Skip to content
atlas

Supervisory authority

Also known as: data protection authority

The public body in each EU country that oversees GDPR, handles complaints and can seek fines; in Denmark, Datatilsynet.

Draft - this entry has not been reviewed yet.

Formal

An independent public authority that each member state must set up under GDPR Article 51 to monitor the rules, investigate complaints and breaches, issue orders and bans, and impose fines - or, as in Denmark, report cases to the police so that the courts set the fine.

In plain English

Like the food inspector who can turn up at any restaurant, ask to see the fridge, order a clean-up and, if nothing changes, take the owner to court.

In practice

A citizen complains that a Danish municipality will not delete old case notes about her; Datatilsynet asks the municipality to explain, finds no legal ground for keeping them and orders them deleted.

Why it matters

Rights on paper mean little if nobody enforces them; the authority gives people somewhere to turn without hiring a lawyer and gives organisations a real reason to comply.

Technical deep dive

Chapter VI of the GDPR (Articles 51-59) sets up the authorities. Each member state provides one or more independent public authorities (Article 51) that must act with complete independence, free from external influence and with adequate resources (Article 52). Competence is territorial (Article 55), and processing by courts acting in their judicial capacity is excluded (Article 55(3)). Article 57 lists more than twenty tasks, from handling complaints and promoting awareness to approving codes of conduct and accrediting certification bodies, and Article 58 divides powers into investigative powers (ordering information, carrying out audits, obtaining access to premises and equipment), corrective powers (warnings, reprimands, orders to comply or to notify data subjects, temporary or definitive bans on processing, suspension of data flows to third countries and administrative fines) and authorisation and advisory powers.

For cross-border processing the one-stop-shop applies. The authority of the controller's or processor's main establishment (Article 4(16)) acts as lead supervisory authority (Article 56), cooperating with the other concerned authorities under Article 60. Disagreements go to the European Data Protection Board, whose consistency mechanism (Articles 63-65) can end in a binding decision. Individuals may lodge a complaint with an authority (Article 77) and have a right to an effective judicial remedy against its decisions (Article 78).

Fines follow Article 83: up to EUR 10 million or 2 % of worldwide annual turnover for infringements such as Articles 25-39, and up to EUR 20 million or 4 % for infringements of the principles, legal bases, data subject rights and international transfers, whichever is higher. Article 83(9) and recital 151 accommodate Denmark and Estonia, whose legal systems do not allow administrative fines of this kind. In Denmark, Datatilsynet therefore investigates and reports serious cases to the police, and the fine is imposed through the criminal justice system; under databeskyttelsesloven § 41 violations are punishable by fine or imprisonment of up to six months, public authorities can also be fined, and the limitation period is five years.

In practice organisations meet the authority mainly through personal data breach notifications, which under Article 33 must reach it without undue delay and where feasible within 72 hours of awareness, through prior consultation after a high-risk DPIA (Article 36), and through complaint cases. The term should not be confused with NIS2 competent authorities, which supervise cybersecurity rather than data protection; Article 35 of NIS2 requires them to inform the data protection authority when an infringement may entail a personal data breach, so one incident can involve both.

What to learn first

Everything this builds on, foundations first.

  1. Confidentiality
  2. →Personal data
  3. →GDPR
  4. →Data controller
  5. →Supervisory authority

Relationships

Mandated by
GDPR

Sources & further reading

Standards & official texts

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.