Skip to main content
Category: Data Transfers

Authorisation by Competent Supervisory Authority

Also known as: Supervisory authority authorisation, Prior authorisation by a supervisory authority
Simply put

This refers to formal approval granted by the data protection regulator that is legally responsible for overseeing an organisation's processing activities. Under the GDPR, each EU member state establishes one or more independent public authorities to monitor how the Regulation is applied, and in certain situations an organisation may need approval from the relevant authority before proceeding. The specific circumstances requiring such authorisation depend on the applicable provisions and any national implementing law, so the exact requirements should be verified against the current official text.

Formal definition

A 'competent supervisory authority' is, in general terms, the independent public authority designated to supervise the application of the GDPR in respect of given processing. Article 51 requires each Member State to provide for one or more independent supervisory authorities responsible for monitoring the application of the Regulation and contributing to its consistent application across the Union. Article 56 addresses the competence of the lead supervisory authority in cross-border processing, while also preserving each supervisory authority's competence to handle a complaint lodged with it or a possible infringement, subject to the cooperation and consistency mechanisms; where authorities disagree, dispute resolution may involve the European Data Protection Board. 'Authorisation' in this context typically denotes a supervisory, approval or enforcement function exercised by the designated regulator, consistent with the broader legal-practice notion of a 'competent authority' as the regulator empowered by legislation to perform such functions. The precise scope of any authorisation requirement, the identity of the competent authority, and the interaction with national implementing law can vary; practitioners should confirm the applicable provisions, article references, and whether the EU GDPR or UK GDPR framework applies against the current official text.

Why it matters

Identifying the competent supervisory authority is a foundational step in managing regulatory relationships under the GDPR. Because each EU member state provides for one or more independent public authorities responsible for monitoring the application of the Regulation, an organisation needs to know which regulator has oversight of a given processing activity before it can seek approval, respond to enquiries, or engage on matters where regulatory involvement is expected. Getting this wrong can lead to engaging the wrong body, delays, or uncertainty about which authority's expectations apply.

The question becomes more complex in cross-border processing. Article 56 addresses the competence of the lead supervisory authority, but it also preserves each supervisory authority's competence to handle a complaint lodged with it or a possible infringement, subject to the cooperation and consistency mechanisms. As IAPP guidance notes, in many cases the lead authority's decision will be accepted or a consensus reached; where a dispute arises between authorities, dispute resolution may involve the European Data Protection Board. This means an organisation cannot always assume a single point of contact will resolve every issue, and should understand how the one-stop-shop mechanism interacts with local authorities' retained competence.

The precise scope of any authorisation requirement, the identity of the competent authority, and the interaction with national implementing law can vary between member states. Requirements may also differ depending on whether the EU GDPR or the UK GDPR framework applies. Practitioners should treat the identity of the competent authority and any approval requirement as matters to confirm against the current official text and applicable national law rather than as settled positions.

Who it's relevant to

Data Protection Officers and compliance leads
DPOs and compliance teams need to identify which supervisory authority is competent for their organisation's processing so they can direct enquiries, engagement, and any required approvals to the correct regulator. In cross-border scenarios they should understand how the lead supervisory authority mechanism under Article 56 interacts with other authorities' retained competence to handle complaints and possible infringements.
Privacy and technology lawyers
Legal advisers assessing whether a given processing activity requires regulator authorisation should confirm the applicable provisions, article references, and whether the EU GDPR or UK GDPR framework applies. Because the scope of any authorisation requirement and the identity of the competent authority can vary with national implementing law, advice should be grounded in the current official text rather than a general assumption.
Organisations operating across multiple member states
Businesses with cross-border processing need to determine their lead supervisory authority while recognising that other authorities remain competent to handle complaints or infringements lodged with them. Where authorities disagree, matters may be resolved through the consistency mechanism and potentially the European Data Protection Board, so multi-state organisations should plan for the possibility of engagement beyond a single point of contact.
Supervisory authority liaison and public-affairs functions
Teams that manage regulator relationships benefit from understanding that each Member State's authority operates independently while contributing to consistent application of the Regulation across the Union. This shapes how engagement, approvals, and dispute situations are handled through the GDPR's cooperation and consistency mechanisms.

Inside Authorisation by Competent Supervisory Authority

Prior authorisation as a distinct mechanism
A supervisory authority's formal approval given in advance of certain processing or transfer activities, distinct from prior consultation (which involves advising rather than approving) and from general enforcement powers. The authorisation is one of the corrective and advisory tools available to supervisory authorities under the GDPR, but its precise scope and procedure can depend on the specific provision or national implementing law invoked.
Identifying the competent supervisory authority
Determining which authority is competent typically turns on the location of the controller's or processor's main or single establishment, or on where affected data subjects are located, subject to the one-stop-shop mechanism and cooperation and consistency procedures. Competence can shift where cross-border processing is involved, so the lead authority should be identified before seeking authorisation.
Situations where authorisation may be required or optional
Certain provisions contemplate authorisation, for example the approval of specific ad hoc contractual arrangements used as a transfer safeguard, or authorisations tied to national derogations that member states may enact. Because member state law can vary the position and because some authorisations are mandatory while others are discretionary, the triggering condition should be confirmed against the specific legal basis relied upon.
Relationship to transfer safeguards
For transfers of personal data to third countries, some safeguards require authorisation by a competent supervisory authority rather than being usable without one. Transfer tools, adequacy decisions, and any required supplementary measures continue to evolve, so an authorisation obtained at one point should not be treated as a permanent or self-sustaining guarantee of lawfulness.
Documentation and accountability trail
An authorisation forms part of the accountability record, generally accompanied by the underlying processing description, purpose, legal basis, and any risk assessment submitted to the authority. The scope of what was authorised, and any conditions attached, should be retained to demonstrate the boundaries of the approval granted.

Common questions

Answers to the questions practitioners most commonly ask about Authorisation by Competent Supervisory Authority.

Does an authorisation from a competent supervisory authority mean my processing is fully compliant with the GDPR?
No. An authorisation from a competent supervisory authority typically addresses a specific mechanism or activity (for example, approving a particular transfer tool or a set of contractual clauses in a given context) and does not certify that your wider processing operation is compliant. You generally remain responsible for meeting all other applicable obligations, including lawful basis under Article 6, any additional condition for special category data under Article 9, transparency, security, and accountability. Treat any authorisation as addressing only the matter it expressly covers, and verify its precise scope against the authority's own wording.
Do I always need prior authorisation from a supervisory authority before I can start processing personal data?
No. Prior authorisation is not a general precondition for processing. Most processing proceeds on the responsibility of the controller relying on an appropriate Article 6 legal basis and, where relevant, an Article 9 condition, without any advance sign-off. Authorisation by a supervisory authority is required only in specific, defined situations set out in the Regulation or in national implementing law. It should not be confused with prior consultation, which is a distinct step that can arise in particular high-risk circumstances. Confirm whether your specific scenario falls within a defined authorisation requirement rather than assuming one applies.
How do we identify which supervisory authority is competent to give the authorisation we need?
Competence generally depends on factors such as where the controller or processor is established, where the processing takes place or has its effects, and the nature of the mechanism in question. In cross-border situations a lead supervisory authority and concerned authorities may be involved, and national implementing law can affect which body handles particular matters. Because these allocation rules can be nuanced, we recommend confirming the competent authority for your specific circumstances, and documenting the reasoning, rather than assuming a single default regulator.
What should we prepare before requesting an authorisation?
In most cases you should assemble a clear description of the processing or mechanism you want authorised, its scope and purposes, the categories of data and data subjects involved, the safeguards you propose, and the legal basis you are relying on. Where the authorisation relates to higher-risk activity, supporting assessment documentation may be expected. Because expectations and required forms can differ between authorities and can change over time, check the relevant authority's current published guidance and submission requirements before applying, and treat any templates as subject to verification.
How long does an authorisation last, and can it be varied or withdrawn?
An authorisation is generally tied to the scope, safeguards, and circumstances presented when it was granted. If those circumstances change materially, the authorisation may no longer cover your activity, and supervisory authorities typically retain powers to review, vary, or withdraw approvals. It should not be treated as permanent or open-ended. We recommend recording the conditions attached, monitoring for changes in your processing or in the applicable legal framework, and re-engaging with the authority where a change may fall outside what was authorised.
How does an authorisation interact with other transfer or safeguard mechanisms we may rely on?
An authorisation typically supports a specific mechanism and does not replace other tools you may need. For example, transfer arrangements can involve distinct instruments and, in some cases, supplementary measures, and these are separate from any authorisation step. Because transfer mechanisms, adequacy positions, and associated expectations evolve, you should not assume that an authorisation obtained for one mechanism covers another or remains aligned with the current framework. Map each mechanism to the obligation it satisfies and verify the position against the current official text and guidance.

Common misconceptions

An authorisation by a supervisory authority makes the processing fully compliant and immune from later challenge.
An authorisation generally addresses only the specific matter and conditions before the authority. It does not certify overall compliance, and the controller or processor typically remains responsible for ongoing obligations. Compliance is context and risk dependent, and an authorisation can be reviewed or its underlying legal framework can change over time.
Authorisation and prior consultation are the same thing.
They are distinct. Prior consultation generally involves the authority providing advice where a high residual risk is identified, whereas an authorisation is a formal approval to proceed with a defined activity. The applicable procedure and legal effect differ, so the correct mechanism should be identified before engaging the authority.
Every organisation must obtain authorisation before undertaking any significant or high-risk processing.
Authorisation is required only in specific situations defined by the relevant provision or national implementing law, and is not a universal precondition for processing. Many activities proceed on an identified legal basis without any supervisory authorisation, subject to the applicable accountability and, where relevant, consultation obligations.

Best practices

Confirm which authority is competent by reference to establishment, the one-stop-shop mechanism, and any cooperation or consistency procedures before initiating an authorisation request.
Verify against the current official text and applicable national implementing law whether authorisation is genuinely required, and distinguish it from prior consultation, so the correct mechanism is engaged.
Where authorisation supports a third-country transfer, document the specific safeguard relied upon and monitor for changes to transfer tools, adequacy decisions, and any supplementary measures, treating the position as capable of evolving rather than permanent.
Retain the full submission and the terms and conditions of any authorisation obtained as part of the accountability record, clearly marking the boundaries of what was approved.
Where regulator practice or the availability of a particular authorisation route is uncertain or divergent between member states, seek clarification and document the assumptions made rather than relying on a single interpretation as settled.
Review authorised activities periodically to confirm they still fall within the scope of the approval and remain consistent with current legal requirements and the underlying risk assessment.