Skip to main content
Category: Supervisory Authorities & Enforcement

Competence of the Lead Supervisory Authority

Also known as: LSA, Competence of the Lead Authority, Lead Supervisory Authority Competence, Article 56 Competence
Simply put

When an organisation processes personal data across more than one EU country, one national data protection regulator is designated as the 'lead' authority to act as the main point of contact for that organisation. This lead authority coordinates oversight of the organisation's cross-border processing, though other regulators generally retain a role in handling complaints raised with them locally. The aim is to give organisations a single primary regulator rather than dealing separately with every national authority.

Formal definition

Under Article 56 GDPR, the lead supervisory authority is generally the supervisory authority of the main establishment or single establishment of a controller or processor, and it acts as the sole interlocutor for that controller or processor in respect of cross-border processing. This competence operates within the cooperation and consistency framework (the 'one-stop-shop' mechanism), under which the lead authority coordinates with other concerned supervisory authorities. Notwithstanding the lead authority's competence, each supervisory authority remains competent to handle a complaint lodged with it or a possible infringement affecting its territory, subject to the referral and cooperation procedures set out in the Regulation. The identification of the lead authority depends on a factual assessment of where the main establishment is located, and a supervisory authority of another member state may in certain circumstances be competent to conduct an investigation; readers should verify the current position against the official text and applicable EDPB guidance, and note that national implementing law and the UK GDPR framework may differ.

Why it matters

For any organisation whose data processing spans multiple EU member states, the competence of the lead supervisory authority determines who its principal regulator is and, in practice, whom it will deal with day to day. Under the one-stop-shop mechanism, the lead authority acts as the sole interlocutor for the controller or processor in respect of its cross-border processing, which is intended to reduce the burden of engaging separately with every national regulator. Getting the identification of the lead authority right therefore shapes how oversight, cooperation, and enforcement will unfold for the organisation's cross-border activities.

The competence is not absolute, and this is where organisations most often misunderstand their exposure. Notwithstanding the lead authority's role, each supervisory authority generally remains competent to handle a complaint lodged with it or a possible infringement affecting its territory, subject to the referral and cooperation procedures in the Regulation. In addition, guidance from a national regulator indicates that the supervisory authority of another country may in certain circumstances be competent to conduct an investigation into an organisation. The single-regulator promise is thus better understood as a coordinated framework than as a guarantee of exclusive dealings with one authority.

Because the identification of the lead authority turns on a factual assessment of where the main establishment is located, errors or overly optimistic assumptions can leave an organisation exposed to oversight it did not anticipate. The position can also differ under national implementing law and under the UK GDPR framework, and it may be affected by evolving EDPB guidance. Readers should verify the current position against the official text and applicable guidance rather than treating any snapshot as settled.

Who it's relevant to

Data protection officers and compliance leads
DPOs and compliance teams need to determine, based on a factual assessment of the main establishment, whether their organisation has a lead authority and which regulator that is. This affects who the primary point of contact will be for cross-border processing, but teams should not assume exclusivity, as other authorities generally retain competence over local complaints and infringements affecting their territory.
In-house counsel and privacy lawyers
Legal advisers assessing regulatory exposure across multiple member states should treat the one-stop-shop as a coordination mechanism rather than a guarantee of dealing with a single regulator. They should account for the possibility that another supervisory authority may in certain circumstances be competent to investigate, and verify the position against the current Article 56 text and applicable EDPB guidance.
Controllers and processors operating across borders
Organisations carrying out cross-border processing benefit from having a lead authority as the sole interlocutor for that processing, which can streamline engagement. However, the correct identification of the main establishment is decisive, and getting it wrong can affect which regulator coordinates oversight and how complaints raised locally in other member states are handled.
UK-facing organisations
Organisations subject to the UK GDPR framework should be aware that the position on lead authority competence and the one-stop-shop may differ from the EU GDPR, and that national implementing law can vary the arrangements. The current applicable framework should be verified rather than assumed to mirror the EU mechanism.

Inside LSA

Lead Supervisory Authority (LSA)
Under the GDPR's one-stop-shop mechanism (generally Article 56), the supervisory authority of the main establishment or single establishment of a controller or processor acts as the lead authority for cross-border processing. Its competence is typically to coordinate the handling of cases affecting data subjects across multiple member states.
Main establishment
The concept that determines which authority is competent as lead. For a controller, this is generally the place of central administration in the EU, unless decisions on the purposes and means of processing are taken at another establishment, in which case that establishment may be treated as the main one. For processors, a separate test applies. Identification can be subject to assessment and is not always straightforward.
Cross-border processing
The trigger for the lead authority framework. It generally covers processing carried out in the context of activities of establishments in more than one member state, or processing that substantially affects or is likely to substantially affect data subjects in more than one member state. The one-stop-shop typically does not apply to purely local processing.
Cooperation and consistency mechanisms
The lead authority does not act in isolation. It cooperates with concerned supervisory authorities (typically Article 60) and, where authorities disagree, the consistency mechanism and the European Data Protection Board may become involved (broadly Articles 63 to 65). The lead role is coordinating rather than exclusive.
Concerned supervisory authorities
Authorities other than the lead that have a legitimate interest in a case, for example because data subjects in their territory are substantially affected or a complaint was lodged with them. They retain a role in the cooperative process alongside the lead authority.
Local competence exception
Even where a lead authority exists, a supervisory authority may in certain cases handle a local matter, for example where the subject matter relates only to an establishment in its member state or substantially affects only data subjects in that member state, subject to the procedures in the Regulation.

Common questions

Answers to the questions practitioners most commonly ask about LSA.

Does having a single Lead Supervisory Authority mean only that authority can ever act against our organisation?
No. The one-stop-shop mechanism designates a lead authority for cross-border processing, but it does not make that authority exclusively competent in all circumstances. Other supervisory authorities may act as concerned authorities, and in certain cases a local authority may handle matters relating to processing that substantially affects data subjects only in its own member state, or urgent matters under the relevant provisions. The lead authority coordinates but does not wholly displace the role of concerned authorities, so treating it as a single point of enforcement for every situation is generally inaccurate.
Is the Lead Supervisory Authority simply the authority in the country where we are headquartered?
Not necessarily. The lead authority is generally determined by the location of the controller's or processor's main establishment, which is typically the place of central administration in the EU, or the establishment where decisions about the purposes and means of processing are taken if these occur elsewhere. This can differ from the registered headquarters. The location must be assessed on the facts of where relevant decision-making actually takes place, and the analysis can differ for controllers versus processors. It is subject to assessment rather than a fixed assumption based on corporate registration.
How do we identify our main establishment in order to determine the Lead Supervisory Authority?
You should assess where your central administration in the EU is located and, importantly, where decisions on the purposes and means of the relevant processing are actually taken, as this may point to a different establishment. The analysis is factual and may vary between different processing activities. Where the position is not clear-cut, guidance from the European Data Protection Board on identifying a lead authority is generally the reference point, and documenting your reasoning is advisable. Some organisations may find they have no main establishment in the EU, which affects whether a lead authority mechanism is available at all.
What happens if a supervisory authority disputes which authority should be the lead?
Disputes over competence can arise between authorities, particularly where it is unclear where the main decision-making occurs. The cooperation and consistency mechanisms, including the role of the European Data Protection Board, are generally intended to resolve such questions. Organisations cannot unilaterally bind authorities to their chosen lead simply by asserting a main establishment; the authorities retain the ability to test that determination. Where there is genuine uncertainty, you should be prepared for the position to be examined rather than treated as settled.
Does designating a Lead Supervisory Authority affect how we handle a data subject complaint?
A data subject may generally lodge a complaint with the supervisory authority in their own member state regardless of where your lead authority sits. That local authority may act as a concerned authority and will typically coordinate with the lead through the cooperation mechanism. This means you may still receive contact from an authority other than your identified lead, so complaint-handling processes should account for concerned authorities and not assume all correspondence will route through a single point.
Should we document our lead authority determination, and how should we keep it current?
Documenting the basis for your main establishment and lead authority determination is generally advisable, as it supports your accountability position and helps in any dispute or query. Because the determination depends on where processing decisions are actually taken, organisational changes such as relocating decision-making functions can alter the analysis. It is therefore sensible to revisit the assessment when your governance structure changes, and to verify your reasoning against current guidance, as the practical application of these rules can evolve.

Common misconceptions

Every organisation operating across the EU automatically has a single regulator it answers to for all matters.
The one-stop-shop applies to cross-border processing, and identifying a lead authority depends on locating a main establishment. Purely local processing, and certain local matters, may still be handled by individual national authorities, so a single point of contact is not guaranteed for all cases.
The lead authority has exclusive and final decision-making power over cross-border cases.
The lead authority coordinates the case, but it must cooperate with concerned authorities. Where they disagree, the consistency mechanism and the European Data Protection Board can become involved. The role is coordinating within a cooperative framework rather than unilateral.
The location of an organisation's registered office or largest office is decisive for choosing the lead authority.
Competence generally turns on the main establishment, which is tied to where decisions on the purposes and means of processing are effectively taken, not merely a registered office. This is a factual assessment and can differ from where an entity is incorporated or where most staff sit.

Best practices

Map your EU establishments and identify where decisions on the purposes and means of processing are actually taken, since this drives the main establishment analysis rather than the registered office alone.
Document your reasoning for the identified main establishment and lead authority, and revisit it when your operational or decision-making structure changes, because the assessment is fact-dependent.
Distinguish clearly between cross-border processing that engages the one-stop-shop and purely local processing that may remain with individual national authorities.
Engage constructively with concerned supervisory authorities and expect a cooperative process, rather than assuming the lead authority will decide unilaterally.
Verify the current position on lead authority identification and cooperation procedures against the official GDPR text and relevant EDPB guidance, as interpretation can evolve.
For controllers and processors, apply the correct main establishment test for each role separately, and confirm whether local competence exceptions may apply to a given matter.