Skip to content
Topic Contested in court

Right to Object

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Data subject right to object to processing

167 linked items 7 Laws31 Case Law29 Guidance81 Enforcement13 News

Overview

20 sources · Jul 23, 2026

Legal Framework

The right to object is codified in Article 21 GDPR and gives data subjects a powerful mechanism to halt processing carried out under Article 6(1)(e) (public interest/official authority) or Article 6(1)(f) (legitimate interests). The right operates differently depending on the processing purpose.

For general processing under those legal bases, the data subject may object "on grounds relating to his or her particular situation," and the burden then shifts to the controller:

"The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims."
GDPR Art. 21(1)

For direct marketing, the right is absolute: once the data subject objects, processing must stop—no balancing test applies. Article 21(3) makes this categorical. Recital 70 reinforces that this right applies "whether with regard to initial or further processing, at any time and free of charge." Controllers must explicitly bring the objection right to the data subject's attention at the latest at the time of first communication, presented clearly and separately from other information (Article 21(4)).

Crucially, the right to object does not apply when processing is based on consent. As the EDPB confirms, withdrawal of consent under Article 7 serves a similar function in that scenario.

Key Developments

The CJEU established early in Google v. Spain that the right to object operates alongside—rather than replaces—the lawfulness assessment under Article 6. The Court confirmed a data subject may "rely in certain conditions on the right to object laid down in subparagraph (a) of the first paragraph of Article 14 of the directive," even when the controller's lawful basis is already under challenge.

In Bavarian Lager, the CJEU addressed the interaction between the right to object and mandatory legal obligations. The Court held that where processing constitutes a legal obligation under what was then Article 5(b) of Regulation 45/2001, "the data subject does not, in principle, have a right to object." However, where an exception to that legal obligation exists, the impact of disclosure on the data subject must still be weighed. This confirms that the right to object is not available against processing required by law, but its protective logic can influence how exceptions to such obligations are applied.

The 2025 Mousse ruling (C-394/23) signals continued judicial engagement with Article 21, specifically in the context of data minimisation and the collection of title and gender identity data in online travel ticket sales—demonstrating that the right to object is being tested against novel data-collection practices.

Status of the Debate

This topic is actively contested in court. The boundaries of Article 21 are being fought over in several directions: the threshold for "compelling legitimate grounds" that override the data subject's objection, the scope of the absolute marketing objection, and how the right interacts with other legal obligations. Bavarian Lager established that mandatory legal processing excludes the objection right in principle, but left open how exceptions should be assessed. Mousse may clarify whether data minimisation failures create a presumption that an objection must succeed. No definitive court split is on record, but the tension between controllers' legitimate-interest arguments and data subjects' particular-situation objections remains unresolved at the CJEU level. A future ruling squarely addressing the evidentiary standard for "compelling legitimate grounds" would resolve the central open question.

Practical Guidance

  • Distinguish the legal basis before responding. If processing relies on consent, Article 21 does not apply—direct the data subject to consent withdrawal. If processing relies on Article 6(1)(e) or (f), the objection triggers the Article 21(1) balancing test.
  • Treat direct marketing objections as absolute. No balancing exercise is permitted; cease processing immediately upon receipt of an objection under Article 21(2).
  • Prepare to demonstrate compelling legitimate grounds. Document the legitimate interest assessment and the specific grounds that override the data subject's situation, as the burden of proof rests on the controller.
  • Surface the right proactively. At the latest at first communication with the data subject, present the objection right clearly and separately from other privacy information, as required by Article 21(4).
  • Offer automated objection mechanisms for online services. Under Article 21(5), information society services must enable objections by automated means using technical specifications.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 7
Art. 21(1) The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data co… GDPR Art. 21(2) Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal… GDPR Art. 21(5) In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, the data subject may exercise his or her right to… GDPR Art. 21(6) Where personal data are processed for scientific or historical research purposes or statistical purposes pursuant to Article 89(1), the data subject, … GDPR art 21 Right to object GDPR Apr 2016 rec 70 Recital 70 — right to object to direct marketing GDPR Apr 2016 rec 69 Recital 69 — data subject right to object GDPR Apr 2016 rec 73 Recital 73 — lawful restrictions on data subject rights GDPR Apr 2016 rec 59 Recital 59 — modalities for data subject rights exercise GDPR Apr 2016 rec 50 Recital 50 — compatible further processing of personal data GDPR Apr 2016 rec 68 Recital 68 — online advertising transparency requirements DSA Oct 2022
Case Law 31
¶7 In Section VII of Chapter II of Directive 95/46, entitled ‘The data subject’s right to object’, the first paragraph of Article 14 of that directive pr… Judgment of the Court (Grand Chamber) of 8 December 2022.#TU and RE v Google LLC.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Directive 95/46/EC – Article 12(b) – Point (a) of the first paragraph of Article 14 – Regulation (EU) 2016/679 – Article 17(3)(a) – Operator of an internet search engine – Research carried out on the basis of a person’s name – Displaying a l ¶14 Under Article 21 of the GDPR, headed ‘Right to object’: ‘1. The data subject shall have the right to object, on grounds relating to his or her particu… Judgment of the Court (First Chamber) of 12 January 2023.#RW v Österreichische Post AG.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 15(1)(c) – Data subject’s right of access to his or her data – Information about the recipients or categories of recipient to whom the personal data have been or will be disclosed – Restrictions.#C ¶38 In particular, that right of access is necessary to enable the data subject to exercise, depending on the circumstances, his or her right to rectifica… Judgment of the Court (First Chamber) of 12 January 2023.#RW v Österreichische Post AG.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 15(1)(c) – Data subject’s right of access to his or her data – Information about the recipients or categories of recipient to whom the personal data have been or will be disclosed – Restrictions.#C ¶14 Entitled ‘Right to object’, Article 21 of that regulation provides, in paragraphs 1 and 2 thereof: ‘1. The data subject shall have the right to object… Judgment of the Court (First Chamber) of 7 December 2023.#UF and AB v Land Hessen.#Requests for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(a) – Principle of ‘lawfulness’ – Point (f) of the first subparagraph of Article 6(1) – Necessity of processing for the purposes of the legitimate interests pursued by the controller or by 154/21 Judgment of the Court (First Chamber) of 12 January 2023.#RW v Österreichische Post AG.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 15(1)(c) – Data subject’s right of access to his or her data – Information about the recipients or categories of recipient to whom the personal data have been or will be disclosed – Restrictions.#C Court of Justice of the European Union Jan 2023 26/22 Judgment of the Court (First Chamber) of 7 December 2023.#UF and AB v Land Hessen.#Requests for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(a) – Principle of ‘lawfulness’ – Point (f) of the first subparagraph of Article 6(1) – Necessity of processing for the purposes of the legitimate interests pursued by the controller or by Court of Justice of the European Union Dec 2023 CJEU HvJ EU 9 januari 2025, C‑394/23 (Mousse). CJEU Jan 2025 413/23 Judgment of the Court (First Chamber) of 4 September 2025.#European Data Protection Supervisor v Single Resolution Board.#Appeal – Protection of natural persons with regard to the processing of personal data – Procedure for granting compensation to shareholders and creditors of a banking institution following the resolution of that institution – Decision of the European Data Protection Supervisor finding that the Single Resolution Board failed to fulfil its obligations relating to the processing Court of Justice of the European Union Sep 2025 203/22 Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor Court of Justice of the European Union Feb 2025 293/12 Digital Rights Ireland Ltd v Minister for Communications CJEU Apr 2014 200/23 Judgment of the Court (First Chamber) of 4 October 2024.#Agentsia po vpisvaniyata v OL.#Request for a preliminary ruling from the Varhoven administrativen sad.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Publication in the commercial register of a company’s constitutive instrument containing personal data – Directive (EU) 2017/1132 – Non-compulsory personal data – Lack of consent of the data subjec Court of Justice of the European Union Oct 2024 487/21 Österreichische Datenschutzbehörde v CRIF CJEU Oct 2023 252/21 Meta Platforms v noyb CJEU Jan 2023 673/17 Bundesverband der Verbraucherzentralen v Planet49 GmbH CJEU Oct 2019 CJEU CLIENT EARTH ET AL. V. EFSA, 16.7.2015 (“CLIENT EARTH”) CJEU Jul 2015 507/17 Google LLC v CNIL CJEU Sep 2019 416/23 Judgment of the Court (First Chamber) of 9 January 2025.#Österreichische Datenschutzbehörde v F R.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(f) and Article 57(4) – Tasks of the supervisory authority – Concepts of a ‘request’ and ‘excessive requests’ – Charging of a reasonable fee or refusal to act on requests in the e Court of Justice of the European Union Jan 2025 CJEU VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”) CJEU Nov 2010 136/17 GC and Others v CNIL CJEU Sep 2019 654/23 Judgment of the Court (First Chamber) of 13 November 2025.#Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP).#Request for a preliminary ruling from the Curtea de Apel Bucureşti.#Reference for a preliminary ruling – Processing of personal data and the protection of privacy in the electronic communications sector – Directive 2002/58/EC – Article 13(1) and (2) – Unsolicited communications – Concept of communication ‘for the purposes of di Court of Justice of the European Union Nov 2025 434/16 Peter Nowak v Data Protection Commissioner CJEU Dec 2017 579/21 Judgment of the Court (First Chamber) of 22 June 2023.#Proceedings brought by J.M.#Request for a preliminary ruling from the Itä-Suomen hallinto-oikeus.#Reference for a preliminary ruling – Processing of personal data – Regulation (EU) 2016/679 – Articles 4 and 15 – Scope of the right of access to information referred to in Article 15 – Information contained in log data – Article 4 – Definition of ‘personal data’ – Definition of ‘recipients’ – Temporal application.#Case C-579/21. Court of Justice of the European Union Jun 2023 CJEU GOOGLE SPAIN SL V. AEPD (THE DPA) & MARIO COSTEJA GONZALEZ, 13.May.2014 (“GOOGLE v. Spain”) CJEU May 2014 343/13 Judgment of the General Court (Sixth Chamber) of 3 December 2015.#CN v European Parliament.#Non-contractual liability — Petition addressed to the Parliament — Dissemination of certain personal data on the Parliament’s website — Absence of a sufficiently serious breach of a rule of law conferring rights on individuals.#Case T-343/13. General Court Dec 2015 Show 11 more →
Guidance 29
§164 If a data processing activity is based on a data subject's consent, this will affect that individual's rights. Data subjects may have the right to dat… Guidelines 05/2020 on consent under Regulation 2016/679 §5 Nonetheless , as under the Directive 95/46/EC of 24 October 1995 (the “ Directive ”) and as stated by the CJEU in its aforementioned Costeja judgement… Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) §13 The Right to request delisting as provided by Article 17 GDPR does not change the findings of the Costeja judgement, in which the CJEU held that a req… Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) §14 Article 17.1 sets out a general principle to erase the data in the six following cases: a. the personal data are no longer necessary in relation to th… Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) guidelines on the application of article 651a gdpr Guidelines 03/2021 on the application of Article 65(1)(a) GDPR EDPB May 2023 guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on relevant and reasoned objection under regulation 2016679 Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679 EDPB Mar 2021 guidelines on the criteria of the right to be forgotten in the search engines cases under th Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) EDPB Jul 2020 29 working party guidelines on transparency under regulation 2016679 Article 29 Working Party - Guidelines on transparency under Regulation 2016/679 EDPB Apr 2018 guidelines on the application of article 60 gdpr Guidelines 02/2022 on the application of Article 60 GDPR EDPB Mar 2022 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 guidelines on the calculation of administrative fines under the gdpr Guidelines 04/2022 on the calculation of administrative fines under the GDPR EDPB May 2023 on processing of personal data through blockchain technologies Guidelines on processing of personal data through blockchain technologies EDPB Jul 2026 guidelines on certification as a tool for transfers Guidelines 07/2022 on certification as a tool for transfers EDPB Feb 2023 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 guidelines on the practical implementation of amicable settlements Guidelines 06/2022 on the practical implementation of amicable settlements EDPB May 2022 leaflet EDPB Leaflet EDPB Mar 2019 opinion 202507 epo adequacydecision Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation EDPB May 2025 guidelines on transparency Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01) EDPB Nov 2025 opinion 202515 dbo certificationcriteria Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH EDPB Jul 2025 opinion 202516 tuv certificationcriteria en 0 Opinion 16/2025 regarding the draft decision of the German North Rhine Westphalia Supervisory Authority regarding Trusted Site Data Privacy (TÜV IT) certification criteria EDPB Jul 2025 262024 on the draft decision of the de bremen Opinion 26/2024 on the draft decision of the DE Bremen Supervisory Authority regarding the “Catalogue of Criteria for the Certification of IT-supported processing of Personal Data pursuant to art 42 GDPR (‘GDPR – information privacy standard’)” presented EDPB Dec 2024 72024 on the draft decision of the german north rhine Opinion 7/2024 on the draft decision of the German North Rhine Westphalia Supervisory Authority regarding the EU Cloud Service Data Protection (Auditor) certification criteria EDPB Apr 2024 Show 9 more →
Enforcement 81
CNIL (France) CNIL fines energy supplier for mishandling data subject access and objection requests CNIL (France) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA finds GDPR applies to US-based Character.AI service Garante per la protezione dei dati personali (Italy) Jul 2026 AEPD (Spain) AEPD (Spain) - PS/00421/2020 AEPD (Spain) Jul 2026 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Whitedecor SRL: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Nov 2025 NL Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Office Nova Concept SRL: Onvoldoende naleving van de rechten van betrokkenen. Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Apr 2025 NL Italian Data Protection Authority (Garante) Università degli Studi di Cassino e del Lazio Meridionale: Niet-naleving van de algemene principes voor gegevensverwerking. Italian Data Protection Authority (Garante) Jul 2025 NL Data Protection Authority of Ireland LinkedIn: Insufficient legal basis for data processing Data Protection Authority of Ireland Oct 2024 Italian Data Protection Authority (Garante) Interflora Italia S.p.A.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Mar 2025 Spanish Data Protection Authority (aepd) BEEDIGITAL AI, S.A.: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Feb 2025 APD/GBA (Belgium) Belgian DPA: Political campaign email without consent violates GDPR and ePrivacy APD/GBA (Belgium) May 2024 Italian Data Protection Authority (Garante) Fastweb S.p.A.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Jun 2024 Italian Data Protection Authority (Garante) Eni Plenitude S.p.A.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Jun 2024 Italian Data Protection Authority (Garante) Azienda Trasporto Passeggeri Emilia-Romagna S.p.A.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Feb 2024 Italian Data Protection Authority (Garante) Sky Italia S.r.l.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Sep 2024 Autoriteit Persoonsgegevens A.S. Watson Health & Beauty Continental Europe B.V.: Insufficient legal basis for data processing Autoriteit Persoonsgegevens May 2024 French Data Protection Authority (CNIL) Candidate for parliamentary elections: Insufficient fulfilment of data subjects rights French Data Protection Authority (CNIL) Dec 2023 Data Protection Authority of Sweden H&M Hennes & Mauritz GBC AB: Insufficient fulfilment of data subjects rights Data Protection Authority of Sweden Oct 2023 Italian Data Protection Authority (Garante) Facile.Energy S.r.l.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Apr 2024 Italian Data Protection Authority (Garante) Olimpia S.r.l.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Apr 2024 Show 61 more →
News 13
European Data Protection Board One-Stop-Shop case digest on right to object and right to erasure updated European Data Protection Board Jun 2026 GDPRhub DSB (Austria) - 2025-0.276.820 GDPRhub Jan 2026 Government Please note that this is not about opting out of the European Health Data Space (EHDS) itself, but rather about the opt-out mechanism that is provided for within the EHDS. Government Apr 2025 Legislation Second revised amendment proposed by members Claassen and De Korte, to replace item 34, regarding an opt-out option for the processing of patient medical data. Legislation May 2025 Legislation Tweede nader gewijzigd amendement van de leden Claassen en De Korte ter vervanging van nr. 34 over een opt-out voor de verwerking van medische gegevens van patiënten Legislation May 2025 NL Government Please note, this does not concern an opt-out from the EHDS itself, but the opt-out provided for within the EHDS. Government Apr 2025 Dirkzwager Dirkzwager: ABRvS geeft uitleg aan het AVG-begrip "de instelling, uitoefening of onderbouwing van een rechtsvordering" Dirkzwager Oct 2022 NL EDPB Record fine for Instagram following EDPB intervention EDPB Sep 2022 Politico European regulators are finalizing a decision blocking Meta from transferring data to the US Politico Aug 2022 Kromann Reumert DeFine is a calculator for GDPR fines based on method of the EDPB Kromann Reumert Feb 2022 noyb No bullsh*t opt-out: free noyb tool for quick and broad Facebook objections! noyb Apr 2023 noyb No complicated procedures: a free tool from noyb allowing you to object to Facebook quickly and easily! noyb Apr 2023 IT en Recht EOKM zoekt een kortrechtelijke procedure om een pornografische website te stoppen. IT en Recht Apr 2023 NL
Literature 6
Journal of Data Protection Privacy The right not to be subject to automated decision-making under the General Data Protection Regulation: Standard permission or default prohibition? Journal of Data Protection Privacy Sep 2017 Unio - EU Law Journal Privacy vs. business convenience: the Mousse judgment and the future of data protection in the EU Unio - EU Law Journal Jun 2025 Journal Scientific and Applied Research HOW GDPR TREATS AUTOMATED DECISION-MAKING Journal Scientific and Applied Research Nov 2025 Computer law & security review Can the GPC standard eliminate consent banners in the EU? Computer law & security review Dec 2025 Frontiers in Genetics Recommendations for Creating Codes of Conduct for Processing Personal Data in Biobanking Based on the GDPR art.40 Frontiers in Genetics Nov 2021 Innovative STEM Education GDPR - General Data Protection Regulation on Sites Requiring Accessibility Innovative STEM Education Jun 2021