Right to Restriction
The right to restriction lets individuals ask an organisation to limit how it uses their personal data in certain situations, rather than deleting the data entirely. When processing is restricted, the organisation may generally continue to store the data but must stop actively using it, at least while the restriction applies. It typically comes into play when someone has a specific reason, such as questioning whether their data is accurate or objecting to how it is used.
Under Article 18 of the GDPR (and the equivalent UK GDPR provision), the right to restriction of processing entitles a data subject to obtain from the controller a limitation on the processing of their personal data where one of the specified grounds applies, including where the data subject disputes the accuracy of the data, or has objected to processing pending verification. In practice, restriction operates as a temporary limitation on the controller's use of the data, typically implemented by flagging, isolating, or otherwise marking records so that they may be stored but not otherwise processed except in limited circumstances. This entry addresses the general framework of the right; the specific grounds, exceptions, permitted processing during restriction, and the interaction with other rights (such as rectification, erasure, and the right to object) depend on the applicable statutory provisions and supervisory authority guidance in the relevant jurisdiction, which readers should consult directly. The scope described here reflects EU and UK data protection law and should not be assumed to apply identically under other regimes.
Why it matters
The right to restriction gives individuals a middle path between leaving their data fully in use and having it erased. This matters because there are situations, such as when someone disputes whether their data is accurate or has objected to how it is used, where deletion is not the appropriate remedy but continued active use would be premature or unfair. Under the GDPR and UK GDPR, restriction allows an organisation to preserve the data while pausing its use pending resolution, which protects both the individual's interests and the organisation's ability to retain records it may still need.
For organisations, handling restriction requests correctly is part of respecting data subject rights and demonstrating accountability to supervisory authorities. Failing to act on a valid restriction request, or continuing to process restricted data outside the limited permitted circumstances, may expose an organisation to complaints and regulatory scrutiny. Because the right typically arises alongside other rights, such as rectification and the right to object, a request framed as one may in practice trigger restriction obligations as well.
The practical weight of this right varies by jurisdiction. It reflects EU and UK data protection law, and the specific grounds, exceptions, and permitted processing during a restriction depend on the applicable statutory provisions and supervisory authority guidance. Organisations should not assume the framework described here applies identically under other regimes, and should consult the relevant law and guidance directly when responding to a request.
Who it's relevant to
Inside Right to Restriction
Common questions
Answers to the questions practitioners most commonly ask about Right to Restriction.

