Call us on +(33)4 28 70 91 81

Article 78 of the GDPR: Right to legal recourse against a supervisory authority

Article 78 of the GDPR: Right to legal recourse against a supervisory authority

Article 78 of the GDPR recognizes that everyone has the right to exercise effective legal recourse against a supervisory authority. This right applies when the competent authority does not handle a complaint or takes a decision deemed unsatisfactory.

Article 78 of the GDPR explained

According to this article:

  • Everyone has the right to challenge a decision of a supervisory authority before a national court;
  • This right also applies in the event of failure to respond within a reasonable time to a complaint;
  • The appeal is brought before the courts of the Member State in which the authority concerned is established;
  • The supervisory authorities themselves can exercise this right under certain conditions.

This is a right of appeal guaranteed by the Charter of Fundamental Rights of the European Union.

Why is this article important for your GDPR compliance?

This right strengthens the accountability and transparency of supervisory authorities. Companies must understand that an administrative decision may be subject to judicial review, which involves rigorous documentation of their practices.

How to comply with Article 78 of the GDPR?

  • Carefully document your interactions with supervisory authorities;
  • Respect deadlines for responding to formal requests;
  • Prepare a solid compliance file justifying your treatment in the event of litigation;
  • In the event of disagreement with an authority, consider the appeal route with the support of your DPO or legal department.

Examples of application of Article 78 of the GDPR

  • A company contests a fine imposed by the CNIL before the Council of State;
  • A person takes legal action after a lack of response to their complaint;
  • A supervisory authority in another country challenges the decision of a lead regulator.

Related Resources

Accelerate your compliance in just a few clicks

With our all-in-one solution, you can accelerate and ensure compliance easily:

  • Automate your compliance with our GDPR software
  • Supported or outsourced by our DPO experts
  • Raise awareness among your teams with our GDPR training e-learning

Request a demo with an expert

Assess your situation in 15 minutes with our free, no-obligation GDPR self-diagnosis.

GDPR: Self-assess now