
Right to object under GDPR: stop marketing immediately, test other uses case by case
A practitioner guide to separating the absolute stop for direct marketing from the case-by-case override test for other GDPR objections.
A customer tells support, "Stop using my data for this." The account team sees an active contract, marketing sees an audience segment, and security sees a fraud-monitoring rule. If all three teams treat the sentence as one global delete command, they will either keep using data the person asked to stop or shut down processing that the objection did not cover.
The first question is narrower: which processing purpose is the person objecting to, and which legal basis supports it? Under GDPR Article 21, that classification changes the response. An objection to direct marketing is a purpose-specific stop. An objection to processing based on public task or legitimate interests is a case-specific test that can be overridden only by compelling legitimate grounds or the establishment, exercise, or defence of legal claims. 1
That distinction is the control. The organisation should stop the use the person named, propagate the decision to every system that carries that use, and preserve only the information needed for a separate lawful purpose or to enforce the objection.
Two objection rules, two thresholds
Article 21 contains several rights under the same heading. For everyday product, marketing, and rights-response work, two paragraphs do most of the practical work.
| Processing situation | What the person must do | What the organisation must prove or do |
|---|---|---|
| Processing based on Article 6(1)(e) public task or Article 6(1)(f) legitimate interests, including profiling based on those provisions | Object at any time on grounds relating to their particular situation. | Stop unless the controller demonstrates compelling legitimate grounds that override the person's interests, rights, and freedoms, or needs the processing for legal claims. 1 |
| Direct marketing, including profiling related to that marketing | Object at any time. | Stop processing the personal data for that marketing purpose. The controller does not get a balancing exercise that can preserve the marketing use. 1 |
The first row is conditional. The person gives a reason connected to their situation, and the controller must test whether its grounds are compelling enough to continue. The second row is unconditional for the marketing purpose: once the person objects, the marketing processing ends.
The difference matters when one dataset supports several operations. A retailer may use an email address to send a requested order update, retain an invoice, detect account takeover, and build a retargeting audience. One objection can stop the audience use without automatically stopping the order update or the legal record. The response must be scoped to the processing the person challenged.
What counts as the objected-to use?
A rights team cannot classify an objection from a field name alone. It needs the operation, purpose, legal basis, recipients, and downstream action.
Take a hotel booking. The hotel uses booking data to confirm a reservation and to share a browsing audience with an advertising platform. The guest objects after seeing hotel advertisements on social media. The relevant processing is the advertising use and the related audience sharing. Reservation messages remain a different operation if they rely on a different purpose and lawful basis. The ICO uses a similar example: an organisation can stop sharing information for advertising while continuing to use it for booking communications. 2
A useful intake record asks four questions:
- What action is being challenged? Collecting, ranking, profiling, sharing, targeting, retaining, or deciding are different operations.
- What purpose does that action serve? "Use the account data" is too broad. "Build a lookalike audience for paid acquisition" is reviewable.
- What legal basis supports that purpose? Article 21(1) applies to Article 6(1)(e) and (f), not automatically to every processing activity.
- Where does the same purpose travel? List internal tables, vendors, ad platforms, campaign tools, model features, and exports that can recreate the use.
The marketing branch is easy to miss when a system calls the output a score rather than an audience. Article 21(2) expressly covers profiling to the extent that it is related to direct marketing. A propensity score, segment, or ranking used to decide whom to target belongs in the same stop path as the message or advertisement it supports. 1
The general objection is an override test
For a non-marketing objection under Article 21(1), the person must object on grounds relating to their particular situation. The point is not to make the person write a legal brief. It is to connect the objection to the effect of the processing on that person rather than treat the right as a universal deletion request.
The controller then has to do more than repeat its original legitimate-interest assessment. It must identify compelling legitimate grounds that override the person's interests, rights, and freedoms, or show that the processing is needed for legal claims. Article 21's threshold is higher than merely showing that the processing was once considered useful. 1
The ICO's legitimate-interests guidance turns that into a working record. It says an organisation relying on legitimate interests should identify the interest, show necessity, balance its interest against the person's interests and rights, and keep a legitimate interests assessment under review. After an objection, it says direct marketing must stop; for other purposes, processing must stop unless the organisation can show compelling legitimate grounds. 3
That creates a practical burden of explanation. A weak response says, "We have a legitimate interest in personalisation." A stronger response identifies the exact purpose, why the person's circumstances do not override it, what safeguards reduce the impact, and why the processing is needed for that purpose. The record should also say whether the decision is limited to one operation or applies to a connected set of uses.
A controller may still have a strong case in a fraud-prevention or legal-claims context, but the case belongs in the objection record. The team should not silently continue the processing because the original LIA exists, and it should not call every continuation a legal-claims exception without identifying the claim and the processing needed to establish, exercise, or defend it.
Direct marketing is the clean stop
Direct marketing has a different response path because Article 21(2) and (3) do not ask the person to win a balancing test. The person can object at any time, and the personal data must no longer be processed for that marketing purpose. The right includes profiling related to the marketing. 1
The ICO's operational guidance describes direct marketing as advertising or marketing targeted at a person through communications such as email, post, or calls. It also distinguishes targeted marketing from routine customer-service messages and says an organisation cannot refuse an objection to direct marketing. 2
For a marketing system, "stop" must reach more than the outbound message queue. The relevant control path usually includes:
- the campaign or audience membership;
- the profile or score used to select the person;
- exports and synchronised audiences held by vendors;
- suppression or do-not-contact enforcement at send time; and
- any job that can rebuild the audience from the same source data.
A single opt-out checkbox does not prove that these paths are connected. The test is whether the organisation can prevent the marketing purpose from being restarted by a later import, model refresh, or vendor sync.
The organisation may need to retain a suppression record. The ICO explains that a suppression list can preserve a person's name or other minimum identifier so the organisation does not mistakenly send direct marketing again; the list is not permission to market. 2
That is a useful example of purpose separation. Retaining a narrow record to enforce the objection can be compatible with stopping marketing to the person. The record should contain the minimum information needed to match future campaigns, have controlled access, and be excluded from marketing audiences.
Objection is not erasure, restriction, or consent withdrawal
These rights can arrive in the same message, but they produce different questions.
Consent withdrawal. If consent is the lawful basis and the person withdraws it, the organisation must stop relying on that consent for the relevant processing. The ICO says a person who previously consented can make clear that they want to withdraw consent without framing the request as a right-to-object request. 2 The system should record which purpose and consent event are affected.
Erasure. An objection asks the organisation to stop a specified processing purpose. Erasure asks for personal data to be deleted, subject to the separate rules and exceptions for that right. The ICO advises that stopping one use does not automatically mean all personal data must be erased. 2
Restriction. Restriction limits how data may be processed in situations defined by Article 18. 1 It can be a useful companion where the law requires processing to pause while an objection or accuracy issue is assessed, but it is not the automatic label for every objection.
Automated decision-making. Article 22 addresses decisions based solely on automated processing that produce legal effects or similarly significant effects. 1 Article 21(2) reaches marketing-related processing and profiling even when the system is selecting an audience rather than making an Article 22 decision. Keep the two analyses separate so a marketing objection does not wait for an automated-decision threshold that the person does not need to meet.
A decision screen for product and rights teams
Use the following sequence when an objection enters through support, privacy requests, a campaign preference centre, or an API.
1. Capture the person's requested boundary
Record the words used, the channel, the identity match, and the processing the person names. If the request is broad, ask a focused clarification question without forcing the person to use the name of a legal right.
"Stop all use" could mean stop advertising, stop a particular inference, stop a vendor disclosure, or delete the account. The team should not convert that ambiguity into a global action before it knows which outcome the person wants.
2. Map the purpose and legal basis
For each challenged use, record the purpose, the Article 6 basis, the data involved, the systems and recipients, and the decision or message produced from it. If the purpose relies on Article 6(1)(e) or (f), route it to the Article 21(1) test. If it is direct marketing, route it to the Article 21(2)-(3) stop. If it relies on another basis, check the applicable right, national law, and any restriction rather than assuming Article 21 supplies the answer.
3. Apply the correct threshold
For direct marketing, stop the purpose and its related profiling. For a general objection, test the person's particular situation against the controller's compelling legitimate grounds or legal-claims need. Name the facts supporting the decision; an unchanged copy of the original LIA is not a response to the person's objection.
4. Propagate the decision
Send the outcome to the systems that carry the same purpose. For marketing, test campaign creation, audience exports, vendor synchronisation, model refreshes, and final delivery. For another purpose, document exactly what stops and what continues. A response that updates the privacy inbox but leaves the ad platform active is not operational compliance.
5. Preserve the smallest enforcement record
Keep the minimum data needed to enforce the decision, show what was assessed, and meet a separate legal or accountability need. A suppression record may need to survive a marketing objection; a booking record may need to survive a marketing stop; neither should be treated as evidence that the marketing purpose can continue.
6. Set a review and response owner
The rights-response team should own the deadline and the written explanation, while the system owner owns execution evidence. The ICO's UK guidance says organisations should respond within one calendar month, with a possible extension of up to two additional months for complex requests, and should explain any extension. 2 Exact timelines and exemptions should still be checked against the governing jurisdiction.
GDPR Article 21 also requires the objection right to be brought to the person's attention clearly and separately by the first communication at the latest. For information society services, it allows automated exercise using technical specifications. 1 A preference centre or API can therefore be part of the legal control, not just a user-experience feature.
Failure modes that should stop sign-off
Treating every objection as a global delete
This destroys the purpose boundary. The fix is to split advertising, service delivery, security, billing, and legal retention into separate processing operations before deciding what stops.
Treating a marketing objection as a balancing exercise
A team reruns its LIA after a person objects to targeted advertising and keeps the audience active because the campaign is commercially useful. Article 21(2) and (3) require the marketing use to stop; the commercial value does not preserve it. 1
Stopping the message but keeping the selection machinery
The person is removed from today's send but remains in the profile, audience export, or model refresh that recreates tomorrow's campaign. The organisation has stopped one delivery event, not the marketing purpose.
Leaving downstream recipients out of scope
The internal CRM marks an objection while a vendor retains the audience. The control record must identify the processors, platforms, and feeds that receive the marketing use and show how the stop reaches them.
Using a generic "legitimate interest" explanation
A label does not answer the Article 21(1) question. The record needs the person's situation, the compelling ground or legal-claims need, the impact, the safeguards, and the reason the ground overrides the objection.
Deleting the suppression record
Erasing every trace of the objection can make the next campaign recreate the same harm. Keep the minimum controlled record needed to enforce the stop, and keep it out of marketing audiences. 2
The record a reviewer can use
A defensible record can be compact if it answers the right questions:
- What processing operation and purpose did the person identify?
- Which legal basis supports that purpose, and does Article 21 apply to it?
- Is the processing direct marketing or profiling related to direct marketing?
- If yes, where is the evidence that the marketing purpose and related profiling stopped across internal and external systems?
- If Article 21(1) applies, what grounds relate to the person's particular situation?
- What compelling legitimate grounds or legal-claims need does the controller rely on, and why do they override the objection?
- Which separate purposes continue, and what legal bases support them?
- What minimum suppression, audit, or legal record must remain, who can access it, and how is it excluded from the stopped purpose?
- Who owns execution, who communicates the outcome, and when is the response due?
The EDPB said its updated one-stop-shop case digest on the right to object and right to erasure examines the internal processes organisations use to comply with these rights, along with frequent infringements and corrective measures. 4 That emphasis points to the practical test: a policy statement is weaker than a purpose map, a routed decision, and evidence that the stop reached every system that could continue the use.
When a person says "stop using my data," start with the purpose rather than the database. Stop direct marketing immediately and purpose-specifically. For other Article 21(1) processing, test the person's situation against compelling grounds and record the result. Then make sure the organisation can enforce the boundary without confusing an objection with erasure, consent withdrawal, or a global shutdown of unrelated processing.
References
- 1Regulation (EU) 2016/679, Article 21
data.europa.eu
- 2
- 3ICO, Legitimate interests
ico.org.uk
- 4
This story was produced automatically by a channel. One sentence is all it takes for Neodrop to keep producing for you.
Related content
More from this channel›
- Records of processing activities: turn the inventory into a working control
- International data transfers under GDPR: why signing the SCCs is not the approval
- Data protection by design and by default: test the starting state
- Valid consent under GDPR: prove the choice, not just the click
- Special category data: the two-part GDPR test
- Pseudonymisation vs anonymisation: decide whether the identity link survives
- Storage limitation: turn retention periods into a working control
- DPIA before launch: turn high-risk processing into a decision
