Main Establishment
A main establishment is the place in the EU that determines which national data protection authority acts as the lead regulator for an organisation operating across several member states. For a controller, it is generally the location of its central administration in the EU, unless another EU establishment actually makes the key decisions about how and why personal data is processed. Identifying it matters because it underpins the 'One Stop Shop' mechanism, allowing an organisation to deal primarily with a single lead supervisory authority.
Under Article 4(16) GDPR, the main establishment of a controller with establishments in more than one member state is, as a general rule, the place of its central administration in the Union, unless decisions on the purposes and means of processing are taken in another EU establishment that has the power to have such decisions implemented, in which case that establishment is treated as the main establishment (Art. 4(16)(a); see also Recital 36). For a processor, the main establishment is generally the location of its central administration in the EU. The concept is central to determining the competent lead supervisory authority for the One Stop Shop cooperation mechanism. The precise application of the notion, particularly for controllers, has been the subject of EDPB guidance (Opinion 04/2024), and its scope and boundaries continue to be clarified through regulatory guidance rather than being fully settled solely by the Regulation text; practitioners should assess each case on its facts and verify against the current official text.
Why it matters
The main establishment is the linchpin of the GDPR's 'One Stop Shop' cooperation mechanism. By identifying where an organisation's central administration sits in the EU, or where decisions on the purposes and means of processing are actually taken, the concept determines which national data protection authority acts as lead supervisory authority for cross-border processing. For an organisation operating across several member states, this can mean the difference between coordinating primarily with one regulator rather than facing parallel engagement with authorities in every member state where it operates.
Because so much turns on this determination, the notion has attracted focused regulatory attention. The EDPB adopted Opinion 04/2024 on the notion of main establishment of a controller under Article 4(16)(a) GDPR, reflecting that the precise application of the concept, particularly for controllers, is being clarified through guidance rather than being fully settled by the Regulation text alone. This matters practically because a superficial or incorrect identification of the main establishment can lead to an organisation asserting a lead authority that does not, in fact, have competence.
Getting the analysis right is a factual exercise, not merely a matter of choosing a convenient location. Where a controller's central administration in the EU does not take the key decisions about processing, and another EU establishment does with the power to have them implemented, that other establishment may be treated as the main establishment instead. Organisations should assess each case on its facts and verify their position against the current official text and applicable EDPB guidance, since the boundaries of the concept continue to be refined.
Who it's relevant to
Inside Main Establishment
Common questions
Answers to the questions practitioners most commonly ask about Main Establishment.