Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: FR
- General data protection
Basic legislative acts
- GDPR regulation
Article 19 Obligation de notification en ce qui concerne la rectification ou l'effacement de données à caractère personnel ou la limitation du traitement
Summary What does Article 19 of the GDPR regulation say?
This short but practically significant article acts as a downstream obligation that flows from Articles 16, 17, and 18 — the rights to rectification, erasure, and restriction of processing.
Once a controller has acted on any of those rights, Article 19 ensures that the correction or change does not stop with the controller alone.
Any recipient who previously received the personal data must also be informed of the update, keeping the data ecosystem consistent.
There is a limited carve-out where notification is impossible or involves disproportionate effort.
Additionally, data subjects can request to know which recipients were informed.
Important points:
- Controllers are required to notify all recipients of any rectification, erasure, or restriction of processing applied to personal data they previously shared.
- This obligation has a narrow exception: notification is not required where it proves impossible or involves disproportionate effort.
- Inform the data subject of the recipients notified, but only if the data subject requests this information.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Le responsable du traitement notifie à chaque destinataire auquel les données à caractère personnel ont été communiquées toute rectification ou tout effacement de données à caractère personnel ou toute limitation du traitement effectué conformément à l'article 16, à l'article 17, paragraphe 1, et à l'article 18, à moins qu'une telle communication se révèle impossible ou exige des efforts disproportionnés. Le responsable du traitement fournit à la personne concernée des informations sur ces destinataires si celle-ci en fait la demande.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
données à caractère personnel
(En. personal data)
Definition
tiers
(En. third party)
Definition
destinataire
(En. recipient)
Definition
traitement
(En. processing)
Definition
responsable du traitement
(En. controller)
Definition
sous-traitant
(En. processor)
Definition
limitation du traitement
(En. restriction of processing)