Organisations should consider restriction when the accuracy of data is disputed, when a person has objected to processing and the issue is unresolved, when processing was unlawful but deletion is not the preferred remedy, or when the data is no longer needed but is still required for a legal claim. Restriction puts the data in limbo while preserving it for limited lawful use.
When restriction is the right GDPR outcome
Restriction is the intermediate state between ordinary processing and full deletion. It is appropriate when an organisation needs to stop most processing, but must retain the data for a narrow purpose such as a legal claim, dispute handling, or a temporary accuracy challenge. The practical question is whether continued use would be disproportionate while the underlying issue remains unresolved.
For practitioners, the key distinction is that restriction does not mean “do nothing”. It means the record stays available, but access and use are tightly limited so the organisation can preserve evidence, respect the individual’s rights, and avoid further substantive processing until the decision path is clear.
Restriction is also useful when deletion would be premature or harmful to governance. If the data may still be needed to defend a claim, resolve a complaint, or document why a prior decision was made, the safest course is often to freeze ordinary use rather than erase the record immediately. That preserves accountability without treating the data as freely reusable.
What restriction changes in day-to-day processing
When data is restricted, the organisation should stop most active operations on it, including profiling, routine sharing, and secondary use. The remaining permitted processing is usually narrow: storage, limited internal access, or use for a legal purpose where the restriction exception applies. That makes restriction a control on scope, not a blanket exemption.
This is why restriction is operationally different from deletion. Deletion removes the record from use altogether, while restriction keeps it under controlled conditions. In practice, teams need a workflow that can mark the record, prevent ordinary downstream processing, and make the restriction visible to staff who might otherwise act on it as if it were fully active.
Restriction decisions often sit inside wider privacy and access governance. NHIMG’s Identity Data Privacy and Consent Guide is a useful reference point for handling personal data lawfully while preserving retention and rights-based constraints.
Why organisations should not treat restriction as a soft deletion
Restriction is not a convenience label for records you are unsure about. It should be used only when there is a concrete legal or rights-based reason to pause ordinary processing. If the real need is simply cleanup, retention expiry, or housekeeping, deletion is usually the more appropriate end state.
The main operational hazard is inconsistent handling across systems. If one platform marks the data as restricted but another still uses it in reporting, automated decisions, or customer-facing workflows, the organisation has not really restricted processing at all. The control only works if the limitation is propagated to every system that can act on the record.
That is why restriction needs a clear policy trigger, a documented owner, and a reliable way to enforce limited-use status in the systems that hold the data. NHIMG’s Identity Security Regulatory Map helps practitioners connect data-handling obligations to the broader control environment, including governance, auditability, and regulatory mapping.
Risk and Threat Considerations
The risk in this area is not only accidental over-retention. The larger issue is unauthorised continued use of personal data after the organisation should have paused ordinary processing, or premature deletion when the record still needs to be preserved for a claim or dispute. Either failure can create legal exposure, evidentiary gaps, or avoidable harm to the data subject.
Failure mechanism: Organisations often fail by leaving restricted records reachable in downstream systems, exports, analytics, or support tooling, so the data remains functionally active even though the policy says it is frozen.
Impact: That can lead to non-compliant processing, incorrect decisions based on data that should have been held in limbo, and loss of evidence if the data is deleted before the legal or objection process is complete.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while GDPR defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Art. 18 — Right to restriction of processing | Directly governs when personal data must be restricted instead of deleted. |
| Art. 17 — Right to erasure ('right to be forgotten') | Pairs with restriction because the question turns on choosing restriction over deletion. | |
| Art. 21 — Right to object | Supports restriction when an objection is pending resolution and processing should be paused. | |
| Recommendation — Apply Art. 18 to pause non-essential processing and preserve only permitted limited-use handling. Assess Art. 17 exceptions before deleting data needed for legal claims or dispute handling. Suspend contested processing under Art. 21 while you evaluate the objection and lawful basis. | ||
| NIST SP 800-53 Rev 5 | AR-4 — Privacy Monitoring and Auditing | Relevant to tracking whether restricted personal data remains appropriately limited in use. |
| Recommendation — Monitor restricted-data handling and audit any use outside the permitted purpose. | ||
Practitioner Guidance
What to verify: Confirm that the trigger for restriction is documented, for example disputed accuracy, unresolved objection, unlawful processing pending remedy, or retention for a legal claim. If none of those conditions exists, restriction is usually the wrong control and should not replace a normal retention or deletion decision.
Decision rule: If the record still has a legitimate preservation purpose, restrict it and limit access; if the preservation purpose has ended, delete it rather than leaving it in a semi-active state. The most common mistake is allowing “restricted” data to linger indefinitely without a review date or a named owner.
What good looks like: Restricted records are clearly labelled, excluded from ordinary business workflows, and only accessible to the small set of people who need them for the permitted purpose. NHIMG’s Identity Data Privacy and Consent Guide can be used to sanity-check whether the handling model still matches the privacy obligation.
Practitioner takeaway: Treat restriction as a tightly bounded legal holding state, not a convenience category. The control is only effective when every downstream system respects the limitation and the organisation has a clear plan to move the data to deletion once the reason for retention ends.
Related resources from NHI Mgmt Group
- How should organisations assess whether pseudonymized data is still personal data under GDPR?
- Why do organisations struggle to keep personal data limited to what is necessary under GDPR?
- Why do organisations struggle to stay compliant with GDPR when processing personal data across multiple systems?
- What is the difference between mapping personal data categories and documenting processing purposes under GDPR?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org