Competence of the Lead Supervisory Authority
When an organisation processes personal data across more than one EU country, one national data protection regulator is designated as the 'lead' authority to act as the main point of contact for that organisation. This lead authority coordinates oversight of the organisation's cross-border processing, though other regulators generally retain a role in handling complaints raised with them locally. The aim is to give organisations a single primary regulator rather than dealing separately with every national authority.
Under Article 56 GDPR, the lead supervisory authority is generally the supervisory authority of the main establishment or single establishment of a controller or processor, and it acts as the sole interlocutor for that controller or processor in respect of cross-border processing. This competence operates within the cooperation and consistency framework (the 'one-stop-shop' mechanism), under which the lead authority coordinates with other concerned supervisory authorities. Notwithstanding the lead authority's competence, each supervisory authority remains competent to handle a complaint lodged with it or a possible infringement affecting its territory, subject to the referral and cooperation procedures set out in the Regulation. The identification of the lead authority depends on a factual assessment of where the main establishment is located, and a supervisory authority of another member state may in certain circumstances be competent to conduct an investigation; readers should verify the current position against the official text and applicable EDPB guidance, and note that national implementing law and the UK GDPR framework may differ.
Why it matters
For any organisation whose data processing spans multiple EU member states, the competence of the lead supervisory authority determines who its principal regulator is and, in practice, whom it will deal with day to day. Under the one-stop-shop mechanism, the lead authority acts as the sole interlocutor for the controller or processor in respect of its cross-border processing, which is intended to reduce the burden of engaging separately with every national regulator. Getting the identification of the lead authority right therefore shapes how oversight, cooperation, and enforcement will unfold for the organisation's cross-border activities.
The competence is not absolute, and this is where organisations most often misunderstand their exposure. Notwithstanding the lead authority's role, each supervisory authority generally remains competent to handle a complaint lodged with it or a possible infringement affecting its territory, subject to the referral and cooperation procedures in the Regulation. In addition, guidance from a national regulator indicates that the supervisory authority of another country may in certain circumstances be competent to conduct an investigation into an organisation. The single-regulator promise is thus better understood as a coordinated framework than as a guarantee of exclusive dealings with one authority.
Because the identification of the lead authority turns on a factual assessment of where the main establishment is located, errors or overly optimistic assumptions can leave an organisation exposed to oversight it did not anticipate. The position can also differ under national implementing law and under the UK GDPR framework, and it may be affected by evolving EDPB guidance. Readers should verify the current position against the official text and applicable guidance rather than treating any snapshot as settled.
Who it's relevant to
Inside LSA
Common questions
Answers to the questions practitioners most commonly ask about LSA.