Skip to main content
Category: Supervisory Authorities & Enforcement

Competence of the Lead Authority

Also known as: Competence of the Lead Supervisory Authority, Lead Supervisory Authority Competence, Article 56 Competence
Simply put

When an organisation processes personal data across several EU countries, one national data protection regulator generally acts as the main point of contact rather than every country's regulator dealing with the organisation separately. This lead authority coordinates oversight of the organisation's cross-border activities. Other national regulators can still be involved in certain situations, such as handling complaints raised locally.

Formal definition

Under Article 56 GDPR, the lead supervisory authority is designated as the sole interlocutor of a controller or processor in respect of cross-border processing carried out by that controller or processor, forming a core element of the one-stop-shop mechanism. The lead authority is typically identified by reference to the location of the controller's or processor's main establishment (as defined in Article 4 and elaborated in EDPB guidance), and it takes the coordinating role for supervision of the relevant cross-border processing. This competence is not exclusive in all circumstances: each supervisory authority generally remains competent to handle a complaint lodged with it or a possible infringement of the Regulation, particularly where the subject matter relates only to an establishment in its member state or substantially affects data subjects only in its territory, subject to the cooperation and consistency procedures in Chapter VII. The precise allocation of competence in a given case is subject to assessment; readers should verify the operative text of Article 56 and applicable EDPB guidance, and note that national implementing law and regulator practice can affect the position.

Why it matters

For organisations operating across multiple EU member states, the competence of the lead authority determines whether they face a single coordinating regulator for their cross-border processing or must engage separately with the supervisory authority in every country where they operate. Article 56 GDPR designates the lead supervisory authority as the sole interlocutor of the controller or processor for cross-border processing, which is the practical heart of the one-stop-shop mechanism. Correctly identifying the lead authority affects who an organisation coordinates with on investigations, enforcement, and cooperation procedures, and getting this wrong can lead to engaging the wrong regulator or misjudging where oversight will originate.

The competence is not exclusive in all circumstances, and this qualification matters considerably in practice. Each supervisory authority generally remains competent to handle a complaint lodged with it or a possible infringement of the Regulation, particularly where the subject matter relates only to an establishment in that regulator's member state or substantially affects data subjects only in its territory. As one national regulator has noted, the supervisory authority of another country can be competent to conduct an investigation into an organisation. Organisations should therefore not assume that identifying a lead authority insulates them entirely from involvement by other regulators.

The precise allocation of competence in any given case is subject to assessment and is shaped by the cooperation and consistency procedures in Chapter VII of the GDPR. Because national implementing law and regulator practice can affect the position, and because the identification of a main establishment can itself be contested, organisations should treat lead authority determinations as fact-specific rather than settled, and should verify against the operative text of Article 56 and applicable EDPB guidance.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads at organisations with processing activities spanning more than one EU member state need to assess which authority is likely to act as lead based on the main establishment, and to understand that other regulators may still handle local complaints. This informs regulatory engagement strategy, breach notification planning, and how the organisation prepares for potential investigations. The determination should be documented and revisited as the business structure changes, since it is subject to assessment rather than fixed.
Privacy and Data Protection Lawyers
Legal advisers rely on a precise reading of Article 56 to advise on which supervisory authority is the sole interlocutor for cross-border processing and where competence may nonetheless remain with another authority. They should distinguish the one-stop-shop coordinating role from the residual competence of other regulators over locally lodged complaints, and should verify positions against the operative GDPR text, EDPB guidance, and relevant national implementing law rather than treating any single interpretation as settled.
Multinational Controllers and Processors
Organisations processing personal data across several EU countries have a direct interest in identifying their main establishment accurately, because this generally drives which authority coordinates oversight of their cross-border activities. They should recognise that the lead authority mechanism reduces but does not eliminate the possibility of involvement by other national regulators, and that the practical position can be affected by cooperation and consistency procedures as well as regulator practice.
Supervisory Authority Liaison and Enforcement Response Teams
Teams responsible for interacting with regulators need to know which authority to treat as the primary point of contact for cross-border matters, while remaining prepared for scenarios where another authority handles a complaint lodged with it or conducts an investigation. Understanding the boundary between lead authority competence and the competence of other concerned authorities helps these teams respond appropriately and route communications correctly.

Inside Competence of the Lead Authority

Lead Supervisory Authority (LSA)
The supervisory authority designated as the primary point of contact for a controller or processor engaged in cross-border processing. Under the GDPR's one-stop-shop mechanism (generally associated with Article 56), the LSA takes the lead in coordinating with other concerned authorities. The precise identification depends on the facts and is subject to assessment rather than being fixed by a single formal registration.
Main Establishment Criterion
Competence of the lead authority is typically anchored to the location of the controller's or processor's main establishment in the EU. For a controller, this is generally the place of central administration in the Union, unless decisions on the purposes and means of processing are taken at another establishment which then determines the main establishment. The analysis is fact-dependent and can be contested.
Cross-Border Processing
The one-stop-shop and lead authority competence apply only where processing is cross-border, generally meaning processing in the context of activities of establishments in more than one member state, or processing that substantially affects data subjects in more than one member state. Where processing is purely local, the concept does not apply.
Concerned Supervisory Authorities
Authorities other than the lead that have an interest because, for example, controllers or processors are established in their territory, data subjects there are substantially affected, or a complaint was lodged with them. The lead authority must cooperate with concerned authorities and does not act in isolation.
Cooperation and Consistency Mechanism
The framework through which the lead authority coordinates with concerned authorities and, where disagreements arise, the matter may be escalated. This supports consistent application across member states, though outcomes and timelines depend on the specific procedure invoked and can vary.
Scope Limitation to Cross-Border Cases
Lead authority competence governs which regulator coordinates cross-border matters; it does not remove the ability of a local authority to handle purely local processing or, in certain urgent or complaint-specific situations, to act. The precise allocation is subject to assessment against the facts and applicable procedure.

Common questions

Answers to the questions practitioners most commonly ask about Competence of the Lead Authority.

Does having a lead supervisory authority mean only one regulator can ever deal with our organisation?
Not necessarily. The one-stop-shop mechanism designates a lead authority for cross-border processing, but other concerned supervisory authorities retain a role, and in some cases a local authority may act on matters that substantially affect data subjects only in its own member state. The lead authority's competence generally coordinates rather than wholly excludes other authorities. The precise allocation is subject to the cooperation and consistency procedures, and you should verify the current position against the official text and relevant guidance.
Is our lead authority simply whichever supervisory authority we choose or find most convenient?
No. Competence of the lead authority is generally determined by the location of the controller's or processor's main establishment or single establishment in the EU, not by preference. The main establishment typically relates to the place of central administration or the establishment where decisions on the purposes and means of processing are taken. This is an objective assessment based on the facts of your organisation, and it may be examined or challenged by regulators rather than simply asserted.
How do we identify which supervisory authority is our lead authority?
In most cases, you assess where your main establishment in the EU is located, generally by reference to the place of central administration, unless decisions on the purposes and means of processing are taken elsewhere, in which case that establishment may be treated as the main establishment. Document the analysis, including your decision-making structures. Where the position is not clear-cut, regulators may ultimately determine competence, so retain reasoning and supporting evidence and treat any conclusion as subject to review.
What should we do if our processing activities are cross-border but we have no establishment in the EU?
The one-stop-shop and lead authority mechanism generally applies where there is an establishment in the EU. Where an organisation has no EU establishment but is nonetheless within scope, the one-stop-shop typically does not operate in the same way, and multiple concerned authorities may each be competent. In such situations you should consider your representative arrangements and seek advice on how competence is allocated, verifying the current position against the official text and applicable guidance.
How does lead authority competence affect where data subjects lodge complaints and where we may face enforcement?
Data subjects can generally lodge a complaint with their own local supervisory authority regardless of where your lead authority sits. That local authority typically handles receipt of the complaint and cooperates with the lead authority under the applicable procedures. Enforcement in cross-border matters is generally coordinated through the lead authority and concerned authorities, but a local authority may act in certain circumstances. Because outcomes depend on the specific procedure followed, plan for engagement with more than one authority.
Should we reassess our lead authority over time, and when?
Yes, generally. The identification of a main establishment reflects your organisational and decision-making structure at a point in time. If you relocate central administration, change where decisions on purposes and means are taken, restructure EU establishments, or alter your cross-border processing, you should reassess. Keep the analysis current and documented, and treat any conclusion as subject to regulatory review rather than settled.

Common misconceptions

The lead authority has exclusive jurisdiction and other authorities are excluded entirely.
The lead authority coordinates cross-border matters through the cooperation mechanism, but concerned supervisory authorities retain a role. In certain situations, such as purely local processing or specific complaint or urgency scenarios, another authority may act. The allocation is fact-dependent and not a total exclusion of all other regulators.
An organization can simply choose or designate its lead authority for administrative convenience.
Competence generally follows the location of the main establishment as determined by where decisions on the purposes and means of processing are effectively taken, not by an organization's self-selection or where it prefers to be regulated. A designation that does not reflect the operational reality can be challenged, and the assessment is fact-based.
Every organization operating in multiple member states automatically has a lead authority.
The one-stop-shop applies only to cross-border processing. An organization without an EU main establishment, or one whose processing is not cross-border, may not benefit from a lead authority, and multiple local authorities may be competent. Whether a lead authority exists depends on the specific establishment and processing facts.

Best practices

Map your EU establishments and identify where decisions on the purposes and means of processing are actually taken, documenting the analysis supporting any identification of a main establishment rather than relying on convenience.
Assess whether your processing is genuinely cross-border before assuming the one-stop-shop applies, and treat purely local processing separately.
Maintain records of the reasoning for your lead authority position so it can be defended if a regulator or complainant challenges it, recognizing that the determination is fact-dependent.
Engage cooperatively and anticipate that concerned supervisory authorities may participate, so build channels for multi-authority interaction rather than treating a single regulator as your only counterpart.
Review the lead authority determination periodically, particularly after reorganizations, changes in decision-making structures, or shifts in where processing activities are directed, as the position can change.
Verify the current cooperation and consistency procedures and any regulator guidance against official sources, since interpretation and practice can vary between authorities.