CHAPTER III — RIGHTS OF THE DATA SUBJECT
Article 23 — Restrictions
Official text
(1)Union or Member State law to which the data controller or processor is subject may restrict by way of a legislative measure the scope of the obligations and rights provided for in Articles 12 to 22 and Article 34, as well as Article 5 in so far as its provisions correspond to the rights and obligations provided for in Articles 12 to 22, when such a restriction respects the essence of the fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to safeguard:
(a)national security;
(b)defence;
(c)public security;
(d)the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security;
(e)other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, including monetary, budgetary and taxation matters, public health and social security;
(f)the protection of judicial independence and judicial proceedings;
(g)the prevention, investigation, detection and prosecution of breaches of ethics for regulated professions;
(h)a monitoring, inspection or regulatory function connected, even occasionally, to the exercise of official authority in the cases referred to in points (a) to (e) and (g);
(i)the protection of the data subject or the rights and freedoms of others;
(j)the enforcement of civil law claims.
(2)In particular, any legislative measure referred to in paragraph 1 shall contain specific provisions at least, where relevant, as to:
(a)the purposes of the processing or categories of processing;
(b)the categories of personal data;
(c)the scope of the restrictions introduced;
(d)the safeguards to prevent abuse or unlawful access or transfer;
(e)the specification of the controller or categories of controllers;
(f)the storage periods and the applicable safeguards taking into account the nature, scope and purposes of the processing or categories of processing;
(g)the risks to the rights and freedoms of data subjects; and
(h)the right of data subjects to be informed about the restriction, unless that may be prejudicial to the purpose of the restriction.
Commentary
1. Introduction: The Function and Constitutional Significance of Article 23
Article 23 GDPR is one of the most important provisions for understanding the limits of data-subject rights under the GDPR. The GDPR strongly protects individuals by granting rights such as access, rectification, erasure, restriction of processing, data portability, objection and protection against certain automated decisions. However, these rights are not absolute.
Modern governments and public authorities sometimes require limited access to personal information, or temporarily need to restrict the exercise of certain data-protection rights, in order to protect competing public interests. For example, an individual under criminal investigation cannot always be given unrestricted access to investigative information if disclosure would reveal evidence, expose witnesses, compromise surveillance or frustrate the investigation. Similarly, unrestricted access to information during a tax investigation could enable a person to conceal assets or destroy evidence.
Article 23 provides the legal framework through which such restrictions may be introduced.
The fundamental principle is therefore:
Article 23 does not create a general governmental power to ignore the GDPR. It creates a narrowly controlled mechanism through which specific GDPR rights and obligations may be restricted by law when strict constitutional and proportionality requirements are satisfied.
This distinction is critical.
A controller cannot simply decide that a particular GDPR right is inconvenient or that disclosure would create administrative difficulties. Nor can a public authority rely directly on one of the objectives listed in Article 23(1) without a proper legislative basis.
There must be a legislative measure, the restriction must pursue one of theexhaustively listed objectives, the essence of the relevant fundamental rights must remain intact, and the restriction must benecessary and proportionate in a democratic society.
Article 23 therefore performs a balancing function between:
-
the fundamental right to privacy;
-
the fundamental right to protection of personal data;
-
the rights of the data subject;
-
legitimate governmental and regulatory interests;
-
criminal justice;
-
public security;
-
judicial independence;
-
protection of other persons; and
-
other important public interests.
The provision should consequently be understood not as an exception that weakens the GDPR generally, but as a constitutional safety valve that permits carefully delimited restrictions where competing fundamental or public interests require them.
2. Article 23(1): The Basic Authority to Restrict GDPR Rights
Article 23(1) provides that Union or Member State law to which the controller or processor is subject may restrict, by legislative measure, the scope of certain GDPR obligations and rights.
Several separate legal requirements are contained within this sentence.
The restriction must:
-
be based on Union or Member State law;
-
take the form of a legislative measure;
-
apply to rights and obligations that Article 23 actually permits to be restricted;
-
pursue one of the objectives listed in Article 23(1)(a), (j);
-
respect the essence of fundamental rights and freedoms;
-
be necessary;
-
be proportionate;
-
operate within a democratic society; and
-
genuinely safeguard the relevant protected objective.
Failure to satisfy any of these requirements can make the restriction unlawful.
3. What Does "Restriction" Mean?
The GDPR does not expressly define the term "restriction" for purposes of Article 23.
In practical terms, a restriction means a legally authorised limitation on the normal exercise of a GDPR right or obligation.
It may therefore take different forms.
Example
legislation could:
-
temporarily delay the exercise of the right of access;
-
permit certain information to be withheld;
-
prevent disclosure of particular categories of information;
-
postpone notification to the data subject;
-
limit the scope of information supplied;
-
restrict the right to object in a defined investigation;
-
restrict the obligation to communicate a personal data breach;
-
limit erasure where retention is required for a specified public-interest investigation.
The concept is therefore broader than simply "removing" a right.
A restriction could concern:
-
when the right can be exercised;
-
what information must be provided;
-
to whom it must be provided;
-
how much information can be disclosed;
-
for how long the right may be restricted; or
-
under what circumstances the right may be exercised.
Example
Suppose a tax authority is investigating suspected tax fraud. The law may provide that an individual's Article 15 access request can temporarily be restricted if disclosure of the requested information would reveal the existence, scope or direction of the investigation. This does not necessarily eliminate the right of access permanently. Instead:
Normal position → access
Investigation begins → limited restriction
Risk to investigation disappears → restriction lifted
Data subject → receives the information
The temporary restriction is therefore exceptional and purpose-specific.
4. Restrictions Are Exceptions and Must Be Interpreted Narrowly
A central principle of Article 23 is that restrictions are exceptions to the normal operation of the GDPR.
The ordinary position is that:
-
data subjects have rights;
-
controllers have obligations;
-
transparency is required;
-
individuals can exercise their GDPR rights.
Article 23 creates an exception to this ordinary position.
Consequently, Article 23 should not be interpreted as granting Member States an unrestricted discretion to weaken data protection.
A restriction should therefore be:
-
specific;
-
justified;
-
limited;
-
foreseeable;
-
reviewable;
-
connected to a legitimate objective; and
-
no broader than necessary.
The existence of a legitimate public interest does not automatically justify every possible restriction.
Example
A government investigating financial crime may legitimately restrict certain information that would reveal an ongoing investigation. It would not automatically follow that the government can: suspend every data-subject right for every person whose information happens to be processed by the authority. That would be substantially broader than necessary. The restriction must be connected to the actual problem being addressed.
5. Which GDPR Rights and Obligations Can Be Restricted?
Article 23(1) contains a limited list of GDPR provisions that may be restricted.
These include:
Article 12
Transparent information, communication and modalities for exercising rights.
Articles 13 and 14
Information provided when personal data are collected from the data subject or obtained from another source.
Article 15
Right of access.
Article 16
Right to rectification.
Article 17
Right to erasure.
Article 18
Right to restriction of processing.
Article 19
Notification obligations concerning rectification, erasure and restriction.
Article 20
Right to data portability.
Article 21
Right to object.
Article 22
Rights relating to automated individual decision-making.
Article 34
Communication of a personal data breach to the data subject.
Article 5 can also be restricted, but only to the extent that its provisions correspond to the rights and obligations contained in Articles 12, 22.
This qualification is extremely important.
Article 23 does not provide a general power to suspend Article 5.
Example
Article 5 contains the principles of:
-
lawfulness, fairness and transparency;
-
purpose limitation;
-
data minimisation;
-
accuracy;
-
storage limitation;
-
integrity and confidentiality; and
-
accountability.
The mere fact that Article 23 refers to Article 5 does not mean that a Member State can simply suspend the principle of data minimisation or purpose limitation whenever it wishes.
The restriction must correspond to the rights and obligations covered by Articles 12, 22.
6. Rights That Cannot Simply Be Restricted Under Article 23
The limited scope of Article 23 is particularly important.
Article 23 does not expressly authorise restrictions of every GDPR right.
Example
Article 77, concerning the right to lodge a complaint with a supervisory authority, is not among the rights listed in Article 23(1).
Similarly, Article 79 concerning judicial remedies is not simply converted into a generally restrictable right through Article 23.
This demonstrates the exceptional character of Article 23.
A Member State cannot say:
"Because national security is involved, all GDPR rights are suspended."
The legislation must identify a right or obligation that falls within the scope of Article 23.
7. Relationship with Other GDPR Derogations
Article 23 should also be distinguished from other GDPR provisions that allow special rules or derogations.
Example
Chapter IX contains provisions dealing with situations such as:
-
freedom of expression;
-
freedom of information;
-
processing for journalistic purposes;
-
academic purposes;
-
artistic purposes;
-
literary purposes;
-
public access to official documents;
-
employment contexts;
-
archiving;
-
scientific or historical research.
Therefore, Article 23 should not be treated as the universal derogation mechanism for the entire GDPR.
The GDPR contains several different mechanisms for reconciling data protection with competing interests.
8. Requirement of a "Legislative Measure"
One of the most important safeguards in Article 23 is the requirement that restrictions must be established by a legislative measure.
A controller cannot invent an Article 23 restriction by itself.
Example
a company cannot simply state in its privacy policy:
"For security reasons, users do not have the right to access their personal data."
That statement does not create an Article 23 restriction.
There must be a valid legal basis in Union or Member State law.
The legislative measure must also be sufficiently clear and precise so that individuals can reasonably understand:
-
when the restriction can apply;
-
which rights may be restricted;
-
why the restriction exists;
-
which controllers can use it;
-
how long it may last;
-
what safeguards exist; and
-
when the restriction will be lifted.
This is closely connected to the broader principles of legality, foreseeability and the rule of law.
9. Foreseeability and Legal Certainty
A restriction on a fundamental right cannot be based on vague or unpredictable legal rules.
The law should provide individuals with an adequate indication of the circumstances and conditions in which the restriction may be applied.
Example
a law stating:
"Authorities may restrict data-subject rights whenever necessary for public interest."
would raise serious concerns because "public interest" is extraordinarily broad.
A stronger legislative provision would specify:
-
the particular authority;
-
the relevant investigation;
-
the categories of data;
-
the rights that may be restricted;
-
the circumstances triggering the restriction;
-
the duration;
-
the safeguards;
-
review procedures; and
-
circumstances requiring disclosure.
The more intrusive the restriction, the greater the need for precision.
10. Temporary and Permanent Restrictions
Article 23 does not require every restriction to have an identical time limit.
Some legitimate objectives may be continuing objectives.
Example
legislation protecting judicial independence may not necessarily have a fixed expiry date.
However, where the reason for restriction is temporary, the restriction should normally also be temporary.
Example
Criminal investigation During an investigation:
Access → restricted
After the investigation:
Risk disappears → restriction lifted
A restriction cannot continue indefinitely merely because it was once justified.
This reflects the principle that the restriction must remain connected to the objective that originally justified it.
11. Respect for the Essence of Fundamental Rights
Article 23 requires that restrictions respect the essence of fundamental rights and freedoms.
This is one of the strongest safeguards in the provision.
The "essence" requirement means that the restriction cannot destroy the fundamental right itself.
There must remain a meaningful core of protection.
A restriction that effectively makes a fundamental right meaningless would fail this requirement.
Example
Suppose a law provides: "No person has any right to access personal data held by a public authority." This is not merely a limited restriction. It could potentially eliminate the substantive core of the right of access for the relevant category of individuals. Article 23 is not intended to authorise such wholesale elimination. The same principle applies where a restriction is framed as temporary but is so broad that, in practice, the right becomes meaningless.
12. The "Essence" Test Comes Before Proportionality
The essence requirement is conceptually distinct from necessity and proportionality.
The analysis can be understood as:
Step 1
Does the measure interfere with a protected right?
Step 2
Does the measure preserve the essence of that right?
If no, the measure fails.
There is no need to proceed to a proportionality analysis.
Step 3
If the essence remains intact, ask whether the restriction pursues a permitted Article 23 objective.
Step 4
Ask whether it is necessary.
Step 5
Ask whether it is proportionate.
This creates a structured constitutional analysis.
13. Necessary and Proportionate in a Democratic Society
Even where a restriction has a legitimate purpose, it must still be:
necessary and proportionate in a democratic society.
These are not merely decorative words.
They impose substantive limits on legislative discretion.
The government must be able to demonstrate why the restriction is needed and why a less intrusive measure would not adequately achieve the objective.
14. The Necessity Requirement
Necessity asks whether the restriction is genuinely required to achieve the legitimate objective.
The question is not:
"Would this restriction make the government's job easier?"
The question is:
"Is this restriction actually necessary to achieve the legally protected objective?"
Administrative convenience is not enough.
Example
A tax authority investigating suspected fraud might argue that allowing access requests creates additional administrative work. That alone would not normally establish necessity. However, if disclosure of the information would reveal:
- the existence of the investigation;
- investigative techniques;
- evidence;
-
information concerning other suspects; or
-
planned enforcement action,
then a targeted restriction may be necessary.
15. The Least Intrusive Measure
Necessity also requires consideration of alternatives.
Suppose an authority wants to prevent disclosure of a document.
It should consider whether it can instead:
-
redact particular passages;
-
disclose some information;
-
provide information after a delay;
-
provide indirect access;
-
disclose information through a supervisory authority;
-
restrict only particular categories of data.
If a less intrusive alternative can achieve the same objective, a broad restriction may fail the necessity or proportionality test.
16. Proportionality
Proportionality requires a balance between:
the public objective
and
the interference with individual rights.
The greater the interference, the stronger the justification must be.
For example:
Minor interference
A short delay in access to a limited category of information.
Greater interference
Withholding substantial information for several months.
Very serious interference
A broad and indefinite denial of access to an individual's entire personal-data record.
The last measure requires exceptionally strong justification and may fail Article 23 altogether.
17. Evidence Supporting Necessity and Proportionality
The legislature should be able to explain:
-
What problem exists?
-
What public interest is threatened?
-
Why does the problem require a restriction?
-
Which GDPR right needs to be restricted?
-
Why is the particular restriction necessary?
-
Why are less intrusive measures inadequate?
-
What risks does the restriction create?
-
What safeguards mitigate those risks?
-
When will the restriction end?
-
How will compliance be reviewed?
This prevents Article 23 restrictions from being based merely on assertions.
18. The Exhaustive List of Legitimate Objectives
Article 23(1)(a), (j) contains the grounds that may justify restrictions.
These grounds should be treated as an exhaustive list for Article 23.
A restriction cannot be justified simply because it serves some other desirable governmental objective.
The legislation must establish a clear connection between:
the restriction → the protected objective.
19. Article 23(1)(a): National Security
National security is one of the strongest grounds capable of justifying restrictions.
It concerns protection of the State against threats affecting its internal or external security.
Examples
could include:
- counter-intelligence;
- protection against foreign interference;
- national security investigations;
- protection of sensitive intelligence;
- threats to constitutional institutions. However, "national security" cannot become a magic phrase that automatically defeats data-subject rights. The State must still demonstrate:
- a genuine national-security objective;
- a real connection between the restriction and that objective;
- necessity;
- proportionality;
- safeguards.
Example
An intelligence authority may possess information identifying covert sources. Providing unrestricted access to that information could expose intelligence operations or endanger individuals. A carefully designed restriction may therefore be justified. But the restriction should target the sensitive information rather than automatically eliminating every right of every person whose information is held by the authority.
20. Article 23(1)(b): Defence
Defence concerns the protection of the State's defence interests.
Potential examples include:
-
military operations;
-
defence intelligence;
-
strategic security information;
-
military personnel investigations;
-
protection of defence infrastructure.
Again, defence is not an unlimited exemption.
A restriction must still satisfy:
-
legality;
-
essence;
-
necessity;
-
proportionality;
-
safeguards.
Example
A defence authority investigating a security breach may temporarily restrict access to information that would reveal the identity of security personnel or operational vulnerabilities. It would be more difficult to justify a blanket denial of all rights merely because an individual is associated with a defence institution.
21. Article 23(1)(c): Public Security
Public security is related to, but distinct from, national security and defence.
It can include the protection of individuals and society against serious threats.
Recital 73 associates public security with protection of human life, including situations involving natural or man-made disasters.
Examples
could include:
- major disasters;
- emergency public-safety operations;
- threats to human life;
- serious public-security incidents.
Example
Following a major industrial accident, authorities may need to process personal information rapidly to identify affected persons and coordinate emergency response. Certain ordinary procedures may need to be modified temporarily. However, emergency conditions do not eliminate data protection. Even during emergencies, restrictions must remain lawful, necessary and proportionate.
22. Article 23(1)(d): Prevention, Investigation, Detection or Prosecution of Criminal Offences
This is one of the most practically significant grounds.
A restriction may be justified where disclosure or exercise of a right could interfere with:
-
crime prevention;
-
criminal investigations;
-
detection of offences;
-
prosecution;
-
execution of criminal penalties;
-
prevention of threats to public security.
Example
Suppose a police investigation is examining a suspected organised crime network. A suspect submits an access request seeking:
- investigative records;
- information about surveillance;
- identity of witnesses;
- information concerning other suspects.
Unrestricted disclosure could compromise the investigation.
A targeted restriction may therefore be justified.
However, once the information no longer presents such a risk, continued restriction becomes harder to justify.
23. Relationship with the Law Enforcement Directive
An important distinction must be made between the GDPR and the EU Law Enforcement Directive.
Certain processing by competent authorities for law-enforcement purposes falls outside the GDPR and is instead governed by the Law Enforcement Directive.
Article 23 is therefore particularly relevant where the processing remains within the GDPR's scope.
Example
a private entity may process personal data in connection with anti-money-laundering obligations or forensic activities.
The GDPR may continue to apply depending on the circumstances.
Article 23 may then permit carefully designed restrictions where disclosure would jeopardise the relevant investigation.
24. Article 23(1)(e): Important Objectives of General Public Interest
This is one of the broadest grounds.
It covers important objectives of general public interest of the Union or Member State, including:
-
important economic interests;
-
financial interests;
-
monetary matters;
-
budgetary matters;
-
taxation;
-
public health;
-
social security.
Because this category is broad, it must not be interpreted as a general licence to restrict rights whenever government considers doing so useful.
The objective must be genuinely:
-
important;
-
public;
-
legally recognised; and
-
sufficiently connected to the restriction.
25. Economic and Financial Interests
Article 23 can support restrictions designed to protect important public economic or financial interests.
Examples
may include:
- tax administration;
- prevention of serious financial fraud;
- protection of public funds;
- financial investigations;
- budgetary enforcement. However, a government cannot justify a restriction merely because responding to data-subject requests costs money.
Important
distinction
Administrative expense ≠ sufficient public-interest justification
The financial burden of complying with the GDPR does not automatically justify restricting data-subject rights.
The restriction must protect a genuine important public interest.
26. Tax Investigations
Tax investigations provide a useful illustration.
Suppose a taxpayer exercises Article 15 access rights while a tax investigation is ongoing.
If disclosure would reveal:
-
investigative strategies;
-
information obtained from third parties;
-
evidence;
-
planned enforcement measures;
the law might legitimately restrict access temporarily.
But once the investigation is completed, the justification for continuing the restriction may disappear.
Therefore:
The restriction should track the risk, not merely the existence of the authority's general statutory powers.
27. Public Health
Public health can also justify restrictions.
Example
in an emergency involving a serious communicable disease, authorities may need to process information quickly and restrict certain rights where immediate disclosure would interfere with emergency operations.
But the mere existence of a pandemic or health emergency is not itself sufficient.
The legislation must demonstrate:
-
what public-health problem exists;
-
why the restriction is needed;
-
what right is being restricted;
-
why less intrusive measures are inadequate;
-
what safeguards apply;
-
when the restriction ends.
28. Social Security
Social-security administration may also involve restrictions where unrestricted rights could undermine investigations or the administration of benefits.
Example
authorities investigating fraudulent claims may need to restrict access to particular investigative information temporarily.
Again, the restriction should be targeted rather than general.
29. Article 23(1)(f): Protection of Judicial Independence and Judicial Proceedings
This ground protects the proper administration of justice.
It covers the protection of:
-
judicial independence;
-
judicial proceedings;
-
the administration of justice;
-
proceedings from inappropriate interference.
The purpose is not merely to protect judges personally.
It also protects the integrity of judicial proceedings.
Example
If disclosure of particular personal information could undermine the integrity of an ongoing judicial proceeding, legislation may permit restrictions in defined circumstances. The CJEU has explained inNorra Stockholm Bygg (C-268/21) that this objective concerns protection of the administration of justice from internal or external interference as well as the proper administration of justice. This ground should be distinguished from criminal investigations, which may fall under Article 23(1)(d).
30. Article 23(1)(g): Professional Ethics
Restrictions may also be justified for:
the prevention, investigation, detection and prosecution of breaches of ethics for regulated professions.
This may cover professions such as:
-
lawyers;
-
doctors;
-
accountants;
-
regulated financial professionals;
-
other professionally regulated occupations.
Example
Suppose a medical regulator investigates allegations that a doctor has falsified patient records. If immediately informing the doctor about every investigative step would enable destruction or manipulation of evidence, legislation may restrict particular information temporarily. However, once disclosure no longer threatens the investigation, the restriction should normally be reconsidered.
31. Article 23(1)(h): Monitoring, Inspection and Regulatory Functions
This provision concerns restrictions connected with:
-
monitoring;
-
inspection;
-
regulation;
-
official authority.
The function must be connected to one of the objectives identified in Article 23(1)(a), (e) or (g).
This is important because Article 23(1)(h) is not an independent unlimited regulatory exemption.
There must be a connection between:
monitoring/inspection/regulation
and
one of the protected public objectives.
Example
A financial regulator investigating market manipulation may restrict certain information if disclosure would undermine the regulatory investigation. Similarly, a professional regulator investigating misconduct may restrict information under the relevant regulatory framework.
32. Article 23(1)(i): Protection of the Data Subject or Rights and Freedoms of Others
This ground demonstrates that Article 23 does not only protect government interests.
Sometimes one person's GDPR rights may need to be restricted to protect another person.
This is particularly important where personal information about multiple individuals is interconnected.
Examples
include:
- workplace harassment investigations;
- disciplinary proceedings;
- whistle-blower investigations;
- protection of witnesses;
- protection of victims;
- safeguarding vulnerable persons.
Example
An employee accused of workplace harassment requests access to all information contained in the investigation file. The file may contain personal information about:
- the complainant;
- witnesses;
- other employees. Providing everything to the accused person could expose witnesses or complainants to retaliation.
A carefully limited restriction may therefore protect the rights and freedoms of those individuals.
The converse can also occur.
A witness may request information that contains sensitive information about the accused person.
The controller may need to balance both individuals' rights.
33. Article 23(1)(j): Enforcement of Civil Law Claims
Article 23 also permits restrictions for enforcement of civil-law claims.
This may be relevant to:
-
litigation;
-
civil investigations;
-
enforcement of contractual rights;
-
preservation of evidence;
-
protection of litigants' interests.
This ground should be distinguished from Article 23(1)(f).
Article 23(1)(f)
Protects:
the judicial system and proceedings themselves.
Article 23(1)(j)
Protects:
the enforcement of civil-law claims and interests of litigants.
This distinction can be important when identifying the precise legal objective behind a restriction.
34. Article 23(2): Specific Requirements for Restrictive Legislation
Article 23(2) is crucial because Article 23(1) establishes when restrictions may be permissible, while Article 23(2) establishes important requirements concerninghow the restriction must be legally structured.
The legislative measure must contain, where relevant, provisions concerning:
(a) purposes/categories of processing;
(b) categories of personal data;
(c) scope of restrictions;
(d) safeguards against abuse or unlawful access/transfer;
(e) controller or categories of controllers;
(f) storage periods and safeguards;
(g) risks to data subjects; and
(h) informing data subjects about the restriction.
The words "where relevant" should not be interpreted as making Article 23(2) optional.
Rather, if a particular requirement genuinely does not apply to the measure, there should be a defensible reason why.
35. Article 23(2)(a): Purposes or Categories of Processing
The legislative measure should identify the purposes of processing or categories of processing affected by the restriction.
This provides clarity about why the restriction exists.
Example
Instead of stating: "Access rights may be restricted for regulatory purposes." a more precise law might provide that access may be restricted where disclosure would prejudice: an ongoing investigation into serious breaches of regulated-professional obligations. The connection between:
processing → restriction → objective
should therefore be clear.
Importantly, the purpose should not be artificially broadened after the fact.
36. Article 23(2)(b): Categories of Personal Data
The legislation should identify the categories of personal data to which the restriction applies.
This is particularly important for sensitive information.
Example
legislation might distinguish:
-
investigative records;
-
intelligence information;
-
witness identities;
-
medical information;
-
financial information;
-
professional disciplinary records.
Special-category data require particular care because restrictions involving such data can produce especially serious consequences for individuals.
Where possible, legislation should identify particular types of information rather than simply referring to "all personal data."
37. Article 23(2)(c): Scope of the Restrictions
The legislative measure must specify how far the restriction goes.
This is one of the most important safeguards.
The law should answer questions such as:
-
Which right is restricted?
-
Is the right completely or partially restricted?
-
Which data are excluded?
-
Which persons are affected?
-
Under what circumstances?
-
For how long?
-
What information can still be disclosed?
-
What triggers lifting of the restriction?
Example
A better restriction would say: Article 15 access may be temporarily restricted only insofar as disclosure of specified investigative information would prejudice an ongoing investigation. This is substantially narrower than: Article 15 does not apply to the authority.
38. Article 23(2)(d): Safeguards Against Abuse or Unlawful Access or Transfer
Restrictions themselves create risks.
When individuals are prevented from exercising rights, controllers and public authorities may possess greater control over personal information.
Therefore, Article 23(2)(d) requires safeguards against:
-
abuse;
-
unlawful access;
-
unlawful transfer;
-
misuse;
-
unauthorised disclosure.
Safeguards may include:
-
access controls;
-
encryption;
-
logging;
-
internal authorisation;
-
segregation of sensitive information;
-
periodic reviews;
-
audit mechanisms;
-
confidentiality obligations;
-
supervisory oversight.
The principle is straightforward:
Restricting the individual's rights cannot mean eliminating controls over the authority's processing.
39. Article 23(2)(e): Identification of the Controller
The legislation should identify the controller or categories of controllers affected.
This provides legal certainty.
It also enables the data subject to understand:
-
who is processing the information;
-
who is applying the restriction;
-
who is responsible for compliance;
-
whom to contact when the restriction ends.
This is particularly important in complex public-administration structures involving several agencies.
40. Article 23(2)(f): Storage Periods and Safeguards
The legislative measure should also address:
-
storage periods;
-
applicable safeguards;
-
the nature of processing;
-
scope;
-
purposes.
This prevents restricted information from being retained indefinitely merely because it was collected during a restricted period.
Example
If investigative records need to be retained during proceedings and for a defined period afterward, the law should establish an appropriate retention framework. Retention should remain connected to the legitimate purpose. A restriction on access does not automatically justify unlimited retention.
41. Article 23(2)(g): Risks to Rights and Freedoms
The legislator should consider the risks created by the restriction itself.
This is an important conceptual point.
The law should not consider only:
"What happens if we do not restrict the right?"
It must also consider:
"What happens if we restrict the right?"
Potential risks include:
-
loss of transparency;
-
inaccurate data remaining uncorrected;
-
discrimination;
-
unlawful profiling;
-
inability to challenge decisions;
-
interference with privacy;
-
harm to dignity;
-
harm to vulnerable persons;
-
reduced ability to detect misuse of personal data.
This risk assessment should inform the design of safeguards.
Where processing is likely to result in a high risk, a DPIA may also be relevant depending on the circumstances.
42. Article 23(2)(h): Right to Be Informed About the Restriction
As a general rule, individuals should know that their GDPR rights have been restricted.
This serves several purposes:
-
transparency;
-
accountability;
-
legal certainty;
-
ability to challenge the restriction;
-
ability to exercise rights once the restriction ends.
However, Article 23(2)(h) expressly recognises an important exception.
Information about the restriction itself may be withheld where disclosure would prejudice the purpose of the restriction.
Example
Suppose a criminal investigation is at an early stage. If the suspect is told: "Your access right has been restricted because you are currently under investigation." that information may itself compromise the investigation. In such circumstances, notification may temporarily be withheld. But this exception should not become permanent merely because the authority finds notification inconvenient.
Once disclosure of the restriction no longer prejudices the objective, the data subject should be informed.
43. Restrictions Should Be Reviewed Periodically
A sound Article 23 framework should include mechanisms for reassessing restrictions.
The relevant questions are:
-
Does the original justification still exist?
-
Is the investigation still active?
-
Does disclosure still create a genuine risk?
-
Can some information now be disclosed?
-
Can the restriction be narrowed?
-
Can the restriction be lifted?
This reflects a central principle:
The legality of a restriction depends on the circumstances that justify it.
If those circumstances materially change, the restriction must also be reconsidered.
44. Article 23 and the Accountability Principle
Article 23 does not eliminate the accountability principle in Article 5(2).
A controller relying upon a restriction should therefore be able to demonstrate why the restriction was applied.
Good practice may include maintaining an internal record containing:
-
the identity of the data subject;
-
the right restricted;
-
the statutory basis;
-
the Article 23 ground relied upon;
-
the factual circumstances;
-
the start date;
-
the expected duration;
-
the necessity assessment;
-
the proportionality assessment;
-
safeguards applied;
-
review dates;
-
the date on which the restriction was lifted.
This is particularly important because restrictions can be difficult to scrutinise from outside the controller.
45. Role of the Data Protection Officer
Where an organisation has a DPO, the DPO may have an important role in assessing Article 23 restrictions.
The DPO can help examine:
-
whether the legal basis exists;
-
whether the relevant right falls within Article 23;
-
whether the restriction is appropriately scoped;
-
whether safeguards are adequate;
-
whether the restriction remains necessary;
-
whether notification can be provided;
-
whether the restriction should be lifted.
The DPO's role should not be confused with that of the decision-maker where national law assigns responsibility elsewhere.
46. Consultation of the Supervisory Authority
Article 36(4) GDPR is particularly relevant.
Where Member States prepare legislative or regulatory measures relating to processing that may affect data protection, the supervisory authority should be consulted in accordance with the GDPR's consultation framework.
Article 57 also gives supervisory authorities functions concerning advice on legislative measures.
This provides an institutional safeguard.
The data-protection authority can identify problems such as:
-
excessive restrictions;
-
inadequate safeguards;
-
insufficient precision;
-
excessive retention;
-
inadequate transparency;
-
disproportionate interference.
47. What Happens if National Legislation Violates Article 23?
Member States do not possess unlimited discretion under Article 23.
A national law purporting to restrict GDPR rights must itself comply with:
-
Article 23 GDPR;
-
the Charter of Fundamental Rights;
-
applicable EU law;
-
relevant fundamental-rights principles.
A national measure that exceeds those limits may be challenged through the appropriate legal mechanisms.
The principle of the primacy of EU law is important here.
Member States cannot use Article 23 as a mechanism to undermine the fundamental structure of EU data protection law.
48. Relationship with Article 8 of the Charter
The right to protection of personal data is recognised in Article 8 of the Charter of Fundamental Rights of the European Union.
That right, like many fundamental rights, is not absolute.
Article 52(1) of the Charter permits limitations where they:
-
are provided for by law;
-
respect the essence of the rights and freedoms;
-
are necessary;
-
genuinely meet objectives of general interest recognised by the Union or protect the rights and freedoms of others;
-
are proportionate.
Article 23 GDPR therefore operates within a wider constitutional framework.
It should not be interpreted in isolation from fundamental-rights protection.
49. Relationship with the European Convention on Human Rights
Recital 73 also refers to the requirements of the Charter and the European Convention on Human Rights.
This is important because restrictions on data-subject rights can affect:
-
private life;
-
family life;
-
freedom of expression;
-
effective remedies;
-
other Convention interests.
The European human-rights framework reinforces the requirement that interference with privacy and related rights must have a lawful basis and satisfy appropriate necessity and proportionality requirements.
50. Article 23 Does Not Mean "No GDPR"
A crucial practical principle is that an Article 23 restriction does not normally switch the GDPR off completely.
Instead, it modifies the application of particular rights or obligations in defined circumstances.
For example:
Incorrect approach:
"Article 23 applies, so the controller does not need to comply with GDPR."
Correct approach:
"A specific right or obligation is restricted to the extent authorised by a valid legislative measure, while the remaining GDPR obligations continue to apply."
This distinction is fundamental.
51. Example: Criminal Investigation
Consider the following scenario.
A financial institution processes information relating to a customer.
A competent authority is investigating suspected money laundering.
The individual requests access to all personal data.
Suppose national legislation provides a valid Article 23 restriction allowing temporary limitation of access where disclosure would prejudice the investigation.
The authority should ask:
Step 1
Does the processing fall within the GDPR?
Step 2
Does the relevant national law constitute a valid legislative measure?
Step 3
Does the restriction concern Article 15, which is within Article 23?
Step 4
Does the restriction pursue Article 23(1)(d)?
Step 5
Would disclosure actually prejudice the investigation?
Step 6
Can some information safely be disclosed?
Step 7
What safeguards apply?
Step 8
How long will the restriction last?
Step 9
When will the individual be informed?
Step 10
When will the restriction be lifted?
This demonstrates that Article 23 requires a structured legal assessment rather than a simple yes/no decision.
52. Example: Workplace Harassment Investigation
Consider a company conducting a formal workplace harassment investigation.
The investigation file contains information about:
-
the complainant;
-
the accused employee;
-
witnesses;
-
HR personnel.
The accused employee submits an access request for the entire file.
Unrestricted disclosure could expose witness identities and sensitive information.
If applicable national law provides a valid Article 23 restriction, the controller may need to balance:
the accused employee's access rights
against
the rights and freedoms of witnesses and complainants.
The controller should not automatically refuse the entire request.
It should consider:
-
redaction;
-
partial disclosure;
-
pseudonymisation;
-
withholding particular information;
-
indirect access;
-
disclosure after the investigation.
This illustrates the principle of minimum necessary restriction.
53. Example: Tax Investigation
A tax authority investigates suspected undeclared income.
The taxpayer submits an access request.
The requested documents contain:
-
investigative leads;
-
third-party information;
-
planned enforcement measures.
Disclosure at that stage may reveal the investigation's strategy.
A valid Article 23 restriction may therefore apply.
But after the investigation is completed, the authority should reassess the restriction.
If the investigative risk has disappeared, continued withholding of information may no longer satisfy necessity and proportionality.
54. Example: Public Health Emergency
Suppose an emergency health situation requires authorities to rapidly identify individuals exposed to a dangerous disease.
A law temporarily modifies certain information and access requirements.
The legislation should still establish:
-
purpose;
-
categories of data;
-
affected controllers;
-
scope of restriction;
-
retention period;
-
security safeguards;
-
risk assessment;
-
notification arrangements;
-
review mechanism.
The emergency does not remove the need for safeguards.
55. Article 23 and Data Minimisation
Article 5's data-minimisation principle deserves particular attention.
Article 23 does not permit unlimited collection merely because a public authority invokes a legitimate objective.
Even where rights are restricted, the authority should avoid collecting information that is unnecessary for the legitimate purpose.
This is important because otherwise a restriction designed to protect one public interest could become a justification for indiscriminate surveillance or excessive data collection.
56. Article 23 and Accuracy
Similarly, restrictions on the right of rectification under Article 16 do not necessarily mean that inaccurate information can simply remain uncorrected indefinitely.
Where legislation permits temporary restriction of rectification because correction would prejudice an investigation, the authority should consider mechanisms that protect data quality.
For example:
-
recording that information is disputed;
-
maintaining audit trails;
-
correcting information where legally possible;
-
reviewing data after the investigation.
The EDPB's approach recognises that exercising rights can sometimes actually assist public authorities, for example, rectification may improve the accuracy of investigative information.
57. Article 23 and the Right of Access
The right of access under Article 15 is often one of the rights most affected by restrictions.
But a restriction should not automatically mean:
"No access whatsoever."
The authority should consider whether:
-
partial access is possible;
-
redaction is possible;
-
anonymisation is possible;
-
third-party information can be removed;
-
indirect access can be provided;
-
access can be delayed rather than permanently refused.
The aim is to restrict only what is genuinely necessary.
58. Article 23 and the Right to Erasure
The right to erasure under Article 17 may also be restricted where deletion would interfere with an investigation or other protected objective.
Example
deleting investigative records at the request of a person under investigation could undermine the investigation.
However, a restriction on erasure does not automatically mean unlimited retention.
The authority must still consider:
-
why retention is required;
-
how long retention is necessary;
-
who can access the information;
-
what security measures apply;
-
when the restriction ends.
59. Article 23 and the Right to Object
The right to object under Article 21 may sometimes interfere with public-interest processing.
Example
a public authority may need to continue processing information for a regulatory investigation despite an objection.
However, legislation must specify the circumstances in which the right is restricted.
The authority cannot simply respond:
"We are a public authority, therefore Article 21 does not apply."
The legal basis and Article 23 requirements remain important.
60. Article 23 and Automated Decision-Making
Article 22 can also be restricted.
This could potentially arise in carefully regulated public-interest contexts involving automated systems.
However, restrictions concerning automated decision-making require particular caution because automated systems may produce:
-
discrimination;
-
inaccurate outcomes;
-
opaque decisions;
-
significant effects on individuals.
Any restriction should therefore be accompanied by safeguards capable of protecting individuals against serious automated decision-making risks.
61. Article 23 and Personal Data Breach Notification
Article 34 is expressly included within Article 23.
This means that legislation can, in appropriate circumstances, restrict the obligation to communicate a personal data breach to affected individuals.
Example
immediate notification could potentially prejudice:
-
a criminal investigation;
-
national security;
-
public security.
But the restriction must still be necessary and proportionate.
The existence of a security incident does not automatically justify withholding notification indefinitely.
62. Emergency Situations and Article 23
Article 23 is especially relevant during emergencies.
However:
Emergency does not equal exemption.
An emergency may justify a restriction only where the specific legal requirements are satisfied.
A government should still consider:
-
necessity;
-
duration;
-
scope;
-
safeguards;
-
review;
-
transparency;
-
eventual restoration of rights.
Temporary extraordinary circumstances should not automatically become permanent reductions in fundamental rights.
63. The Importance of Sunset and Review Mechanisms
Where a restriction responds to a temporary situation, legislation should ideally provide:
-
an expiry date;
-
periodic review;
-
conditions for renewal;
-
criteria for lifting the restriction.
This helps prevent emergency measures from becoming permanent by inertia.
Even where the legislation does not contain a fixed sunset clause, the restriction should remain subject to necessity and proportionality.
64. Practical Compliance Framework for Controllers
A controller confronted with a potentially restricted data-subject request should follow a structured process.
Step 1 - Identify the right
Determine whether the request concerns:
-
Articles 12, 22;
-
Article 34; or
-
an Article 5 principle corresponding to those provisions.
Step 2 - Identify the legislative measure
Determine the precise Union or Member State law authorising the restriction.
Step 3 - Identify the objective
Determine whether the measure relies on:
-
national security;
-
defence;
-
public security;
-
criminal justice;
-
general public interest;
-
judicial independence;
-
professional ethics;
-
regulatory functions;
-
rights of others; or
-
civil-law enforcement.
Step 4 - Determine the precise scope
Identify exactly what information or right is being restricted.
Step 5 - Conduct necessity assessment
Ask:
Is the restriction genuinely necessary?
Step 6 - Consider less intrusive alternatives
Ask:
Can the same objective be achieved through redaction, partial disclosure, delay or another measure?
Step 7 - Conduct proportionality assessment
Ask:
Is the interference with the individual's rights proportionate to the public interest being protected?
Step 8 - Apply safeguards
Implement appropriate technical and organisational protections.
Step 9 - Determine notification
Assess whether the individual can be informed about the restriction.
Step 10 - Review
Set a review date and determine when the restriction should end.
Step 11 - Document
Record the reasoning and evidence supporting the restriction.
65. A Useful Article 23 Legal Test
Article 23 can ultimately be understood through the following sequence:
1. Is there a legislative measure?
2. Does it restrict a right or obligation covered by Article 23?
3. Is the measure aimed at one of the exhaustive Article 23(1)(a) - (j) objectives?
4. Does it respect the essence of the fundamental right?
5. Is the restriction necessary?
6. Is it proportionate?
7. Are less intrusive alternatives inadequate?
8. Does the legislation contain the safeguards required by Article 23(2)?
9. Are individuals informed unless notification would prejudice the objective?
10. Is the restriction periodically reviewed and lifted when no longer justified?
Only where these requirements are satisfactorily addressed can an Article 23 restriction be considered legally robust.
66. Key Legal Principle: Article 23 Restricts Rights, Not the Rule of Law
The deepest principle underlying Article 23 is that fundamental rights may sometimes be restricted, but the State remains bound by law when doing so.
Article 23 therefore does not represent a conflict between "security" and "privacy" in which one must simply defeat the other.
Instead, it creates a framework for reconciliation.
The State may protect:
-
national security;
-
public security;
-
criminal investigations;
-
taxation;
-
public health;
-
judicial proceedings;
-
professional ethics;
-
other persons' rights.
But it must do so through:
-
law;
-
precision;
-
necessity;
-
proportionality;
-
safeguards;
-
accountability;
-
review.
67. Article 23 and the Principle of Minimum Interference
A particularly important principle emerging from Article 23 is:
Restrict no more of the individual's rights than is necessary to achieve the protected objective.
If only one category of information creates a risk, restrict that category.
If only one right needs to be restricted, do not restrict several.
If the restriction is necessary for three months, do not automatically continue it for three years.
If redaction is sufficient, do not impose complete secrecy.
If indirect access is sufficient, do not necessarily deny access altogether.
This principle transforms proportionality from an abstract constitutional concept into a practical compliance requirement.
68. The Difference Between Restriction and Denial
This distinction is especially important.
A restriction means the right continues to exist but its exercise is limited.
A denial may effectively destroy the right.
Article 23 generally contemplates restrictions rather than wholesale destruction of rights.
Therefore, legislation and controllers should ask:
"What is the minimum interference necessary?"
rather than:
"How can we prevent the person from exercising the right?"
This difference captures the rights-protective character of Article 23.
69. Final Assessment
Article 23 is best understood as a strictly controlled derogation mechanism.
It recognises that data protection must sometimes coexist with powerful competing interests such as:
-
national security;
-
defence;
-
public safety;
-
criminal justice;
-
taxation;
-
public health;
-
social security;
-
judicial independence;
-
professional regulation;
-
protection of other individuals;
-
civil litigation.
However, Article 23 does not give governments or controllers an open-ended discretion to restrict GDPR rights.
The architecture of the provision imposes multiple safeguards.
First, there must be a legislative measure.
Second, the restriction must concern a right or obligation falling within the limited material scope of Article 23.
Third, it must pursue one of the exhaustively identified objectives.
Fourth, it must respect the essence of fundamental rights and freedoms.
Fifth, it must be necessary.
Sixth, it must be proportionate.
Seventh, the legislation must, where relevant, provide detailed safeguards concerning:
-
purposes;
-
categories of data;
-
scope;
-
safeguards against abuse;
-
controllers;
-
retention;
-
risks;
-
notification.
Finally, the restriction should not survive beyond the circumstances that justify it.
The most important conceptual point is therefore:
Article 23 does not transform data-subject rights into optional rights. It permits narrowly tailored restrictions on those rights where a democratically enacted legal measure is genuinely required to protect an important and legally recognised public or private interest.
The provision consequently represents a balance between effective governance and fundamental-rights protection. It accepts that privacy and data protection cannot always prevail absolutely, but equally rejects the proposition that public interests automatically override individual data-protection rights.
70. Article 23 - Exam/Practice-Oriented Summary
For practical analysis, Article 23 can be remembered through the formula:
L-S-O-E-N-P-S
L, Legislative measure There must be a legal measure authorising the restriction.
S, Scope Only specified GDPR rights and obligations can be restricted.
O, Objective The restriction must pursue one of the Article 23(1)(a), (j) objectives.
E, Essence The essence of fundamental rights must remain intact.
N, Necessity The restriction must genuinely be necessary.
P, Proportionality It must not go beyond what is required.
S, Safeguards Article 23(2) safeguards must structure the restriction.
This gives Article 23 its central constitutional character:
Lawful restriction, not unrestricted exemption.
71. Conclusion
Article 23 occupies a distinctive position within the GDPR. Most provisions of the GDPR are designed to strengthen individual control over personal data; Article 23 recognises circumstances in which that control may legitimately have to yield, at least temporarily or partially, to other compelling interests.
But that yielding is conditional.
A State cannot invoke "national security", "public interest", "criminal investigation", "taxation", "public health" or another Article 23 objective merely as a label. The State must establish a genuine connection between the objective and the restriction. It must legislate clearly, define the affected processing and data, identify the controllers, establish safeguards, assess risks, preserve the essence of fundamental rights, and demonstrate necessity and proportionality.
For controllers, Article 23 therefore should never be treated as a simple refusal mechanism. It is a structured legal test.
The proper question is not:
"Can we refuse the data subject's request?"
It is:
"What precise restriction is authorised by law, why is it necessary, how far can it legitimately extend, what safeguards apply, and when must the individual's right be restored?"
That is the core logic of Article 23 GDPR.