Skip to main content
Category: Impact Assessments & Documentation

Availability to the Supervisory Authority

Also known as: Making records available to the supervisory authority, Availability of documentation to the regulator
Simply put

This refers to a controller's or processor's obligation, in certain circumstances, to provide their data protection documentation to the independent regulator that oversees compliance with data protection law. The supervisory authority is the official public body responsible for monitoring how organisations apply the rules, and it may request access to relevant records. Exactly what must be made available, and when, depends on the specific obligation and context.

Formal definition

'Availability to the supervisory authority' describes the accountability-related duty of controllers and processors to make specified documentation and information accessible to the competent supervisory authority, the independent public authority that, under the GDPR framework, monitors application of the Regulation and receives breach notifications. A recognised example is the general cooperation obligation, under which controllers and processors are expected to cooperate with the supervisory authority in the performance of its tasks on request. The obligation should not be conflated with proactive prior consultation or with breach notification (which under the GDPR is generally required within 72 hours of becoming aware, accompanied by reasons for any delay). The precise scope, including which records must be produced, the timing, the form of provision, and any documentation-keeping thresholds or exemptions (for example those relevant to smaller organisations), is defined by the applicable provisions and should be verified against the current official text of the GDPR (and, where relevant, the UK GDPR and national implementing law, which may vary). Note that the specific article references governing records of processing activities and the general cooperation duty are not contained in the evidence provided and should be confirmed against the Regulation text.

Why it matters

Availability to the supervisory authority sits at the heart of the GDPR's accountability principle. The framework does not only ask organisations to comply in substance; it expects them to be able to demonstrate compliance to the independent regulator that monitors application of the rules. Under the GDPR framework, each Member State provides for one or more independent public authorities responsible for monitoring the application of the Regulation, and these authorities may request access to relevant records. If documentation cannot be produced in a usable form on request, an organisation's accountability posture is weakened regardless of how sound its underlying practices may be.

The obligation should not be confused with adjacent duties that carry their own distinct timing and triggers. Breach notification, for example, is generally required within 72 hours of the controller becoming aware, and where notification is not made within that period it must be accompanied by reasons for the delay. That is a separate reactive duty, distinct from the ongoing expectation that documentation and records be available and that the organisation cooperate with the supervisory authority in the performance of its tasks. Treating these obligations as interchangeable can lead to gaps in a compliance program.

Because the precise scope of what must be produced, the timing, the form of provision, and any documentation-keeping thresholds or exemptions (including those that may be relevant to smaller organisations) are defined by the applicable provisions, organisations should verify the position against the current official text of the GDPR and, where relevant, the UK GDPR and national implementing law, which may vary. The practical takeaway is that readiness to respond to a regulator is itself a compliance concern, not merely a byproduct of doing the underlying work.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads are typically the primary point of contact for the supervisory authority and are generally responsible for ensuring that documentation can be located and produced on request. They should confirm which records fall within scope, the form in which they must be provided, and whether any documentation-keeping thresholds or exemptions apply to their organisation, verifying these points against the current official text of the GDPR and relevant national law.
Controllers
Controllers carry primary accountability under the framework and are generally expected to maintain relevant records and cooperate with the supervisory authority in the performance of its tasks. Controllers should distinguish this ongoing availability and cooperation duty from separate obligations such as breach notification, which is generally required within 72 hours of becoming aware and, where delayed, must be accompanied by reasons for the delay.
Processors
Processors are also subject to accountability and cooperation expectations in their own right. They should understand what documentation they may be required to make available and how their cooperation duty operates in relation to both the supervisory authority and the controllers they serve, confirming the precise scope against the applicable provisions.
Privacy Engineers and Records Management Teams
Those responsible for building and maintaining systems and records need to ensure documentation is stored in a form that can be retrieved and provided to a regulator in a usable manner. Because the required form and timing depend on the specific obligation and context, these teams should design retention and retrieval processes with regulator-readiness in mind rather than assuming after-the-fact reconstruction will suffice.
Smaller Organisations
Certain documentation-keeping thresholds and exemptions may be particularly relevant to smaller organisations. Because the position varies and may be affected by national implementing law and member state derogations, smaller organisations should not assume an exemption applies without confirming the applicable criteria against the current official text.

Inside Availability to the Supervisory Authority

Duty to make records available (Article 30(4) GDPR)
Article 30(4) GDPR provides that the controller or processor, and where applicable their representative, shall make the record of processing activities available to the supervisory authority on request. This is the core statutory anchor for the concept: the record maintained under Article 30(1) and (2) must be capable of being produced to the regulator when asked.
General duty to cooperate (Article 31 GDPR)
Article 31 GDPR requires the controller and the processor, and where applicable their representatives, to cooperate, on request, with the supervisory authority in the performance of its tasks. Availability of records typically sits within this broader cooperation obligation, so a request for records is generally an exercise of the authority's supervisory functions.
Who bears the obligation
The obligation falls on the controller or processor and, where applicable, on a representative appointed under the Regulation. Note that the scope of the record-keeping duty itself can be affected by exemptions (for example the derogation for certain smaller organisations), so whether a full record must exist and be produced is subject to assessment in each case.
Trigger and manner of production
The duty is generally activated by a request from the supervisory authority rather than requiring proactive publication. The Regulation does not prescribe a single technical format or fixed deadline in the text of Article 30(4); practitioners should verify any timing, form, or procedural expectations against the current official text and applicable national implementing law and regulator guidance.
Relationship to the record's content
What must be made available is the record of processing activities as described in Article 30, which typically includes categories of processing, purposes, categories of data subjects and personal data, recipients, transfers, and, where possible, retention periods and security measures. The availability duty concerns producing that content, not creating new documentation on demand.

Common questions

Answers to the questions practitioners most commonly ask about Availability to the Supervisory Authority.

Does 'availability to the supervisory authority' mean the same thing as publishing your records of processing activities or making them public?
No. Availability to the supervisory authority is a targeted duty to make certain information accessible to the regulator on request, not a general publication or transparency obligation toward the public. Article 30(4) GDPR requires that records of processing activities be made available to the supervisory authority on request, which is distinct from the transparency duties owed to data subjects under Articles 13 and 14. The two should not be conflated: a record can satisfy the availability duty without being publicly disclosed, and public-facing privacy notices do not by themselves discharge the availability obligation.
Is this duty only relevant during a formal investigation or after a complaint has been made?
Not necessarily. The general duty to cooperate with the supervisory authority under Article 31 GDPR applies to controllers and processors (and, where applicable, their representatives) in the performance of the authority's tasks, and is not limited to situations where an investigation or complaint is already underway. Similarly, the Article 30(4) obligation to make records available on request can arise outside a contentious context. In practice, the trigger and scope of a request can vary, and readers should assess each request against its stated legal basis and the requesting authority's remit.
What records or information typically need to be made available on request?
Under Article 30(4) GDPR, the records of processing activities maintained under Article 30 are expressly required to be made available to the supervisory authority on request. Beyond that specific record, the broader cooperation duty in Article 31 GDPR can extend to other information the authority reasonably needs to perform its tasks. The precise scope of any given request depends on the authority's legal powers and the terms of the request itself, so the exact materials to be provided should be assessed case by case rather than assumed.
Who within an organisation is responsible for making records available to the supervisory authority?
The obligation generally rests with the controller or the processor, and where applicable their representative, as reflected in Articles 30 and 31 GDPR. Many organisations assign operational responsibility to a data protection officer or a designated compliance function, but the underlying legal duty remains with the controller or processor. It is typically advisable to define internally, in advance, who receives and coordinates responses to regulator requests so that availability can be demonstrated promptly.
In what format and how quickly should records be provided when the supervisory authority asks?
The GDPR text does not prescribe a single fixed format or a universal deadline for the Article 30(4) availability duty, and expectations can vary between supervisory authorities and according to the terms of the request. In most cases records should be provided in a legible, complete, and up-to-date form within a reasonable period. Because timing and format expectations can differ by regulator and national practice, readers should verify the specific requirements against the requesting authority's guidance and any applicable national implementing law.
How can an organisation prepare in advance to meet this duty?
Practical preparation generally includes maintaining accurate and current records of processing activities as contemplated by Article 30, keeping them in a form that can be produced without extensive reconstruction, and establishing an internal process for receiving, validating, and responding to requests from a supervisory authority consistent with the cooperation duty in Article 31. Organisations often also document who is authorised to respond and how the authenticity of a request is checked. The appropriate level of preparation should be assessed against the organisation's size, processing activities, and risk profile.

Common misconceptions

The records of processing activities must be published or continuously accessible to the public or the regulator.
Article 30(4) GDPR frames the duty as making the record available to the supervisory authority, generally on request, rather than as a publication obligation. The concept is about being able to produce the record to the regulator, not about open publication.
Making records available is a stand-alone technical task unconnected to any wider obligation.
Availability to the supervisory authority generally operates alongside the broader cooperation duty in Article 31 GDPR, under which controllers and processors must cooperate with the authority in performing its tasks. Producing records is typically one manifestation of that cooperation rather than an isolated requirement.
Only controllers have to make records available.
The Article 30 and Article 31 duties apply to both controllers and processors, and to representatives where applicable. The precise scope of the record-keeping duty, and therefore what can be produced, is subject to the Regulation's exemptions and should be assessed for each organisation.

Best practices

Maintain the record of processing activities under Article 30 in a form that can be produced promptly on request, keeping in mind that Article 30(4) requires it to be made available to the supervisory authority.
Treat availability as part of the wider cooperation duty under Article 31 GDPR, and establish an internal process for responding to supervisory authority requests in a coordinated and cooperative manner.
Assign clear ownership for holding, updating, and producing the records, distinguishing controller and processor responsibilities and, where relevant, the role of any appointed representative.
Assess whether any record-keeping exemption applies to your organisation before relying on it, since the scope of what must exist and be produced is context dependent and subject to assessment.
Verify any expectations about response timing, format, or procedure against the current official text of the GDPR, applicable national implementing law, and the relevant regulator's guidance, as these can vary between member states.
Keep the underlying record accurate and current so that what is made available reflects actual processing at the time of the request.