Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Consumer Privacy Rights

Right to Restriction

Also known as: Right to restrict processing, Right of restriction, Restriction of processing, Article 18 GDPR right
Simply put

The right to restriction lets individuals ask an organisation to limit how it uses their personal data in certain situations, rather than deleting the data entirely. When processing is restricted, the organisation may generally continue to store the data but must stop actively using it, at least while the restriction applies. It typically comes into play when someone has a specific reason, such as questioning whether their data is accurate or objecting to how it is used.

Formal definition

Under Article 18 of the GDPR (and the equivalent UK GDPR provision), the right to restriction of processing entitles a data subject to obtain from the controller a limitation on the processing of their personal data where one of the specified grounds applies, including where the data subject disputes the accuracy of the data, or has objected to processing pending verification. In practice, restriction operates as a temporary limitation on the controller's use of the data, typically implemented by flagging, isolating, or otherwise marking records so that they may be stored but not otherwise processed except in limited circumstances. This entry addresses the general framework of the right; the specific grounds, exceptions, permitted processing during restriction, and the interaction with other rights (such as rectification, erasure, and the right to object) depend on the applicable statutory provisions and supervisory authority guidance in the relevant jurisdiction, which readers should consult directly. The scope described here reflects EU and UK data protection law and should not be assumed to apply identically under other regimes.

Why it matters

The right to restriction gives individuals a middle path between leaving their data fully in use and having it erased. This matters because there are situations, such as when someone disputes whether their data is accurate or has objected to how it is used, where deletion is not the appropriate remedy but continued active use would be premature or unfair. Under the GDPR and UK GDPR, restriction allows an organisation to preserve the data while pausing its use pending resolution, which protects both the individual's interests and the organisation's ability to retain records it may still need.

For organisations, handling restriction requests correctly is part of respecting data subject rights and demonstrating accountability to supervisory authorities. Failing to act on a valid restriction request, or continuing to process restricted data outside the limited permitted circumstances, may expose an organisation to complaints and regulatory scrutiny. Because the right typically arises alongside other rights, such as rectification and the right to object, a request framed as one may in practice trigger restriction obligations as well.

The practical weight of this right varies by jurisdiction. It reflects EU and UK data protection law, and the specific grounds, exceptions, and permitted processing during a restriction depend on the applicable statutory provisions and supervisory authority guidance. Organisations should not assume the framework described here applies identically under other regimes, and should consult the relevant law and guidance directly when responding to a request.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for handling data subject rights need clear procedures for recognising a restriction request, applying the appropriate ground, and implementing the limitation, often by flagging or isolating records. Because a request may arise alongside a dispute over accuracy or an objection to processing, they should be prepared to identify when restriction obligations are triggered even where the individual has not used that exact term.
Legal counsel and compliance teams
Legal and compliance staff advise on the specific grounds, exceptions, and permitted processing during a restriction, which depend on the applicable statutory provisions and supervisory authority guidance in the relevant jurisdiction. They also assess how the right interacts with related rights such as rectification, erasure, and the right to object, and should confirm the framework for regimes beyond the EU and UK rather than assuming it applies identically.
Web developers and systems teams
Implementing restriction typically requires technical means to mark records so that data can be stored but not actively processed. Developers and systems teams may need to build capabilities to flag, isolate, or otherwise segregate restricted records and to ensure downstream systems do not continue using data that is subject to a restriction.
Marketing and analytics teams
Where an individual's data is subject to restriction, teams that rely on that data for marketing or analytics must generally stop using it while the restriction applies, subject to the limited exceptions in the applicable law. Understanding when data has been restricted helps avoid continued processing that could give rise to complaints or regulatory scrutiny.

Inside Right to Restriction

Statutory Basis (GDPR Article 18)
The right to restriction of processing is established under Article 18 of the GDPR, allowing data subjects in the EU to require that a controller limit its processing of their personal data in specified circumstances rather than erasing it. Equivalent or analogous rights may exist in other regimes, but scope and terminology can differ, so this entry focuses on the EU/GDPR framing.
Grounds for Invoking Restriction
Restriction may generally be requested where the accuracy of the data is contested (pending verification), where processing is unlawful but the data subject prefers restriction to erasure, where the controller no longer needs the data but the data subject needs it for legal claims, or where an objection to processing is pending a balancing assessment. The applicability of each ground depends on the specific facts.
Effect on Processing
When restriction applies, personal data may typically be stored but not otherwise processed without the data subject's consent, except for the establishment, exercise, or defence of legal claims, the protection of another person's rights, or reasons of important public interest, as set out in the GDPR.
Relationship to Cookies and Tracking
In the cookie consent context, restriction can be relevant where personal data collected via cookies, pixels, SDKs, or similar technologies is contested or unlawfully processed. Restriction concerns the subsequent processing of that data under the GDPR; it is distinct from the ePrivacy rules governing the initial placing of or access to information on a device, and from the withdrawal of cookie consent itself.
Notification and Lifting of Restriction
Controllers are generally expected to inform the data subject before a restriction is lifted, and, where feasible, to communicate the restriction to recipients to whom the data was disclosed. The practical mechanics depend on the controller's systems and record-keeping.
Scope and Limitations
This entry describes the general GDPR framework and does not resolve fact-specific questions, such as whether a particular ground applies, how a balancing test should be decided, or how restriction interacts with technologies that are difficult to isolate. Enforcement positions and DPA guidance continue to evolve.

Common questions

Answers to the questions practitioners most commonly ask about Right to Restriction.

Is the right to restriction the same as the right to erasure?
No. The right to restriction (under Article 18 of the GDPR) and the right to erasure (under Article 17) are distinct. Erasure results in personal data being deleted, whereas restriction generally means the data is retained but its processing is limited, typically so that the controller may store the data but not otherwise use it without the data subject's consent or another lawful basis. Restriction is often a temporary or interim measure, for example while the accuracy of data is being verified or while a competing claim is assessed, rather than a permanent removal. The two rights may apply in different circumstances, and a request for one does not automatically trigger the other.
Does restricting processing mean a controller must delete or stop storing the data?
No. Restriction generally requires the controller to limit how personal data is processed, but continued storage of the data is typically permitted and is often the point of the exercise. Under the GDPR, where processing is restricted, personal data may usually still be stored, and further processing is generally allowed only with the data subject's consent, for the establishment or defence of legal claims, for the protection of another person's rights, or for reasons of important public interest. Restriction is therefore closer to placing data on hold than to erasing it. This entry does not address how any specific data protection authority interprets the boundaries of permitted storage in contested cases.
How can restriction of processing be implemented technically?
Common approaches include temporarily moving the affected data to a separate system, making it inaccessible to users or applications, or applying flags or markers that block further processing while preserving the record. The GDPR does not prescribe a single method, so the appropriate technical measure generally depends on the systems involved and the reason for the restriction. Whichever method is used, it should reliably prevent the restricted data from being used for anything beyond permitted purposes. The suitability of any particular technique is a factual and organizational judgment that falls outside the scope of this definition.
In the cookie and tracking context, when might a restriction request arise?
A restriction request may arise where personal data has been collected through cookies, pixels, SDKs, or similar technologies and the data subject contests its accuracy or objects to its processing, or where processing may be unlawful but the individual prefers restriction over erasure. In such cases the underlying data held about the individual may need to be placed on hold rather than actively used for analytics or advertising. Whether and how the ePrivacy rules on placing or accessing information on a device interact with a GDPR restriction request depends on the facts, and this entry does not resolve that interaction.
Should a controller notify anyone when a restriction is lifted?
Under the GDPR, a data subject who obtained a restriction of processing must generally be informed by the controller before the restriction is lifted. Separately, the controller is generally required to communicate any restriction of processing to each recipient to whom the personal data has been disclosed, unless this proves impossible or involves disproportionate effort. The precise scope of these notification duties can depend on the circumstances, and this entry does not cover how they apply to particular recipient relationships.
How should a controller document and log a restriction request?
As a general matter of accountability under the GDPR, controllers should be able to demonstrate how they handled a restriction request, including when it was received, the basis on which restriction was applied, the technical measures taken, any communications to recipients, and when the restriction was lifted. Maintaining such records supports the ability to respond to the data subject and to any inquiry from a supervisory authority. This entry does not prescribe a specific retention period or format, and record-keeping practices should be assessed against the applicable framework and any relevant guidance.

Common misconceptions

The right to restriction is the same as the right to erasure (right to be forgotten).
They are distinct rights under the GDPR. Restriction generally means the data is retained but its processing is limited, whereas erasure means the data is deleted. A data subject may choose restriction over erasure in some situations, for example where they need the data preserved for legal claims.
Withdrawing cookie consent automatically triggers a right to restriction.
Withdrawing consent and requesting restriction are separate mechanisms. Withdrawal stops future consent-based processing, while restriction under Article 18 applies only on specific grounds. The ePrivacy rules on placing cookies and the GDPR rights over the resulting personal data operate on different legal bases and should not be conflated.
Restriction obligations are identical across all jurisdictions.
The right to restriction as described here derives from the GDPR and applies in the EU (with a comparable UK equivalent). Other regimes, including individual US state privacy laws such as the CCPA/CPRA, structure data subject rights differently and may not offer an identical restriction right. Always confirm the applicable legal scope.

Best practices

Build a documented intake and handling process for restriction requests, including how to verify the requester's identity and which GDPR ground is being relied upon.
Implement technical means to flag or segregate restricted personal data so it can be stored without being further processed, and ensure this covers data collected through cookies, pixels, SDKs, and similar technologies.
Keep clear records of restriction requests, the grounds invoked, actions taken, and the date restriction was applied or lifted, in line with GDPR accountability and record-keeping expectations.
Notify the data subject before lifting a restriction, and, where feasible, communicate the restriction to any recipients to whom the relevant data was disclosed.
Coordinate restriction handling with consent withdrawal and objection workflows in your CMP and downstream systems, recognising these are distinct mechanisms with different triggers.
Seek legal review for fact-specific or contested cases, since determining whether a ground applies or how a balancing test resolves depends on facts beyond the definition and on evolving DPA guidance.
Promotional banner for the Pentest Readiness checklist download