Availability to the Supervisory Authority
This refers to a controller's or processor's obligation, in certain circumstances, to provide their data protection documentation to the independent regulator that oversees compliance with data protection law. The supervisory authority is the official public body responsible for monitoring how organisations apply the rules, and it may request access to relevant records. Exactly what must be made available, and when, depends on the specific obligation and context.
'Availability to the supervisory authority' describes the accountability-related duty of controllers and processors to make specified documentation and information accessible to the competent supervisory authority, the independent public authority that, under the GDPR framework, monitors application of the Regulation and receives breach notifications. A recognised example is the general cooperation obligation, under which controllers and processors are expected to cooperate with the supervisory authority in the performance of its tasks on request. The obligation should not be conflated with proactive prior consultation or with breach notification (which under the GDPR is generally required within 72 hours of becoming aware, accompanied by reasons for any delay). The precise scope, including which records must be produced, the timing, the form of provision, and any documentation-keeping thresholds or exemptions (for example those relevant to smaller organisations), is defined by the applicable provisions and should be verified against the current official text of the GDPR (and, where relevant, the UK GDPR and national implementing law, which may vary). Note that the specific article references governing records of processing activities and the general cooperation duty are not contained in the evidence provided and should be confirmed against the Regulation text.
Why it matters
Availability to the supervisory authority sits at the heart of the GDPR's accountability principle. The framework does not only ask organisations to comply in substance; it expects them to be able to demonstrate compliance to the independent regulator that monitors application of the rules. Under the GDPR framework, each Member State provides for one or more independent public authorities responsible for monitoring the application of the Regulation, and these authorities may request access to relevant records. If documentation cannot be produced in a usable form on request, an organisation's accountability posture is weakened regardless of how sound its underlying practices may be.
The obligation should not be confused with adjacent duties that carry their own distinct timing and triggers. Breach notification, for example, is generally required within 72 hours of the controller becoming aware, and where notification is not made within that period it must be accompanied by reasons for the delay. That is a separate reactive duty, distinct from the ongoing expectation that documentation and records be available and that the organisation cooperate with the supervisory authority in the performance of its tasks. Treating these obligations as interchangeable can lead to gaps in a compliance program.
Because the precise scope of what must be produced, the timing, the form of provision, and any documentation-keeping thresholds or exemptions (including those that may be relevant to smaller organisations) are defined by the applicable provisions, organisations should verify the position against the current official text of the GDPR and, where relevant, the UK GDPR and national implementing law, which may vary. The practical takeaway is that readiness to respond to a regulator is itself a compliance concern, not merely a byproduct of doing the underlying work.
Who it's relevant to
Inside Availability to the Supervisory Authority
Common questions
Answers to the questions practitioners most commonly ask about Availability to the Supervisory Authority.