Skip to main content
Category: Data Subject Rights

Right to Restrict Processing

Also known as: Right to Restriction of Processing, Right of Restriction, Restriction of Processing (Article 18)
Simply put

The right to restrict processing lets an individual ask an organisation to limit how it uses their personal data, without requiring that data to be deleted. When a restriction applies, the organisation may generally keep storing the data but must pause most other uses of it until the issue prompting the restriction is resolved. This right applies only in certain circumstances rather than on demand.

Formal definition

A data subject right established under Article 18 of the EU GDPR, and mirrored in the UK GDPR, entitling a data subject to obtain from the controller the restriction of processing of their personal data where one of the specified conditions applies (for example, where the accuracy of the data is contested, where processing is unlawful but the data subject opposes erasure, where the controller no longer needs the data but the data subject requires it for legal claims, or pending verification following an objection to processing). Where processing is restricted, the controller may generally continue to store the personal data but must obtain the data subject's consent or another qualifying ground before further processing, subject to the specific exceptions set out in the applicable regime. The right is qualified and conditional rather than absolute, and the obligation to give effect to it falls on the controller. Restriction is distinct from erasure: the data is retained, remains personal data, and the restriction is intended to be a temporary or conditional state. This entry does not cover procedural mechanics such as response timeframes, notification of restriction to recipients, the lifting of a restriction, applicable exemptions, or how analogous or differing rights operate under non-GDPR regimes such as the CCPA/CPRA or HIPAA, which treat individual rights differently.

Why it matters

The right to restrict processing gives individuals a meaningful option between full erasure and unchecked continued use of their personal data. In situations where an individual contests the accuracy of their data, disputes the lawfulness of processing but does not want the data erased, or has raised an objection that is still being assessed, restriction acts as a holding measure. It preserves the status quo so that an organisation cannot continue acting on data that may be inaccurate or improperly processed while the underlying issue is being resolved. For data subjects, this protects against decisions or downstream uses that could be difficult to reverse.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads need to ensure their organisation can recognise valid restriction requests, identify which of the Article 18 conditions applies, and implement a state in which storage continues but most other processing is paused. Because the right is conditional rather than absolute, assessing whether a qualifying ground exists is a core part of handling these requests.
Data Controllers
The obligation to give effect to a restriction falls on the controller. Controllers must be able to distinguish restriction from erasure operationally, keeping the data while suspending further processing, and must obtain consent or another qualifying ground before resuming processing, subject to the exceptions set out in the applicable regime.
Privacy Engineers and Data Governance Teams
Giving effect to restriction typically requires technical and governance mechanisms that can flag specific records as restricted, prevent most uses while allowing continued storage, and reflect that the data remains personal data throughout. This distinguishes restriction from deletion workflows and requires that a restricted state be enforceable across relevant systems.
Legal and Compliance Professionals
Because the right applies only in defined circumstances, legal and compliance teams play a role in evaluating whether a request meets one of the Article 18 grounds, for example, contested accuracy, unlawful processing where erasure is opposed, data no longer needed but required for legal claims, or a pending objection. This entry does not address timeframes, exemptions, or the differing treatment of individual rights under non-GDPR regimes.

Inside Right to Restrict Processing

Scope of the Right
The right to restrict processing, as established under the EU GDPR (and mirrored in the UK GDPR), allows a data subject to require a controller to limit the way personal data is used, rather than to have it deleted. When restriction applies, the data may generally continue to be stored but not otherwise processed. Treatment under other regimes such as the CCPA/CPRA differs and should not be assumed equivalent.
Triggering Circumstances
Restriction is typically available in specific situations under the GDPR, generally including where the data subject contests the accuracy of the data (for a period allowing verification), where processing is unlawful but the individual opposes erasure, where the controller no longer needs the data but the individual requires it for legal claims, or where an objection to processing is pending verification. This entry does not enumerate exhaustive article-level conditions.
Effect of Restriction
Once restriction is in place, the controller may generally only store the data, and any further processing typically requires the data subject's consent, the establishment or defense of legal claims, the protection of another person's rights, or important public interest grounds. The permitted exceptions vary by circumstance.
Controller Obligations
The obligation to give effect to restriction rests with the data controller as the party determining the purposes and means of processing. A processor acting on the controller's behalf must generally act on documented instructions to implement the restriction. The controller is typically also expected to inform the data subject before any restriction is lifted.
Notification to Recipients
Under the GDPR, the controller is generally required to communicate a restriction to each recipient to whom the data has been disclosed, unless this proves impossible or involves disproportionate effort. This supports downstream consistency of the restriction.
Relationship to Other Rights
Restriction is a distinct right that sits alongside, but is not the same as, the rights to rectification, erasure, and objection. It often functions as an interim measure while another request, such as an accuracy challenge or objection, is being assessed.

Common questions

Answers to the questions practitioners most commonly ask about Right to Restrict Processing.

Does restricting processing mean the controller must delete the personal data?
No. Restriction and erasure are distinct rights. When processing is restricted, the controller generally continues to store the personal data but must refrain from other processing of it, subject to limited exceptions. Deletion is not required and, in many cases, would defeat the purpose of restriction, since the data may need to be retained while a dispute over accuracy or the lawfulness of processing is resolved. If the data subject also wants erasure, that is a separate request assessed on its own grounds.
Once processing is restricted, is the controller completely barred from doing anything with the data?
Not entirely. Restriction limits active processing, but storage of the data is generally still permitted, and further processing may be lawful in specific circumstances typically recognised under the applicable regime, for example, with the data subject's consent, for the establishment, exercise or defence of legal claims, for the protection of another person's rights, or for reasons of important public interest. The precise exceptions depend on the instrument in question and its interpretation, so they should be checked against the governing law rather than assumed.
How can restriction be implemented technically without deleting or moving the data?
Common approaches include temporarily moving the data to a separate system or dataset, flagging or marking the records so that processing is suppressed, or restricting access through permissions so the data cannot be actively used. The chosen method should reliably prevent the restricted processing while preserving the data. The objective is demonstrable suppression of processing rather than any single prescribed control, and the approach should be documented so the controller can evidence that restriction was effective.
Does the controller need to notify anyone when processing has been restricted or when the restriction is lifted?
Where the data has been disclosed to recipients, the controller is generally expected to communicate the restriction to each recipient, unless doing so proves impossible or involves disproportionate effort. In addition, before a restriction is lifted, the data subject typically should be informed. The specific notification obligations and their thresholds are set by the governing instrument, so the exact wording and any exemptions should be confirmed against that instrument. This entry does not address cross-border transfer notification mechanics.
What should a controller check before restricting rather than continuing to process the data?
The controller should identify the ground on which restriction is being sought, for example, contested accuracy, unlawful processing where the data subject prefers restriction to erasure, the controller no longer needing the data but the data subject needing it for legal claims, or a pending assessment of an objection to processing. Each ground carries different conditions and may make restriction time-limited (for instance, until accuracy is verified). The applicable ground should be recorded so the decision is defensible and evidenced.
How does a restriction request interact with automated systems and downstream processes?
Restriction is only effective if it propagates to every system and process that would otherwise act on the data, including backups, analytics pipelines, automated decisioning, and integrations that share the data with recipients. Achieving this generally depends on knowing where the data resides, which draws on data governance capabilities such as data lineage and cataloguing. Controllers should ensure that flags or access restrictions are honoured by downstream processes rather than assuming that a single database change suffices.

Common misconceptions

Restricting processing means the data must be deleted.
Restriction and erasure are separate rights. Restriction generally means the controller retains the personal data but limits how it may be used; the data typically continues to be stored while further processing is suspended. Erasure is a different remedy with its own conditions.
Restriction absolutely prohibits any further use of the data.
Restriction limits processing but does not create a blanket bar. Under the GDPR, storage is generally still permitted, and further processing may occur in defined situations such as with the individual's consent, for legal claims, to protect another person's rights, or for important public interest reasons.
The right to restrict processing applies identically across all privacy regimes.
This right is defined under the EU GDPR and reflected in the UK GDPR. Other frameworks, such as the CCPA/CPRA or HIPAA, structure individual rights differently, and equivalent treatment should not be assumed. Cross-border and multi-regime handling should be assessed against the applicable law.

Best practices

Establish a documented workflow that recognizes a restriction request as distinct from erasure, rectification, or objection requests, and routes each to the correct handling path.
Implement a technical mechanism, such as flagging or logically segregating affected records, so that restricted data can generally continue to be stored while further processing is suspended, and retain evidence that the restriction was applied.
Ensure processors act only on documented controller instructions when giving effect to a restriction, and confirm that contractual arrangements support timely implementation.
Communicate the restriction to recipients who have received the data where required, and record where doing so is impossible or would involve disproportionate effort.
Notify the data subject before lifting any restriction, and keep a record of the basis on which the restriction is ended.
Confirm which legal regime applies before assuming this right is available or scoping its effect, as treatment differs outside the EU/UK GDPR context and this entry does not address cross-border transfer or retention mechanics.