Competence of the Lead Authority
When an organisation processes personal data across several EU countries, one national data protection regulator generally acts as the main point of contact rather than every country's regulator dealing with the organisation separately. This lead authority coordinates oversight of the organisation's cross-border activities. Other national regulators can still be involved in certain situations, such as handling complaints raised locally.
Under Article 56 GDPR, the lead supervisory authority is designated as the sole interlocutor of a controller or processor in respect of cross-border processing carried out by that controller or processor, forming a core element of the one-stop-shop mechanism. The lead authority is typically identified by reference to the location of the controller's or processor's main establishment (as defined in Article 4 and elaborated in EDPB guidance), and it takes the coordinating role for supervision of the relevant cross-border processing. This competence is not exclusive in all circumstances: each supervisory authority generally remains competent to handle a complaint lodged with it or a possible infringement of the Regulation, particularly where the subject matter relates only to an establishment in its member state or substantially affects data subjects only in its territory, subject to the cooperation and consistency procedures in Chapter VII. The precise allocation of competence in a given case is subject to assessment; readers should verify the operative text of Article 56 and applicable EDPB guidance, and note that national implementing law and regulator practice can affect the position.
Why it matters
For organisations operating across multiple EU member states, the competence of the lead authority determines whether they face a single coordinating regulator for their cross-border processing or must engage separately with the supervisory authority in every country where they operate. Article 56 GDPR designates the lead supervisory authority as the sole interlocutor of the controller or processor for cross-border processing, which is the practical heart of the one-stop-shop mechanism. Correctly identifying the lead authority affects who an organisation coordinates with on investigations, enforcement, and cooperation procedures, and getting this wrong can lead to engaging the wrong regulator or misjudging where oversight will originate.
The competence is not exclusive in all circumstances, and this qualification matters considerably in practice. Each supervisory authority generally remains competent to handle a complaint lodged with it or a possible infringement of the Regulation, particularly where the subject matter relates only to an establishment in that regulator's member state or substantially affects data subjects only in its territory. As one national regulator has noted, the supervisory authority of another country can be competent to conduct an investigation into an organisation. Organisations should therefore not assume that identifying a lead authority insulates them entirely from involvement by other regulators.
The precise allocation of competence in any given case is subject to assessment and is shaped by the cooperation and consistency procedures in Chapter VII of the GDPR. Because national implementing law and regulator practice can affect the position, and because the identification of a main establishment can itself be contested, organisations should treat lead authority determinations as fact-specific rather than settled, and should verify against the operative text of Article 56 and applicable EDPB guidance.
Who it's relevant to
Inside Competence of the Lead Authority
Common questions
Answers to the questions practitioners most commonly ask about Competence of the Lead Authority.