Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: EN
- General data protection
Basic legislative acts
- GDPR regulation
Article 23 Restrictions
Summary What does Article 23 of the GDPR regulation say?
This article establishes the conditions under which Union or Member State law can legitimately restrict the data protection rights and obligations set out elsewhere in the GDPR — most notably those in Articles 5 and 12 to 22, which cover core data protection principles and data subject rights.
It acts as a controlled exception to those provisions, permitting restrictions only where necessary to safeguard a defined set of public interests, ranging from national security and defence to the enforcement of civil law claims.
The article also sets out the minimum content requirements that any such legislative restriction must contain, ensuring that even where rights are curtailed, a structured framework governs how that curtailment is applied.
Important points:
- Union or Member State law may restrict core data subject rights and controller obligations, but only through a legislative measure and only to safeguard one of the explicitly listed public interests.
- Any legislative measure introducing such a restriction must include specific provisions covering elements such as the purpose of processing, categories of data, scope of the restriction, safeguards against abuse, and storage periods.
- Data subjects retain a right to be informed about any restriction imposed, unless informing them would be prejudicial to the purpose of the restriction itself.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Union or Member State law to which the data controller or processor is subject may restrict by way of a legislative measure the scope of the obligations and rights provided for in Articles 12 to 22 and Article 34, as well as Article 5 in so far as its provisions correspond to the rights and obligations provided for in Articles 12 to 22, when such a restriction respects the essence of the fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to safeguard:
national security;
defence;
public security;
the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security;
other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, including monetary, budgetary and taxation a matters, public health and social security;
the protection of judicial independence and judicial proceedings;
the prevention, investigation, detection and prosecution of breaches of ethics for regulated professions;
a monitoring, inspection or regulatory function connected, even occasionally, to the exercise of official authority in the cases referred to in points (a) to (e) and (g);
the protection of the data subject or the rights and freedoms of others;
the enforcement of civil law claims.
In particular, any legislative measure referred to in paragraph 1 shall contain specific provisions at least, where relevant, as to:
the purposes of the processing or categories of processing;
the categories of personal data;
the scope of the restrictions introduced;
the safeguards to prevent abuse or unlawful access or transfer;
the specification of the controller or categories of controllers;
the storage periods and the applicable safeguards taking into account the nature, scope and purposes of the processing or categories of processing;
the risks to the rights and freedoms of data subjects; and
the right of data subjects to be informed about the restriction, unless that may be prejudicial to the purpose of the restriction.
Relevant recitals
Recital 19 Relationship with Directive (EU) 2016/680
The protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security and the free movement of such data, is the subject of a specific Union legal act. This Regulation should not, therefore, apply to processing activities for those purposes. However, personal data processed by public authorities under this Regulation should, when used for those purposes, be governed by a more specific Union legal act, namely Directive (EU) 2016/680 of the European Parliament and of the Council(7). Member States may entrust competent authorities within the meaning of Directive (EU) 2016/680 with tasks which are not necessarily carried out for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and prevention of threats to public security, so that the processing of personal data for those other purposes, in so far as it is within the scope of Union law, falls within the scope of this Regulation.
With regard to the processing of personal data by those competent authorities for purposes falling within scope of this Regulation, Member States should be able to maintain or introduce more specific provisions to adapt the application of the rules of this Regulation. Such provisions may determine more precisely specific requirements for the processing of personal data by those competent authorities for those other purposes, taking into account the constitutional, organisational and administrative structure of the respective Member State. When the processing of personal data by private bodies falls within the scope of this Regulation, this Regulation should provide for the possibility for Member States under specific conditions to restrict by law certain obligations and rights when such a restriction constitutes a necessary and proportionate measure in a democratic society to safeguard specific important interests including public security and the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security. This is relevant for instance in the framework of anti-money laundering or the activities of forensic laboratories.
Recital 73 Grounds for restricting rights
Restrictions concerning specific principles and the rights of information, access to and rectification or erasure of personal data, the right to data portability, the right to object, decisions based on profiling, as well as the communication of a personal data breach to a data subject and certain related obligations of the controllers may be imposed by Union or Member State law, as far as necessary and proportionate in a democratic society to safeguard public security, including the protection of human life especially in response to natural or manmade disasters, the prevention, investigation and prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security, or of breaches of ethics for regulated professions, other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, the keeping of public registers kept for reasons of general public interest, further processing of archived personal data to provide specific information related to the political behaviour under former totalitarian state regimes or the protection of the data subject or the rights and freedoms of others, including social protection, public health and humanitarian purposes. Those restrictions should be in accordance with the requirements set out in the Charter and in the European Convention for the Protection of Human Rights and Fundamental Freedoms.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
processing
Definition
controller
Definition
processor
Definition
profiling
Definition
personal data breach
Definition
personal data
Footnote 7