What is the "Right to Object" under the GDPR?
The GDPR's Right to Object allows individuals to stop certain uses of their personal data, particularly for direct marketing. Learn when the right applies, how organizations must respond, when objections may be refused, and the role of Legitimate Interests Assessments (LIAs).
Key points: (1) The GDPR gives individuals the right to object to the processing of their personal data in certain circumstances. (2) Individuals have an absolute right to object to the use of their personal data for direct marketing purposes, including related profiling. (3) In other cases, organizations may continue processing if they can demonstrate compelling legitimate grounds that override the individual's rights and interests. (4) Organizations must inform individuals of their right to object, and this information must be presented clearly and separately from other privacy information where required by the GDPR. (5) Individuals may exercise the right to object verbally or in writing, and organizations should have procedures to recognize and appropriately handle these requests. (6) Controllers must respond without undue delay and, in most cases, within one month of receiving the request.
What Is the Right to Object and Why Is It Important?
The right to object is one of the fundamental rights granted to individuals under the GDPR. It allows people to ask an organization to stop processing their personal data in certain circumstances. Unlike some other GDPR rights, however, the right to object does not apply to all types of processing. Whether it is available depends on the purpose of the processing and the legal basis the organization relies on.

The Article 21 of the GDPR provides different levels of protection depending on why the data is being processed:
- Direct marketing: Individuals have an absolute right to object to the processing of their personal data for direct marketing purposes, including profiling related to direct marketing. Once an objection is made, the organization must stop using the data for those purposes.
- Legitimate interests or public interest tasks: Individuals may object when processing is based on an organization's legitimate interests or when it is necessary for the performance of a task carried out in the public interest or under official authority. In these cases, the organization must stop processing unless it can demonstrate compelling legitimate grounds that override the individual's interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defense of legal claims.
- Scientific, historical, or statistical research: The right to object is more limited where personal data is processed for scientific or historical research or statistical purposes. Organizations may continue processing when it is necessary to perform a task carried out for reasons of public interest.
The GDPR requires organizations to proactively inform individuals of their right to object in certain circumstances. Specifically, this information must be provided at the latest at the time of the first communication with the individual when:
- Personal data is processed for direct marketing purposes.
- The processing is based on the public task, or legitimate interests.
The information must be presented clearly and separately from other privacy information, helping ensure that individuals are aware of their rights before their personal data is processed.
Where an organization intends to rely on the exception that permits continued processing for scientific or historical research or statistical purposes because the processing is necessary for a task carried out in the public interest, its Privacy Notice should clearly explain that the processing is conducted on those legal bases. This transparency helps individuals understand when the right to object may be limited and supports the GDPR's broader principles of fairness, transparency, and accountability.
By giving individuals greater control over how their personal information is used—particularly for marketing and other processing that may significantly affect them—the right to object promotes fairness, transparency, and accountability, while requiring organizations to carefully balance their legitimate business interests against the fundamental rights and freedoms of individuals.
How Can an Objection Be Made?
The GDPR is designed to make the right to object easy to exercise. An individual may object to the processing of their personal data:
- In writing or verbally;
- By email, letter, telephone, social media, or in person; and
- Through any part of the organization.
The individual does not need to use the words "right to object" or refer to the GDPR. It is enough that they clearly communicate that they want the organization to stop processing their personal data for a particular purpose.
Because a valid objection may be received by any employee, organizations should ensure that staff are trained to recognize these requests and know how to escalate them promptly to the appropriate team.
Verifying Identity
If an organization has reasonable doubts about the identity of the individual making the objection, it may request additional information to verify the person's identity. Any request for identification should be proportionate and limited to what is reasonably necessary.
Where identity verification is required, the one-month response period begins once the organization has received the additional information needed to confirm the individual's identity.
Whenever additional identification is requested, the organization should explain:
- Why the additional information is necessary;
- The individual's right to lodge a complaint with a supervisory authority; and
- The individual's right to seek a judicial remedy.
What Happens After an Individual Exercises the Right to Object?
How an organization must respond depends on why the personal data is being processed and the lawful basis relied upon.
- Processing for Direct Marketing: The right to object is absolute when personal data is processed for direct marketing purposes, including any profiling related to direct marketing. Once an individual objects, the organization must stop using their personal data for direct marketing without exception. This does not necessarily require the organization to erase the individual's personal data. In many cases, it is appropriate to suppress the data by retaining only the minimum information necessary to ensure that the individual does not receive future marketing communications.
- Processing Based on Legitimate Interests or Public Task: Where processing is based on legitimate interests or the performance of a task carried out in the public interest or under official authority, the right to object is not absolute. The individual should explain the reasons for the objection, and the controller must carefully assess whether it has sufficiently compelling grounds to continue the processing. If it cannot demonstrate that those grounds override the individual's rights and freedoms, it must stop the processing.
- Processing for Scientific or Historical Research and Statistics: The GDPR provides a limited exception for certain processing carried out for scientific research, historical research, or statistical purposes. Where the processing is based on a public task, is necessary for reasons of public interest, and appropriate safeguards—such as data minimization and, where possible, pseudonymization—have been implemented, the right to object may not apply.
If the organization concludes that it cannot continue the processing, it must stop processing the personal data for the purpose to which the individual objected.
This does not always require the data to be erased.
Objection and LIAs
See: What are "Legitimate Interests" under the GDPR? to better understand what a LIA is.
When an individual exercises the right to object under Article 21 GDPR, the organization should revisit the Legitimate Interests Assessment (LIA) as it relates to the processing of data of that particular individual rather than simply relying on the analysis that justified the processing in the first place.
The original LIA is conducted before processing begins and asks whether the organization's legitimate interests outweigh the rights and freedoms of the individuals generally affected by the processing. However, once a specific individual objects, the legal standard changes for the processing that relates to the objecting individual. Under Article 21(1), the controller must stop processing unless it can demonstrate compelling legitimate grounds for the processing that override the interests, rights, and freedoms of that particular individual, or establish that the processing is necessary for the establishment, exercise, or defense of legal claims.
The objection itself becomes a new and highly relevant factor in the analysis. The controller should therefore reconsider in light of the reasons provided by the individual, reassess the impact of the processing on that particular person, and determine whether its interests remain sufficiently compelling to justify continuing the processing.
In practice, the organization should consider questions such as:
- What specific reasons has the individual given for objecting?
- Do those reasons reveal a greater impact on the individual's rights or freedoms than originally anticipated?
- Can the organization's objective be achieved through a less intrusive means?
- Are additional safeguards available that would adequately address the individual's concerns?
- Do the organization's interests remain sufficiently compelling to justify continuing the processing despite the objection?
The outcome of this reassessment should be documented as part of the organization's accountability obligations. If the controller concludes that compelling legitimate grounds do not exist, it must stop the processing for that individual.
A Useful Analogy: Constitutional Balancing in the United States: The shift from an ordinary legitimate interests balancing test to the requirement to demonstrate compelling legitimate grounds is conceptually similar to the heightened scrutiny applied in certain areas of U.S. constitutional law.
Under U.S. constitutional doctrine, government action that affects fundamental constitutional rights is often evaluated using different levels of judicial scrutiny. Under strict scrutiny, the government must demonstrate a compelling governmental interest and show that its action is narrowly tailored to achieve that interest using the least restrictive means reasonably available. This is a substantially higher burden than the more deferential standards applied in ordinary cases.
Although Article 21 GDPR does not import the U.S. constitutional framework or require strict scrutiny, it reflects a similar principle. Once an individual affirmatively objects, the controller can no longer rely solely on its ordinary legitimate interest. Instead, it must justify continuing the processing by demonstrating compelling legitimate grounds that outweigh the individual's rights and freedoms in the particular circumstances.
This illustrates an important practical point: an objection does not bar processing but it raises the threshold for continuing the processing. Therefore, organizations should treat the receipt of an objection as a trigger to revisit and strengthen their balancing analysis rather than merely reaffirming the original LIA.
Best practices for handling Objection Requests

Although the GDPR does not prescribe a specific procedure for handling objections, organizations should establish internal processes to ensure requests are handled consistently and within the applicable time limits. Good practices include:
- maintaining a policy for receiving, recording, and responding to objections;
- documenting verbal objections;
- confirming the scope of the objection where it is unclear;
- maintaining a log of objections and response deadlines;
- training staff to recognize objections, regardless of how they are submitted; and
- providing simple electronic methods for individuals to exercise their right to object where appropriate.
Organizations may offer standard forms to simplify the process, but individuals cannot be required to use them.
Requests Made on Behalf of Others: An objection does not have to be submitted personally by the individual. A lawyer, family member, or other authorized representative may exercise the right to object on the individual's behalf, provided they have appropriate authority to do so.
Organizations should take reasonable steps to verify that authority, such as requesting a signed authorization or power of attorney where appropriate. If there are concerns about the individual's ability to understand the implications of the request or the representative's authority, organizations should follow the applicable national laws governing legal representation and decision-making.
Controllers Remain Responsible: Where personal data is processed by a processor or service provider, the controller remains legally responsible for considering and responding to objections. Organizations should ensure their contracts with processors require timely cooperation so that objections can be evaluated and implemented without undue delay.
Individuals who lack legal capacity: The GDPR does not specifically address requests made on behalf of individuals who lack the mental capacity to manage their own affairs. Instead, organizations should follow the applicable laws of the relevant Member State governing legal representation and decision-making.
Time limits, refusals, and fees
Time to respond: Under the GDPR, controllers must respond to a Subject Access Request (SAR) without undue delay and, in most cases, within one month of receiving the request. In certain circumstances, this deadline may be extended where permitted by the GDPR. (See Data Subject Rights under EU Data Protection Law.)
When can a controller refuse a request? Whether a controller may refuse an objection depends on the purpose of the processing and the lawful basis relied upon. As explained above, while the right to object provides important protections for individuals, it is not always absolute.
- The right to object is absolute where personal data is processed for direct marketing. Once an individual objects, the organization must stop the processing for marketing purposes.
- For processing based on legitimate interests or public task, however, the right is not absolute. An organization may refuse the objection only if it can demonstrate compelling legitimate grounds that override the individual's rights and freedoms.
- If the processing is based on the lawful basis of legal obligation, vital interests, or contractual necessity, or if the processing is necessary for the establishment, exercise, or defense of legal claims, the request may be denied.
- The request may also be denied where the GDPR provides a specific exception for certain scientific or historical research or statistical processing carried out in the public interest.
In addition, EU Member State law may, in limited circumstances, restrict the exercise of the right to object where permitted by the GDPR.
Manifestly unfounded or excessive requests: A controller may also refuse to act on a request—or charge a reasonable fee—if the request is manifestly unfounded or excessive, particularly where it is repetitive.
In these circumstances, the controller may:
- charge a reasonable fee to cover the administrative costs of responding; or
- refuse to comply with the request altogether.
The controller bears the burden of demonstrating that the request is manifestly unfounded or excessive and must be able to justify its decision.
Informing the individual: If a controller refuses to comply with a request, whether in whole or in part, it must inform the individual without undue delay and no later than one month after receiving the request. The response must explain:
- the reasons for refusing to take action;
- the individual's right to lodge a complaint with the competent supervisory authority; and
- the individual's right to seek a judicial remedy.
Additional Reading
Article 21 of the GDPR
Suitable Recitals (69) Right to Object (70) Right to Object to Direct Marketing