contests the accuracy of the data (for a period allowing verification), where processing is unlawful but the individual prefers restriction over erasure, where the controller no longer needs the data but the individual needs it for legal claims, or where a related objection to processing is pending. The precise triggering conditions should be confirmed against the current regulation, as this list is illustrative rather than exhaustive.
Effect of restriction on processing
When processing is restricted, the data may generally continue to be stored, but other processing operations are typically permitted only with the data subject's consent, for the establishment or defense of legal claims, for the protection of another person's rights, or for reasons of important public interest. In practice this often means marking or segregating the affected records so that active use is suspended while retention continues.
Notification obligations
A controller is generally expected to inform the data subject before any restriction is lifted, and in many cases to communicate the restriction to recipients to whom the data was disclosed, unless doing so proves impossible or involves disproportionate effort. The exact wording of these obligations should be checked against the current regulatory text.
Relationship to other data subject rights
Restriction is a distinct right and is not the same as erasure (the so-called right to be forgotten), rectification, or objection, although it frequently interacts with them—for example, being invoked temporarily while accuracy is verified or an objection is assessed. It suspends rather than eliminates processing.

Common questions

Answers to the questions practitioners most commonly ask about Right to Restriction of Processing.

Does the right to restriction of processing mean the data must be deleted?
No. Restriction and erasure are distinct rights. Restriction generally requires the controller to limit how personal data is processed while retaining it, rather than removing it. In most cases restricted data may continue to be stored, and the controller may resume other processing only in defined circumstances (such as the data subject's consent or the establishment or defence of legal claims). Erasure, by contrast, involves the actual removal of the data. Because the two rights serve different purposes and are triggered by different conditions, they should not be treated as interchangeable. Verify the specific conditions and exceptions against the current official text of the applicable regulation.
Is the right to restriction of processing a universal legal requirement that applies the same way everywhere?
No. This right is a feature of specific data protection regimes and its precise scope and conditions depend on the governing law and jurisdiction. It is prominently associated with the EU's GDPR and the equivalent UK regime, but requirements differ across the EU, the United Kingdom, the United States, and other jurisdictions, and some frameworks do not provide an equivalent right at all. Presenting one region's formulation as globally applicable would be inaccurate. Readers should confirm which law governs a given processing activity and consult the latest authoritative source, as regulations are periodically amended.
When a restriction request is granted, how should the data be handled operationally?
Broadly, restriction means the data should be retained but generally not processed further beyond storage, except in the limited situations permitted by the applicable law. In practice this often involves flagging or marking the affected records so that systems and personnel recognise the restricted status, and in some cases temporarily moving the data to a separate system or otherwise making it inaccessible for ordinary processing. The specific technical approach is not prescribed in detail and depends on the organisation's systems and risk posture. Application to particular circumstances requires professional judgment and should be checked against the governing regulatory text.
Do we need to notify anyone before lifting a restriction?
In many data protection regimes that recognise this right, the controller is generally expected to inform the data subject before a restriction is lifted. Organisations typically build this notification step into their request-handling procedures so that a resumption of processing is not treated as a purely internal decision. The exact wording and timing obligations vary by jurisdiction and should be confirmed against the current official text rather than assumed. This entry describes the general expectation and does not constitute advice on a specific case.
Does restricting processing affect our obligations toward third parties or recipients of the data?
It may. Under regimes such as the GDPR, controllers are generally expected to communicate a restriction to recipients to whom the personal data was disclosed, unless doing so proves impossible or involves disproportionate effort, and to inform the data subject about those recipients on request. Practically, this means organisations should maintain records of onward disclosures so that restrictions can be propagated. The precise threshold for 'disproportionate effort' is fact-specific and its interpretation continues to develop, so readers should verify the applicable obligations against the latest authoritative source.
How does restriction fit alongside other data subject rights when handling a request?
Restriction is one of several distinct rights and can interact with others such as access, rectification, objection, and erasure; in some situations restriction functions as an interim measure while another matter (for example the accuracy of the data or a pending objection) is resolved. Organisations generally treat it as a separate workflow with its own triggering conditions, exceptions, and record-keeping, rather than folding it into a single generic request process. Because the interplay between rights is fact-specific and varies by jurisdiction, the correct handling in a given case requires professional judgment and reference to the governing regulation.

Common misconceptions

Restriction means the organization must delete the data.
Restriction generally requires the controller to limit or suspend most processing while continuing to store the data; it is not equivalent to erasure. Deletion is a separate right with its own conditions. Retaining restricted data in a segregated or marked state is typically consistent with, and often required by, the restriction mechanism.
A valid restriction request means all processing must stop entirely and immediately.
Storage of the data generally continues, and the GDPR permits certain limited processing during a restriction—for instance with the individual's consent, for legal claims, to protect another person's rights, or for important public interest reasons. The obligation is to suspend other active use, not to cease every operation without exception.
The right to restriction applies universally across all jurisdictions.
The right as described here derives from the EU GDPR and applies within its territorial scope, which can extend extraterritorially to organizations processing EU data subjects' data in defined circumstances. Comparable rights under the UK GDPR or other regimes may differ in conditions and effect, and some jurisdictions may not provide an equivalent right at all. Application depends on the governing law.

Best practices

Establish a documented procedure to identify, log, and triage restriction requests promptly, and confirm which legal regime (e.g., EU GDPR, UK GDPR) applies before determining obligations.
Implement technical means to mark, flag, or segregate restricted records so that storage continues while other processing is effectively suspended, and ensure downstream systems honor the restriction.
Verify whether the request meets one of the recognized grounds for restriction under the applicable regulation, and record the assessment and rationale for each decision.
Notify recipients to whom the data was disclosed of the restriction where required, and inform the data subject before any restriction is lifted, documenting these communications.
Distinguish restriction from adjacent rights such as erasure, rectification, and objection in staff training and internal workflows to avoid handling one as another.
Periodically review procedures against the current authoritative regulatory text and seek professional judgment for fact-specific cases, as obligations are context-dependent and subject to amendment.
Promotional banner for the Penetration Report Template Kit