GDPR Article 18: right to restriction of processing
GDPR Article 18 gives a data subject the right to obtain restriction of processing in four situations listed in Article 18(1)(a) to (d). Article 18(2) limits what a controller may then do with the data, and Article 18(3) requires the controller to inform the data subject before any restriction is lifted.
Applies to: Any controller subject to the GDPR that receives a request to suspend processing, or that is holding personal data whose accuracy is disputed or whose lawfulness is in question while a decision is pending.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanRestriction is the least implemented of the GDPR rights, mostly because systems tend to have a delete button and a keep button and nothing in between. Article 18 requires exactly the thing in between: hold the data, stop using it.
Article 18(1): the four grounds
The data subject shall have the right to obtain from the controller restriction of processing where one of the following applies:
(a) the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data;
(b) the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
(c) the controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims;
(d) the data subject has objected to processing pursuant to Article 21(1) pending the verification whether the legitimate grounds of the controller override those of the data subject.
Two of these are automatic consequences of other rights rather than standalone requests. Ground (a) attaches to any accuracy dispute, so a rectification complaint carries a restriction obligation with it for the verification period. Ground (d) attaches to any Article 21(1) objection while you work out whether your legitimate grounds win.
That means a controller can owe a restriction duty without anyone having used the word restriction.
Article 18(2): what you may still do
Where processing has been restricted under paragraph 1, such personal data shall, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
Storage is carved out at the start of the sentence, which is the whole design. You keep the record. Beyond keeping it, you need one of four justifications, and ordinary business use is not among them.
Article 18(3): before you switch it back on
A data subject who has obtained restriction of processing pursuant to paragraph 1 shall be informed by the controller before the restriction of processing is lifted.
This is short and easy to miss in an implementation. Lifting a restriction is an event that requires advance notice to the person, not a silent internal state change once your investigation closes.
Why ground (b) exists
Article 18(1)(b) looks strange at first. The processing is unlawful, and the person does not want the data erased. Why would anyone choose that?
Because erasure destroys evidence. Someone who intends to complain to a supervisory authority or bring a claim may need the unlawfully processed data to still exist. Ground (c) covers the mirror image, where the controller is finished with the data but the person still needs it for legal claims and does not want it routinely deleted.
Both grounds exist to stop deletion being used, deliberately or accidentally, to end a dispute.
Restriction against erasure
The comparison people usually want is with the right to erasure. Erasure removes the data. Restriction preserves it in a frozen state. A person can often choose between them, and under Article 18(1)(b) that choice is explicitly theirs, not the controller's.
Practically, restriction is also what you fall back on when erasure is unavailable because a retention obligation applies. The data has to stay, so the answer to a person who wants it left alone is to restrict rather than to refuse.
Implementing it
The common failure is architectural rather than legal. A restriction flag that only your CRM respects is not a restriction if the nightly export, the analytics warehouse and the email platform never see it. Deciding where the flag lives, and what reads it, is the actual work.
The related objection right that feeds ground (d) is covered in Article 21, and the timescales and format rules that apply to responding to any of these requests sit in Article 12.
Compliance checklist
- Build a restriction state into your systems that is distinct from deletion, because Article 18 requires you to keep the data while not using it.
- Treat a disputed-accuracy complaint as an Article 18(1)(a) restriction trigger for the period you need to verify, not merely as a correction ticket.
- Recognise that a person can demand restriction instead of erasure where processing is unlawful, under Article 18(1)(b), and that the choice is theirs.
- Flag restricted records so that downstream jobs, exports, backups and marketing suppression lists do not process them by default.
- Notify the data subject before lifting a restriction, which Article 18(3) requires as a standalone step.
Sources
Last verified: 2026-09-10
Informational, not legal advice.