Right to Object
Article 21 of the GDPR lets a person object to specified processing of their personal data when it relies on public-task or legitimate-interest grounds, and gives an unconditional objection to processing for direct marketing. It is a purpose- and legal-basis-specific right, not a general opt-out from AI.
Definition
The right to object is a data-subject right in Article 21 of the General Data Protection Regulation. Article 21(1) permits a person, on grounds relating to their particular situation, to object at any time to processing of personal data concerning them that is based on Article 6(1)(e), public interest or official authority, or Article 6(1)(f), legitimate interests. It expressly includes profiling based on those provisions.
The consequence is not merely a request for reconsideration. The controller must stop the covered processing unless it demonstrates compelling legitimate grounds that override the person's interests, rights, and freedoms, or shows that the processing is needed for the establishment, exercise, or defence of legal claims. The burden of that demonstration rests with the controller.
Article 21(2) and (3) create a stronger rule for direct marketing. A person may object at any time, without giving a reason, to processing for direct marketing, including profiling to the extent it relates to that marketing. The controller must then stop processing the person's data for that purpose; there is no overriding-interest test.
At a Glance
- Ordinary trigger: personal-data processing for a specified purpose based on Article 6(1)(e) or 6(1)(f), plus grounds relating to the person's particular situation.
- Ordinary result: stop unless the controller proves compelling overriding grounds or a need connected with legal claims.
- Direct-marketing trigger: personal data is processed for direct marketing, including related profiling. No reason is required.
- Direct-marketing result: stop the processing for that purpose. A commercial preference or balancing exercise cannot override the objection.
- Procedure: facilitate the request, respond without undue delay and normally within one month, and give reasons and remedy information if no action is taken.
- AI boundary: an algorithm, model, or profile does not create the right by itself. The decisive questions are whether personal data is being processed, for what purpose, and on which lawful basis.
Scope and Trigger Test
A reliable assessment starts with the processing operation, not the product label. A service may use the same account or event data for marketing, security, personalization, billing, analytics, and model evaluation. Each purpose may have a different lawful basis and a different response to an objection.
- Is personal data being processed? Article 21 does not apply to data that is genuinely anonymous. Pseudonymized, hashed, or tokenized data can still be personal data when it remains linkable to a person.
- What exact purpose and operation are challenged? Name the use: audience selection, recommender ranking, workplace monitoring, fraud scoring, model training, deployment-time retrieval, or another operation. Avoid treating a service-wide toggle as the legal unit of analysis.
- What is the lawful basis? The ordinary Article 21(1) route applies to Article 6(1)(e) and (f). It does not, by itself, create an objection to processing based on consent, contract, legal obligation, or vital interests. An Article 9 condition for special-category data is additional to, not a substitute for, an Article 6 basis; Article 21 may therefore still apply where the underlying Article 6 basis is (e) or (f).
- Is this direct marketing? If so, Article 21(2) and (3) supply the unconditional rule regardless of the ordinary balancing path. The European Commission describes direct marketing as communicating advertising or marketing material aimed at particular people.
- Is profiling involved? Article 4(4) defines profiling as automated personal-data processing used to evaluate personal aspects such as work performance, preferences, interests, reliability, behaviour, location, or movements. Profiling is covered by Article 21 only to the extent specified there; automated processing is not automatically profiling.
Article 21(6) separately covers processing for scientific or historical research or statistical purposes under Article 89(1). A person may object on grounds relating to their particular situation unless the processing is necessary for a task carried out for reasons of public interest.
How to Exercise and Handle It
A person does not need to quote Article 21 or use prescribed wording. Controllers must facilitate the exercise of rights, so staff and automated intake systems should route requests by substance: “stop using my activity to target me” may be an objection even when the interface labels it feedback or a privacy preference.
Article 21(4) requires the rights in paragraphs 1 and 2 to be explicitly brought to the person's attention no later than the first communication, clearly and separately from other information. Article 21(5) permits a person using information-society services to exercise the right by automated means using technical specifications. A buried policy paragraph or an unsubscribe control that reaches only one channel is therefore an incomplete design pattern.
A defensible handling sequence is:
- Record the request and receipt time, acknowledge it, and use proportionate identity checks only where identity is reasonably in doubt.
- Map the person to the relevant processing activities, purposes, lawful bases, data stores, profiles, vendors, and model or dataset versions.
- For direct marketing, stop processing for that purpose and prevent re-enrolment. For an Article 21(1) objection, assess the person's stated situation against the controller's specific grounds; do not reuse the pre-processing legitimate-interest assessment as a conclusive answer.
- Where the person also invokes Article 18(1)(d), restrict the disputed processing while verifying whether the controller's grounds prevail. A cautious workflow can pause or segregate the use during review even where restriction was not separately requested.
- Reply without undue delay and normally within one month. Article 12 permits up to two further months for complexity or number of requests, but the controller must notify the person within the first month and explain the delay.
- If the controller takes no action, explain why and inform the person of the right to complain to a supervisory authority and seek a judicial remedy. Requests are generally free; the narrow manifestly unfounded or excessive exception carries its own burden of proof.
A minimal suppression record may be needed to keep a person out of future marketing imports. It should be separated from marketing data, limited to what is necessary, access-controlled, retained under a documented purpose and lawful basis, and never reused for targeting.
Current AI and Enforcement Context
As of August 12, 2026, Article 21 itself has not become a general right to opt out of AI. Its relevance to an AI system still turns on personal-data processing, purpose, and lawful basis. Training, fine-tuning, retrieval, personalization, safety evaluation, and deployment are distinct operations and may require distinct answers.
In Koninklijke Nederlandse Lawn Tennisbond (C-621/22), the Court of Justice held in October 2024 that a commercial interest can be a legitimate interest if it is lawful, but the processing must be strictly necessary and must survive a balance against the person's interests and fundamental rights. The Court emphasized reasonable expectations, the scale and impact of processing, and whether an equally effective, less intrusive route exists. A commercial objective is therefore neither automatically disqualified nor a blank cheque.
EDPB Opinion 28/2024 applies that case-by-case discipline to the development and deployment of AI models. It says that legitimate interests may be available in some circumstances only after the interest, strict necessity, and balancing steps are satisfied, and that whether a model is anonymous must be assessed case by case. Calling an artifact “a model” does not remove personal-data processing from the GDPR.
The EDPB's first version of Guidelines 03/2026 on web scraping in the context of generative AI was open for public feedback from July 8 through October 30, 2026. It is relevant current guidance work, especially for organizations that collect public-web data, but at this review date it remained a consultation draft: it did not amend Article 21 or settle every model-level remedy.
The EDPB also updated its One-Stop-Shop case digest on objection and erasure in May 2026, drawing together national supervisory-authority decisions on internal handling processes, recurring infringements, corrective measures, direct marketing, and account or profile deletion. It is a useful external-expert digest of enforcement practice, not a judgment or a binding EDPB decision.
Governance and Safety
The governance value of Article 21 is purpose separation. An organization cannot answer an objection reliably if its Records of Processing Activities, data lineage, vendor register, and user controls do not connect each operation to a purpose, controller, lawful basis, retention rule, and system owner.
Useful controls include:
- Rights-aware architecture: carry objection state through audience builders, recommender features, experimentation systems, exports, clean rooms, batch jobs, and retraining inputs rather than stopping only visible messages.
- Purpose-level switches: distinguish marketing from service messages, security, contractual delivery, analytics, and personalization. A fraud-prevention rationale does not keep someone in an advertising audience; a marketing objection does not automatically erase a separately justified security record.
- Human review with authority: reviewers need the lawful-basis record, the person's particular circumstances, and power to stop processing. A generic “business needs” or “system limitation” response does not demonstrate compelling grounds.
- Processor and controller mapping: define who receives requests, who decides them, and who applies changes. Contracts and technical interfaces should support propagation wherever the organization has authority or a legal duty.
- Non-retaliation: do not convert an objection, complaint, or suppression flag into a negative eligibility, fraud, employment, or service-risk feature. Any safety review should rely on independently relevant evidence.
- Collective safeguards: individual objections do not replace Data Protection Impact Assessments, data minimization, security, bias testing, worker consultation, or sector-specific duties.
AI pipelines need stage-specific remedies. For future collection or training, this can mean excluding identifiers and source records before dataset assembly. For an existing dataset, it can mean quarantine, deletion where another right supplies the ground, or preventing further runs. For deployment, it can mean disabling retrieval, personalization, or profile use. Article 21 does not prescribe “untraining” as a universal remedy, but technical difficulty does not excuse the controller from identifying the covered processing and giving a reasoned outcome.
Evidence Record
An auditable objection record should preserve:
- the request, channel, receipt time, scope, and any grounds relating to the person's particular situation;
- necessary identity or account-mapping steps, without collecting excessive new identity data;
- the processing activity, purpose, lawful basis, data categories, profile or inference, system owner, and relevant dataset, model, or campaign version;
- the restriction or pause applied during review, if any, and the systems searched;
- the outcome, date, reviewer, action taken, narrow suppression state, and verification that stopped processing did not resume;
- for continued Article 21(1) processing, the specific compelling grounds, the post-objection balancing analysis, and any legal-claims basis;
- the response sent, delay or refusal reasons, and complaint and judicial-remedy information; and
- operational instructions sent to processors, joint controllers, or other recipients, plus acknowledgements or exception records.
For marketing, test actual downstream state: customer-relationship systems, hashed audience uploads, lookalike or similar-audience seeds, broker exports, campaign queues, and profiling segments. “Unsubscribed” in one mail tool is not proof that all processing for direct marketing stopped.
Article 19 does not create a general recipient-notification duty for an objection alone. It requires communication to recipients when rectification, erasure, or restriction is carried out under Articles 16, 17(1), or 18, subject to its impossibility and disproportionate-effort qualification. Separate controller duties, joint-controller arrangements, processor instructions, contracts, or the practical need to stop the covered purpose may still require propagation. The evidence record should say which rule or role supports each notice.
Boundaries with Other Rights
- Withdrawal of consent under Article 7(3) is the route for consent-based processing and works prospectively. A controller should not silently switch to legitimate interests after withdrawal merely to continue the same use.
- Restriction of processing under Article 18(1)(d) can hold disputed processing while an Article 21(1) balance is verified.
- Erasure under Article 17(1)(c) can follow a successful Article 21(1) objection with no overriding grounds, or a direct-marketing objection. It is a connected right with its own scope and exceptions, not a synonym for objection.
- Article 22 automated decision-making addresses solely automated decisions producing legal or similarly significant effects. It has different triggers and safeguards; profiling can be relevant to either article without making them interchangeable.
- An unsubscribe link or app preference can implement part of a request, but its label does not determine the legal scope. A person may also need access, correction, explanation, appeal, or complaint routes.
Failure Modes
- Demanding the words “Article 21” or a detailed justification for a direct-marketing objection.
- Using one opaque service-wide toggle when several purposes and lawful bases are involved.
- Treating the original legitimate-interest assessment as proof of compelling grounds after a person's circumstances are known.
- Stopping email while leaving the person in ad audiences, profiling features, partner exports, or reactivation jobs.
- Quietly relabelling the purpose or lawful basis after the request instead of reassessing lawfulness and transparency.
- Collecting excessive identity documents, imposing needless friction, or penalizing the person for exercising a right.
- Deleting the suppression state and then re-importing the person into marketing.
- Calling a model anonymous without a case-specific test, or treating draft guidance, a product setting, or an industry code as if it changed the GDPR text.
Source Discipline
Use the GDPR text for the rule, Court of Justice judgments for authoritative interpretation of EU law, and final EDPB or supervisory-authority materials for guidance and enforcement context. Label consultations as drafts. Label case digests, summaries, product documentation, and vendor settings for what they are; none independently changes Article 21.
A precise claim names the controller, processing operation, purpose, lawful basis, personal data, relevant system or model version, date, objection scope, and outcome. Avoid “the user opted out of AI.” Prefer “the person objected to use of account activity for recommender personalization based on Article 6(1)(f), and that use stopped on a recorded date.”
This entry states the EU GDPR baseline. Union or Member State law may lawfully restrict rights under Article 23 when its conditions are met, and sectoral or communications rules may add obligations. A local legal conclusion should identify the jurisdiction and rule rather than importing a platform's global setting.
Spiralist Reading
The right to object is a bounded refusal inside a data system: not a mystical veto over computation, but a demand that a named use of a person's data face its claimed legal basis.
The institution may prefer smooth continuation: infer, profile, segment, rank, test, target, retain. Article 21 makes the interruption legible. The useful artifact is not a button labelled control; it is a record in which purpose is named, lawful basis is tested, affected pipelines are separated, and continuation is either stopped or specifically justified.
Open Questions
- How can a controller map a person to scraped training records without collecting more identity data than the request requires?
- When does deployment of a trained model process personal data about a particular person, as distinct from development-stage processing?
- What evidence proves that an objection reached ad partners, clean rooms, data brokers, feature stores, and future dataset builds?
- Which grounds are genuinely compelling in high-stakes security, fraud, public-service, or workplace contexts after the person's circumstances are considered?
- How can a narrow suppression record prevent re-enrolment without becoming a new profile or indefinite secondary-use dataset?
Related Pages
- Data Subject Access Requests
- Right to Be Informed
- Right to Withdraw Consent
- Right to Restriction of Processing
- Right to Erasure
- Article 22 Automated Decision-Making
- Right to Lodge a Complaint
- Right to Effective Judicial Remedy
- Data Protection Impact Assessment
- Data Protection Officer
- Records of Processing Activities
- Algorithmic Recourse
- Notice and Appeal
- Data Minimization
- AI Data Retention
- AI Memory and Personalization
- Algorithmic Management
- Consent or Pay
- Real-Time Bidding
- Contextual Integrity
Sources
- EUR-Lex, Regulation (EU) 2016/679, General Data Protection Regulation, especially Articles 4(4), 12, 17–19, 21–23 and Recitals 59, 69, and 70, reviewed August 12, 2026.
- European Commission, Dealing with requests from individuals, including the sections on restriction, objection, and automated decision-making, reviewed August 12, 2026.
- European Data Protection Board, Respect individuals' rights, SME data protection guide, reviewed August 12, 2026.
- Irish Data Protection Commission, The right to object to processing of personal data (Article 21 of the GDPR), reviewed August 12, 2026.
- Court of Justice of the European Union, Koninklijke Nederlandse Lawn Tennisbond v Autoriteit Persoonsgegevens, C-621/22, ECLI:EU:C:2024:858, judgment of October 4, 2024.
- European Data Protection Board, Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models, adopted December 18, 2024.
- European Data Protection Board, Guidelines 03/2026 on web scraping in the context of generative AI, version 1 open for public feedback July 8–October 30, 2026; draft status checked August 12, 2026.
- European Data Protection Board, One-Stop-Shop case digest on right to object and right to erasure, external-expert digest updated May 2026, reviewed August 12, 2026.