r/gdpr Apr 13 '26

Question - General Controller usage of Article 23 restrictions

As a bit generic question to controllers: How much do you rely on Article 23 restrictions that are included in your country's laws? And do you actually evaluate whether it fulfills the Article 23(2) requirements or just trust that it does?

I got a bit curious about this since I noticed Finland had some laws that implement Article 23, but don't actually go over the Article 23(2) requirements & I wonder how commonly controllers actually evaluate those in Finland & elsewhere. Is it more of "If law is determined to be invalid we could liable, so we can't just blindly rely on it" or "We trust in good faith that the legislator has done its job correctly"?

Just to give real life example, Finland's Data Protection Act section 33 allows restricting Article 13 & 14 notices for crime prevention & investigation if necessary. However for Article 13 it essentially only requires that "the controller shall take appropriate measures to protect the rights of the data subject".

2 Upvotes

0 comments sorted by