Skip to main content
Category: Supervisory Authorities & Enforcement

Main Establishment

Simply put

A main establishment is the place in the EU that determines which national data protection authority acts as the lead regulator for an organisation operating across several member states. For a controller, it is generally the location of its central administration in the EU, unless another EU establishment actually makes the key decisions about how and why personal data is processed. Identifying it matters because it underpins the 'One Stop Shop' mechanism, allowing an organisation to deal primarily with a single lead supervisory authority.

Formal definition

Under Article 4(16) GDPR, the main establishment of a controller with establishments in more than one member state is, as a general rule, the place of its central administration in the Union, unless decisions on the purposes and means of processing are taken in another EU establishment that has the power to have such decisions implemented, in which case that establishment is treated as the main establishment (Art. 4(16)(a); see also Recital 36). For a processor, the main establishment is generally the location of its central administration in the EU. The concept is central to determining the competent lead supervisory authority for the One Stop Shop cooperation mechanism. The precise application of the notion, particularly for controllers, has been the subject of EDPB guidance (Opinion 04/2024), and its scope and boundaries continue to be clarified through regulatory guidance rather than being fully settled solely by the Regulation text; practitioners should assess each case on its facts and verify against the current official text.

Why it matters

The main establishment is the linchpin of the GDPR's 'One Stop Shop' cooperation mechanism. By identifying where an organisation's central administration sits in the EU, or where decisions on the purposes and means of processing are actually taken, the concept determines which national data protection authority acts as lead supervisory authority for cross-border processing. For an organisation operating across several member states, this can mean the difference between coordinating primarily with one regulator rather than facing parallel engagement with authorities in every member state where it operates.

Because so much turns on this determination, the notion has attracted focused regulatory attention. The EDPB adopted Opinion 04/2024 on the notion of main establishment of a controller under Article 4(16)(a) GDPR, reflecting that the precise application of the concept, particularly for controllers, is being clarified through guidance rather than being fully settled by the Regulation text alone. This matters practically because a superficial or incorrect identification of the main establishment can lead to an organisation asserting a lead authority that does not, in fact, have competence.

Getting the analysis right is a factual exercise, not merely a matter of choosing a convenient location. Where a controller's central administration in the EU does not take the key decisions about processing, and another EU establishment does with the power to have them implemented, that other establishment may be treated as the main establishment instead. Organisations should assess each case on its facts and verify their position against the current official text and applicable EDPB guidance, since the boundaries of the concept continue to be refined.

Who it's relevant to

Data Protection Officers and compliance leads
DPOs and compliance teams in organisations that process personal data across more than one EU member state need to identify the main establishment to determine which authority is their lead supervisory authority under the One Stop Shop. This shapes how they document decision-making structures and how they prepare to engage with regulators.
Privacy and data protection lawyers
Lawyers advising cross-border controllers and processors must apply the Article 4(16) analysis carefully, distinguishing central administration from the place where processing decisions are actually taken and implemented. They should factor in EDPB guidance such as Opinion 04/2024 and advise that the position may need to be reassessed as guidance develops.
In-house governance and corporate structuring teams
Those responsible for corporate structure and governance should understand that the location and decision-making powers of EU establishments can affect which regulator has lead competence. Structural changes to where processing decisions are made and implemented may alter the main establishment analysis.
Processors operating in the EU
Processors with establishments in the EU should note that their main establishment is generally the location of their central administration in the EU, which is relevant to identifying the competent lead authority for cross-border matters affecting them.

Inside Main Establishment

Place of central administration (controllers)
For a controller with establishments in more than one member state, the main establishment is generally the place of its central administration in the EU, unless decisions on the purposes and means of processing are taken in another EU establishment that also has the power to implement those decisions, in which case that establishment is treated as the main establishment.
Location of processing decision-making
The concept focuses on where decisions about the purposes and means of processing are actually taken and can be implemented, rather than simply where a company is headquartered on paper. This effective decision-making location is central to identifying the main establishment.
Main establishment for processors
For a processor with establishments in more than one member state, the main establishment is generally the place of its central administration in the EU, or, if there is no central administration in the EU, the establishment where the main processing activities in the context of a processor's EU establishment take place.
Basis for the lead supervisory authority
The main establishment is the criterion used to identify the competent lead supervisory authority under the one-stop-shop mechanism for cross-border processing. The supervisory authority of the main establishment generally acts as lead authority, subject to the cooperation and consistency arrangements.
Cross-border processing context
The concept is primarily relevant where processing is cross-border, meaning it takes place in more than one member state or substantially affects data subjects in more than one member state. Its practical significance arises chiefly in this context.

Common questions

Answers to the questions practitioners most commonly ask about Main Establishment.

Is an organisation's main establishment simply the place where it is headquartered or registered?
Not necessarily. For a controller, the main establishment is generally the place of its central administration in the EU, unless decisions about the purposes and means of processing are taken at another establishment and that establishment has the power to have those decisions implemented, in which case the latter is treated as the main establishment. A registered office or headquarters is only decisive where it actually corresponds to where processing decisions are effectively made. The concept turns on the reality of decision-making power rather than corporate formalities, and its application can be fact-specific and subject to regulatory and case-law assessment.
Does having a main establishment in the EU mean an organisation automatically deals with only one supervisory authority for everything?
Not in all cases. The main establishment identifies the lead supervisory authority under the one-stop-shop mechanism for cross-border processing, but this does not exclude other supervisory authorities entirely. Concerned supervisory authorities can be involved, and certain matters (for example those relating to purely local processing) may fall to a local authority. The one-stop-shop is a mechanism for cooperation and consistency rather than an absolute grant of exclusive competence, and its operation should be assessed case by case.
How does an organisation determine its main establishment when processing decisions are spread across multiple EU offices?
The analysis generally focuses on where decisions about the purposes and means of processing are actually taken and where they can be implemented. Where this authority is genuinely distributed, organisations typically document their internal governance to identify the establishment with effective decision-making power for the relevant processing. This is an evidentiary and factual exercise, and the outcome may differ across different processing activities. Where the position is unclear, organisations should be prepared for regulators to scrutinise the substance rather than the label, and to seek guidance where uncertainty remains.
How is the main establishment identified for a processor rather than a controller?
For a processor, the main establishment is generally its place of central administration in the EU, or, where it has no central administration in the EU, the establishment where the main processing activities in the context of its EU activities take place, to the extent the processor is subject to specific obligations under the Regulation. The controller and processor analyses are distinct, so a controller and its processor may have different main establishments and potentially different lead authorities. The precise application should be verified against the current text of the Regulation.
What should an organisation with no establishment in the EU consider regarding this concept?
The main establishment concept and the associated one-stop-shop mechanism are generally premised on the organisation having an establishment in the EU. An organisation with no EU establishment but that is nonetheless within the territorial scope of the Regulation does not typically benefit from a lead supervisory authority in the same way and may, in most cases, need to appoint a representative and engage with supervisory authorities in the member states where affected individuals are located. The specific obligations should be assessed against the applicable provisions and current guidance.
How should an organisation document and revisit its main establishment determination?
Because the determination depends on where decision-making power over processing genuinely sits, organisations typically record the reasoning, the relevant governance structures, and the establishment identified, so the position can be explained if challenged. It is generally advisable to revisit the analysis when corporate structures, reporting lines, or the locus of processing decisions change, since the identified main establishment and lead authority may shift accordingly. This remains a fact-based assessment, and organisations should consider current regulatory guidance where the position is uncertain.

Common misconceptions

The main establishment is simply the company's registered headquarters or place of incorporation.
While the place of central administration is the starting point for a controller, the analysis turns on where decisions about the purposes and means of processing are actually taken and implemented. An establishment other than the registered headquarters can be the main establishment where that establishment makes and can implement those decisions. The assessment is factual and subject to case-by-case evaluation.
The rules for identifying a processor's main establishment are the same as for a controller.
The GDPR sets out distinct approaches. For processors, the analysis generally centres on the place of central administration in the EU or, absent that, the establishment where the main processing activities in the context of the processor's EU establishment take place, rather than the controller-specific test based on where processing decisions are taken and implemented.
Having a main establishment automatically guarantees a single lead supervisory authority for all matters.
The main establishment is used to identify a lead supervisory authority for cross-border processing, but this operates subject to the GDPR's cooperation and consistency mechanisms. Other concerned supervisory authorities can retain a role in certain circumstances, and disputes over competence may arise, so the one-stop-shop is not an absolute or unqualified outcome.

Best practices

Map where decisions on the purposes and means of processing are actually taken and implemented within the EU, rather than relying solely on the registered headquarters, and document the factual basis for your conclusion.
Analyse controller and processor roles separately, applying the correct criteria for each, since an organisation acting in both capacities may reach different conclusions for different processing activities.
Assess whether your processing is genuinely cross-border before relying on the main establishment concept, as its main practical relevance arises in the cross-border and one-stop-shop context.
Maintain records that evidence the location of central administration and decision-making, so you can substantiate any claimed lead supervisory authority if challenged.
Treat the lead supervisory authority identification as subject to the GDPR's cooperation and consistency mechanisms, and avoid assuming a single authority will handle every matter without input from other concerned authorities.
Reassess the main establishment analysis when your organisational structure or decision-making arrangements change, and verify positions against the current official GDPR text and relevant regulatory guidance.