Article 31 of the GDPR: Cooperation with the Supervisory Authority
Article 31 of the GDPR Explained
The controller and the processor must cooperate with the competent supervisory authority, upon its request, in the performance of its tasks.
This includes:
- Requests for information (e.g., records, documentation, proof of compliance);
- On-site inspections or controls;
- The implementation of recommendations or corrective measures.
This obligation applies to all organisations, whether public or private.
Why Is This Article Important for Your GDPR Compliance?
The transparency and cooperation with the supervisory authority are essential to demonstrate your commitment to compliance. A lack of collaboration can exacerbate sanctions in the event of an audit. This is a pillar of the accountability of data controllers and processors.
Application Examples of Article 31 of the GDPR
- A company receives a request for information from the French supervisory authority: it transmits its register and internal policies;
- A public body is subject to an inspection: it cooperates actively by facilitating access to its premises and data;
- A data processor responds to a request for explanation regarding a specific processing operation implemented on behalf of a client.
Related Resources
Accelerate Your Compliance in a Few Clicks
Thanks to our all-in-one solution, you can easily accelerate and ensure your compliance:
- Automate your compliance with our GDPR software
- Supported or outsourced by our DPO experts
- Raise awareness among your teams with our GDPR training e-learning
Assess your situation in 15 minutes with our free, no-obligation GDPR self-assessment.
How to comply with Article 31 of the GDPR?