CINXE.COM

Right to object | ICO

<!doctype html> <!--[if lte IE 8 ]><html lang="en" class="ie8"><![endif]--> <!--[if lte IE 9 ]><html lang="en" class="ie9"><![endif]--> <!--[if (gt IE 9)|!(IE)]><!--> <html lang="en"> <head prefix="og: http://ogp.me/ns#"> <meta charset="utf-8"> <meta http-equiv="X-UA-Compatible" content="IE=edge"> <meta name="viewport" content="initial-scale=1.0, width=device-width"> <title>Right to object | ICO</title> <meta name="DC.Subject" content="Right to object" /> <meta name="DC.Date" content="Tuesday, November 19, 2024" /> <meta name="DC.Creator" content="" /> <meta name="DC.Publisher" content="ICO" /> <meta name="DC.Title" content="Right to object" /> <meta name="DC.PageID" content="5700" /> <meta property="og:title" content="Right to object" /> <meta property="og:type" content="website" /> <meta property="og:url" content="https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-object/" /> <meta property="og:description" content="" /> <meta property="og:image" content="" /> <meta name="twitter:title" content="Right to object" /> <meta name="twitter:description" content="" /> <meta name="robots" content="index" /> <link rel="shortcut icon" type="image/x-icon" href="/media2/lhphq55z/favicon.ico" /> <link rel="stylesheet" type="text/css" href="/css/site.css?v=2vrG7eADocFkX9vchR9h5gTORmu6STTHxmyTWJsW9nw" /> </head> <body id="top" class="bg-white min-h-screen "> <a class="flex items-center justify-center px-3 py-2 bg-secondary text-white text-xl sr-only focus:relative focus:w-full focus:h-fit" href="#main-content"> <span class="font-serif text-serif-base pr-2">Skip to main content</span> <span class="icon icon-arrow-down"></span> </a> <header class="w-full fixed md:static z-10 md:z-auto print:hidden"> <div class="bg-primary"> <div class="lg:container px-4 py-3.5 md:flex"> <div class="md:pr-8"> <a href="/"> <div class="bg-left bg-contain bg-no-repeat h-8 w-20 inline-block md:hidden" style="background-image: url('/media2/qkcg1rdf/logo-small.svg?width=80&amp;height=32&amp;v=1db03b868bf60c0');"></div> <div class="bg-left bg-contain bg-no-repeat h-24 w-40 hidden md:inline-block" style="background-image: url('/media2/myukqaa2/ico-header-logo.svg?width=160&amp;height=96&amp;v=1db03b866f17e90');"></div> <span class="sr-only">Home</span> </a> </div> <div class="grow items-stretch hidden md:flex"> <div class="font-serif text-center md:text-left text-white text-serif-base md:flex items-end md:pl-8 border-secondary border-dotted md:border-l-2"> <span>The ICO exists to empower you through information.</span> </div> </div> <div class="flex flex-col items-end md:pl-8"> <script type="application/json" id="language-settings"> {"cookieDomain":"ico.org.uk","options":[{"text":"English","href":"https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-object/","icon":"icon-lang-en","value":"English"},{"text":"Cymraeg","href":"https://cy.ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-object/","icon":"icon-lang-cy","value":"Welsh"}]} </script> <div id="language-toggle"></div> <div class="grow flex items-end"> <button type="button" id="search-toggle" class="absolute rounded p-2 top-3 right-12 md:hidden hover:bg-secondary" aria-controls="search"> <span id="search-icon" class="block icon icon-search text-white text-xl"></span> <span class="sr-only">Search</span> </button> <div id="search" class="motion-safe:transition-all motion-safe:duration-200 hidden md:block w-full sm:w-fit max-h-0 md:max-h-fit overflow-hidden md:overflow-auto"> <form action="https://icosearch.ico.org.uk/s/search.html" method="GET" id="search-form" class="pt-3.5 md:pt-0"> <input type="hidden" name="collection" value="ico-meta" /> <input type="hidden" name="profile" value="_default" /> <div class="flex"> <label for="search-query" class="sr-only">Search</label> <input type="search" name="query" id="search-query" class="grow min-w-0 px-2 py-1 border-t border-b border-l border-r-0 border-white/50 focus:border-white focus:ring-0 rounded-l bg-secondary motion-safe:transition-colors hocus:bg-white text-white hocus:text-black sm:w-60 md:w-48" /> <button type="submit" class="text-transparent bg-secondary rounded-r p-2 border-t border-b border-r border-white/50"> <span class="block text-white text-xl icon icon-search"></span> <span class="sr-only">Search</span> </button> </div> </form> </div> </div> </div> </div> </div> <div class="bg-secondary"> <div class="lg:container md:px-4"> <button type="button" id="navbar-toggle" class="absolute rounded p-2 top-3 right-3 md:hidden hover:bg-secondary" aria-controls="navbar"> <span class="block icon icon-menu text-white text-xl"></span> <span class="sr-only">Menu</span> </button> <nav id="navbar" class="bg-secondary motion-safe:transition-all motion-safe:duration-200 hidden md:block max-h-0 md:max-h-fit overflow-hidden md:overflow-auto"> <ul class="border-primary border-dotted border-t-2 md:border-t-0 md:flex md:flex-wrap"> <li class="md:flex"> <a href="/" class="relative flex justify-between items-center text-white text-serif-lg md:text-base whitespace-nowrap md:whitespace-normal pl-9 md:pl-3 pr-4 md:pr-3 py-2 md:py-1 font-serif md:font-sans before:absolute before:w-2.5 before:top-2 before:bottom-2 before:left-4 md:before:hidden md:border-y-5 md:border-transparent before:bg-theme-grey md:hover:border-t-theme-grey"> <span>Home</span> <span class="icon icon-arrow-right text-xl md:hidden"></span> </a> </li> <li class="md:flex"> <a href="/for-the-public/" class="relative flex justify-between items-center text-white text-serif-lg md:text-base whitespace-nowrap md:whitespace-normal pl-9 md:pl-3 pr-4 md:pr-3 py-2 md:py-1 font-serif md:font-sans before:absolute before:w-2.5 before:top-2 before:bottom-2 before:left-4 md:before:hidden md:border-y-5 md:border-transparent before:bg-theme-green md:hover:border-t-theme-green"> <span>For the public</span> <span class="icon icon-arrow-right text-xl md:hidden"></span> </a> </li> <li class="md:flex"> <a href="/for-organisations/" class="relative flex justify-between items-center text-white text-serif-lg md:text-base whitespace-nowrap md:whitespace-normal pl-9 md:pl-3 pr-4 md:pr-3 py-2 md:py-1 font-serif md:font-sans before:absolute before:w-2.5 before:top-2 before:bottom-2 before:left-4 md:before:hidden md:border-y-5 md:border-transparent before:bg-theme-yellow md:hover:border-t-theme-yellow bg-primary md:border-t-theme-yellow"> <span>For organisations</span> <span class="icon icon-arrow-right text-xl md:hidden"></span> </a> </li> <li class="md:flex"> <a href="/make-a-complaint/" class="relative flex justify-between items-center text-white text-serif-lg md:text-base whitespace-nowrap md:whitespace-normal pl-9 md:pl-3 pr-4 md:pr-3 py-2 md:py-1 font-serif md:font-sans before:absolute before:w-2.5 before:top-2 before:bottom-2 before:left-4 md:before:hidden md:border-y-5 md:border-transparent before:bg-theme-orange md:hover:border-t-theme-orange"> <span>Make a complaint</span> <span class="icon icon-arrow-right text-xl md:hidden"></span> </a> </li> <li class="md:flex"> <a href="/action-weve-taken/" class="relative flex justify-between items-center text-white text-serif-lg md:text-base whitespace-nowrap md:whitespace-normal pl-9 md:pl-3 pr-4 md:pr-3 py-2 md:py-1 font-serif md:font-sans before:absolute before:w-2.5 before:top-2 before:bottom-2 before:left-4 md:before:hidden md:border-y-5 md:border-transparent before:bg-theme-red md:hover:border-t-theme-red"> <span>Action we&#x27;ve taken</span> <span class="icon icon-arrow-right text-xl md:hidden"></span> </a> </li> <li class="md:flex"> <a href="/about-the-ico/" class="relative flex justify-between items-center text-white text-serif-lg md:text-base whitespace-nowrap md:whitespace-normal pl-9 md:pl-3 pr-4 md:pr-3 py-2 md:py-1 font-serif md:font-sans before:absolute before:w-2.5 before:top-2 before:bottom-2 before:left-4 md:before:hidden md:border-y-5 md:border-transparent before:bg-theme-blue md:hover:border-t-theme-blue"> <span>About the ICO</span> <span class="icon icon-arrow-right text-xl md:hidden"></span> </a> </li> </ul> </nav> </div> </div> </header> <main id="main-content" class="pt-20 md:pt-0 md:mt-7 mb-3 md:mb-4"> <div class="lg:container px-4 mb-4 print:hidden"> <nav aria-label="breadcrumb"> <ul class="-mx-1 flex flex-wrap text-sm"> <li class="mx-1"> <span class="after:content-['/'] after:ml-1"> <a href="/for-organisations/" class="text-link hover:underline">For organisations</a> </span> </li> <li class="mx-1"> <span class="after:content-['/'] after:ml-1"> <a href="/for-organisations/uk-gdpr-guidance-and-resources/" class="text-link hover:underline">UK GDPR guidance and resources</a> </span> </li> <li class="mx-1"> <span class="after:content-['/'] after:ml-1"> <a href="/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/" class="text-link hover:underline">Individual rights - guidance and resources</a> </span> </li> <li class="mx-1"> <span class="after:content-['/'] after:ml-1"> <a href="/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/" class="text-link hover:underline">A guide to individual rights</a> </span> </li> <li class="mx-1"> <span>Right to object</span> </li> </ul> </nav> </div> <div class="lg:container px-4"> <div class="border-dotted border-b-2 border-neutral-200 pb-2 sm:pb-3.5 md:pb-6 mb-2 sm:mb-3.5 md:mb-5"> <div class="md:flex md:items-center"> <h1 class="py-0.5 font-serif leading-none sm:border-l-10 sm:pl-3 text-serif-2xl sm:text-serif-3xl border-theme-yellow">Right to object</h1> <div class="md:pl-2 md:ml-auto mt-2 md:mt-2 print:hidden"> <a href="#0" id="download-options-toggle" class="font-serif text-serif-base text-link flex items-center"> Download options <span class="hidden">(Opens download panel)</span> <i class="inline-block icon icon-download text-xl text-white bg-pink-600 rounded-full p-2 ml-2"></i> </a> </div> </div> <div class="download-container bg-pink-600 mt-5 rounded-lg motion-safe:transition-all motion-safe:duration-200 overflow-hidden max-h-0 hidden" id="download-options-container"> <form method="post" action="/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-object/" class="p-3 text-white md:flex md:items-center" target="_blank"> <input type="hidden" name="currentUrl" value="/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-object/" /> <input type="hidden" name="nodeId" value="5700" /> <input type="hidden" name="formId" /> <input type="hidden" name="recordId" /> <fieldset class="md:flex md:items-center"> <legend class="font-serif text-serif-base contents">Pages</legend> <ul class="flex mt-1 md:mt-0 ml-2"> <li class="md:ml-2"> <input type="radio" name="pages" id="pages-all" value="all" class="hidden appearance-none cursor-pointer peer" checked> <label for="pages-all" class="cursor-pointer rounded p-2 pr-3 flex justify-center items-center peer-checked:bg-pink-700 text-sm md:text-base"> <i class="icon icon-book mr-2 text-base md:text-lg"></i>All pages </label> </li> <li class="ml-2"> <input type="radio" name="pages" id="pages-this" value="this" class="hidden appearance-none cursor-pointer peer"> <label for="pages-this" class="cursor-pointer rounded p-2 pr-3 flex justify-center items-center peer-checked:bg-pink-700 text-sm md:text-base"> <i class="icon icon-file-blank mr-2 text-base md:text-lg"></i>This page </label> </li> </ul> </fieldset> <fieldset class="md:ml-10 md:flex md:items-center mt-3 md:mt-0"> <legend class="font-serif text-serif-base contents">Format</legend> <ul class="flex mt-1 md:mt-0 ml-2"> <li class="md:ml-2"> <input type="radio" name="types" id="types-pdf" value="pdf" class="hidden appearance-none cursor-pointer peer" checked> <label for="types-pdf" class="cursor-pointer rounded p-2 pr-3 flex justify-center items-center peer-checked:bg-pink-700 text-sm md:text-base"> <i class="icon icon-file-pdf mr-2 text-base md:text-lg"></i>PDF </label> </li> </ul> </fieldset> <div class="ml-auto mt-3 md:mt-0"> <button class="btn bg-primary flex items-center text-base md:text-lg"> Download <i class="icon icon-download text-white ml-2 text-lg"></i> </button> </div> </form> </div> </div> <div class="grid grid-cols-4"> <div class="col-span-4 md:hidden border-b-2 border-dotted border-neutral-200 flex justify-between pb-2 mb-4 cursor-pointer print:hidden" id="multipage-nav-toggle"> <p class="text-sm text-primary justify-start">Contents</p> <div class="justify-end"> <span class="icon icon-search text-primary" id="multipage-search-button"></span> <span class="icon icon-pointer-down text-primary"></span> </div> </div> <aside class="col-span-4 md:col-span-1 hidden md:block motion-safe:transition-all motion-safe:duration-200 overflow-hidden md:overflow-auto max-h-0 md:max-h-fit mb-6 md:mb-0" id="multipage-nav"> <form id="multipage-search" class="mb-3 flex" method="get"> <label for="multipage-search-input" class="sr-only">Search this document</label> <input type="search" name="search" value="" class="w-full py-2 px-2 text-sm bg-slate-100 border-r-0" id="multipage-search-input" /> <button type="submit" title="Search" class="icon icon-search px-2 bg-slate-100 border border-solid border-l-0 border-slate-700"> </button> </form> <nav> <ul> <li> <div class="mb-2 pb-2 border-b-2 border-dotted border-neutral-200"> <a href="/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/" class="pt-2 pr-2 pb-2 flex justify-between text-sm border-l-4 border-solid text-link border-transparent hover:border-neutral-200 hover:bg-neutral-100 pl-[10px]" data-id="5616"> <span>A guide to individual rights</span> </a> </div> <ul> <li> <div> <a href="/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-be-informed/" class="pt-2 pr-2 pb-2 flex justify-between text-sm border-l-4 border-solid text-link border-transparent hover:border-neutral-200 hover:bg-neutral-100 pl-[10px]" data-id="5661"> <span>Right to be informed</span> </a> </div> </li> </ul> <ul> <li> <div> <a href="/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-of-access/" class="pt-2 pr-2 pb-2 flex justify-between text-sm border-l-4 border-solid text-link border-transparent hover:border-neutral-200 hover:bg-neutral-100 pl-[10px]" data-id="5669"> <span>Right of access</span> </a> </div> </li> </ul> <ul> <li> <div> <a href="/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-rectification/" class="pt-2 pr-2 pb-2 flex justify-between text-sm border-l-4 border-solid text-link border-transparent hover:border-neutral-200 hover:bg-neutral-100 pl-[10px]" data-id="5674"> <span>Right to rectification</span> </a> </div> </li> </ul> <ul> <li> <div> <a href="/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-erasure/" class="pt-2 pr-2 pb-2 flex justify-between text-sm border-l-4 border-solid text-link border-transparent hover:border-neutral-200 hover:bg-neutral-100 pl-[10px]" data-id="5678"> <span>Right to erasure</span> </a> </div> </li> </ul> <ul> <li> <div> <a href="/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-restrict-processing/" class="pt-2 pr-2 pb-2 flex justify-between text-sm border-l-4 border-solid text-link border-transparent hover:border-neutral-200 hover:bg-neutral-100 pl-[10px]" data-id="5683"> <span>Right to restrict processing</span> </a> </div> </li> </ul> <ul> <li> <div> <a href="/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-data-portability/" class="pt-2 pr-2 pb-2 flex justify-between text-sm border-l-4 border-solid text-link border-transparent hover:border-neutral-200 hover:bg-neutral-100 pl-[10px]" data-id="5690"> <span>Right to data portability</span> </a> </div> </li> </ul> <ul> <li> <div> <a href="/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-object/" class="pt-2 pr-2 pb-2 flex justify-between text-sm border-l-4 border-solid bg-neutral-100 text-neutral-600 border-theme-yellow pl-[10px]" data-id="5700"> <span>Right to object</span> </a> </div> </li> </ul> <ul> <li> <div> <a href="/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/rights-related-to-automated-decision-making-including-profiling/" class="pt-2 pr-2 pb-2 flex justify-between text-sm border-l-4 border-solid text-link border-transparent hover:border-neutral-200 hover:bg-neutral-100 pl-[10px]" data-id="5705"> <span>Rights related to automated decision making including profiling</span> </a> </div> </li> </ul> </li> </ul> </nav> </aside> <div class="col-span-4 md:col-span-3 md:pl-10"> <div class="mb-10"> <div class="umb-block-grid" data-grid-columns="12;" style="--umb-block-grid--grid-columns: 12;"> <div class="umb-block-grid__layout-container"> <div class="umb-block-grid__layout-item" data-content-element-type-alias="richTextBlock" data-content-element-type-key="d7ec1d8a-2a00-439e-95b4-9f3537f5ece4" data-element-udi="umb://element/22571e55e9854789995ef964024037f0" data-col-span="12" data-row-span="1" style=" --umb-block-grid--item-column-span: 12; --umb-block-grid--item-row-span: 1; "> <div class="prose prose-sm md:prose-base prose-h2:font-serif sm:prose-h2:border-l-10 sm:prose-h2:pl-3 sm:prose-h2:-ml-3 sm:prose-h2:relative sm:prose-h2:left-[-10px] prose-h3:font-serif sm:prose-lead:border-l-10 sm:prose-lead:pl-3 sm:prose-lead:-ml-3 sm:prose-lead:relative sm:prose-lead:left-[-10px] prose-hr:my-4 prose-h2:border-theme-yellow-light prose-lead:border-theme-yellow-light prose-theme-yellow sm:ml-[10px] sm:pl-3"> <h2>At a glance</h2><ul> <li>The UK GDPR gives individuals the right to object to the processing of their personal data in certain circumstances.</li> <li>Individuals have an absolute right to stop their data being used for direct marketing.</li> <li>In other cases where the right to object applies you may be able to continue processing if you can show that you have a compelling reason for doing so.</li> <li>You must tell individuals about their right to object.</li> <li>An individual can make an objection verbally or in writing.</li> <li>You have one calendar month to respond to an objection.</li> </ul><h2>Checklists</h2><div class="rt-block rt-letter"> <h3>Preparing for objections to processing</h3> <p><span>☐</span> We know how to recognise an objection and we understand when the right applies.</p> <p><span>☐</span> We have a policy in place for how to record objections we receive verbally.</p> <p><span>☐</span> We understand when we can refuse an objection and are aware of the information we need to provide to individuals when we do so.</p> <p><span>☐</span> We have clear information in our privacy notice about individuals’ right to object, which is presented separately from other information on their rights.</p> <p><span>☐</span> We understand when we need to inform individuals of their right to object in addition to including it in our privacy notice.</p> <h3>Complying with requests which object to processing<strong> <br></strong></h3> <p><span>☐</span> We have processes in place to ensure that we respond to an objection without undue delay and within one month of receipt.</p> <p><span>☐</span> We are aware of the circumstances when we can extend the time limit to respond to an objection.</p> <p><span>☐</span> We have appropriate methods in place to erase, suppress or otherwise cease processing personal data.</p> </div><h2>In brief</h2><ul> <li><a href="#ib1">What is the right to object?</a></li> <li><a href="#ib2">When does the right to object apply?</a></li> <li><a href="#ib3">Direct marketing</a></li> <li><a href="#ib4">Processing based upon public task or legitimate interests</a></li> <li><a href="#ib5">Do we need to tell individuals about the right to object?</a></li> <li><a href="#ib6">Do we always need to erase personal data to comply with an objection?</a></li> <li><a href="#ib7">Can we refuse to comply with an objection for other reasons?</a></li> <li><a href="#unfounded">What does manifestly unfounded mean?</a></li> <li><a href="#excessive">What does excessive mean?</a></li> <li><a href="#ib8">What should we do if we refuse to comply with an objection?</a></li> <li><a href="#ib9">How do we recognise an objection?</a></li> <li><a href="#ib10">Can we charge a fee?</a></li> <li><a href="#ib11">How long do we have to comply?</a></li> <li><a href="#ib12">Can we extend the time for a response?</a></li> <li><a href="#ib13">Can we ask an individual for ID?</a></li> </ul><h3><a id="ib1"></a>What is the right to object?</h3><p>Article 21 of the UK GDPR gives individuals the right to object to the processing of their personal data at any time. This effectively allows individuals to stop or prevent you from processing their personal data.</p><p>An objection may be in relation to all of the personal data you hold about an individual or only to certain information. It may also only relate to a particular purpose you are processing the data for.</p><h3><a id="ib2"></a>When does the right to object apply?</h3><p>The right to object only applies in certain circumstances. Whether it applies depends on your purposes for processing and your lawful basis for processing.</p><p>Individuals have the absolute right to object to the processing of their personal data if it is for direct marketing purposes.</p><p>Individuals can also object if the processing is for:</p><ul> <li>a task carried out in the public interest;</li> <li>the exercise of official authority vested in you; or</li> <li>your legitimate interests (or those of a third party).</li> </ul><p>In these circumstances the right to object is not absolute.</p><p>If you are processing data for scientific or historical research, or statistical purposes, the right to object is more limited.</p><p>These various grounds are discussed further below.</p><h3><a id="ib3"></a>Direct marketing</h3><p>An individual can object to the processing of their personal data for direct marketing at any time. This includes any profiling of data that is related to direct marketing.</p><p>This is an absolute right and there are no exemptions or grounds for you to refuse. Therefore, when you receive an objection to processing for direct marketing, you must not process the individual’s data for this purpose.</p><p>However, this does not automatically mean that you need to erase the individual’s personal data, and in most cases it will be preferable to suppress their details. Suppression involves retaining just enough information about them to ensure that their preference not to receive direct marketing is respected in future.</p><h3><a id="ib4"></a>Processing based upon public task or legitimate interests</h3><p>An individual can also object where you are relying on one of the following lawful bases:</p><ul> <li>‘public task’ (for the performance of a task carried out in the public interest),</li> <li>‘public task’ (for the exercise of official authority vested in you), or</li> <li>legitimate interests.</li> </ul><p>An individual must give specific reasons why they are objecting to the processing of their data. These reasons should be based upon their particular situation.</p><p>In these circumstances this is not an absolute right, and you can refuse to comply if:</p><ul> <li>you can demonstrate compelling legitimate grounds for the processing, which override the interests, rights and freedoms of the individual; or</li> <li>the processing is for the establishment, exercise or defence of legal claims.</li> </ul><p>If you are deciding whether you have compelling legitimate grounds which override the interests of an individual, you should consider the reasons why they have objected to the processing of their data. In particular, if an individual objects on the grounds that the processing is causing them substantial damage or distress (eg the processing is causing them financial loss), the grounds for their objection will have more weight. In making a decision on this, you need to balance the individual’s interests, rights and freedoms with your own legitimate grounds. During this process you should remember that the responsibility is for you to be able to demonstrate that your legitimate grounds override those of the individual.</p><p>If you are satisfied that you do not need to <span>comply with the request</span> you should let the individual know. You should explain your decision, and inform them of their right to make a complaint to the ICO or another supervisory authority; and their ability to seek to enforce their rights through a judicial remedy.</p><p><strong>Research purposes</strong></p><p>Where you are processing personal data for scientific or historical research, or statistical purposes, the right to object is more restricted.</p><p>Article 21(6) states:</p><blockquote> <p>‘Where personal data are processed for scientific or historical research purposes or statistical purposes pursuant to Article 89(1), the data subject, on grounds relating to his or her personal situation, shall have the right to object to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.’</p> </blockquote><p>Effectively this means that if you are processing data for these purposes and have appropriate safeguards in place (eg data minimisation and pseudonymisation where possible) the individual only has a right to object if your lawful basis for processing is:</p><ul> <li>public task (on the basis that it is necessary for the exercise of official authority vested in you), or</li> <li>legitimate interests.</li> </ul><p>The individual does not have a right to object if your lawful basis for processing is public task because it is necessary for the performance of a task carried out in the public interest.</p><p>Article 21(6) therefore differentiates between the two parts of the <a href="https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/public-task/">public task lawful basis</a> (performance of a task carried out in the public interest <strong>or </strong>in the exercise of official authority vested in you).</p><p>This may cause difficulties if you are relying on the public task lawful basis for processing. It may not always be clear whether you are carrying out the processing solely as a task in the public interest, or in the exercise of official authority. Indeed, it may be difficult to differentiate between the two.</p><p>As such, it is good practice that if you are relying upon the public task lawful basis and receive an objection, you should consider the objection on its own merits and go on to consider the steps outlined in the next paragraph, rather than refusing it outright. If you do intend to refuse an objection on the basis that you are carrying out research or statistical work solely for the performance of a public task carried out in the public interest you should be clear in your privacy notice that you are only carrying out this processing on this basis.</p><p>If you do receive an objection you may be able to continue processing, if you can demonstrate that you have a compelling legitimate reason or the processing is necessary for legal claims. You need to go through the steps outlined in the previous section to demonstrate this.</p><p>As noted above, if you are satisfied that you do not need to <span>comply with the request </span>you should let the individual know. You should provide an explanation for your decision, and inform them of their right to make a complaint to the ICO or another supervisory authority, as well as their ability to seek to enforce their rights through a judicial remedy.</p><h3><a id="ib5"></a>Do we need to tell individuals about the right to object?</h3><p>The UK GDPR is clear that you must inform individuals of their right to object at the latest at the time of your first communication with them where:</p><ul> <li>you process personal data for direct marketing purposes, or</li> <li>your lawful basis for processing is:</li> <li>public task (for the performance of a task carried out in the public interest),</li> <li>public task (for the exercise of official authority vested in you), or</li> <li>legitimate interests.</li> </ul><p>If one of these conditions applies, you should explicitly bring the right to object to the individual’s attention. You should present this information clearly and separately from any other information.</p><p>If you are processing personal data for research or statistical purposes you should include information about the right to object (along with information about the other rights of the individual) in your privacy notice.</p><h3><a id="ib6"></a>Do we always need to erase personal data to comply with an objection?</h3><p>Where you have received an objection to the processing of personal data and you have no grounds to refuse, you need to stop<span> or not begin</span> processing the data.</p><p>This may mean that you need to erase personal data as the definition of processing under the UK GDPR is broad, and includes storing data. However, as noted above, this will not always be the most appropriate action to take. </p><p>Erasure may not be appropriate if you process the data for other purposes as you need to retain the data for those purposes. For example, when an individual objects to the processing of their data for direct marketing, you can place their details onto a suppression list to ensure that you continue to comply with their objection. However, you need to ensure that the data is clearly marked so that it is not processed for purposes the individual has objected to.</p><h3><a id="ib7"></a>Can we refuse to comply with an objection for other reasons?</h3><p>If an exemption applies, you can refuse to comply with an objection (wholly or partly). Not all of the exemptions apply in the same way, and you should look at each exemption carefully to see how it applies to a particular request. For more information, please see our guidance on <a href="/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/exemptions/">Exemptions</a>.</p><p>You can also refuse to comply with a request if it is:</p><ul> <li>manifestly unfounded; or</li> <li>excessive.</li> </ul><p>In order to decide if a request is manifestly unfounded or excessive you must consider each request on a case-by-case basis. You should not have a blanket policy.</p><p>You must be able to demonstrate to the individual why you consider the request is manifestly unfounded or excessive and, if asked, explain your reasons to the Information Commissioner. </p><h3><span><a id="unfounded"></a>What does manifestly unfounded mean?</span></h3><p>A request may be manifestly unfounded if:</p><ul> <li>the individual clearly has no intention to exercise their right to object. For example an individual makes a request, but then offers to withdraw it in return for some form of benefit from the organisation; or</li> <li>the request is malicious in intent and is being used to harass an organisation with no real purposes other than to cause disruption. For example: <ul> <li>the individual has explicitly stated, in the request itself or in other communications, that they intend to cause disruption;</li> <li>the request makes unsubstantiated accusations against you or specific employees;</li> <li>the individual is targeting a particular employee against whom they have some personal grudge; or</li> <li>the individual systematically sends different requests to you as part of a campaign, eg once a week, with the intention of causing disruption.</li> </ul> </li> </ul><p>This is not a simple tick list exercise that automatically means a request is manifestly unfounded. You must consider a request in the context in which it is made, and you are responsible for demonstrating that it is manifestly unfounded.</p><p>Also, you should not presume that a request is manifestly unfounded because the individual has previously submitted requests which have been manifestly unfounded or excessive or if it includes aggressive or abusive language.</p><p>The inclusion of the word “manifestly” means there must be an obvious or clear quality to it being unfounded. You should consider the specific situation and whether the individual genuinely wants to exercise their rights. If this is the case, it is unlikely that the request will be manifestly unfounded.</p><div class="rt-example"> <p><strong>Example</strong></p> <p>An individual believes that information held about them is inaccurate. They repeatedly request its correction but you have previously investigated and told them you regard it as accurate.</p> <p>The individual continues to make requests along with unsubstantiated claims against you as the controller.</p> <p>You refuse the most recent request because it is manifestly unfounded and you notify the individual of this.</p> </div><h3><a id="excessive"></a>What does excessive mean?</h3><p>A request may be excessive if:</p><ul> <li>it repeats the substance of previous requests; or</li> <li>it overlaps with other requests.</li> </ul><p>However, it depends on the particular circumstances. It will<span> </span><strong>not necessarily</strong><span> </span>be excessive just because the individual:</p><ul> <li>makes a request about the same issue. An individual may have legitimate reasons for making requests that repeat the content of previous requests. For example, if the controller has not handled previous requests properly;</li> <li>makes an overlapping request, if it relates to a completely separate set of information; or</li> <li>previously submitted requests which have been manifestly unfounded or excessive.</li> </ul><h3><a id="ib8"></a>What should we do if we refuse to comply with an objection?</h3><p>You must inform the individual without undue delay and within one month of receipt of the request.</p><p>You should inform the individual about:</p><ul> <li>the reasons you are not taking action;</li> <li>their right to make a complaint to the ICO or another supervisory authority; and</li> <li>their ability to seek to enforce this right through a judicial remedy.</li> </ul><p>You should also provide this information if you request a reasonable fee or need additional information to identify the individual.</p><h3><a id="ib9"></a>How do we recognise an objection?</h3><p>The UK GDPR does not specify how to make a valid objection. Therefore, an objection to processing can be made verbally or in writing. It can also be made to any part of your organisation and does not have to be to a specific person or contact point.</p><p>A request does not have to include the phrase 'objection to processing' or Article 21 of the UK GDPR - as long as one of the conditions listed above apply.</p><p>This presents a challenge as any of your employees could receive a valid verbal objection. However, you have a legal responsibility to identify that an individual has made an objection to you and to handle it accordingly. Therefore you may need to consider which of your staff who regularly interact with individuals may need specific training to identify an objection.</p><p>Additionally, it is good practice to have a policy for recording details of the objections you receive, particularly those made by telephone or in person. You may wish to check with the requester that you have understood their request, as this can help avoid later disputes about how you have interpreted the objection. We also recommend that you keep a log of verbal objections.</p><h3><a id="ib10"></a>Can we charge a fee?</h3><p>In most cases you cannot charge a fee to comply with an objection.</p><p>However, you can charge a “reasonable fee” for the administrative costs of complying with the request if it is manifestly unfounded or excessive. You should base the reasonable fee on the administrative costs of complying with the request.</p><p>If you decide to charge a fee you should contact the individual promptly and inform them. You do not need to comply with the request until you have received the fee.</p><p>Alternatively, you can refuse to comply with a manifestly unfounded or excessive request.</p><h3><a id="ib11"></a>How long do we have to comply?</h3><p>You must comply with an objection without undue delay and at the latest within one month of receipt of the request or (if later) within one month of receipt of:</p><ul> <li>any information requested to confirm the requester’s identity (see<span><span> </span></span><a href="#ib13">Can we ask an individual for ID?</a>); or</li> </ul><ul> <li>a fee (only in certain circumstances – see <a href="#ib10">Can we charge a fee?</a>)</li> </ul><p>You should calculate the time limit from the day you receive the request (whether it is a working day or not) until the corresponding calendar date in the next month.</p><div class="rt-example"> <p><strong>Example</strong></p> <p>An organisation receives a request on 3 September. The time limit will start from the same day. This gives the organisation until 3 October to comply with the request.</p> </div><p>If this is not possible because the following month is shorter (and there is no corresponding calendar date), the date for response is the last day of the following month.</p><p>If the corresponding date falls on a weekend or a public holiday, you have until the next working day to respond.</p><p>This means that the exact number of days you have to comply with a request varies, depending on the month in which the request was made.</p><div class="rt-example"> <p><strong>Example</strong></p> <p>An organisation receives a request on 31 March. The time limit starts from the same day. As there is no equivalent date in April, the organisation has until 30 April to comply with the request.</p> <p>If 30 April falls on a weekend, or is a public holiday, the organisation has until the end of the next working day to comply.</p> </div><p>For practical purposes, if a consistent number of days is required (eg for operational or system purposes), it may be helpful to adopt a 28-day period to ensure compliance is always within a calendar month.</p><h3><a id="ib12"></a>Can we extend the time for a response?</h3><p>You can extend the time to respond by a further two months if the request is complex or you have received a number of requests from the individual. You must let the individual know within one month of receiving their request and explain why the extension is necessary.</p><h3><a id="ib13"></a>Can we ask an individual for ID?</h3><p>If you have doubts about the identity of the person making the objection you can ask for more information. However, it is important that you only request information that is necessary to confirm who they are. The key to this is proportionality. You should take into account what data you hold, the nature of the data, and what you are using it for.</p><p>You need to let the individual know as soon as possible that you need more information from them to confirm their identity before responding to their objection. The period for responding to the objection begins when you receive the additional information.</p> </div> </div> <div class="umb-block-grid__layout-item" data-content-element-type-alias="furtherReadingBlock" data-content-element-type-key="349dc532-9e3f-4f24-9fa4-2e5b86aa0eda" data-element-udi="umb://element/7c51b901400847f98cc48b0e9e0000c4" data-col-span="12" data-row-span="1" style=" --umb-block-grid--item-column-span: 12; --umb-block-grid--item-row-span: 1; "> <further-Reading x-href="https://www.legislation.gov.uk/eur/2016/679" x-target="_blank" x-title="Relevant provisions in the UK GDPR - See Articles 6, 12, 21, 89 and Recitals 69 and 70" x-location="External link"></further-Reading> </div> <div class="umb-block-grid__layout-item" data-content-element-type-alias="richTextBlock" data-content-element-type-key="d7ec1d8a-2a00-439e-95b4-9f3537f5ece4" data-element-udi="umb://element/58d4d3ff83254183bda76682c1ce7b3c" data-col-span="12" data-row-span="1" style=" --umb-block-grid--item-column-span: 12; --umb-block-grid--item-row-span: 1; "> <div class="prose prose-sm md:prose-base prose-h2:font-serif sm:prose-h2:border-l-10 sm:prose-h2:pl-3 sm:prose-h2:-ml-3 sm:prose-h2:relative sm:prose-h2:left-[-10px] prose-h3:font-serif sm:prose-lead:border-l-10 sm:prose-lead:pl-3 sm:prose-lead:-ml-3 sm:prose-lead:relative sm:prose-lead:left-[-10px] prose-hr:my-4 prose-h2:border-theme-yellow-light prose-lead:border-theme-yellow-light prose-theme-yellow sm:ml-[10px] sm:pl-3"> <div class="rt-block rt-green"> <p><strong>Further reading – ICO guidance</strong></p> <p>The <a href="https://ico.org.uk/for-organisations/accountability-framework/individuals-rights/#Individual" title="Individual rights">Accountability Framework</a> looks at the ICO’s expectations in relation to the right to object.</p> </div> </div> </div> </div> </div> </div> <nav class="print:hidden inline-flex flex-col items-start gap-5"> <a href="/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-data-portability/" class="group text-primary"> <div class="flex items-center"> <i class="icon icon-arrow-left text-4xl"></i> <span class="pl-3 flex flex-col"> <span class="text-lg font-semibold">Previous</span> <span class="text-sm underline underline-offset-4 decoration-dotted decoration-1 group-hover:decoration-solid">Right to data portability</span> </span> </div> </a> <a href="/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/rights-related-to-automated-decision-making-including-profiling/" class="group text-primary"> <div class="flex items-center"> <i class="icon icon-arrow-right text-4xl"></i> <span class="pl-3 flex flex-col"> <span class="text-lg font-semibold">Next</span> <span class="text-sm underline underline-offset-4 decoration-dotted decoration-1 group-hover:decoration-solid">Rights related to automated decision making including profiling</span> </span> </div> </a> </nav> </div> </div> </div> </main> <a href="#top" id="button-top" class="transition-opacity duration-500 flex items-center justify-center fixed right-4 bottom-4 z-10 rounded-full outline outline-white w-8 h-8 bg-primary opacity-0 hidden print:hidden"> <span class="icon icon-arrow-up text-white"></span> <span class="sr-only">Back to top</span> </a> <footer class="sticky top-[100vh] print:hidden"> <div class="lg:container px-4 border-t-2 border-dotted border-neutral-200 mt-6"> <div class="py-3"> <button onClick="window.print()" class="flex items-center group"> <i class="icon icon-printer text-lg text-white rounded-full p-1 bg-neutral-400"></i> <span class="ml-2 text-sm text-link group-hover:underline">Print this page</span> </button> </div> </div> <div class="bg-neutral-100"> <div class="lg:container px-4"> <div class="py-5 flex"> <div class="hidden md:block flex-auto"> <ul class="grid gap-4 grid-cols-4"> <li> <div class="mb-3"> <a href="/for-the-public/" class="font-serif text-serif-base text-link hover:underline">For the public</a> </div> <ul class="text-sm text-neutral-600 -mt-1"> <li class="mt-1"> <a href="/for-the-public/official-information/" class="hover:underline">Official information</a> </li> <li class="mt-1"> <a href="/for-the-public/nuisance-calls/" class="hover:underline">Nuisance calls</a> </li> </ul> </li> <li> <div class="mb-3"> <a href="/for-organisations/" class="font-serif text-serif-base text-link hover:underline">For organisations</a> </div> <ul class="text-sm text-neutral-600 -mt-1"> <li class="mt-1"> <a href="/for-organisations/uk-gdpr-guidance-and-resources/" class="hover:underline">UK GDPR guidance and resources</a> </li> <li class="mt-1"> <a href="/for-organisations/foi/" class="hover:underline">Freedom of information</a> </li> <li class="mt-1"> <a href="/for-organisations/eir-and-access-to-information/" class="hover:underline">EIR and access to information</a> </li> <li class="mt-1"> <a href="/for-organisations/direct-marketing-and-privacy-and-electronic-communications/" class="hover:underline">Direct marketing</a> </li> <li class="mt-1"> <a href="/for-organisations/advice-and-services/" class="hover:underline">Advice and services</a> </li> </ul> </li> <li> <div class="mb-3"> <a href="/action-weve-taken/" class="font-serif text-serif-base text-link hover:underline">Action we&#x27;ve taken</a> </div> <ul class="text-sm text-neutral-600 -mt-1"> <li class="mt-1"> <a href="/action-weve-taken/enforcement/" class="hover:underline">Enforcement action</a> </li> <li class="mt-1"> <a href="https://icosearch.ico.org.uk/s/search.html?collection=ico-meta&amp;profile=decisions&amp;query" class="hover:underline">Decision notices</a> </li> <li class="mt-1"> <a href="https://ico.org.uk/action-weve-taken/audits-and-overview-reports/" class="hover:underline">Audits</a> </li> </ul> </li> <li> <div class="mb-3"> <a href="/about-the-ico/" class="font-serif text-serif-base text-link hover:underline">About the ICO</a> </div> <ul class="text-sm text-neutral-600 -mt-1"> <li class="mt-1"> <a href="/about-the-ico/who-we-are/" class="hover:underline">Who we are</a> </li> <li class="mt-1"> <a href="/about-the-ico/what-we-do/" class="hover:underline">What we do</a> </li> <li class="mt-1"> <a href="/about-the-ico/media-centre/" class="hover:underline">Media centre</a> </li> <li class="mt-1"> <a href="/about-the-ico/jobs/" class="hover:underline">Careers</a> </li> <li class="mt-1"> <a href="/about-the-ico/modern-slavery-statement/" class="hover:underline">Modern Slavery Statement</a> </li> </ul> </li> </ul> </div> <div class="hidden md:block flex-auto mx-8 border-l-2 border-dotted border-neutral-400"> </div> <div class="flex-auto"> <div class="font-serif text-serif-base text-link mb-3">Follow us</div> <ul class="flex flex-col sm:flex-row md:flex-col sm:flex-wrap sm:gap-x-4 gap-y-2 text-sm text-neutral-600"> <li class="sm:flex-auto md:flex-none"> <a class="flex items-center hover:underline" href="https://twitter.com/iconews" target="_blank"> <img class="rounded-full mr-2" src="/media2/g1plb1os/twitter.svg?width=24&amp;height=24&amp;v=1db03b86976f0f0" width="24" height="24" alt="Icon for the Twitter @ICONews social link" /> <span>Twitter @ICONews</span> </a> </li> <li class="sm:flex-auto md:flex-none"> <a class="flex items-center hover:underline" href="http://www.youtube.com/user/icocomms" target="_blank"> <img class="rounded-full mr-2" src="/media2/z3vdkkxj/youtube.svg?width=24&amp;height=24&amp;v=1db042ab32beee0" width="24" height="24" alt="Icon for the YouTube social link" /> <span>YouTube</span> </a> </li> <li class="sm:flex-auto md:flex-none"> <a class="flex items-center hover:underline" href="http://linkedin.com/company/information-commissioner&#x27;s-office" target="_blank"> <img class="rounded-full mr-2" src="/media2/cgdpvn4n/linkedin.svg?width=24&amp;height=24&amp;v=1db042ab2dda7d0" width="24" height="24" alt="Icon for the LinkedIn social link" /> <span>LinkedIn</span> </a> </li> <li class="sm:flex-auto md:flex-none"> <a class="flex items-center hover:underline" href="http://facebook.com/ICOnews" target="_blank"> <img class="rounded-full mr-2" src="/media2/g2nhkyjv/facebook.svg?width=24&amp;height=24&amp;v=1db03b86b4b62d0" width="24" height="24" alt="Icon for the Facebook social link" /> <span>Facebook</span> </a> </li> <li class="sm:flex-auto md:flex-none"> <a class="flex items-center hover:underline" href="/about-the-ico/media-centre/e-newsletter/"> <img class="rounded-full mr-2" src="/media2/thzeryz5/envelope.svg?width=24&amp;height=24&amp;v=1db03b86a1d4310" width="24" height="24" alt="Icon for the Subscribe to our e-newsletter social link" /> <span>Subscribe to our e-newsletter</span> </a> </li> </ul> </div> </div> </div> </div> <div class="bg-secondary"> <div class="lg:container px-4"> <div class="py-3 md:hidden"> <div class="font-serif text-center md:text-left text-white text-serif-base md:flex items-end md:pl-8 border-secondary border-dotted md:border-l-2"> <span>The ICO exists to empower you through information.</span> </div> </div> </div> </div> <div class="bg-primary"> <div class="lg:container px-4"> <div class="pt-2"> <ul class="-mx-3 flex flex-wrap text-white text-sm md:text-base"> <li class="mx-3 my-1"> <a href="/global/contact-us/" class="hover:underline">Contact us</a> </li> <li class="mx-3 my-1"> <a href="/global/privacy-notice/" class="hover:underline">Privacy notice</a> </li> <li class="mx-3 my-1"> <a href="/global/cookies/" class="hover:underline">Cookies</a> </li> <li class="mx-3 my-1"> <a href="/global/accessibility/" class="hover:underline">Accessibility</a> </li> <li class="mx-3 my-1"> <a href="/about-the-ico/who-we-are/wales-office/" class="hover:underline">Cymraeg</a> </li> <li class="mx-3 my-1"> <a href="/global/request-publications/" class="hover:underline">Publications</a> </li> <li class="mx-3 my-1"> <a href="/global/disclaimer/" class="hover:underline">Disclaimer</a> </li> <li class="mx-3 my-1"> <a href="/global/copyright-and-re-use-of-materials/" class="hover:underline">&#xA9; Copyright</a> </li> </ul> </div> <div class="py-5"> <div class="md:flex md:items-center"> <div class="pr-4 mb-2 md:mb-0"> <img class="w-10" src="/media2/r34b3hma/ogl.png?width=40&amp;height=16&amp;v=1db03b8684a57d0" width="40" height="16" alt="" /> </div> <div class="prose prose-sm prose-white"> <p>All text content is available under the <a href="http://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/">Open Government Licence v3.0</a>, except where otherwise stated.</p> </div> </div> </div> </div> </div> </footer> <script type="text/javascript" src="https://cc.cdn.civiccomputing.com/9/cookieControl-9.9.min.js"></script> <script type="application/json" id="cookie-settings"> {"apiKey":"dbf86e044f3ab8c4df852af5c7c6ceb2dd7678dd","necessaryCookies":[".AspNetCore.Antiforgery.*","language"],"statement":{"description":"For more detailed information, see our","name":"Cookies page","url":"https://ico.org.uk/global/cookies/","updated":"04/09/2024"},"text":{"title":"Cookies on the ICO website","intro":"We use some essential cookies to make this site work. We\u0027d like to set analytics cookies to understand how you use this site. We may use services from Vimeo and YouTube that may also use cookies.","acceptSettings":"Accept non-essential cookies","rejectSettings":"Reject non-essential cookies","necessaryTitle":"Essential cookies","necessaryDescription":"These cookies are necessary for core functionality, such as security and network management. They always need to be on.","closeLabel":"Save and close","cornerButton":"Cookie options","on":"On","off":"Off"},"optionalCookies":[{"name":"analytics","label":"Analytics cookies","description":"We use Silktide to measure how you use the ICO website. These cookies collect information about how you got to the site, the pages you visit and how long you spend on each page, and what you click on."},{"name":"videoPlayer","label":"Video player cookies","description":"We use services from Vimeo and YouTube to show you embedded videos on the ICO website. Vimeo and Google may use cookies to receive information about the videos you watch for analytics and advertising purposes."}]} </script> <script type="text/plain" id="silktide-settings">12d0c703744ea255b679f823daf1645f</script> <script type="text/javascript" src="/js/index.js?v=TYEGb_GH5SkF5NJRh7cZpx-oDut7QIjlT7FB7jistDU"></script> </body> </html>

Pages: 1 2 3 4 5 6 7 8 9 10