|

Restriction Of Processing Under Article 18

Restriction of processing is the right candidates skip. It sits in Article 18 of the GDPR, between erasure and objection. The data stays where it is. Your use of it stops.

That combination is the whole point. Deleting data can destroy the record a person needs for a claim. Sometimes nobody can yet say whether you may keep using it at all. A restriction of processing buys time and destroys nothing.

When restriction of processing applies

Article 18(1) gives four grounds and no others.

The first is a dispute about accuracy. Someone says the data is wrong, so you park it while you check.

Ground two covers unlawful processing where the person does not want deletion. The wording is precise. Processing is unlawful, the data subject opposes erasure, and asks for restriction of their use instead.

Third comes the case where your need ends before theirs. You have finished with the data. They still need you to hold it for a legal claim.

The fourth follows an objection. Someone has objected under Article 21(1). You are weighing whether your grounds override their interests.

A general request to stop using data sits outside that list. The UK regulator sets out the same four grounds in its guidance on the right to restrict processing. It is a useful cross-check when the wording of Article 18 starts to blur.

What a restriction of processing has to do

A marker in the case file restricts nothing on its own. Recital 67 of the GDPR names three ways of doing it properly:

  • temporarily moving the selected data to another processing system
  • making the selected personal data unavailable to users
  • temporarily removing published data from a website

The same recital adds the part people skip past. In automated filing systems the restriction of processing “should in principle be ensured by technical means”. The data must then be safe from further processing and from change. A flag needs a control underneath it.

What you may still do

Storage is always permitted. Article 18(2) adds four narrow exceptions to that. You may process with the person’s consent. Legal claims are covered too, whether you are establishing, exercising or defending one. The rights of another person and reasons of important public interest complete the list.

Everything else waits, including routine work nobody thinks of as processing. A marketing export counts. So does a backup restore that writes the record back into production. So does an analytics job that sweeps the whole table.

Lifting it

Article 18(3) requires you to inform the person before the restriction of processing comes off. Not afterwards, and not buried in the message that gives them the outcome.

Article 19 sits alongside it. Where you have disclosed the data to recipients, you tell each of them about the restriction. That duty falls away only where it proves impossible or involves disproportionate effort. You also name those recipients to the data subject, if they ask.

Where restriction and objection meet

Ground four is the one exam questions circle. An objection under Article 21(1) stops nothing by itself. You assess whether your legitimate grounds override the person’s interests. While you assess, the data sits under a restriction of processing.

So the two work in sequence rather than as alternatives. The restriction holds the position, then the objection gets decided. Read a scenario closely enough to see which stage it describes. A candidate who treats an objection as an instant stop will pick a plausible wrong answer, and so will one who reads a restriction as a decision on the merits. The same discipline pays off across the lawful grounds for processing.

What counts as unlawful processing

Ground two turns on the word “unlawful”, and the Court of Justice has narrowed what that word reaches. Take Case C-60/22, UZ v Bundesrepublik Deutschland, decided on 4 May 2023. The Fifth Chamber held that a failure to comply with Articles 26 and 30 confers no right to erasure or to restriction of processing by itself.

The reasoning matters more than the outcome. A missing joint controller arrangement is still a breach. So is a missing record of processing activities, and a supervisory authority can act on either. Neither one makes the underlying processing unlawful for the purposes of Article 17(1)(d) and Article 18(1)(b). The exception is a failure that also breaches the accountability principle in Article 5(2).

Hold on to that distinction. Documentation failures and lawfulness failures live in different articles, and the exam knows it.

Sitting the question

The CIPP/E Body of Knowledge, the IAPP document listing what the exam can test, puts data subjects’ rights in Domain II. Rights carry the heaviest question range there. Restriction of processing gets the least revision time of any of them.

Two habits help. Work out which of the four grounds a scenario describes before you look at the options. Then check what the question actually asks. Article 18(2) covers what you may do with the data; Article 18(3) covers what you must say to the person. Scenarios that move across borders reward the same discipline, as the piece on territorial scope sets out.

Want to know where your gaps sit before committing a fortnight to revision? The free CIPP/E assessment will tell you in about twenty minutes.

Reading the statute helps as well. The GDPR official text costs nothing, and Article 18 rewards a slow reading.

Where the questions rather than the material are the problem, the CIPP/E Exam Question Masterclass shows how the wording of an option decides the answer.

Similar Posts