Right to Restrict Processing and Right to Object: GDPR Articles 18 and 21
Last updated July 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
The right to restrict processing (Article 18 of the GDPR) lets a person tell you to pause what you do with their data without deleting it, so you may store it but not otherwise use it. The right to object (Article 21) lets a person challenge processing you base on legitimate interests or a public task, and gives them an absolute, no-questions veto over direct marketing. They are the two data subject rights teams handle worst, because both ask you to change how a system behaves rather than just hand over a copy. Here is what each one requires, and how they connect.
General information, not legal advice. These rights turn on your lawful basis and the specific facts, so take advice where a case is close.
What the right to restrict processing means
Restriction is a pause button. When it applies, you can keep storing the personal data, but you cannot otherwise process it, with narrow exceptions: with the person's consent, for the establishment or defense of a legal claim, to protect someone else's rights, or for an important public interest. In practice, restriction usually means flagging the records so no team touches them and no automated job acts on them, while the underlying data stays put.
Article 18 gives four grounds, and restriction is often a temporary state that resolves into another right, most often the right to rectification when the pause was about contested accuracy, or the right to erasure when the person decides they want the data gone rather than held.
| Ground | When it applies | What usually happens next |
|---|---|---|
| Accuracy contested | The person says the data is wrong and you need time to check | You verify, then correct or confirm; restriction lifts |
| Unlawful processing | Processing is unlawful but the person wants restriction instead of erasure | Data is held, not deleted, at the person's preference |
| Needed for a legal claim | You no longer need the data, but the person needs you to keep it for a claim | You retain it beyond your normal schedule |
| Pending an objection | The person has objected under Article 21 and you are weighing it | Restriction holds until you decide the objection |
The trap in Article 18 is the last line of the article: before you lift a restriction, you must tell the person you are about to lift it. Teams remember to impose the restriction and forget that ending it is itself a notified act. Build that notice into the workflow, not into someone's memory.
What the right to object means
Article 21 is really two rights wearing one number. The first is a qualified right: a person can object to processing you carry out on the basis of legitimate interests or the performance of a public task, on grounds relating to their particular situation. When they do, you must stop unless you can show compelling legitimate grounds that override their interests, rights, and freedoms, or the processing is for a legal claim. The burden is on you to justify continuing, not on them to justify objecting.
The second is absolute. Where a person objects to processing for direct marketing, you must stop, full stop. There is no balancing test, no legitimate-interest argument that survives it, and no exception. Once someone objects to marketing, that data can no longer be processed for marketing at all. In the US the equivalent signal is the browser-level opt-out that state laws now require you to honor, which the universal opt-out mechanism explainer covers in full. This is why any team that runs outreach needs a suppression list that actually holds: when you send campaigns at scale, an objection has to remove the person from every future send, not just the one they replied to, because a second message after an opt-out is a clear breach.
Right to restrict processing vs right to object
They are easy to confuse because both interrupt normal processing, but they do different jobs.
| Restrict processing (Art 18) | Object (Art 21) | |
|---|---|---|
| What it does | Pauses processing while something is resolved | Challenges whether processing should continue at all |
| Usual trigger | Contested accuracy, unlawful use, legal-claim retention, pending objection | Processing based on legitimate interests, public task, or direct marketing |
| Your position | Store but do not use, pending a decision | Stop, unless you show compelling grounds (except marketing, where you always stop) |
| Typical outcome | Correction, erasure, or resumption after notice | Processing stops, or continues with a documented justification |
| Absolute version | None | Direct marketing: unconditional stop |
The connection between them is built into Article 18 itself: when a person objects under Article 21, you can restrict the relevant processing while you work out whether your grounds for continuing override their objection. So an objection often triggers a temporary restriction, and the two rights run in sequence rather than in competition.
How long do you have to respond?
The standard GDPR clock applies to both: one month from receipt, extendable by two further months for complex or numerous requests if you tell the person within the first month and explain why. A restriction, though, has a practical urgency the deadline does not capture. If someone contests accuracy or objects to processing, the restriction should go on quickly, because continuing to process contested or objected-to data while the month runs is exactly what the right is meant to stop.
Can you refuse an objection?
For a marketing objection, no. It is absolute and you stop. For an Article 21 objection to legitimate-interests or public-task processing, you can continue only if you can demonstrate compelling legitimate grounds that override the person's interests, or that you need the data for a legal claim. That is a real test with the burden on you, and "it is useful to us" does not clear it. If you decide to continue, document the specific grounds at the time, and tell the person, along with their right to complain. A refusal you cannot explain in a sentence is a refusal you should not make.
Fitting both into a rights workflow
Restriction and objection are the rights that expose whether you actually know where a person's data flows. You cannot pause processing you have forgotten about, and you cannot honor a marketing objection that only reaches one of the four systems that send email. Both depend on the same foundation as access and erasure: knowing every place a person's data lives. Personal data discovery surfaces those locations across your systems, so a restriction covers all of them and an objection removes the person everywhere, not just where someone remembered to look.
These two rights sit alongside six others. The data subject rights overview maps all eight GDPR rights against California's six, so when an objection arrives next to an access or deletion request, as they often do together, you can tell quickly which clock and which rules each one runs on. Handled as a set rather than one email at a time, the awkward rights stop being the ones that catch you out.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.