When a complaint involves multiple regulators, such as GDPR intersecting with consumer protection or financial services oversight, you face a coordination challenge. The EDPB has called for clearer legal frameworks to enable cross-regulatory information sharing. Until that framework is in place, you need a practical process now.
This template provides a structured referral mechanism for complaints that span multiple regulatory domains. It helps document the issue, identify the relevant authorities, and create a paper trail that protects your organization while ensuring the complainant's concerns reach the right desk.
Purpose of the Template
Use this template when you receive a complaint that:
- Involves both personal data processing and another regulated activity (financial services, telecommunications, consumer rights).
- Requires expertise or enforcement powers your primary supervisory authority doesn't hold.
- Affects data subjects across multiple member states with different sectoral regulations.
- Implicates AI systems subject to both GDPR and emerging AI-specific rules.
The template structures your internal assessment, documents your rationale for referral, and creates the communication framework for coordinating with other authorities, even without formal information-sharing agreements.
Prerequisites
Before using this template, ensure:
Internal clarity on regulatory touchpoints. Map which processing activities fall under multiple regulatory regimes. For example, processing payment data involves both GDPR and payment services directives. Deploying automated decision-making in credit scoring involves GDPR Article 22 and consumer credit regulations.
Designated points of contact. Identify who in your organization coordinates with each type of supervisory authority. Your DPO handles the supervisory authority relationship, but who manages dialogue with your financial supervisory authority or telecommunications authority? Document this now.
Complaint intake procedures that flag cross-regulatory issues. Train your first-line complaint handlers to recognize when an issue spans domains. Keywords to watch: "credit decision," "insurance premium," "network access," "content moderation," "automated rejection."
Understanding of your lead supervisory authority. For cross-border processing under Article 56, you know which authority leads. For cross-sectoral issues within a single member state, know which supervisory authority takes point on which aspect of a complaint.
The Template
Section 1: Complaint Summary and Initial Classification
Complaint reference: [Your internal tracking number]
Date received: [Date]
Complainant: [Individual/organization, with pseudonymization if needed for internal tracking]
Processing activity implicated: [Specific service, system, or dataset]
Nature of complaint:
[Two-sentence summary of what the complainant alleges]
Primary regulatory domain: ☐ GDPR ☐ ePrivacy ☐ Other: _______________
Secondary regulatory domains identified:
☐ Consumer protection (specify: _______________)
☐ Financial services regulation
☐ Telecommunications regulation
☐ Sector-specific data rules (health, employment, etc.)
☐ Competition/antitrust
☐ Other: _______________
Cross-border element: ☐ Yes ☐ No
If yes, member states involved: _______________
Section 2: Regulatory Competence Assessment
GDPR obligations at issue:
☐ Lawful basis (Article 6)
☐ Transparency obligations (Articles 13-14)
☐ Data subject rights (Articles 15-22, specify: _______)
☐ Appropriate technical and organisational measures (Article 32)
☐ Data protection by design and default (Article 25)
☐ Other: _______________
Non-GDPR regulatory obligations at issue:
[List the specific sectoral rules, directives, or national laws that apply. Be specific, don't just write "consumer law," cite the actual regulation or directive number if known.]
Enforcement powers required:
What does this complaint need that your primary supervisory authority may not provide?
☐ Access to financial transaction records beyond personal data scope
☐ Technical network inspection capabilities
☐ Authority to suspend a license or service authorization
☐ Power to investigate market abuse or anti-competitive practices
☐ Other: _______________
Section 3: Referral Decision and Coordination Plan
Decision: ☐ Single authority (GDPR only) ☐ Parallel referral ☐ Sequential referral ☐ Request joint operation
Rationale:
[Explain why you've chosen this path. If you're requesting parallel referral to multiple authorities, explain why the complaint can't be split cleanly. If you're suggesting sequential handling, explain the dependency.]
Authorities to be contacted:
Primary: [Name of supervisory authority]
Aspect of complaint: [What they'll investigate]
Contact point: [Email/portal]Secondary: [Name of other supervisory authority]
Aspect of complaint: [What they'll investigate]
Contact point: [Email/portal]
Information to be shared:
☐ Complaint text (redacted if necessary)
☐ Relevant processing documentation (privacy notice, legitimate interests assessment, etc.)
☐ Technical specifications of the system in question
☐ Previous correspondence with the complainant
☐ Internal investigation findings to date
Confidentiality and lawful basis for sharing:
Document your lawful basis for sharing information with each authority. For your supervisory authority, it's GDPR Article 31 (cooperation obligation). For other regulators, cite the specific sectoral law that permits or requires disclosure, or note that you're sharing at the supervisory authority's formal request under their investigative powers.
Section 4: Internal Coordination
DPO involvement: ☐ Leading ☐ Advising ☐ Informed
Legal counsel involvement: ☐ Leading ☐ Advising ☐ Informed
Business unit owner: [Name/role]
Escalation threshold: [What triggers executive involvement]
Timeline:
Complaint acknowledged to individual: [Date]
Referral to supervisory authority: [Target date]
Referral to secondary supervisory authority(s): [Target date]
Internal response deadline: [Date, per Article 12(3) if applicable]
Customization
Adapt Section 2 to your risk profile. If you're in financial services, expand the "Non-GDPR regulatory obligations" section to include specific references to PSD2, MiFID II, or national banking regulations. If you're in telecommunications, reference the ePrivacy Directive and national implementation. The template should reflect the regulatory intersections you face.
Adjust the decision tree in Section 3. Some organizations will default to parallel referral (send to all relevant authorities simultaneously). Others prefer sequential handling (resolve the GDPR piece first, then address sectoral issues). Your choice depends on whether the issues are interdependent. If the lawfulness of processing under GDPR determines whether a financial service can proceed, you need sequential handling with GDPR first.
Tailor information-sharing protocols to your supervisory authority's guidance. Some authorities have published frameworks for how they coordinate with other regulators. The Irish Data Protection Commission, for example, has discussed resource-pooling arrangements. If your lead supervisory authority has issued guidance on joint operations or cross-regulatory coordination, reference it in Section 3.
Build in your Article 30 records. If the complaint reveals a gap in your processing records, note it. Section 4 should trigger a review of whether your records of processing activities accurately reflect the cross-regulatory nature of the processing.
Validation Steps
Before you send the referral:
Check that you've answered the "why both?" question. If you're referring to multiple authorities, your rationale in Section 3 should clearly explain why a single supervisory authority can't address the full complaint. Be specific about what each authority brings.
Verify your lawful basis for information sharing. Without the legal framework the EDPB has called for, you're navigating a patchwork. Don't share confidential business information or third-party personal data with a sectoral supervisory authority unless you have a clear lawful basis. If the supervisory authority has issued a formal information request under their statutory powers, that's your basis. If you're voluntarily referring, you need to rely on your legitimate interests (and document the assessment) or another lawful basis under Article 6.
Confirm your complainant communication is clear. When you tell the individual you're referring their complaint to multiple authorities, explain what each will investigate. Don't leave them wondering whether their complaint is being bounced around. Transparency obligations under Articles 13-14 extend to how you handle their complaint.
Test the coordination mechanism. Before you finalize this template for operational use, run a tabletop exercise with a hypothetical cross-regulatory complaint. Walk through each section with your DPO, legal counsel, and the relevant business unit. Identify where handoffs break down or where you lack the information to complete a section. Fix those gaps now.
The EDPB's call for a lawful basis to facilitate information sharing signals where enforcement is heading, toward more integrated, cross-regulatory operations. Until that framework arrives, this template gives you a structured way to manage the complexity you're facing today.



