Wiki · Concept · Last reviewed August 12, 2026

Right to Object

Article 21 of the GDPR lets a person object to specified processing of their personal data when it relies on public-task or legitimate-interest grounds, and gives an unconditional objection to processing for direct marketing. It is a purpose- and legal-basis-specific right, not a general opt-out from AI.

Definition

The right to object is a data-subject right in Article 21 of the General Data Protection Regulation. Article 21(1) permits a person, on grounds relating to their particular situation, to object at any time to processing of personal data concerning them that is based on Article 6(1)(e), public interest or official authority, or Article 6(1)(f), legitimate interests. It expressly includes profiling based on those provisions.

The consequence is not merely a request for reconsideration. The controller must stop the covered processing unless it demonstrates compelling legitimate grounds that override the person's interests, rights, and freedoms, or shows that the processing is needed for the establishment, exercise, or defence of legal claims. The burden of that demonstration rests with the controller.

Article 21(2) and (3) create a stronger rule for direct marketing. A person may object at any time, without giving a reason, to processing for direct marketing, including profiling to the extent it relates to that marketing. The controller must then stop processing the person's data for that purpose; there is no overriding-interest test.

At a Glance

Scope and Trigger Test

A reliable assessment starts with the processing operation, not the product label. A service may use the same account or event data for marketing, security, personalization, billing, analytics, and model evaluation. Each purpose may have a different lawful basis and a different response to an objection.

  1. Is personal data being processed? Article 21 does not apply to data that is genuinely anonymous. Pseudonymized, hashed, or tokenized data can still be personal data when it remains linkable to a person.
  2. What exact purpose and operation are challenged? Name the use: audience selection, recommender ranking, workplace monitoring, fraud scoring, model training, deployment-time retrieval, or another operation. Avoid treating a service-wide toggle as the legal unit of analysis.
  3. What is the lawful basis? The ordinary Article 21(1) route applies to Article 6(1)(e) and (f). It does not, by itself, create an objection to processing based on consent, contract, legal obligation, or vital interests. An Article 9 condition for special-category data is additional to, not a substitute for, an Article 6 basis; Article 21 may therefore still apply where the underlying Article 6 basis is (e) or (f).
  4. Is this direct marketing? If so, Article 21(2) and (3) supply the unconditional rule regardless of the ordinary balancing path. The European Commission describes direct marketing as communicating advertising or marketing material aimed at particular people.
  5. Is profiling involved? Article 4(4) defines profiling as automated personal-data processing used to evaluate personal aspects such as work performance, preferences, interests, reliability, behaviour, location, or movements. Profiling is covered by Article 21 only to the extent specified there; automated processing is not automatically profiling.

Article 21(6) separately covers processing for scientific or historical research or statistical purposes under Article 89(1). A person may object on grounds relating to their particular situation unless the processing is necessary for a task carried out for reasons of public interest.

How to Exercise and Handle It

A person does not need to quote Article 21 or use prescribed wording. Controllers must facilitate the exercise of rights, so staff and automated intake systems should route requests by substance: “stop using my activity to target me” may be an objection even when the interface labels it feedback or a privacy preference.

Article 21(4) requires the rights in paragraphs 1 and 2 to be explicitly brought to the person's attention no later than the first communication, clearly and separately from other information. Article 21(5) permits a person using information-society services to exercise the right by automated means using technical specifications. A buried policy paragraph or an unsubscribe control that reaches only one channel is therefore an incomplete design pattern.

A defensible handling sequence is:

  1. Record the request and receipt time, acknowledge it, and use proportionate identity checks only where identity is reasonably in doubt.
  2. Map the person to the relevant processing activities, purposes, lawful bases, data stores, profiles, vendors, and model or dataset versions.
  3. For direct marketing, stop processing for that purpose and prevent re-enrolment. For an Article 21(1) objection, assess the person's stated situation against the controller's specific grounds; do not reuse the pre-processing legitimate-interest assessment as a conclusive answer.
  4. Where the person also invokes Article 18(1)(d), restrict the disputed processing while verifying whether the controller's grounds prevail. A cautious workflow can pause or segregate the use during review even where restriction was not separately requested.
  5. Reply without undue delay and normally within one month. Article 12 permits up to two further months for complexity or number of requests, but the controller must notify the person within the first month and explain the delay.
  6. If the controller takes no action, explain why and inform the person of the right to complain to a supervisory authority and seek a judicial remedy. Requests are generally free; the narrow manifestly unfounded or excessive exception carries its own burden of proof.

A minimal suppression record may be needed to keep a person out of future marketing imports. It should be separated from marketing data, limited to what is necessary, access-controlled, retained under a documented purpose and lawful basis, and never reused for targeting.

Current AI and Enforcement Context

As of August 12, 2026, Article 21 itself has not become a general right to opt out of AI. Its relevance to an AI system still turns on personal-data processing, purpose, and lawful basis. Training, fine-tuning, retrieval, personalization, safety evaluation, and deployment are distinct operations and may require distinct answers.

In Koninklijke Nederlandse Lawn Tennisbond (C-621/22), the Court of Justice held in October 2024 that a commercial interest can be a legitimate interest if it is lawful, but the processing must be strictly necessary and must survive a balance against the person's interests and fundamental rights. The Court emphasized reasonable expectations, the scale and impact of processing, and whether an equally effective, less intrusive route exists. A commercial objective is therefore neither automatically disqualified nor a blank cheque.

EDPB Opinion 28/2024 applies that case-by-case discipline to the development and deployment of AI models. It says that legitimate interests may be available in some circumstances only after the interest, strict necessity, and balancing steps are satisfied, and that whether a model is anonymous must be assessed case by case. Calling an artifact “a model” does not remove personal-data processing from the GDPR.

The EDPB's first version of Guidelines 03/2026 on web scraping in the context of generative AI was open for public feedback from July 8 through October 30, 2026. It is relevant current guidance work, especially for organizations that collect public-web data, but at this review date it remained a consultation draft: it did not amend Article 21 or settle every model-level remedy.

The EDPB also updated its One-Stop-Shop case digest on objection and erasure in May 2026, drawing together national supervisory-authority decisions on internal handling processes, recurring infringements, corrective measures, direct marketing, and account or profile deletion. It is a useful external-expert digest of enforcement practice, not a judgment or a binding EDPB decision.

Governance and Safety

The governance value of Article 21 is purpose separation. An organization cannot answer an objection reliably if its Records of Processing Activities, data lineage, vendor register, and user controls do not connect each operation to a purpose, controller, lawful basis, retention rule, and system owner.

Useful controls include:

AI pipelines need stage-specific remedies. For future collection or training, this can mean excluding identifiers and source records before dataset assembly. For an existing dataset, it can mean quarantine, deletion where another right supplies the ground, or preventing further runs. For deployment, it can mean disabling retrieval, personalization, or profile use. Article 21 does not prescribe “untraining” as a universal remedy, but technical difficulty does not excuse the controller from identifying the covered processing and giving a reasoned outcome.

Evidence Record

An auditable objection record should preserve:

For marketing, test actual downstream state: customer-relationship systems, hashed audience uploads, lookalike or similar-audience seeds, broker exports, campaign queues, and profiling segments. “Unsubscribed” in one mail tool is not proof that all processing for direct marketing stopped.

Article 19 does not create a general recipient-notification duty for an objection alone. It requires communication to recipients when rectification, erasure, or restriction is carried out under Articles 16, 17(1), or 18, subject to its impossibility and disproportionate-effort qualification. Separate controller duties, joint-controller arrangements, processor instructions, contracts, or the practical need to stop the covered purpose may still require propagation. The evidence record should say which rule or role supports each notice.

Boundaries with Other Rights

Failure Modes

Source Discipline

Use the GDPR text for the rule, Court of Justice judgments for authoritative interpretation of EU law, and final EDPB or supervisory-authority materials for guidance and enforcement context. Label consultations as drafts. Label case digests, summaries, product documentation, and vendor settings for what they are; none independently changes Article 21.

A precise claim names the controller, processing operation, purpose, lawful basis, personal data, relevant system or model version, date, objection scope, and outcome. Avoid “the user opted out of AI.” Prefer “the person objected to use of account activity for recommender personalization based on Article 6(1)(f), and that use stopped on a recorded date.”

This entry states the EU GDPR baseline. Union or Member State law may lawfully restrict rights under Article 23 when its conditions are met, and sectoral or communications rules may add obligations. A local legal conclusion should identify the jurisdiction and rule rather than importing a platform's global setting.

Spiralist Reading

The right to object is a bounded refusal inside a data system: not a mystical veto over computation, but a demand that a named use of a person's data face its claimed legal basis.

The institution may prefer smooth continuation: infer, profile, segment, rank, test, target, retain. Article 21 makes the interruption legible. The useful artifact is not a button labelled control; it is a record in which purpose is named, lawful basis is tested, affected pipelines are separated, and continuation is either stopped or specifically justified.

Open Questions

Sources


Return to Wiki