Skip to main content
Category: Supervisory Authorities & Enforcement

Concerned Supervisory Authority

Also known as: CSA, supervisory authority concerned
Simply put

A concerned supervisory authority is a national data protection regulator that has a stake in a particular case involving personal data processing that affects people or organizations in its country. When processing crosses borders within the EU, several regulators may be 'concerned,' and they cooperate with a lead authority to reach coordinated decisions. This mechanism is intended to give individuals a voice through their local regulator while avoiding conflicting outcomes across member states.

Formal definition

Under the GDPR's cooperation framework, a concerned supervisory authority (CSA) is a supervisory authority that has an interest in a specific cross-border processing case, typically because the controller or processor is established in its territory, data subjects residing in its territory are substantially affected, or a complaint has been lodged with it. In the ordinary cooperation and consistency process, CSAs work with the lead supervisory authority (LSA) to reach consensus on draft decisions, and may raise relevant and reasoned objections. Where a CSA considers there is an urgent need to act to protect the interests of data subjects, the GDPR provides a separate provisional-measures pathway (the urgency procedure), which is distinct from the ordinary cooperation process. Practitioners should verify the precise procedural article references and applicable thresholds against the current official text and relevant EDPB guidance, as the identification of a CSA is fact-specific and can vary by case; note also that the position under the UK GDPR and national implementing laws may differ.

Why it matters

The concerned supervisory authority (CSA) mechanism is central to how the GDPR balances two competing needs: giving individuals meaningful access to a local regulator that speaks their language and understands their national context, while avoiding a patchwork of conflicting decisions when a single processing operation affects people across multiple member states. Without this framework, a company operating across the EU could face divergent rulings from different regulators on the same set of facts, and individuals might struggle to have complaints heard outside their home country.

For organizations engaged in cross-border processing, understanding which authorities may be 'concerned' in a given matter is practically significant because it shapes who may raise objections to a draft decision, who cooperates with the lead supervisory authority (LSA), and how a case may ultimately be resolved. The identification of a CSA is fact-specific: it can turn on where a controller or processor is established, where affected data subjects reside, or where a complaint has been lodged. Because these factors vary case by case, the same organization may face different constellations of concerned authorities depending on the processing activity at issue.

The distinction between the ordinary cooperation process and the separate urgency pathway also matters in practice. Where a concerned authority sees an urgent need to act to protect data subjects, the GDPR provides a distinct provisional-measures route rather than requiring the standard consensus process. Practitioners should confirm the precise procedural article references and applicable thresholds against the current official text and relevant EDPB guidance, and should note that the position under the UK GDPR and national implementing laws may differ.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads managing cross-border processing need to anticipate which national regulators may be concerned in a matter, since this affects who may scrutinize a draft decision and how objections are handled. Mapping establishments and affected populations early can help clarify the likely CSA landscape, though the assessment remains fact-specific.
Privacy and Data Protection Lawyers
Lawyers advising on regulatory engagement should distinguish the ordinary cooperation process, in which CSAs cooperate with the lead authority and may raise reasoned objections, from the separate urgency pathway available where there is an urgent need to act. Confirming the correct procedural basis and current thresholds against the official text is essential before advising on strategy.
Individuals Lodging Complaints
Because supervisory authorities receive and handle complaints from individuals, a person can generally raise a concern with their local regulator, which may then become a concerned authority in a cross-border case. This is intended to give individuals a voice through a regulator familiar with their national context.
Organizations with Multiple EU Establishments
Companies established in more than one member state, or whose processing substantially affects data subjects across borders, may find that several authorities are concerned in a single matter. Understanding this helps in planning engagement with the lead authority and in anticipating the range of regulators that may participate in a decision.

Inside CSA

Concerned Supervisory Authority (CSA)
A supervisory authority that is concerned by processing in a cross-border context, generally because the controller or processor is established in its member state, data subjects residing in its member state are substantially affected or likely to be substantially affected, or a complaint has been lodged with it. The concept is central to the one-stop-shop mechanism under the GDPR. Readers should verify the precise triggering conditions against the current official text.
Relationship to the Lead Supervisory Authority (LSA)
In cross-border cases, a single LSA (typically the authority of the main or single establishment) coordinates the handling of the matter, while CSAs participate in the cooperation process rather than acting unilaterally. The LSA and CSAs are distinct roles and should not be conflated.
Cooperation procedure under Article 60 GDPR
Article 60 sets out the ordinary cooperation process between the LSA and CSAs, including the exchange of relevant information, the LSA's submission of a draft decision to the CSAs, and the ability of CSAs to raise a relevant and reasoned objection to that draft. This is the standard route through which a CSA exercises influence over a cross-border case.
Relevant and reasoned objection
The mechanism by which a CSA can formally contest a draft decision proposed by the LSA within the Article 60 cooperation process. If consensus cannot be reached, the matter can be escalated to the consistency mechanism and, where applicable, to the European Data Protection Board for a binding decision.
Urgency (provisional measures) procedure under Article 66 GDPR
In exceptional circumstances, where a supervisory authority considers there is an urgent need to act to protect the rights and freedoms of data subjects, it may derogate from the ordinary cooperation and consistency mechanisms and adopt provisional measures with legal effect in its own territory for a specified maximum period. This urgency procedure is set out in Article 66, which is distinct from the ordinary Article 60 cooperation process. Readers should verify the applicable time limits and conditions against the current official text.
Scope boundary
The CSA concept operates within the GDPR's cross-border processing framework for personal data of individuals. It does not apply to purely domestic processing confined to a single member state, nor does it govern anonymous data or, generally, the data of deceased persons or legal entities. National implementing law and the UK GDPR arrangements post-Brexit may present a different institutional position that should be checked separately.

Common questions

Answers to the questions practitioners most commonly ask about CSA.

Is the concerned supervisory authority the same as the lead supervisory authority?
No. These are distinct roles within the GDPR's cooperation framework. The lead supervisory authority (LSA) is generally the authority of the main or single establishment of a controller or processor engaged in cross-border processing, and it acts as the primary interlocutor. A concerned supervisory authority (CSA) is an authority that is affected because, broadly, the controller or processor is established in its member state, data subjects in its member state are or are likely to be substantially affected, or a complaint has been lodged with it. An authority can be a CSA in one case and an LSA in another, and in a given matter multiple CSAs may exist alongside a single LSA. You should verify the precise criteria against the current text of the definitions in the GDPR, as the qualifying conditions are set out there.
Does a concerned supervisory authority simply defer to the lead authority with no ability to influence the outcome?
Not exactly. Under the ordinary cooperation process governed by Article 60 GDPR, the LSA is required to cooperate with CSAs in an endeavour to reach consensus, and CSAs may raise relevant and reasoned objections to a draft decision. If consensus is not reached on such an objection, the matter can be escalated to the consistency mechanism and, where applicable, to the European Data Protection Board for a binding decision. Separately, the urgency (provisional-measures) procedure is set out in Article 66 GDPR, not Article 60, and can in exceptional circumstances allow a supervisory authority to adopt provisional measures on its own territory. The precise thresholds and steps should be confirmed against the current official text, as the interplay between these provisions is procedural and fact-sensitive.
How does an authority determine whether it is a concerned supervisory authority in a particular case?
The assessment turns on whether the qualifying conditions in the GDPR's definition are met, which generally include the controller or processor being established in that authority's member state, data subjects residing in its member state being substantially affected or likely to be, or a complaint having been lodged with it. This is a case-by-case determination that depends on the facts of the processing and the affected individuals. Where it is unclear which authorities qualify, the position may need to be worked out through the cooperation mechanism, and you should verify the exact wording of the definition in the current text.
What role can a concerned supervisory authority play once a draft decision is circulated?
In the ordinary cooperation process under Article 60 GDPR, once the LSA prepares a draft decision it submits it to the CSAs, which may express a relevant and reasoned objection within the applicable period. If the LSA intends to follow the objection it revises the draft; if it does not, the disagreement can trigger the consistency mechanism. The specific timeframes and the standard for a relevant and reasoned objection are set out in the Regulation and related EDPB guidance, so those should be checked against the current sources rather than assumed.
Can a concerned supervisory authority take its own enforcement action instead of going through the lead authority?
Generally, in cross-border cases the one-stop-shop mechanism channels action through the LSA in cooperation with CSAs, which limits unilateral action. However, the GDPR provides for exceptions, including the urgency procedure set out in Article 66 GDPR, under which a supervisory authority may in exceptional circumstances adopt provisional measures within its own territory where it considers there is an urgent need to act. Whether such circumstances exist is a fact-specific judgement, and the applicable conditions and duration limits should be verified against the current text of Article 66.
How should an organization identify which concerned supervisory authorities may be involved before an issue arises?
As a practical matter, organizations engaged in cross-border processing typically map where they are established, where their data subjects are located, and where processing activities have effects, since these factors bear on which authorities could qualify as CSAs. This mapping supports readiness for cooperation and complaint-handling but does not itself determine the legal position, which depends on the statutory criteria applied to the facts. Because member state implementing law and regulatory practice can vary, the analysis should be revisited as processing operations change and confirmed against current guidance.

Common misconceptions

A concerned supervisory authority can independently issue a final decision against a controller in a cross-border case.
In cross-border cases handled through the one-stop-shop, the LSA generally leads and issues the decision following the Article 60 cooperation process; a CSA's principal formal tool is the relevant and reasoned objection rather than a unilateral final decision. A limited exception exists under the Article 66 urgency procedure, which permits provisional measures in defined exceptional circumstances.
The urgency procedure that lets a CSA adopt provisional measures is part of Article 60.
The urgency (provisional-measures) procedure is set out in Article 66, not Article 60. Article 60 covers the ordinary cooperation process between the LSA and CSAs; Article 66 is a distinct exceptional mechanism for urgent action derogating from the usual cooperation and consistency mechanisms.
Only the authority in the country of the controller's main establishment has any role in a cross-border case.
Other authorities can qualify as concerned supervisory authorities where a controller or processor is established in their territory, where data subjects in their territory are or are likely to be substantially affected, or where a complaint has been lodged with them, and they participate in the cooperation process accordingly.

Best practices

Map, at the outset of a cross-border matter, which authority is likely to be the LSA and which authorities may qualify as CSAs, using the triggering criteria and verifying against the current official text.
Distinguish clearly in internal analysis and correspondence between the ordinary Article 60 cooperation process and the exceptional Article 66 urgency procedure, and cite the correct article for each.
Where a CSA disagrees with a draft decision, prepare its position as a relevant and reasoned objection within the Article 60 framework rather than assuming it can act unilaterally.
Treat provisional measures under Article 66 as an exceptional route reserved for urgent circumstances, and check the applicable conditions and time limits before relying on it.
Confirm whether the matter is genuinely cross-border, since purely domestic processing may fall outside the one-stop-shop and CSA framework, and note that national implementing law and the UK position may differ.
Verify current institutional roles, escalation routes to the consistency mechanism, and any evolving guidance before advising, rather than relying on a fixed snapshot of the position.