What is the "Right to Restrict Processing" under the GDPR?
The GDPR's right to restrict processing allows individuals to require organizations to temporarily limit the use of their personal data. This article explains Article 18 GDPR, when the right applies, controller obligations, exceptions, deadlines, and practical compliance tips.
Key points: (1) The GDPR gives individuals the right to request that the processing of their personal data be restricted in certain circumstances. (2) The right to restrict processing is not absolute and only applies where one of the conditions in Article 18 GDPR is met. (3) When processing is restricted, an organization may generally store the personal data, but it must not otherwise process it unless an exception applies. (4) Individuals may request restriction verbally or in writing, and organizations should have procedures in place to recognize and handle these requests. (5) Controllers must respond without undue delay and, in most cases, within one month of receiving the request. (6) The right to restrict processing is closely connected to the right to rectification, the right to object, and, in some cases, the right to erasure.
What is the right to restrict processing and why is it important?
The right to restrict processing allows individuals to ask an organization to temporarily limit how it uses their personal data in certain circumstances. Rather than requiring the organization to delete the data, this right generally requires it to stop actively using the data while continuing to store it until a particular issue is resolved.
This right serves as an important safeguard where there is a dispute about the lawfulness or accuracy of the processing. It helps preserve personal data while protecting the individual's interests until the controller can determine how the matter should be resolved.
The right to restrict processing is closely connected to the right to rectification, the right to object, and, in some cases, the right to erasure. For example, if an individual challenges the accuracy of their personal data and requests that it be corrected, they may also request that the controller restrict processing of the data while its accuracy is being verified.
The right is set out in Article 18 of the GDPR, which provides that individuals may request restriction of processing in the following circumstances:
- The individual contests the accuracy of the personal data. Processing may be restricted while the controller verifies whether the data is accurate.
- The processing is unlawful, but the individual does not want the data erased. Instead of deletion, the individual may request that the controller restrict the use of the data.
- The controller no longer needs the personal data for its original purpose, but the individual needs it for the establishment, exercise, or defense of legal claims.
- The individual has objected to processing under Article 21 GDPR, and the controller is determining whether its legitimate grounds override the individual's rights and interests.
In many cases, a restriction is temporary. For example, it may remain in place while a controller verifies the accuracy of disputed data or evaluates an objection to processing based on legitimate interests.
How can an individual request a restriction of processing?
The GDPR does not prescribe a specific format for making a request to restrict processing. As a result, an individual may submit a request verbally or in writing, and it may be made to any part of the organization. The request does not have to be sent to a designated privacy contact or data protection officer.
A request also does not need to refer to the "right to restrict processing," cite Article 18 GDPR, or use any particular legal terminology. If an individual clearly indicates that they want an organization to temporarily stop or limit the use of their personal data, the request should generally be treated as a valid request to restrict processing.
Because any employee may receive a valid request, organizations should ensure that employees—particularly those who regularly interact with customers, employees, or other data subjects—are trained to recognize these requests and promptly forward them to the appropriate personnel for handling.
Verifying the identity of the requester
If an organization has reasonable doubts about the identity of the person requesting a restriction of processing, it may ask for additional information to verify the requester's identity before responding.
Any request for additional information should be proportionate. Controllers should request only the information necessary to confirm the individual's identity and should not create unnecessary barriers to exercising GDPR rights.
Where additional information is needed to verify identity, the one-month deadline for responding to the request begins once the controller has received the information necessary to confirm the individual's identity.
If the controller requests additional information, it should inform the individual without undue delay of:
- why the additional information is needed to verify their identity;
- their right to lodge a complaint with the competent supervisory authority; and
- their right to seek a judicial remedy if they believe their rights under the GDPR have been infringed.
What should a controller do when processing is restricted?
If a controller receives a valid request to restrict processing and no exception applies, it must take appropriate steps to ensure that the individual's personal data is no longer processed except as permitted by the GDPR.
The GDPR defines "processing" broadly. It includes not only the use of personal data, but also activities such as collecting, organizing, structuring, disclosing, transmitting, and erasing personal data.
The GDPR does not prescribe a single method for restricting processing. Instead, controllers should adopt measures that are appropriate for their systems and the nature of the processing. Examples include:
- temporarily moving the data to a separate processing system;
- making the data inaccessible to users who do not need access; or
- temporarily removing personal data from public-facing websites or other published locations.
Once processing has been restricted, the controller may generally continue to store the personal data, but it must not otherwise process it unless one of the following exceptions applies:
- the individual has given their consent;
- the processing is necessary for the establishment, exercise, or defense of legal claims;
- the processing is necessary to protect the rights of another natural or legal person; or
- the processing is necessary for reasons of important public interest under EU or Member State law.
If the controller later decides to lift the restriction, it must inform the individual before processing resumes, as required by Article 18(3) GDPR.
Informing recipients of the restriction
If the controller has disclosed the personal data to other recipients, it must take reasonable steps to inform each recipient that the processing of the data has been restricted, unless doing so would be impossible or involve a disproportionate effort.
This helps ensure that the restriction is respected throughout the processing chain and that recipients do not continue processing the personal data in a manner that is inconsistent with the restriction.
Upon request, the controller must also inform the individual about the recipients that have been notified of the restriction.
The GDPR defines a "recipient" broadly to include any natural or legal person, public authority, agency, or other body to whom personal data has been disclosed. This includes other controllers, processors, and individuals who process personal data under the direct authority of a controller or processor.
Temporary restriction while a request is being assessed
As a matter of good practice—and in some situations as required by Article 18—the controller should temporarily restrict processing while it assesses the request where:
- the individual has challenged the accuracy of the personal data and the controller is verifying its accuracy; or
- the individual has objected to processing under Article 21 GDPR and the controller is determining whether its legitimate interests override those of the individual.
Temporarily restricting processing during this assessment helps protect the individual's rights while allowing the controller to reach an informed decision. Once the assessment is complete, the controller should either maintain the restriction if the request is justified or inform the individual that the restriction will be lifted before processing resumes, as required by Article 18(3) GDPR.
Best practices for handling requests to restrict

When implementing a restriction of processing, controllers should consider the following practical measures:
Establish procedures for retaining personal data that would otherwise be deleted where the individual has requested restriction instead of erasure.
- Implement technical and organizational safeguards to prevent unauthorized processing or modification of restricted data while the restriction remains in effect.
- Clearly flag or annotate restricted records within internal systems so that employees and automated processes can readily identify that the data is subject to a processing restriction.
Although the GDPR does not require organizations to adopt formal procedures for handling requests to restrict processing, having clear internal processes helps ensure requests are handled consistently and within the applicable deadlines.
Good practices include:
- maintaining a written procedure for receiving and handling requests to restrict processing;
- documenting verbal requests so there is a clear record of when they were received;
- clarifying the request where it is unclear which processing activities the individual wants restricted;
- maintaining a log of requests, response deadlines, and outcomes; and
- providing electronic methods for submitting requests where appropriate.
Organizations may also provide standard request forms to make the process easier for individuals. However, individuals cannot be required to use a particular form in order to exercise their GDPR rights.
Requests involving third-party data: A request to restrict processing may involve personal data that also relates to other individuals. In these situations, controllers should consider whether implementing the restriction could affect the rights and freedoms of others.
Relevant considerations may include:
- the sensitivity of the personal data;
- any duty of confidentiality owed to another individual;
- whether another individual has consented to the requested action;
- whether that individual is capable of giving consent; and
- whether implementing the restriction would otherwise be reasonable in the circumstances.
Each request should be assessed on its own facts while balancing the rights of all affected individuals.
Clarifying broad or complex requests: In some cases, it may not be clear which processing activities an individual wants restricted or which personal data is covered by the request. Where appropriate, the controller may ask the individual for additional information to help identify the relevant processing.
For example, the controller may ask the individual to identify particular services, transactions, dates, or categories of personal data involved.
Even if the individual chooses not to provide additional details, the controller must still make reasonable efforts to identify the relevant processing and determine whether the request can be fulfilled.
Controllers remain responsible: A controller remains responsible for complying with the GDPR even when personal data is processed by a processor or other service provider. Controllers should ensure that their contracts with processors require timely cooperation in responding to requests to restrict processing. Reliance on a processor does not extend the GDPR deadline for responding to the individual.
Requests made on behalf of another individual: The GDPR does not require a request to restrict processing to be made personally by the individual concerned. A request may be submitted by a lawyer, family member, or other authorized representative, provided that person has authority to act on the individual's behalf.
Before acting on such a request, controllers should take reasonable steps to verify the representative's authority. Depending on the circumstances, this may include requesting a signed authorization, a power of attorney, or other appropriate evidence that the representative is authorized to exercise the individual's GDPR rights.
In some cases, a controller may be satisfied that a representative's authority is already well established and may process the request without requiring additional documentation. However, controllers are generally entitled to request formal proof of authorization before implementing a restriction of processing.
Where there are concerns that the individual may not fully understand the implications of authorizing another person to act on their behalf, it may be appropriate to communicate directly with the individual where possible before taking action.
Individuals who lack legal capacity: The GDPR does not contain specific rules governing requests made on behalf of individuals who lack the legal or mental capacity to exercise their own data protection rights.
Instead, controllers should follow the applicable laws of the relevant EU Member State regarding legal representation, guardianship, and decision-making authority when determining whether a representative may validly exercise the right to restrict processing on behalf of another individual.
Time limits, refusals, and fees
Time to respond: Under the GDPR, controllers must respond to a request to restrict processing without undue delay and, in most cases, within one month of receiving the request. In certain circumstances, this deadline may be extended where permitted by the GDPR. (See Data Subject Rights under EU Data Protection Law.)
When can a controller refuse a request?: The right to restrict processing is an important safeguard, but it is not absolute. A controller may refuse a request where none of the grounds for restriction set out in Article 18 GDPR applies.
For example, a controller may refuse a request where:
- the individual has not demonstrated that one of the Article 18 conditions is met;
- the processing is lawful and none of the statutory grounds for restriction exists; or
- an applicable exemption or restriction under EU or Member State law permits the controller to continue processing.
Each request should be assessed on a case-by-case basis, taking into account the facts presented by the individual and the controller's legal obligations under the GDPR.
Where a controller decides not to restrict processing, it should clearly explain the reasons for its decision and inform the individual of:
- their right to lodge a complaint with the competent supervisory authority; and
- their right to seek a judicial remedy.
In addition, Member State laws may restrict the exercise of the right to restrict processing in certain circumstances.
Can a controller charge a fee?: In most cases, requests to restrict processing must be handled free of charge. However, under Article 12 GDPR, a controller may charge a reasonable fee or refuse to act on a request if it can demonstrate that the request is manifestly unfounded or excessive, particularly because of its repetitive nature. Any fee must be limited to the administrative costs of processing the request.
The burden of demonstrating that a request is manifestly unfounded or excessive rests with the controller.
Manifestly unfounded or excessive requests: A controller may refuse to act on a request to restrict processing—or charge a reasonable fee—if it can demonstrate that the request is manifestly unfounded or excessive, particularly where it is repetitive.
In these circumstances, the controller may:
- charge a reasonable fee reflecting the administrative costs of handling the request; or
- refuse to comply with the request altogether.
The burden of proving that a request is manifestly unfounded or excessive rests with the controller. Any decision to refuse a request or charge a fee should be carefully documented and justified.
Informing the individual: If a controller refuses, in whole or in part, to comply with a request to restrict processing, it must inform the individual without undue delay and, in any event, within one month of receiving the request.
The response should explain:
- the reasons for refusing to take action;
- the individual's right to lodge a complaint with the competent supervisory authority; and
- the individual's right to seek a judicial remedy.
Providing a clear explanation helps demonstrate transparency and accountability, two of the GDPR's core principles.
Additional Reading
Article 18 of the GDPR
Suitable Recitals - (67) Restriction of Processing
