Article 23 GDPR: Restrictions on Data Subject Rights and Processing
1. What Article 23 Says
Article 23 GDPR allows Union or Member State law to restrict the scope of obligations and rights under GDPR by way of legislative measures (not just ad hoc decisions).
Such restrictions must:
- Respect the essence of fundamental rights and freedoms; and
- Be a necessary and proportionate measure in a democratic society.
2. Who Can Impose Restrictions?
- Member States or the EU → through laws, regulations, or directives, not through arbitrary controller policies.
- Controllers alone cannot invent restrictions. They must act under a legal basis granted by Union or Member State law.
So:
- A controller cannot simply “restrict†processing or deny rights unless a specific law allows it.
- A Member State can restrict processing rights through legislation, for example national security laws, tax investigations, or criminal investigations.
3. Legitimate Grounds for Restriction (Art. 23(1))
Restrictions may be imposed for reasons such as:
- National security, defence, or public security.
- Prevention, investigation, detection, or prosecution of criminal offences.
- Important objectives of general public interest (e.g., economic or financial stability).
- Protection of judicial independence or legal proceedings.
- Protection of data subjects or rights of others.
- Enforcement of civil law claims.
4. Examples
- Anti-Money Laundering (AML): National law may restrict the right of access so that suspects are not tipped off.
- Police Investigations: A Member State may restrict data subjects' right to erasure or access while an investigation is ongoing.
- Tax Authority: Access rights may be restricted to protect the integrity of tax audits.
- National Security: Member State laws may permit intelligence agencies to process data outside some GDPR rights.
5. Safeguards (Art. 23(2))
Any restriction law must include:
- Purpose of processing.
- Categories of personal data.
- Scope of restriction.
- Safeguards to prevent abuse.
- Controller categories involved.
- Retention periods.
- Risks to rights and freedoms.
- Data subject's right to be informed (unless it risks the objective of the restriction).
✅ Conclusion
- Controllers cannot impose restrictions on their own.
- Member States or the EU can impose restrictions, but only through law or directive, and only where necessary, proportionate, and respectful of fundamental rights.
- Article 23 is essentially the “lawful derogation†tool of GDPR — balancing privacy rights against other vital state or societal interests.