A rigorous examination of one of the GDPR's most misunderstood and frequently misapplied provisions — the constitutional balancing mechanism between data protection rights and broader public interests.
GDPR Article 23 is one of the most misunderstood and frequently misapplied provisions within the GDPR. Unlike most GDPR provisions, which expand transparency and data subject rights, Article 23 permits the restriction of certain obligations and rights when justified by Union or Member State law.
The European Data Protection Board (EDPB) has emphasised that Article 23 restrictions are exceptional measures and must be interpreted narrowly. A lawful restriction requires all of the following:
A specific, formal Union or Member State legal measure — not internal policy or controller discretion.
A recognised safeguarding objective as enumerated in Article 23(1).
Demonstrable need — mere convenience is wholly insufficient.
The least intrusive measure must be selected, with limited scope and duration.
Fundamental rights and freedoms must not be extinguished — only limited or delayed.
Article 23 creates a constitutional balancing mechanism between competing interests recognised under EU and Member State law. It acknowledges that unrestricted transparency and individual rights may, in specific circumstances, undermine broader societal interests.
Transparency, access, rectification, erasure, portability, and the full suite of data subject rights enshrined in the GDPR.
Consequently, legislators — not controllers — may restrict specific GDPR obligations and rights where necessary to protect broader societal interests. The provision is a legislative tool, not an administrative convenience.
This architectural understanding is foundational: Article 23 operates at the level of law-making, not at the level of organisational policy or controller discretion.
A restriction is lawful only when all of the following conditions are simultaneously satisfied. The EDPB repeatedly emphasises that controllers must be able to evidence necessity and proportionality through documented analysis.
Internal policy, controller discretion, and contractual provisions are all insufficient. A formal Union or Member State legal measure is required.
Restrictions cannot destroy the right itself. Rights may be delayed, limited, or partially withheld — but never extinguished entirely.
There must be a demonstrated, evidenced need. Mere convenience, operational burden, or preference is wholly insufficient.
The least intrusive measure must be selected. Scope and duration must be limited to what is strictly necessary.
The restriction must pursue one of the specific objectives enumerated in Article 23(1) — no other objectives qualify.
Article 23(1) permits restrictions only for specific, enumerated objectives. Controllers and legislators cannot expand this list. The following represent the recognised categories:

Article 23 permits restrictions affecting a defined set of GDPR provisions. Critically, Article 5 principles may only be restricted insofar as they correspond to the rights and obligations listed below.
Transparent communications to data subjects
Information when data are collected directly
Information when data are obtained indirectly
Right of access
Right to rectification
Right to erasure
Right to restriction of processing
Notification obligations
Data portability
Right to object
Automated decision-making protections
Notification of personal data breaches to data subjects
Core principles — but only insofar as they correspond to the above rights and obligations
The EDPB stresses that Article 23 should not be interpreted as a general suspension mechanism for GDPR compliance. Certain rights and obligations remain beyond the reach of Article 23 restrictions.
Data subjects retain the right to lodge a complaint with a supervisory authority regardless of any Article 23 restriction.
Access to courts and effective judicial remedies cannot be extinguished through Article 23 legislative measures.
The investigative, corrective, and advisory powers of supervisory authorities remain intact.
Core GDPR governance requirements and accountability obligations generally cannot be suspended.
The fundamental right to data protection itself — as enshrined in Article 8 of the EU Charter — cannot be extinguished.
Article 23(2) imposes specific requirements on the legislation that authorises restrictions. These elements create a statutory accountability framework rather than permitting unrestricted government discretion. Legislation that fails to address these elements may itself be challengeable.
The legislation must specify the purposes for which restricted processing occurs.
The categories of personal data subject to restriction must be identified.
The extent and nature of the restrictions must be clearly defined.
Protective measures preventing misuse of the restriction must be specified.
The identity or categories of controllers authorised to apply restrictions must be stated.
Retention periods for restricted data must be defined.
The legislation must address risks to data subjects' rights and freedoms.
Rights of data subjects to be informed about restrictions, where appropriate, must be addressed.
The following scenarios illustrate circumstances in which Article 23 restrictions may be lawfully applied. Each example demonstrates the necessity of legislative grounding, proportionality, and temporal limitation.
A suspect requests access to all investigative records. Immediate disclosure would reveal witness identities, investigative techniques, and ongoing surveillance operations.
Outcome: Access rights temporarily restricted, supported by criminal procedure legislation. Restriction lifted when investigation risk subsides. Generally consistent with Article 23.
A bank receives a subject access request. Disclosure would reveal suspicious transaction monitoring and alert the subject to the investigation.
Outcome: Access delayed or partially restricted, grounded in AML legislation. Potentially justified under Article 23.
A financial regulator investigates market abuse. The data subject seeks access to investigative material that would compromise the ongoing enforcement action.
Outcome: Temporary withholding justified by supervision and enforcement objectives. Potentially lawful under Article 23.
The following scenarios illustrate circumstances in which purported Article 23 restrictions are unlawful. These examples represent common misapplications encountered in practice.
An organisation receives large numbers of access requests and claims operational burden as justification for restriction.
Analysis: Not necessary. Not proportionate. Not supported by legislation. No Article 23 objective exists.
Result: Non-compliant.
A controller refuses disclosure because the information may embarrass the organisation or expose internal failings.
Analysis: Reputational protection is not an Article 23(1) objective. No legislative basis exists for this restriction.
Result: Restriction unlawful.
A government agency permanently denies all access requests across all categories of data subject without case-by-case assessment.
Analysis: Violates the essence of rights. Fails the proportionality test. Fails the necessity test. Fails the temporality requirement.
Result: Non-compliant.
Article 23 does not operate in isolation. The following GDPR provisions intersect directly with Article 23 and must be considered holistically when designing and implementing restriction frameworks.
Core principles — lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity, confidentiality, accountability.
Restriction does not create a lawful basis for processing — these are separate legal questions.
Governance obligations remain in full force — restrictions do not suspend accountability.
Restrictions must be engineered into systems — data protection by design applies.
Restriction rationale should be documented in records of processing activities.
DPIAs are often necessary where restrictions are systemic or large-scale.
Mature Article 23 compliance programmes operationalise restrictions through governance, engineering controls, auditability, and periodic review. The following twenty controls represent the advanced practitioner standard.
Central inventory of all legislative measures relied upon, mapping each restriction to applicable law.
Formal documented test demonstrating why each restriction is needed — not merely convenient.
Demonstrates that the least intrusive option has been selected, with limited scope and duration.
Legal review required before any restriction is implemented — no unilateral controller decisions.
Multidisciplinary oversight body providing independent review of restriction decisions.
Immutable record of all restriction decisions, including rationale, legal basis, and review dates.
Technical controls managing restricted disclosures dynamically based on case status.
ABAC restricts information access based on investigation status and authorisation level.
Segregates restricted records from ordinary records to prevent inadvertent disclosure.
Tags datasets subject to Article 23 limitations to enable automated handling.
Ensures restrictions are not perpetual — automated expiry triggers mandatory review.
Periodic reassessment of necessity and proportionality at defined intervals.
Tamper-evident logging of all restriction-related activities and decisions.
Mandatory Article 23 review embedded within the DPIA process for systemic restrictions.
Identifies all affected personal data categories and their restriction status.
Stores legal justifications, necessity assessments, and proportionality analyses securely.
Automates lawful handling of restricted requests, ensuring consistent and documented responses.
Supports regulator inspection and access despite operational restrictions being in place.
Tracks number of restrictions, duration, legal basis relied upon, and reviews completed.
Periodic testing of necessity, proportionality, accuracy, expiry mechanisms, and documentation quality.
The following principles represent the distilled guidance for practitioners operating at the advanced level of Article 23 compliance. These are the standards against which supervisory authorities and courts will assess restriction programmes.
Article 23 is fundamentally a constitutional limitation provision. Controllers cannot create Article 23 restrictions through policy — legislative authorisation is essential and non-negotiable.
Necessity and proportionality are continuing obligations. Every restriction should be viewed as temporary unless legislation clearly justifies a longer duration. Periodic reassessment is mandatory.
The strongest Article 23 compliance programmes operationalise restrictions through governance structures, engineering controls, auditability, and periodic review — not solely through legal interpretation.
Mature organisations treat Article 23 restrictions as requiring evidence, traceability, oversight, and demonstrable safeguards capable of withstanding supervisory authority scrutiny and judicial review.
The measure of an advanced Article 23 compliance programme is not whether restrictions are applied — it is whether every restriction applied can be evidenced, justified, reviewed, and defended before a supervisory authority or court of law.
GDPR Article 23 - Restrictions: