Skip to main content
Category: Supervisory Authorities & Enforcement

Joint Operations

Also known as: Joint operations of supervisory authorities
Simply put

In data protection, 'joint operations' generally refers to coordinated activities that data protection regulators from different EU member states can carry out together, such as joint investigations or shared enforcement measures affecting individuals in more than one country. The evidence packet provided does not contain any authoritative privacy or GDPR sources on this term; the supplied sources relate to unrelated subjects (a military video game, military doctrine, and cannabis dispensaries) and cannot support a definition of the GDPR concept. Readers should verify the precise meaning and requirements against the current official text of the GDPR before relying on this entry.

Formal definition

The verification flags indicate that 'joint operations' should be defined as the mechanism, associated in EU data protection with Article 62 GDPR, allowing supervisory authorities to conduct joint investigations and joint enforcement measures where a controller or processor operates in several member states or where a significant number of data subjects in more than one member state are likely affected. This concept is distinct from joint controllership under Article 26 GDPR, which concerns two or more controllers jointly determining the purposes and means of processing. However, none of the sources in the evidence packet address data protection, GDPR, Article 62, or the specific procedural features attributed to the concept (for example inviting other authorities to participate, conferring investigative powers on seconded staff, or applicable deadlines and provisional measures). Because no supporting privacy-domain source is present, the specific legal requirements, powers, and timeframes cannot be stated or cited reliably here and must be confirmed against the authoritative GDPR text and current regulator guidance.

Why it matters

Joint operations are a core part of the GDPR's cross-border enforcement architecture. Because a controller or processor may operate across several member states, and because a single processing activity can affect data subjects in more than one country, individual national supervisory authorities acting alone may be poorly placed to investigate or remedy an issue effectively. The joint operations mechanism, generally associated with Article 62 GDPR, allows supervisory authorities to pool their efforts through joint investigations and joint enforcement measures, which supports the consistent application of data protection law across the Union.

Who it's relevant to

Supervisory authorities and their staff
Regulators are the primary actors in joint operations, since the mechanism is designed to let them coordinate investigations and enforcement across borders. Staff who may be seconded to or receive powers from another authority should understand that the extent of those powers generally depends on the host member state's law, which can vary.
Data protection officers and compliance leads at cross-border organisations
Organisations established in, or processing data affecting individuals in, more than one member state may face coordinated regulatory attention rather than isolated national inquiries. DPOs and compliance leads should account for this when assessing enforcement exposure, while verifying the precise procedural implications against the current GDPR text and regulator guidance.
Privacy and enforcement lawyers
Legal advisers handling regulatory investigations need to distinguish joint operations under Article 62 from related but separate mechanisms, including joint controllership under Article 26 and the broader cooperation and consistency procedures. Because operational detail and member state derogations can shift the position, advisers should confirm specifics against authoritative sources in each matter.

Inside Joint Operations

Joint operations of supervisory authorities (Article 62)
A cooperation mechanism under the GDPR by which supervisory authorities of different member states conduct joint operations, including joint investigations and joint enforcement measures, particularly where a controller or processor has establishments in several member states or where a significant number of data subjects in more than one member state are likely to be substantially affected. This is distinct from joint controllership under Article 26, which concerns two or more controllers jointly determining purposes and means of processing.
Invitation to participate
Under Article 62, where a supervisory authority's territorial competence is engaged (for example, because a controller or processor is established in more than one member state or data subjects in several member states are likely to be substantially affected), a supervisory authority may invite other concerned supervisory authorities to take part in joint operations. The provision generally frames such participation as something the inviting authority is expected to offer to competent authorities.
Conferral of powers on seconded members or staff
Article 62 addresses the situation where a controller or processor has establishments in the host authority's member state, or where the host authority's data subjects are involved. In such cases the members or staff of a seconding (assisting) supervisory authority may be conferred investigative powers, or take part in exercising investigative powers, in accordance with the host member state's law and subject to the host authority's guidance and supervision. The precise scope and limits of these powers are governed by the host member state's law, so the reader should verify the national position.
Host authority responsibility and liability
Where seconded members or staff of an assisting authority operate on the host member state's territory, the host supervisory authority generally assumes responsibility for their actions, including liability, consistent with the framework set out in Article 62. National implementing law may affect the detailed allocation, so this should be confirmed against the applicable member state text.
Response to a request to participate
Article 62 contemplates timeframes for a supervisory authority to respond to a request to participate in a joint operation, and provides that, in cases of urgency, mechanisms exist to enable provisional measures or a prompt response. The exact deadline and urgency conditions should be verified against the current official text of the Regulation rather than relied on from memory.
Relationship to the broader cooperation and consistency framework
Joint operations under Article 62 sit within the GDPR's wider cooperation and consistency mechanism (including mutual assistance and the lead authority / one-stop-shop arrangements). They are a tool for coordinated cross-border enforcement among authorities, not an instrument imposing obligations directly on controllers or processors, though such entities may be the subject of the resulting investigation or enforcement action.

Common questions

Answers to the questions practitioners most commonly ask about Joint Operations.

Does "joint operations" under the GDPR mean the same thing as joint controllership under Article 26?
No. These are distinct concepts and should not be conflated. "Joint operations of supervisory authorities" is addressed in Article 62 GDPR and concerns co-operation and co-ordinated enforcement activities between supervisory authorities, including joint investigations and joint enforcement measures. Joint controllership under Article 26 concerns two or more controllers who jointly determine the purposes and means of processing and must arrange their respective responsibilities. The Article 62 concept relates to how regulators act together; the Article 26 concept relates to how controllers share responsibility. Readers should verify the precise scope against the current official text.
Is "joint operations" simply an administrative or non-privacy term with no bearing on data protection enforcement?
No. This characterisation is incorrect. Joint operations under Article 62 GDPR are a specific mechanism within the co-operation and consistency framework of the Regulation. They allow supervisory authorities to conduct joint investigative and enforcement actions, which are directly relevant to cross-border processing and the enforcement of data protection obligations. The term carries a defined privacy-enforcement meaning and should not be dismissed as having no relevance.
When may a supervisory authority invite another authority to take part in a joint operation?
Article 62 GDPR generally contemplates that supervisory authorities may conduct joint operations, including joint investigations and enforcement measures, and that where a controller or processor has establishments in several member states, or where processing is likely to substantially affect data subjects in more than one member state, an authority of each affected member state generally has a right to participate. Readers should check the exact wording and any applicable European Data Protection Board guidance, as procedural details and practice can evolve.
What powers can a seconded or host authority's members exercise during a joint operation?
Article 62 generally provides that where a host supervisory authority permits, members or staff of a seconding supervisory authority may exercise investigative powers under the law of the host member state, and that such powers are typically exercised under the guidance and in the presence of members or staff of the host authority. The precise allocation of powers, liability, and the applicable national law can vary, so the operational arrangements and the host member state's implementing law should be verified in each case.
Is there a deadline for responding to a request to participate in a joint operation?
Article 62 sets out time-bound obligations connected to co-operation requests within this part of the Regulation, and the co-operation framework generally imposes response periods on supervisory authorities. Rather than relying on a figure from memory, practitioners should confirm the specific response period and any conditions directly against the current text of the Regulation, as the exact duration and its triggers are prescribed there.
How does a joint operation interact with the wider co-operation and consistency mechanisms?
Joint operations under Article 62 sit within the broader co-operation and consistency framework of the GDPR, which also includes mutual assistance between authorities and the lead supervisory authority / concerned authority arrangements for cross-border cases. Joint operations are one practical tool for co-ordinated cross-border enforcement, but they operate alongside, and are subject to, these related mechanisms and any relevant European Data Protection Board guidance. The interaction can be nuanced in practice, so the operational and procedural boundaries should be assessed case by case and against current guidance.

Common misconceptions

"Joint operations" is the same thing as "joint controllership" under Article 26.
These are distinct concepts. Joint operations under Article 62 concern coordinated investigations and enforcement carried out jointly by supervisory authorities of different member states. Joint controllership under Article 26 concerns two or more controllers who jointly determine the purposes and means of processing. Conflating them misdirects any compliance analysis.
Joint operations have no privacy or data protection relevance and are a general-purpose term.
Within the GDPR, joint operations is a defined cooperation mechanism (Article 62) that is directly relevant to cross-border enforcement of data protection law. It enables supervisory authorities to conduct joint investigations and enforcement, so it is materially relevant to how privacy obligations are supervised and enforced.
A seconded authority's staff can exercise their home-country powers freely on another member state's territory during a joint operation.
Under Article 62, any investigative powers exercised by seconded members or staff on the host territory are conferred and exercised in accordance with the host member state's law and under the host authority's guidance and supervision, and the host authority generally bears responsibility for their actions. National implementing law affects the detail, so the position should be verified.

Best practices

Confirm at the outset whether the matter concerns Article 62 joint operations among supervisory authorities or Article 26 joint controllership, because the legal analysis, obligations, and responsible parties differ entirely.
For organisations operating across several member states, map your establishments and the member states where data subjects are likely to be substantially affected, as these factors help identify which authorities may become concerned and could participate in a joint operation.
Identify the lead supervisory authority and the concerned authorities relevant to your cross-border processing, and understand how the wider cooperation and consistency mechanism may bring multiple regulators into a coordinated investigation.
When an investigation involves seconded members or staff from another authority, verify the specific powers, limits, guidance, and supervision arrangements under the host member state's implementing law rather than assuming a uniform EU-wide position.
Verify current procedural details, including any response timeframes and urgency or provisional-measures provisions, against the official text of Article 62 and applicable national law before relying on them.
Maintain internal escalation and legal-review procedures so that a request or notification connected to a joint operation is routed promptly to the appropriate legal, DPO, and management functions, given that cross-border enforcement can move quickly.