Glossary · Data protection
Supervisory Authority
An independent public authority established under the GDPR to monitor and enforce its application, handle complaints, and exercise corrective powers.
Role and independence
Article 51 of the GDPR requires every EU member state to provide one or more independent public authorities that monitor application of the Regulation and protect people's rights and freedoms in relation to personal-data processing. These bodies are commonly called data protection authorities.
Tasks and powers
Under Articles 57 and 58, a supervisory authority informs the public and organizations, handles complaints, conducts investigations, and advises public institutions. It can request information, carry out data-protection audits, issue warnings or reprimands, order compliance, restrict or ban processing, and impose administrative fines where the GDPR permits. A complaint and an authority's own investigation are therefore different routes to the same regulator.
Which authority is competent?
Territorial competence under Article 55 is the starting point. For cross-border processing, Article 56 generally makes the authority of the controller's or processor's main or single establishment the lead supervisory authority under the cooperation procedure. The lead-authority concept is not a free choice and does not apply to every processing operation; local authorities retain competence in situations defined by the GDPR. An organization should map its establishments and processing activities before documenting the relevant contacts.
Notifying a personal data breach
Under Article 33, a controller notifies the authority competent under Article 55 without undue delay and, where feasible, within 72 hours after becoming aware of a breach, unless the breach is unlikely to pose a risk to people's rights and freedoms. A processor instead notifies the controller without undue delay. The separate communication to affected people under Article 34 uses a higher, likely-high-risk threshold. A practical response plan should identify the authority, submission route, responsible roles, and information needed for the notification before an incident occurs.