CHAPTER IIIRIGHTS OF THE DATA SUBJECT

Article 18Right to restriction of processing

Official text

(1)The data subject shall have the right to obtain from the controller restriction of processing where one of the following applies:

(a)the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data;

(b)the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;

(c)the controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims;

(d)the data subject has objected to processing pursuant to Article 21 (1) pending the verification whether the legitimate grounds of the controller override those of the data subject.

(2)Where processing has been restricted under paragraph 1, such personal data shall, with the exception of storage, only be processed with the data subject’s consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.

(3)A data subject who has obtained restriction of processing pursuant to paragraph 1 shall be informed by the controller before the restriction of processing is lifted.

Commentary

6. Article 18(1)(d): Restriction Pending Verification of an Objection under Article 21

The fourth ground for restriction under Article 18 arises where the data subject has objected to processing pursuant to Article 21(1) GDPR, and the controller is still assessing whether its legitimate interests override the rights and freedoms of the data subject. This provision recognises that balancing competing interests often requires time. During that period, continued processing could prejudice the data subject if the objection is ultimately upheld. Article 18(1)(d) therefore functions as an interim safeguard, preserving the status quo until the controller reaches a lawful decision.

Article 21(1) allows a data subject to object, on grounds relating to their particular situation, to processing based on Article 6(1)(e) (performance of a task carried out in the public interest or exercise of official authority) orArticle 6(1)(f) (legitimate interests). Once an objection is made, the controller must demonstratecompelling legitimate grounds that override the interests, rights, and freedoms of the data subject, or show that the processing is necessary for the establishment, exercise, or defence of legal claims.

This balancing exercise is inherently fact-specific. It may require an examination of the purposes of processing, the reasonable expectations of the data subject, the sensitivity of the personal data, the impact on the individual, and the availability of less intrusive alternatives. During this period of uncertainty, Article 18(1)(d) entitles the data subject to require that processing be restricted.

Unlike Article 18(1)(a), where the restriction lasts until the controller verifies the accuracy of personal data, restriction under Article 18(1)(d) continues pending the verification of the controller's legitimate grounds. The duration therefore depends upon the complexity of the balancing exercise, but the controller remains bound by the general obligation under Article 12(3) to respond without undue delay and, in principle, within one month.

Practical Example

Consider an insurance company that relies on legitimate interests under Article 6(1)(f) to profile policyholders for fraud detection. A policyholder objects, arguing that their personal circumstances make such profiling disproportionate and discriminatory. Until the insurer determines whether its legitimate interests override those concerns, Article 18 allows the policyholder to require restriction of the processing. The insurer may retain the data but cannot continue using them for profiling unless one of the exceptions in Article 18(2) applies. The importance of this provision lies in preventing controllers from continuing potentially unlawful processing merely because they have not yet completed the balancing assessment. It protects the effectiveness of Article 21 by ensuring that the objection is not rendered meaningless through continued processing during the review period.

7. Article 18(2): Permitted Processing During Restriction

Once restriction has been imposed, the general rule is simple: the controller may store the personal data but may not perform any further processing operations. Storage is expressly permitted because the purpose of restriction is to preserve, not destroy, the data. However, Article 18(2) recognises four limited exceptions under which processing beyond storage remains permissible.

These exceptions must be interpreted restrictively, because they derogate from a fundamental data subject right. The controller bears the burden of demonstrating that one of the statutory exceptions applies.

The first exception permits further processing where the data subject gives new consent. This consent must satisfy all the conditions of Articles 4(11) and 7 GDPR: it must be freely given, specific, informed, and unambiguous.

Importantly, this consent is distinct from any consent that may originally have served as the legal basis for the processing. A controller cannot rely on historic consent that preceded the restriction request. Instead, the consent must specifically authorise processing during the restriction period.

Example

a customer requests restriction of processing after closing a bank account but later consents to the bank sharing limited transaction records with a financial adviser assisting in litigation. Such processing is permissible because it rests on a new, specific consent.

The second exception allows processing where it is necessary for legal proceedings. This mirrors Article 17(3)(e) and reflects the broader principle that data protection rights should not prevent access to justice.

Legal claims include civil, criminal, administrative, labour, and regulatory proceedings. The concept covers both existing litigation and proceedings that are reasonably foreseeable. Purely hypothetical claims are insufficient.

This exception ensures that restriction does not prevent either party from preserving evidence, complying with disclosure obligations, or presenting relevant material before courts or tribunals.

Nevertheless, controllers must demonstrate that the processing is necessary. The exception cannot be used as a blanket justification for resuming unrestricted processing.

The third exception recognises that restricting processing may sometimes interfere with the rights of others. Consequently, controllers may continue limited processing where it is necessary to protect the rights of another individual or organisation.

Examples

include:

  • protecting another person's contractual rights;
  • safeguarding intellectual property;
  • preventing fraud against third parties;
  • protecting vulnerable individuals. This provision requires a careful balancing exercise. Controllers should not invoke it routinely or speculatively. The interference with the restricted processing must genuinely be required to protect identifiable rights.

D. Reasons of Important Public Interest

Finally, Article 18(2) permits processing where necessary for reasons of important public interest of the Union or a Member State.

Although Article 18 does not define this concept, guidance can be drawn from other provisions of the GDPR, particularly Articles 9, 23, and 89. Examples include:

  • public health emergencies;

  • national security;

  • law enforcement;

  • taxation;

  • financial supervision;

  • social security administration;

  • judicial independence.

The public interest must be significant rather than merely convenient. Moreover, the controller must demonstrate that continued processing is necessary and proportionate.

Because this exception directly limits an individual's fundamental rights, supervisory authorities and courts are likely to interpret it narrowly.

8. Article 18(3): Notification Before Restriction is Lifted

Article 18(3) provides an important procedural safeguard:

Before lifting the restriction of processing, the controller must inform the data subject.

This obligation serves several purposes.

First, it enhances transparency by ensuring that individuals know when normal processing is about to resume.

Secondly, it allows the data subject an opportunity to challenge the controller's decision. For example, the individual may argue that the dispute has not been resolved, that the legal claims remain ongoing, or that the balancing exercise under Article 21 has been conducted incorrectly.

Thirdly, it reinforces accountability by requiring controllers to document both the decision to impose restriction and the reasons for removing it.

The GDPR does not specify how much notice must be given. However, the notification should be sufficiently early to enable the data subject to react meaningfully, including by contacting the controller, lodging a complaint with the supervisory authority, or seeking judicial remedies where appropriate.

9. Technical and Organisational Measures

Recital 67 provides valuable guidance on implementing restriction in practice.

Controllers should ensure that restricted personal data:

  • are clearly marked within information systems;

  • cannot be modified without authorisation;

  • are inaccessible for routine business operations;

  • remain identifiable as subject to restriction.

Appropriate technical measures may include:

  • access-control mechanisms;

  • role-based permissions;

  • database flags;

  • encrypted archives;

  • separate storage environments;

  • automated workflow restrictions.

Organisational measures may include:

  • internal policies;

  • staff training;

  • audit trails;

  • documented procedures for activating and removing restrictions.

Merely recording the restriction in a spreadsheet while allowing employees to continue processing the data would not satisfy Article 18.

10. Relationship with Article 19 GDPR

Article 19 complements Article 18 by requiring controllers to communicate restrictions to recipients of the affected personal data.

Whenever personal data have been disclosed to third parties and later become subject to restriction, the controller must inform those recipients unless this proves impossible or involves disproportionate effort.

This ensures that downstream recipients also adapt their processing to reflect the restriction.

Unlike Article 17(2), Article 19 concerns known recipients rather than all controllers processing publicly available information.

11. Restriction in Research and Archiving Contexts

Recital 156 highlights the importance of Article 18 within scientific research, historical research, archiving, and statistical processing.

The GDPR recognises that unrestricted exercise of certain data subject rights may sometimes undermine valuable research activities. Accordingly, Article 89 permits Member States to introduce specific derogations where appropriate safeguards exist.

Such safeguards include:

  • pseudonymisation;

  • data minimisation;

  • access controls;

  • organisational security measures.

However, derogations are not automatic. They must satisfy the principles of necessity and proportionality and remain consistent with the fundamental rights guaranteed by the Charter of Fundamental Rights of the European Union.

12. Practical Compliance Challenges

Although Article 18 appears straightforward, implementing restriction can be technically complex.

Controllers frequently face difficulties in:

  • identifying all copies of restricted data across distributed systems;

  • preventing automated processing by legacy applications;

  • synchronising restrictions with processors and cloud providers;

  • ensuring backup systems respect restrictions;

  • documenting restriction decisions for accountability purposes.

Modern organisations should therefore incorporate restriction capabilities into their privacy-by-design frameworks under Article 25.

Data governance programmes should include:

  • procedures for receiving restriction requests;

  • automated marking of restricted records;

  • suspension of workflows involving restricted data;

  • notification mechanisms under Article 19;

  • review processes before restrictions are lifted.

Failure to establish such mechanisms may expose controllers to enforcement action and administrative fines.

13. Relationship with the Right to Erasure

Article 18 and Article 17 are often described as complementary rights.

The essential distinction is that Article 17 seeks deletion, whereasArticle 18 seeks preservation without active processing.

The choice belongs primarily to the data subject.

For example:

  • If unlawfully processed health records are required as evidence in discrimination proceedings, the data subject may prefer restriction rather than deletion.

  • If customer records are no longer needed by the controller but remain necessary for a contractual dispute, Article 18 protects those records from destruction.

In this sense, Article 18 prevents controllers from frustrating the data subject's legitimate interests by deleting information that may later become indispensable.