GDPR Article 23 - Restrictions:

A rigorous examination of one of the GDPR's most misunderstood and frequently misapplied provisions — the constitutional balancing mechanism between data protection rights and broader public interests.

Executive Summary

GDPR Article 23 is one of the most misunderstood and frequently misapplied provisions within the GDPR. Unlike most GDPR provisions, which expand transparency and data subject rights, Article 23 permits the restriction of certain obligations and rights when justified by Union or Member State law.

The European Data Protection Board (EDPB) has emphasised that Article 23 restrictions are exceptional measures and must be interpreted narrowly. A lawful restriction requires all of the following:

Legislative Measure

A specific, formal Union or Member State legal measure — not internal policy or controller discretion.

Legitimate Objective

A recognised safeguarding objective as enumerated in Article 23(1).

Necessity

Demonstrable need — mere convenience is wholly insufficient.

Proportionality

The least intrusive measure must be selected, with limited scope and duration.

Essence Preserved

Fundamental rights and freedoms must not be extinguished — only limited or delayed.

Purpose and Legal Architecture of Article 23

Article 23 creates a constitutional balancing mechanism between competing interests recognised under EU and Member State law. It acknowledges that unrestricted transparency and individual rights may, in specific circumstances, undermine broader societal interests.

Data Protection Rights

Transparency, access, rectification, erasure, portability, and the full suite of data subject rights enshrined in the GDPR.

Competing Public Interests

  • Criminal investigations and prosecutions
  • National security and defence
  • Judicial proceedings and independence
  • Regulatory and supervisory investigations
  • Public security and safety

Consequently, legislators — not controllers — may restrict specific GDPR obligations and rights where necessary to protect broader societal interests. The provision is a legislative tool, not an administrative convenience.

This architectural understanding is foundational: Article 23 operates at the level of law-making, not at the level of organisational policy or controller discretion.

Core Legal Test for Applying Article 23

A restriction is lawful only when all of the following conditions are simultaneously satisfied. The EDPB repeatedly emphasises that controllers must be able to evidence necessity and proportionality through documented analysis.

1

Legislative Measure Exists

Internal policy, controller discretion, and contractual provisions are all insufficient. A formal Union or Member State legal measure is required.

2

Essence of Rights Respected

Restrictions cannot destroy the right itself. Rights may be delayed, limited, or partially withheld — but never extinguished entirely.

3

Necessity Demonstrated

There must be a demonstrated, evidenced need. Mere convenience, operational burden, or preference is wholly insufficient.

4

Proportionality Applied

The least intrusive measure must be selected. Scope and duration must be limited to what is strictly necessary.

5

Legitimate Objective Pursued

The restriction must pursue one of the specific objectives enumerated in Article 23(1) — no other objectives qualify.

Legitimate Objectives Permitting Restrictions

Article 23(1) permits restrictions only for specific, enumerated objectives. Controllers and legislators cannot expand this list. The following represent the recognised categories:

Rights and Obligations That May Be Restricted

Article 23 permits restrictions affecting a defined set of GDPR provisions. Critically, Article 5 principles may only be restricted insofar as they correspond to the rights and obligations listed below.

Transparency & Information Rights

Article 12

Transparent communications to data subjects

Article 13

Information when data are collected directly

Article 14

Information when data are obtained indirectly

Individual Rights

Article 15

Right of access

Article 16

Right to rectification

Article 17

Right to erasure

Article 18

Right to restriction of processing

Further Rights & Obligations

Article 19

Notification obligations

Article 20

Data portability

Article 21

Right to object

Article 22

Automated decision-making protections

Article 34

Notification of personal data breaches to data subjects

Article 5

Core principles — but only insofar as they correspond to the above rights and obligations

Rights That Cannot Normally Be Restricted Through Article 23

The EDPB stresses that Article 23 should not be interpreted as a general suspension mechanism for GDPR compliance. Certain rights and obligations remain beyond the reach of Article 23 restrictions.

Right to Lodge a Complaint

Data subjects retain the right to lodge a complaint with a supervisory authority regardless of any Article 23 restriction.

Effective Judicial Remedy

Access to courts and effective judicial remedies cannot be extinguished through Article 23 legislative measures.

Supervisory Authority Powers

The investigative, corrective, and advisory powers of supervisory authorities remain intact.

Accountability Obligations

Core GDPR governance requirements and accountability obligations generally cannot be suspended.

Fundamental Right to Data Protection

The fundamental right to data protection itself — as enshrined in Article 8 of the EU Charter — cannot be extinguished.

Required Elements of the Legislative Measure

Article 23(2) imposes specific requirements on the legislation that authorises restrictions. These elements create a statutory accountability framework rather than permitting unrestricted government discretion. Legislation that fails to address these elements may itself be challengeable.

01

Purposes of Processing

The legislation must specify the purposes for which restricted processing occurs.

02

Categories of Personal Data

The categories of personal data subject to restriction must be identified.

03

Scope of Restrictions

The extent and nature of the restrictions must be clearly defined.

04

Safeguards Against Abuse

Protective measures preventing misuse of the restriction must be specified.

05

Identity of Controllers

The identity or categories of controllers authorised to apply restrictions must be stated.

06

Storage Periods

Retention periods for restricted data must be defined.

07

Risks to Rights and Freedoms

The legislation must address risks to data subjects' rights and freedoms.

08

Information Rights Regarding Restrictions

Rights of data subjects to be informed about restrictions, where appropriate, must be addressed.

Examples of Appropriate Article 23 Restrictions

The following scenarios illustrate circumstances in which Article 23 restrictions may be lawfully applied. Each example demonstrates the necessity of legislative grounding, proportionality, and temporal limitation.

Active Criminal Investigation

A suspect requests access to all investigative records. Immediate disclosure would reveal witness identities, investigative techniques, and ongoing surveillance operations.

Outcome: Access rights temporarily restricted, supported by criminal procedure legislation. Restriction lifted when investigation risk subsides. Generally consistent with Article 23.

Anti-Money Laundering Investigation

A bank receives a subject access request. Disclosure would reveal suspicious transaction monitoring and alert the subject to the investigation.

Outcome: Access delayed or partially restricted, grounded in AML legislation. Potentially justified under Article 23.

Regulatory Enforcement

A financial regulator investigates market abuse. The data subject seeks access to investigative material that would compromise the ongoing enforcement action.

Outcome: Temporary withholding justified by supervision and enforcement objectives. Potentially lawful under Article 23.

Examples of Inappropriate Article 23 Restrictions

The following scenarios illustrate circumstances in which purported Article 23 restrictions are unlawful. These examples represent common misapplications encountered in practice.

Administrative Convenience

An organisation receives large numbers of access requests and claims operational burden as justification for restriction.

Analysis: Not necessary. Not proportionate. Not supported by legislation. No Article 23 objective exists.

Result: Non-compliant.

Reputational Protection

A controller refuses disclosure because the information may embarrass the organisation or expose internal failings.

Analysis: Reputational protection is not an Article 23(1) objective. No legislative basis exists for this restriction.

Result: Restriction unlawful.

Blanket Access Denial

A government agency permanently denies all access requests across all categories of data subject without case-by-case assessment.

Analysis: Violates the essence of rights. Fails the proportionality test. Fails the necessity test. Fails the temporality requirement.

Result: Non-compliant.

Key Intersecting GDPR Articles

Article 23 does not operate in isolation. The following GDPR provisions intersect directly with Article 23 and must be considered holistically when designing and implementing restriction frameworks.

Foundational Provisions

Article 5

Core principles — lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity, confidentiality, accountability.

Article 6

Restriction does not create a lawful basis for processing — these are separate legal questions.

Article 24

Governance obligations remain in full force — restrictions do not suspend accountability.

Article 25

Restrictions must be engineered into systems — data protection by design applies.

Article 30

Restriction rationale should be documented in records of processing activities.

Article 35

DPIAs are often necessary where restrictions are systemic or large-scale.

Rights Articles Most Commonly Affected

Twenty Cross-Cutting and Technical Controls for Article 23 Compliance

Mature Article 23 compliance programmes operationalise restrictions through governance, engineering controls, auditability, and periodic review. The following twenty controls represent the advanced practitioner standard.

1

Restriction Legal Basis Register

Central inventory of all legislative measures relied upon, mapping each restriction to applicable law.

2

Necessity Assessment Framework

Formal documented test demonstrating why each restriction is needed — not merely convenient.

3

Proportionality Assessment Framework

Demonstrates that the least intrusive option has been selected, with limited scope and duration.

4

Restriction Approval Workflow

Legal review required before any restriction is implemented — no unilateral controller decisions.

5

Restriction Governance Committee

Multidisciplinary oversight body providing independent review of restriction decisions.

1

Restriction Decision Logging

Immutable record of all restriction decisions, including rationale, legal basis, and review dates.

2

Rights Suppression Engine

Technical controls managing restricted disclosures dynamically based on case status.

3

Attribute-Based Access Control

ABAC restricts information access based on investigation status and authorisation level.

4

Case-Based Access Segmentation

Segregates restricted records from ordinary records to prevent inadvertent disclosure.

5

Restriction Metadata Tagging

Tags datasets subject to Article 23 limitations to enable automated handling.

1

Automated Restriction Expiry

Ensures restrictions are not perpetual — automated expiry triggers mandatory review.

2

Restriction Review Scheduler

Periodic reassessment of necessity and proportionality at defined intervals.

3

Audit Trail Integrity Controls

Tamper-evident logging of all restriction-related activities and decisions.

4

DPIA Integration Control

Mandatory Article 23 review embedded within the DPIA process for systemic restrictions.

5

Data Inventory Mapping

Identifies all affected personal data categories and their restriction status.

1

Secure Evidence Repository

Stores legal justifications, necessity assessments, and proportionality analyses securely.

2

Rights Request Orchestration

Automates lawful handling of restricted requests, ensuring consistent and documented responses.

3

Supervisory Authority Disclosure Procedure

Supports regulator inspection and access despite operational restrictions being in place.

4

Restriction Metrics Dashboard

Tracks number of restrictions, duration, legal basis relied upon, and reviews completed.

5

Independent Compliance Testing

Periodic testing of necessity, proportionality, accuracy, expiry mechanisms, and documentation quality.

Advanced Points

The following principles represent the distilled guidance for practitioners operating at the advanced level of Article 23 compliance. These are the standards against which supervisory authorities and courts will assess restriction programmes.

Constitutional Limitation, Not Controller Exemption

Article 23 is fundamentally a constitutional limitation provision. Controllers cannot create Article 23 restrictions through policy — legislative authorisation is essential and non-negotiable.

Ongoing Obligations, Not One-Time Assessments

Necessity and proportionality are continuing obligations. Every restriction should be viewed as temporary unless legislation clearly justifies a longer duration. Periodic reassessment is mandatory.

Operationalise Through Governance and Engineering

The strongest Article 23 compliance programmes operationalise restrictions through governance structures, engineering controls, auditability, and periodic review — not solely through legal interpretation.

Treat Restrictions as a Specialised Accountability Domain

Mature organisations treat Article 23 restrictions as requiring evidence, traceability, oversight, and demonstrable safeguards capable of withstanding supervisory authority scrutiny and judicial review.

The measure of an advanced Article 23 compliance programme is not whether restrictions are applied — it is whether every restriction applied can be evidenced, justified, reviewed, and defended before a supervisory authority or court of law.

Datari Home