The GDPR relies on a network of independent public bodies to monitor and enforce data protection law across the European Economic Area. These supervisory authorities, commonly called Data Protection Authorities (DPAs), hold investigative, corrective, and advisory powers that directly affect every organisation processing personal data within their jurisdiction.
Each EU member state must designate at least one independent supervisory authority under Article 51 GDPR. Some states have several authorities with different territorial or sectoral responsibilities. The relevant authority therefore depends on the processing and the organisation, rather than simply its preferred contact address.
Swiss supervisory authority powers and fines compared with GDPR
Switzerland’s Federal Data Protection and Information Commissioner (FDPIC) supervises private persons and federal bodies under Swiss data protection law. It can investigate and issue binding corrective decisions, including orders concerning processing. It does not impose the GDPR-style administrative fines available to EU supervisory authorities. The FDPIC explains this distinction in its analysis of investigation powers.
| Question | EU GDPR | Swiss federal data protection law |
|---|---|---|
| Who investigates? | Competent independent supervisory authority | FDPIC within its federal supervisory remit |
| Can processing be restricted? | Article 58 permits restrictions and bans | FDPIC can issue binding corrective orders |
| Who imposes relevant fines? | Competent GDPR enforcement body, subject to national procedures | Cantonal criminal prosecution authorities |
| Main upper penalty discussed here | Higher of EUR 20 million or 4% of worldwide annual turnover for the upper tier | CHF 250,000 for specified intentional offences by private persons |
| Is every breach automatically fined? | No; Article 83 requires an individual assessment | No; criminal offence requirements must be met |
Swiss criminal penalties are not a general turnover-based corporate fine. A limited mechanism can instead allow a company to be fined where the contemplated fine does not exceed CHF 50,000 and identifying the individual would require disproportionate investigation. The FDPIC’s criminal-law explanation distinguishes these penalties from civil claims.
For a Swiss business offering services to people in the EU or monitoring their behaviour there, the GDPR may also apply under Article 3. Assess each law separately; a Swiss establishment does not make the FDPIC an EU lead supervisory authority. Cantonal public-sector supervision also requires its own competence check. This comparison concerns the federal Swiss framework, not every cantonal procedure.
What Is a Supervisory Authority Under GDPR?
Articles 51-59 of the GDPR establish the legal framework for supervisory authorities. Article 51 requires each member state to provide for one or more independent public authorities responsible for monitoring the application of the regulation. Independence is a structural requirement: DPAs must be free from external influence, adequately funded, and staffed with qualified personnel.
What Powers Do Supervisory Authorities Have?
Article 58 divides DPA powers into three categories. Investigative powers (Article 58(1)) include ordering controllers and processors to provide information, carrying out audits, obtaining access to premises, and reviewing certifications. Corrective powers (Article 58(2)) include issuing warnings, reprimands, and orders to comply, imposing temporary or definitive bans on processing, ordering data rectification or erasure, and imposing administrative fines under Article 83.
Advisory and authorisation powers (Article 58(3)) cover issuing opinions on legislative proposals, approving binding corporate rules, and authorising contractual clauses for international data transfers.
The upper Article 83 tier is the higher of EUR 20 million or 4% of worldwide annual turnover for an undertaking. The lower tier is the higher of EUR 10 million or 2%. The applicable tier, infringement, undertaking and circumstances require separate analysis; the maximum is not an automatic penalty. A corrective order can matter even where no fine is imposed.
How Does the One-Stop-Shop Mechanism Work?
For qualifying cross-border processing, Articles 56 and 60 provide for a lead supervisory authority at the controller’s or processor’s main or single EEA establishment. For a controller with several EEA establishments, Article 4(16)(a) starts from its EEA central administration; another EEA establishment qualifies where it makes the relevant purposes-and-means decisions and has power to have them implemented. For a processor, Article 4(16)(b) instead uses its EEA central administration or, if there is none, the EEA establishment where its main processing activities take place. Apply the test to the actual role and processing, as explained in the EDPB’s lead-authority guidelines.
When a complaint involves cross-border processing, the LSA coordinates with Concerned Supervisory Authorities in other affected member states. The LSA prepares a draft decision and shares it with all concerned DPAs. If no objections are raised, the decision is adopted. If disagreements arise, the case may escalate to the EDPB’s dispute resolution mechanism under Article 65.
The EDPB and Cross-Border Cooperation
The European Data Protection Board (EDPB), established under Article 68, is the successor to the Article 29 Working Party. It comprises the heads of each national DPA and the European Data Protection Supervisor. The EDPB supports consistent application through guidelines, decisions within its statutory powers and coordination across borders.
Guidance, binding decisions and individual cases
The Board’s guidelines explain a common interpretation; binding dispute-resolution decisions address the circumstances specified by the GDPR. These instruments are not interchangeable. When recording the legal basis for an operational decision, identify whether the document is a guideline, an adopted binding decision, an authority’s own decision or a consultation draft.
For a cross-border case, keep the lead authority and concerned authorities distinct. An organisation cannot choose its lead authority merely by registering a postal address in a preferred country. The actual decision-making establishment and the processing concerned matter. A business without an EU establishment cannot create access to the one-stop-shop simply by appointing an Article 27 representative.
Use the EDPB guide for institutional context and the controller and processor distinction to identify which organisation must answer a particular request.
How to Interact with Your Supervisory Authority
Organisations interact with their DPA in several mandatory and voluntary contexts. Mandatory interactions include breach notification, prior consultation for high-risk processing, and responding to investigations. Voluntary interactions include seeking guidance on compliance questions and submitting codes of conduct for approval.
When Must You Notify the DPA?
Article 33 requires controllers to notify their supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. The notification must describe the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach.
Processors must notify the controller without undue delay after becoming aware of a breach (Article 33(2)). The controller then decides whether to notify the DPA. Failure to notify within 72 hours requires an explanation of the delay.
Article 36 requires prior consultation with the DPA when a Data Protection Impact Assessment indicates that processing would result in a high risk that the controller cannot sufficiently mitigate. Article 36 sets an advice period of up to eight weeks, extendable by six weeks for complexity; it can be suspended while requested information is obtained. Processing with the unresolved high risk should not begin while consultation is being treated as a formality.
Organisations should also designate a Data Protection Officer where required by Article 37 and communicate the DPO’s contact details to the supervisory authority. The DPO serves as the primary liaison with the DPA on all matters related to processing.
Building a Constructive Relationship with Your DPA
Maintaining a constructive relationship with your supervisory authority reduces enforcement risk. DPAs generally respond more favourably to organisations that cooperate during investigations, maintain thorough compliance documentation, and demonstrate proactive measures to address identified risks.
Legal disclaimer: This article provides general information about GDPR supervisory authorities. It does not constitute legal advice. Organisations should consult qualified legal counsel regarding their specific regulatory obligations.
FAQ
What is a supervisory authority under GDPR?
Article 4(21) defines supervisory authorities as the independent public authorities each EU/EEA member state establishes to monitor GDPR compliance. Examples include CNIL (France), BfDI and relevant state authorities (Germany), DPC (Ireland), and AEPD (Spain). The UK ICO enforces the UK framework; it is not an EU/EEA GDPR supervisory authority.
Which supervisory authority has jurisdiction over a company?
Start with the establishment, processing and relevant national allocation of competence. A lead supervisory authority is relevant to qualifying cross-border processing, not every domestic activity. Special rules and exceptions, including processing by public authorities, must also be considered.
Can multiple supervisory authorities investigate the same company?
Yes. In cross-border cases, the lead DPA cooperates with concerned DPAs (Art. 60). Any EU DPA can investigate local cases and handle complaints from residents in their territory. Complaints against Meta (Irish DPC lead) can be filed with any EU DPA.
What powers do supervisory authorities have under GDPR?
Article 58 powers: investigative (audits, requests for information, access to premises), corrective (warnings, reprimands, ordering compliance, banning processing, imposing fines), and authorisation (approving BCRs, SCCs, certification bodies).
Practical response file for an authority request
A useful response file starts with the authority’s letter, its reference number, the requested information and the applicable response date. Confirm authenticity through an official channel if needed. Assign a coordinator who can reach legal, security and the business owner; an investigation often requires facts from several systems.
Preserve relevant evidence without expanding access unnecessarily. Record which notices, contracts and processing records were in force at the time under investigation. A current document should not be presented as though it existed at the earlier date. Separate established facts, estimates and questions still under investigation.
For each question, maintain a row containing the requested fact, source document, responsible person, proposed answer and approval status. If a record cannot be located, explain the search and the gap. Do not silently replace a missing historical control with a newly created policy. Remediation is useful but must be accurately dated.
Before sending, reconcile the chronology across the incident file, service logs and earlier communications. Check attachments for unrelated personal data and disclose only what the lawful request requires. Use the authority’s designated secure channel and retain the submission receipt. If more time is needed, contact the authority before the deadline and explain the specific outstanding work; do not assume an extension has been granted.
Afterwards, track every corrective commitment as an action with an owner and verification evidence. The audit methodology can help organise that evidence, while the Article 14 information guide helps where the inquiry concerns indirectly collected data. Closing an internal task does not discharge an authority’s order unless its actual requirements have been fulfilled.