Concerned Supervisory Authority
A concerned supervisory authority is a national data protection regulator that has a stake in a particular case involving personal data processing that affects people or organizations in its country. When processing crosses borders within the EU, several regulators may be 'concerned,' and they cooperate with a lead authority to reach coordinated decisions. This mechanism is intended to give individuals a voice through their local regulator while avoiding conflicting outcomes across member states.
Under the GDPR's cooperation framework, a concerned supervisory authority (CSA) is a supervisory authority that has an interest in a specific cross-border processing case, typically because the controller or processor is established in its territory, data subjects residing in its territory are substantially affected, or a complaint has been lodged with it. In the ordinary cooperation and consistency process, CSAs work with the lead supervisory authority (LSA) to reach consensus on draft decisions, and may raise relevant and reasoned objections. Where a CSA considers there is an urgent need to act to protect the interests of data subjects, the GDPR provides a separate provisional-measures pathway (the urgency procedure), which is distinct from the ordinary cooperation process. Practitioners should verify the precise procedural article references and applicable thresholds against the current official text and relevant EDPB guidance, as the identification of a CSA is fact-specific and can vary by case; note also that the position under the UK GDPR and national implementing laws may differ.
Why it matters
The concerned supervisory authority (CSA) mechanism is central to how the GDPR balances two competing needs: giving individuals meaningful access to a local regulator that speaks their language and understands their national context, while avoiding a patchwork of conflicting decisions when a single processing operation affects people across multiple member states. Without this framework, a company operating across the EU could face divergent rulings from different regulators on the same set of facts, and individuals might struggle to have complaints heard outside their home country.
For organizations engaged in cross-border processing, understanding which authorities may be 'concerned' in a given matter is practically significant because it shapes who may raise objections to a draft decision, who cooperates with the lead supervisory authority (LSA), and how a case may ultimately be resolved. The identification of a CSA is fact-specific: it can turn on where a controller or processor is established, where affected data subjects reside, or where a complaint has been lodged. Because these factors vary case by case, the same organization may face different constellations of concerned authorities depending on the processing activity at issue.
The distinction between the ordinary cooperation process and the separate urgency pathway also matters in practice. Where a concerned authority sees an urgent need to act to protect data subjects, the GDPR provides a distinct provisional-measures route rather than requiring the standard consensus process. Practitioners should confirm the precise procedural article references and applicable thresholds against the current official text and relevant EDPB guidance, and should note that the position under the UK GDPR and national implementing laws may differ.
Who it's relevant to
Inside CSA
Common questions
Answers to the questions practitioners most commonly ask about CSA.