Art. 56 GDPR – Competence of the lead supervisory authority
- Without prejudice to Article 55, the supervisory authority of the main establishment or of the single establishment of the controller or processor shall be competent to act as lead supervisory authority for the cross-border processing carried out by that controller or processor in accordance with the procedure provided in Article 60.
- By derogation from paragraph 1, each supervisory authority shall be competent to handle a complaint lodged with it or a possible infringement of this Regulation, if the subject matter relates only to an establishment in its Member State or substantially affects data subjects only in its Member State.
- 1In the cases referred to in paragraph 2 of this Article, the supervisory authority shall inform the lead supervisory authority without delay on that matter. 2Within a period of three weeks after being informed the lead supervisory authority shall decide whether or not it will handle the case in accordance with the procedure provided in Article 60, taking into account whether or not there is an establishment of the controller or processor in the Member State of which the supervisory authority informed it.
- 1Where the lead supervisory authority decides to handle the case, the procedure provided in Article 60 shall apply. 2The supervisory authority which informed the lead supervisory authority may submit to the lead supervisory authority a draft for a decision. 3The lead supervisory authority shall take utmost account of that draft when preparing the draft decision referred to in Article 60(3).
- Where the lead supervisory authority decides not to handle the case, the supervisory authority which informed the lead supervisory authority shall handle it according to Articles 61 and 62.
- The lead supervisory authority shall be the sole interlocutor of the controller or processor for the cross-border processing carried out by that controller or processor.
Frequently Asked Questions about Article 56
+ What is the lead supervisory authority under the GDPR?
Article 56 establishes the lead supervisory authority as the main regulator for cross-border processing, usually the authority of the country where the organisation has its main establishment.
+How is the lead supervisory authority determined?
It is generally the authority of the member state where the controller or processor has its main establishment or single establishment in the EU.
+ What is the one-stop-shop mechanism?
The one-stop-shop lets organisations with cross-border processing deal mainly with a single lead authority, which coordinates with other concerned authorities.