Authorisation by Competent Supervisory Authority
This refers to formal approval granted by the data protection regulator that is legally responsible for overseeing an organisation's processing activities. Under the GDPR, each EU member state establishes one or more independent public authorities to monitor how the Regulation is applied, and in certain situations an organisation may need approval from the relevant authority before proceeding. The specific circumstances requiring such authorisation depend on the applicable provisions and any national implementing law, so the exact requirements should be verified against the current official text.
A 'competent supervisory authority' is, in general terms, the independent public authority designated to supervise the application of the GDPR in respect of given processing. Article 51 requires each Member State to provide for one or more independent supervisory authorities responsible for monitoring the application of the Regulation and contributing to its consistent application across the Union. Article 56 addresses the competence of the lead supervisory authority in cross-border processing, while also preserving each supervisory authority's competence to handle a complaint lodged with it or a possible infringement, subject to the cooperation and consistency mechanisms; where authorities disagree, dispute resolution may involve the European Data Protection Board. 'Authorisation' in this context typically denotes a supervisory, approval or enforcement function exercised by the designated regulator, consistent with the broader legal-practice notion of a 'competent authority' as the regulator empowered by legislation to perform such functions. The precise scope of any authorisation requirement, the identity of the competent authority, and the interaction with national implementing law can vary; practitioners should confirm the applicable provisions, article references, and whether the EU GDPR or UK GDPR framework applies against the current official text.
Why it matters
Identifying the competent supervisory authority is a foundational step in managing regulatory relationships under the GDPR. Because each EU member state provides for one or more independent public authorities responsible for monitoring the application of the Regulation, an organisation needs to know which regulator has oversight of a given processing activity before it can seek approval, respond to enquiries, or engage on matters where regulatory involvement is expected. Getting this wrong can lead to engaging the wrong body, delays, or uncertainty about which authority's expectations apply.
The question becomes more complex in cross-border processing. Article 56 addresses the competence of the lead supervisory authority, but it also preserves each supervisory authority's competence to handle a complaint lodged with it or a possible infringement, subject to the cooperation and consistency mechanisms. As IAPP guidance notes, in many cases the lead authority's decision will be accepted or a consensus reached; where a dispute arises between authorities, dispute resolution may involve the European Data Protection Board. This means an organisation cannot always assume a single point of contact will resolve every issue, and should understand how the one-stop-shop mechanism interacts with local authorities' retained competence.
The precise scope of any authorisation requirement, the identity of the competent authority, and the interaction with national implementing law can vary between member states. Requirements may also differ depending on whether the EU GDPR or the UK GDPR framework applies. Practitioners should treat the identity of the competent authority and any approval requirement as matters to confirm against the current official text and applicable national law rather than as settled positions.
Who it's relevant to
Inside Authorisation by Competent Supervisory Authority
Common questions
Answers to the questions practitioners most commonly ask about Authorisation by Competent Supervisory Authority.