Laws · GDPR ·art-23-par-1 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Union or Member State law to which the data controller or processor is subject may restrict by way of a legislative measure the scope of the obligations and rights provided for in Articles 12 to 22 and Article 34, as well as Article 5 in so far as its provisions correspond to the rights and obligations provided for in Articles 12 to 22, when such a restriction respects the essence of the fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to safeguard:
How it connects
Cited by
- Guidelines 10/2020 on restrictions under Article 23 GDPR
- Guidelines 04/2021 on Codes of Conduct as tools for transfers
- Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications
- Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR
- Study on the secondary use of personal data in the context of scientific research
All 45
- Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH
- Privacy International v Secretary of State
- Rb. Den Haag - C/09/689833
- Munich Court: §11(8) RBStV validly restricts Art. 15 GDPR access for broadcasting
- AEPD (Spain) - EXP202102529
- Court rejects DFW request for Ziggo customer IP addresses due to insufficient transparency
- GC T-318/24: EPSO access logs and Article 17 access requests under Regulation 2018/1725
- Austrian court: university may refuse GDPR rectification of student's chosen name without
- Dutch Supreme Court: patient not entitled to access peer-review assessment of medical file
- Austrian FAC: DPA rightly found loyalty program consent for profiling invalid under GDPR
- Rb. Midden-Nederland - UTR 21/3403
- Opinion 15/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal to be used as tool for transfers pursuant to Articles 42 and 46 GDPR
- Opinion 14/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 GDPR
- Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)
- EDPB-EDPS Joint Opinion 02/2023 on the Proposal for a Regulation of the European Parliament and of the Council on the establishment of the digital euro
- EDPB-EDPS Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
- Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)
- Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR
- Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data
- EDPB contribution to the 6th round of consultations on the draft Second Additional Protocol to the Council of Europe Budapest Convention on Cybercrime
- EDPB-EDPS Joint Opinion 04/2021 on the Proposal for a Regulation of the European Parliament and of the Council on a framework for the issuance, verification and acceptance of interoperable certificates on vaccination, testing and recovery
- EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)
- Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications
- EDPB-EDPS Joint Opinion 2/2021 on standard contractual clauses for the transfer of personal data to third countries
- Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies
- Maximilian Schrems v Meta Platforms Ireland Limited
- UF and AB v Land Hessen
- Norra Stockholm Bygg AB v Per Nycander AB
- VS v Inspektor v Inspektorata kam Visshia sadeben savet
- Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság
- SIA 'SS' v Valsts ieņēmumu dienests
- Mircom International Content Management & Consulting (M.I.C.M.) Limited v Telenet BVBA
- Land Nordrhein-Westfalen v D.-H. T. as liquidator of J & S Service UG
- VQ v Land Hessen
- Commission of the European Communities v Council of the European Union
- Austrian court reviews postal service selling political affinity data of customers
- BVwG - W214 2235505-1
- BVwG - W292 2292202-1
- OGH - 6Ob148/25w
- Finnish DPA orders Espoo to ensure pupil data protection in Google learning tools
Related across sources
14/2021 Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football… Administrative Court of Cyprus May 12, 2026 Controllers Processors Supervisory Authorities
Opinion 22/2024 certain obligations following from the reliance on processor(s) and sub-processor(s) A dopted 1 Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub - processor(s) Adopted on 7 October 2024 Adopted 2 Executive summary The… Opinion ·EDPB Oct 9, 2024 Processors Controllers Processing Agreement
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
S 5 SF 65/24 DS SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus… Social Court Nuremberg Jun 10, 2026 Processors Controllers Integrity and Confidentiality Principle
C-60/22 UZ v Bundesrepublik Deutschland In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik… CJEU ·Fifth Chamber May 4, 2023 Right to Restriction Right to be Forgotten Personal Data
Guidelines 8/2022 identifying a controller or processor's lead supervisory authority Guidelines for identifying a controller or processor’s lead supervisory authority Guidelines ·EDPB Apr 17, 2023 Supervision Controllers Supervisory Authorities