Abstract
<p>The study shows that Art. 23 GDPR represents a central mechanism for balancing data protection and other legitimate interests. It systematically analyzes the conditions, limits, and possible applications of data protection restrictions. The focus is on the catalogue of legitimate objectives, the substantive limits arising from the essence of fundamental rights and proportionality, and the minimum requirements of Article 23(2) GDPR. In addition, the case law of the ECJ, which in some cases severely restricts the legislative scope, is critically assessed. Using the example of the healthcare sector, the work shows how restrictions can be designed in a manner consistent with fundamental rights and where there is a need for adjustment.</p>