Table of Contents
Article 23 of GDPR: Restrictions to individual rights and GDPR principles
Having defined the principles of data protection and privacy (Article 5) along with the individual rights (Articles 12 to 22), Article 23 allows for those principles and rights to be restricted.
In essence, under Article 23 of GDPR, EU member countries to adopt laws and regulations to restrict the rights granted under GDPR.
EU member countries have power to restrict GDPR rights and principles (Article 23(1) GDPR)
GDPR provides the ability to EU member countries to adopt laws and regulations to restrict the GDPR principles and data subject rights in the following instances:
- For national security (Article 23(1)(a) GDPR)
- For national defence (Article 23(1)(b) GDPR)
- For public security (Article 23(1)(c) GDPR)
- To protect against crimes and threats to public security (Article 23(1)(d) GDPR)
- For important objectives of the general public interest such as monetary, budgetary, taxation, public health and social security (Article 23(1)(e) GDPR)
- To project judicial independence (Article 23(1)(f) GDPR)
- To protect against breach of ethics by regulated professions (Article 23(1)(g) GDPR)
- For official authority functions (Article 23(1)(h) GDPR)
- To protect individuals and the rights and freedoms (Article 23(1)(i) GDPR)
- To enforce a civil claim (Article 23(1)(j) GDPR)
The data subject rights that may be restricted are the following:
- Companies’ obligation in communicating information in a transparent way to individuals (Article 12 GDPR)
- Nature of information companies must provide individuals to collect their data (Article 13 GDPR)
- Nature of information companies must provide individuals if they collect their data from another source (Article 14 GDPR)
- Access rights to personal data (Article 15 GDPR)
- Rectification rights (Article 16 GDPR)
- Right to erasure or right to be forgotten (Article 17 GDPR)
- Right to restrict company processing personal data (Article 18 GDPR)
- Companies’ notification obligation when rectifying or erasing data (Article 19 GDPR)
- Portability rights (Article 20 GDPR)
- Objection rights (Article 21 GDPR)
- Right not to be subject to automated decision-making, including profiling (Article 22 GDPR)
The principles that EU member countries can restrict are the following:
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
Legal specification requirements (Article 23(2) GDPR)
When adopting laws and regulations to restrict the data subject rights or the principles under GDPR, the EU member countries must ensure to specify the following in their legislative content:
- The purpose of processing personal data or a special category of personal data (Article 23(2)(a) GDPR)
- The category of personal data (Article 23(2)(b) GDPR)
- The scope of the intended restrictions (Article 23(2)(c) GDPR)
- How to protect against abuse, illegal access or transfer of data (Article 23(2)(d) GDPR)
- The specification of the controllers (Article 23(2)(e) GDPR)
- For how long personal data can be stored and how to protect them (Article 23(2)(f) GDPR)
- The risks associated to the individual rights and freedoms (Article 23(2)(g) GDPR)
- The right for individuals to be informed unless this can compromise the purpose of the restriction (Article 23(2)(h) GDPR)
Recitals applicable to Article 23 of GDPR
Relevant Recitals: 73
GDPR Regulation article-by-article overview
Read our comprehensive overview of the GDPR Regulation, article by article, where we summarize each of the 99 articles contained in GDPR to give you a complete understanding of its content.
Cited Legislation in Article 23 or relevant recitals
None
GDPR Text: Article 23 of GDPR and Relevant Recitals
GDPR Text Source: EUR-Lex
Official GDPR Text: General Data Protection Regulation
Official GDPR Title: REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), corrected by Corrigendum, OJL 127, 23.5.2018, p. 2 ((EU) 2016/679)