Restrictions of data subjects’ rights — Commission’s internal rules



Commission Decision (EU) 2018/1927 — internal rules concerning the processing of personal data by the Commission in the field of competition in relation to the provision of information to data subjects and the restriction of certain rights

Commission Decision (EU) 2018/1961 — internal rules concerning the provision of information to data subjects and the restriction of certain of their rights in the context of the processing of personal data for the purpose of internal audit activities

Commission Decision (EU) 2018/1962 — internal rules concerning the processing of personal data by the European Anti-Fraud Office (OLAF) in relation to the provision of information to data subjects and the restriction of certain of their rights

Commission Decision (EU) 2018/1996 — internal rules concerning the provision of information to data subjects and the restriction of certain of their rights in the context of the processing of personal data for the purpose of trade defence and trade policy investigations

Commission Decision (EU) 2019/154 — internal rules concerning the restriction of the right of access of data subjects to their medical files

Commission Decision (EU) 2019/165 — internal rules concerning the provision of information to data subjects and the restriction of certain of their data protection rights by the Commission in the context of administrative inquiries, pre-disciplinary, disciplinary and suspension proceedings

Commission Decision (EU) 2019/236 — internal rules concerning the provision of information to data subjects and the restriction of certain of their rights in the context of the processing of personal data by the Commission for the purposes of internal security of the EU institutions


They set out internal rules, based on which the European Commission may restrict the rights of individuals, which they exercise under Regulation (EU) 2018/1725. The internal rules apply to the processing of personal data within specific fields and for specific purposes.


Personal data are any information relating to an identified or identifiable natural person (‘data subject’). A natural person is identifiable, if he/she can be identified, directly or indirectly, in particular by reference to an identifier (such as a name, an identification number, location data, or an online identifier) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

The new EU legal framework on the protection and free flow of personal data consists of, in particular:

These regulations are considered as equivalent and have to be interpreted as being the same.

Article 25 of Regulation (EU) 2018/1725 provides for the possibility that, in certain cases, the EU institutions and bodies can restrict the rights of individuals, on the condition that such restrictions are laid down in EU law. In line with that, the Commission has adopted 7 Commission decisions, which provide the grounds for possible restrictions in order to safeguard important objectives of general EU public interest.

Based on those decisions and following a case-by-case assessment of the necessity and proportionality of restrictions, the European Commission decides whether the rights of an individual should be restricted in an individual case.

The following rights of individuals may be restricted:

The 7 Commission decisions all follow a similar format, each including some or all of these elements:

The 7 Commission decisions cover the restriction of data subjects in the following fields:



For more information, see:


Commission Decision (EU) 2018/1927 of 5 December 2018 laying down internal rules concerning the processing of personal data by the European Commission in the field of competition in relation to the provision of information to data subjects and the restriction of certain rights (OJ L 313, 10.12.2018, pp. 39-44)

Commission Decision (EU) 2018/1961 of 11 December 2018 laying down internal rules concerning the provision of information to data subjects and the restriction of certain of their rights in the context of the processing of personal data for the purpose of internal audit activities (OJ L 315, 12.12.2018, pp. 35-40)

Commission Decision (EU) 2018/1962 of 11 December 2018 laying down internal rules concerning the processing of personal data by the European Anti-Fraud Office (OLAF) in relation to the provision of information to data subjects and the restriction of certain of their rights in accordance with Article 25 of Regulation (EU) 2018/1725 of the European Parliament and of the Council (OJ L 315, 12.12.2018, pp. 41-46)

Commission Decision (EU) 2018/1996 of 14 December 2018 laying down internal rules concerning the provision of information to data subjects and the restriction of certain of their rights in the context of the processing of personal data for the purpose of trade defence and trade policy investigations (OJ L 320, 17.12.2018, pp. 40-44)

Commission Decision (EU) 2019/154 of 30 January 2019 laying down internal rules concerning the restriction of the right of access of data subjects to their medical files (OJ L 27, 31.1.2019, pp. 33-35)

Commission Decision (EU) 2019/165 of 1 February 2019 laying down internal rules concerning the provision of information to data subjects and the restriction of certain of their data protection rights by the Commission in the context of administrative inquiries, pre-disciplinary, disciplinary and suspension proceedings (OJ L 32, 4.2.2019, pp. 9-13)

Commission Decision (EU) 2019/236 of 7 February 2019 laying down internal rules concerning the provision of information to data subjects and the restriction of certain of their rights in the context of the processing of personal data by the European Commission for the purposes of internal security of the Union institutions (OJ L 37, 8.2.2019, pp. 144-149)


Applicable for the European Commission:

Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, pp. 39-98)

Commission Decision (EU, Euratom) 2017/46 of 10 January 2017 on the security of communication and information systems in the European Commission (OJ L 6, 11.1.2017, pp. 40-51)

Successive amendments to Decision (EU, Euratom) 2017/46 have been incorporated in the basic text. This consolidated version is of documentary value only.

Commission Decision (EU, Euratom) 2015/443 of 13 March 2015 on Security in the Commission (OJ L 72, 17.3.2015, pp. 41-52)

Applicable in the EU countries:

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, pp. 1-88)

See consolidated version.

Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, pp. 89-131)

See consolidated version.

last update 03.04.2019