Article 55 of the GDPR: Competence of Supervisory Authorities
Article 55 of the GDPR Explained
Each supervisory authority is competent to:
- Monitor the application of GDPR within the territory of its Member State;
- Intervene with controllers or processors established in that country;
- Investigate and sanction processing operations carried out locally.
However, national authorities are not competent in the context of cross-border processing operations, which fall under the one-stop shop mechanism (Article 56).
Why This Article is Key for Your GDPR Compliance
Knowing the competent authority helps to avoid notification or declaration errors, and to ensure that procedures are addressed to the appropriate body. This also guarantees a quick response tailored to the specific needs of the country.
Practical Applications of GDPR Article 55
- A French company is audited by the French supervisory authority for its data processing operations within the national territory;
- A Spanish authority conducts an investigation into a sub-processor based in Madrid;
- A German SME contacts its local authority to report an internal data breach.
Related Resources
Accelerate your compliance in a few clicks
With our all-in-one solution, you can easily accelerate and ensure your compliance:
- Automate your compliance with our GDPR software
- Supported or outsourced by our DPO experts
- Raise awareness among your teams with our GDPR e-learning training
Evaluate your situation in 15 minutes with our free, no-obligation GDPR self-assessment.
How to Comply with GDPR Article 55?