Practical guide
How to draft a GDPR restriction of processing request
4 min read · Updated May 2026 · Editorial oversight: Avv. Federico Papa
A request for restriction of processing is a legal remedy under Article 18 of the GDPR that enables data subjects to temporarily suspend the processing of their personal data without requiring permanent erasure. This interim protective measure applies in specific statutory scenarios, such as where data accuracy is contested or processing is unlawful, ensuring immediate protection pending final verification. The right to restriction represents a core safeguard within the data control framework, allowing data to be frozen during legal disputes or technical inquiries. Accurate drafting requires precise identification of both the statutory grounds and the scope of restricted data to ensure that the Data Controller effectively observes the obligation to abstain from processing.
In brief
The request for restriction of processing under Art. 18 GDPR provides a temporary suspension of personal data processing without permanent erasure. This protective measure applies when data accuracy is contested, processing is unlawful, for legal claims, or pending verification of an objection. Proper drafting requires identifying the Data Controller, the DPO, and the specific statutory grounds. Pursuant to Art. 19 GDPR, the controller must notify all data recipients of the restriction. Response is required within one month under Art. 12 GDPR. Legal professionals may use AI for procedural automation.
The steps
- 1.
Identification of the parties and professional contact details
The first step requires accurately stating the data subject's details and the identifying information of the Data Controller. It is essential to specify the Controller's registered office or certified email address (PEC), together with the contact details of the Data Protection Officer (DPO), if designated. Proper identification ensures that the request is promptly routed to compliance personnel and handled within the timeframe prescribed by Article 12 of the GDPR.
- 2.
Identification of legal grounds under Art. 18
The data subject must explicitly specify which of the four grounds set out in Article 18(1) of the GDPR is being invoked. The restriction may be claimed where the accuracy of data is contested, where processing is unlawful but erasure is opposed, where the controller no longer requires the data but it is needed by the data subject for the establishment, exercise, or defence of legal claims, or pending verification of an objection under Article 21. Omitting the specific statutory ground and its rationale may entitle the Controller to reject the request for lack of justification.
- 3.
Defining the scope of data and processing operations
The request must clearly delineate the categories of personal data subject to restriction and the specific processing operations that must be suspended. Restriction differs from erasure: it requires marking stored personal data to limit its future processing solely to storage or legal claims. A vague description of the targeted data may render compliance technically unfeasible for the Controller, compromising the protection sought.
- 4.
Invoking the obligation to notify recipients
Pursuant to Article 19 of the GDPR, the request must demand that the Controller notify each recipient to whom the personal data has been disclosed of the restriction. This step is essential to extend the scope of protection to third parties or commercial partners processing the same data. The Controller is exempt from this notification obligation only where compliance proves impossible or involves a disproportionate effort.
- 5.
Response deadline and submission methods
The request must be transmitted via methods providing conclusive proof of delivery, preferably via certified email (PEC) to ensure a certain date. In compliance with Article 12 of the GDPR, the Controller must be formally reminded of the duty to provide information on action taken without undue delay and at the latest within one month. Where reasonable doubts regarding identity exist, attaching a valid identity document is recommended to prevent requests for clarification under Article 12(6) of the GDPR.
Legal basis: art. 12 GDPRart. 18 GDPRart. 19 GDPR
The template structure
The standard sections that make up the document. The full template can be opened and completed directly on edit.legal.
Sender
Full identifying details of the data subject and contact information for official notices under Article 12.
Data Controller
Identification of the recipient entity and the Data Protection Officer (DPO), if designated.
Subject: right to restriction
Formal declaration of the exercise of the right to restriction of processing under Article 18 GDPR.
Ground for restriction
Indication of the specific statutory condition justifying the request for temporary restriction.
Request for restriction
Formal demand to suspend processing operations and notify recipients of the restriction under Article 19 GDPR.
Place, date, signature
Signature of the data subject or legal representative, with an enclosed copy of the identity document where required for verification.
Mistakes to avoid
- Confusing the right to restriction with the right to erasure by demanding data destruction rather than temporary suspension.
- Failing to enclose an identity document when identity is in doubt, causing requests for clarification that suspend statutory response times.
- Failing to specify the statutory ground under Article 18(1) of the GDPR, rendering the request generic and legally ineffective.
- Sending the request to a general contact address rather than the registered office or dedicated data protection PEC address.
Frequently asked questions
What are the response deadlines for the Data Controller?
The Controller must respond without undue delay and at the latest within one month of receiving the request. This period may be extended by two further months in complex cases. Pursuant to Article 12 of the GDPR, the data subject must be informed of any extension within the first month.
Can the Data Controller refuse to grant the restriction?
Yes, if the Controller demonstrates that the request is manifestly unfounded or excessive. Any refusal must be fully reasoned and inform the data subject of their right to lodge a complaint with the supervisory authority and seek a judicial remedy.
Is there any fee for exercising the right to restriction?
No, exercising the right to restriction is free of charge under Article 12 of the GDPR. Only in cases of manifestly unfounded or repetitive requests may the Controller charge a reasonable fee based on administrative costs.

What edit.legal automates
- —Automatic selection of the applicable statutory ground under Article 18 GDPR to prevent formal rejection.
- —Dynamic generation of recipient notification clauses under Article 19 GDPR to extend protection across the processing chain.
- —Precise incorporation of transparency duties and response deadlines under Article 12 GDPR to enable streamlined tracking via AI.
Put edit.legal to the test on actual cases
Try edit.legal for free on an active case. No credit card required.
Try edit.legal for freeThis guide is for informational purposes only and does not constitute legal advice for your specific case.