Skip to main content
Category: Supervisory Authorities & Enforcement

Mutual Assistance

Also known as: Mutual Legal Assistance, MLA
Simply put

Mutual assistance is a process by which countries help each other on a government-to-government basis, typically in criminal investigations and prosecutions. It allows one state to formally request cooperation from another, such as serving judicial documents or obtaining evidence located abroad. The evidence provided here describes the term in a general cross-border criminal-cooperation sense rather than in a data protection-specific context.

Formal definition

In the international cooperation context, mutual assistance (also referred to as mutual legal assistance, or MLA) is a formal process through which states seek and provide government-to-government assistance in criminal investigations and prosecutions, including the service of judicial documents and related requests. It operates between competent state authorities under applicable arrangements rather than as a private or informal exchange. Note: the supplied evidence does not address the distinct concept of mutual assistance among supervisory authorities under the GDPR, so this definition should not be read as describing that regime; practitioners should verify the intended scope and consult the relevant instrument or the current official text before applying the term.

Why it matters

Mutual assistance, in the cross-border criminal-cooperation sense described by the supplied evidence, is the formal channel through which one country obtains help from another in criminal investigations and prosecutions. Because evidence, witnesses, and judicial documents are frequently located across national borders, states cannot generally compel cooperation directly within another jurisdiction; they rely instead on government-to-government requests routed through competent authorities. This makes mutual assistance a foundational mechanism for enforcing criminal law where relevant material sits abroad.

For privacy and compliance practitioners, the significance lies in scope discipline. The term 'mutual assistance' also appears within the GDPR framework to describe cooperation between supervisory authorities, but the evidence provided here does not address that regime. Conflating the two can lead to material errors, for example treating a criminal MLA request as though it were a data protection cooperation procedure, or assuming that data disclosed under one framework carries the safeguards of another. Practitioners should confirm which regime a request or obligation actually falls under before responding.

The distinction also matters for lawful basis and transfer analysis. Where a criminal mutual assistance request results in personal data crossing borders, separate questions arise under applicable data protection and transfer rules that the criminal-cooperation instrument itself does not resolve. Because arrangements, adequacy positions, and transfer tools evolve over time and can vary by member state, any specific application should be verified against the current official text of the relevant instrument.

Who it's relevant to

Prosecutors and criminal justice authorities
Competent authorities involved in criminal investigations and prosecutions are the primary users of mutual assistance, using it to seek or provide government-to-government cooperation such as serving judicial documents or obtaining evidence located in another state, subject to the applicable arrangements.
Data protection officers and privacy counsel
DPOs and privacy lawyers need to distinguish this criminal-cooperation concept from the separate GDPR notion of mutual assistance between supervisory authorities. Where a criminal mutual assistance request implicates personal data, they should assess the data protection and cross-border transfer questions separately and verify the governing framework before advising.
Compliance leads handling cross-border requests
Compliance teams that receive or route government requests should first confirm which regime a request falls under, since the evidence here describes only the criminal-cooperation sense of the term. Misclassifying a request risks applying the wrong procedures and safeguards.
Engineers and data custodians
Those who hold or provide access to data that may be the subject of a formal state request should escalate to legal and compliance rather than act on informal contact, because mutual assistance in this context operates between competent state authorities under formal arrangements, not through private or informal channels.

Inside Mutual Assistance

Cooperation between supervisory authorities
Mutual assistance describes the mechanism under the GDPR by which supervisory authorities of different member states cooperate and support one another to ensure consistent application of the Regulation. It typically operates alongside the broader cooperation and consistency framework.
Requests for information and enforcement support
One authority may request relevant information from another and may seek support with supervisory measures such as investigations or the exchange of data needed to handle a matter. The scope of assistance generally covers activities that help each authority perform its tasks.
Duty to respond within a defined timeframe
Requested authorities are generally expected to respond to mutual assistance requests without undue delay and within a period set by the Regulation. Practitioners should verify the exact timeframe against the current official text rather than relying on memory.
Grounds for refusal
An authority may, in limited circumstances, decline a request, for example where it is not competent for the subject matter of the request or where compliance would breach EU or member state law to which it is subject. The precise grounds should be confirmed against the Regulation.
Provisional measures and urgency procedure
Where an authority does not receive assistance in time, it may in certain cases adopt provisional measures on its territory. This intersects with the urgency procedure but is a distinct concept and should be assessed on the facts.
Relationship to the one-stop-shop and consistency mechanism
Mutual assistance supports, but is distinct from, the one-stop-shop lead authority arrangement and the consistency mechanism. It is an operational duty of cooperation rather than a mechanism for allocating lead competence.

Common questions

Answers to the questions practitioners most commonly ask about Mutual Assistance.

Is mutual assistance the same as the consistency mechanism?
No. Mutual assistance and the consistency mechanism are distinct cooperation tools under the GDPR. Mutual assistance generally concerns supervisory authorities helping one another with specific requests, such as information sharing or carrying out investigative measures. The consistency mechanism is a separate process aimed at ensuring the GDPR is applied consistently across the EU, typically involving the European Data Protection Board. Treating the two as interchangeable is a common error; you should verify the applicable provisions against the current official text to confirm which process applies to a given situation.
Does mutual assistance mean a data controller can request help directly from a supervisory authority in another country?
Not in the sense the question implies. Mutual assistance is generally a cooperation duty between supervisory authorities, not a service that controllers or processors invoke to obtain cross-border assistance. Organisations typically interact with their relevant supervisory authority, and any cooperation between authorities happens at the regulator level. Confusing an organisation-facing service with an inter-authority obligation is a frequent misconception, and the precise mechanics should be checked against the current Regulation text and applicable guidance.
Which supervisory authority should an organisation deal with when mutual assistance between regulators may be involved?
In most cases an organisation engages with the supervisory authority that is competent for its situation, and any assistance between authorities is handled between the regulators themselves rather than by the organisation. Where cross-border processing is involved, the identification of the relevant authority can depend on the specific circumstances and, in some cases, on how the one-stop-shop and lead authority arrangements apply. Because these determinations are context dependent, you should confirm the competent authority for your particular case rather than assume.
How should an organisation prepare in case its supervisory authority receives a mutual assistance request from another authority?
Organisations generally cannot control whether authorities exchange requests, but they can prepare by maintaining accurate records of processing activities, clear documentation of legal bases, and organised evidence of compliance measures. This typically supports a faster and more coherent response if a supervisory authority seeks information. The specific expectations can vary between regulators, so the scope and format of any response should be aligned with the requirements communicated by the competent authority in the individual matter.
What documentation is typically useful if a regulator's cooperation activity touches an organisation's processing?
Useful documentation generally includes records of processing activities, records evidencing the applicable Article 6 legal basis (and any additional Article 9 condition for special category data), relevant Data Processing Agreements under Article 28, any Data Protection Impact Assessments prepared under Article 35, and evidence of technical and organisational measures. What is required in a specific instance depends on the nature of the request, so organisations should tailor the materials to the authority's stated needs and verify current expectations rather than rely on a fixed checklist.
How does mutual assistance interact with cross-border processing and multiple establishments?
Where an organisation has establishments or processing activities spanning several member states, more than one supervisory authority may have an interest, and cooperation between those authorities can become relevant. The precise interaction with lead authority and one-stop-shop arrangements is fact specific and can involve recognised areas of complexity or divergence in practice between regulators. Organisations operating across borders should map their establishments and processing to understand which authorities may be concerned, and confirm the position against current guidance and the official Regulation text.

Common misconceptions

Mutual assistance is the same thing as the one-stop-shop mechanism.
They are related but distinct. The one-stop-shop concerns identifying a lead supervisory authority for cross-border processing, whereas mutual assistance is the broader duty of authorities to help one another with information and enforcement-related tasks. An authority can provide mutual assistance outside a formal lead-authority scenario.
A requested authority must always comply with any assistance request.
Assistance is generally expected, but refusal is possible in limited situations, such as where the authority is not competent for the subject matter or where complying would conflict with applicable EU or member state law. Whether a refusal is justified is assessed on the specific facts.
Mutual assistance obligations bind private organisations directly.
Mutual assistance is primarily an obligation among supervisory authorities. Organisations are affected indirectly, for example when an authority acting on a request seeks information or conducts an investigation, but the duty itself runs between regulators.

Best practices

Map which supervisory authority is likely to act as lead for your cross-border processing, and recognise that other concerned authorities may still be involved through mutual assistance.
Confirm the applicable response timeframes and grounds for refusal against the current official text of the Regulation rather than relying on summaries, as detail matters in practice.
Prepare to respond promptly and consistently when contacted by any supervisory authority, since a request may originate from cooperation between regulators in different member states.
Maintain accessible, well-documented records of processing so that information sought via inter-authority cooperation can be provided accurately and without undue delay.
Track that cooperation practices and any accompanying guidance can evolve, and periodically review your understanding against updated regulator and EDPB materials.
Where a matter spans multiple member states, seek advice on potential divergence in national implementing law that could affect how an authority handles or supports a request.