Data protection supervisory authority

Last updated:
14.10.2024
Data protection regulations impose numerous information obligations on both controllers and their respective data protection officers regarding supervisory authorities. The stricter European General Data Protection Regulation (GDPR), which came into effect in May 2018, further specifies these obligations. Not only will failures be subject to significantly higher fines in the future, but proper implementation of data protection also requires the ability to provide information at any time.
Data protection supervisory authority
Key Takeaways
  • Companies must avoid heavy fines for GDPR violations.
  • Responsibility for data protection authorities is divided between the federal and state levels.
  • The one-stop-shop principle is intended to simplify cross-border data processing.
  • Notification of the data protection officer to the competent state authority in accordance with Art. 37 (7) GDPR.
  • Despite the GDPR, there is no single unified data protection supervisory authority in Europe.

Since May 2018: Stricter sanctions & consistent data protection authorities

The EU General Data Protection Regulation (GDPR) has significantly expanded the scope of supervisory authorities and tightened sanctions for non-compliance. With fines of up to 20 million euros or up to 4% of total global annual turnover, companies cannot afford mistakes in data protection. In Germany, cases of painful fines are increasing, such as the 35 million euro fine recently imposed on fashion giant H&M for a data protection violation.

However, it is not just German data protection authorities that are taking a consistent approach: since the GDPR came into force in May 2018, fines totaling hundreds of millions of euros have been imposed across the EU. In this respect, delegating these tasks to a reliable and professionally experienced service provider is an optimal solution to take the fear out of handling information requests in day-to-day business.

Data protection information requests – our services for you

There is a lot of information to be found on the internet, but when it comes to sensitive topics like freedom of information vs. data protection, you should rely on the expertise of a professional. We relieve you of your obligation to provide information to supervisory authorities by taking on this duty for you. As your external data protection officer we are happy to coordinate communication with data protection authorities, first and foremost the supervisory authority, on your behalf.

Furthermore, we provide support in all areas of the obligation to provide information to data subjects and strive to find an optimal solution for all parties involved. Therefore, information obligations do not have to be a burden on your company and your operational processes.

Information obligations – which data protection authority should you contact?

There is a lot of confusion when it comes to the monitoring and supervision of compliance with the General Data Protection Regulation in private and public-sector companies. Many companies are familiar with terms like Federal Commissioner for Data Protection, State Data Protection Commissioner, and State Office for Data Protection Supervision, which appear daily on the internet, but they cannot define them precisely. Yet there is a clear distinction between these commissioners:

  • Under the current legal situation, the Federal Commissioner for Data Protection is responsible for monitoring public sectors. In doing so, they also provide advisory input on political decisions. The Federal Commissioner for Data Protection is both an individual and an authority.
  • The respective State Data Protection Commissioner, who is also both an individual and an authority, is responsible for monitoring privately organized companies. This follows from the federal principle, according to which various competencies are divided between the federal government and the states.

Previously, companies had to deal with various European data protection authorities for cross-border data-related activities. The GDPR eliminates this unsatisfactory situation, at least in part.

Registering your data protection officer with the competent supervisory authority

Art. 37 (7) GDPR requires the contact details of your DPO to be communicated to the competent supervisory authority in your federal state. To help you keep track, we have clearly summarized the responsibilities of the state supervisory authorities and the individual state data protection commissioners for you. In addition, you will find information on where you can register your appointed data protection officer in writing with the data protection authority.

One-stop shop for cross-border data processing

The competent supervisory authority for cross-border data processing often determined by the so-called one-stop-shop mechanism. Since in day-to-day data protection practice, data protection officers at companies previously struggled with being confronted by the differing legal interpretations of various European data protection supervisory authorities, the GDPR provides a remedy here. Article 56(6) of the GDPR stipulates that, in the case of cross-border data processing, a lead supervisory authority is responsible for monitoring the company under certain circumstances. This is a major relief for companies, as there is only one point of contact for assessing data protection compliance in cross-border data transfers.

Article 56(1) of the GDPR defines the scope of the provision. This applies when

  • cross-border data processing
  • is carried out by a controller or processor and
  • when a lead supervisory authority can be determined based on the main establishment of the company in question.

Problems with your future data protection authority?

While the one-stop-shop principle sounds logical, it can lead to problems in practice. For example, when the head office and the main establishment are not the same. Especially in complex organizations and corporate groups, it is often unclear which supervisory authority should be the "sole" point of contact as the lead supervisory authority – not least because there are often many processing operations in total, the assessment of which would fall under the jurisdiction of different supervisory authorities according to the law.

The assessment of multiple independent branches can be equally problematic. The question of whether the assessment of data protection matters can be transferred to a supervisory authority with reference to the main establishment, when the means and purposes of data processing are determined in the independent branches, regularly causes difficulties.

Even for corporate groups, it is not certain that the principle of a single supervisory authority can be maintained. Independent companies within a corporate group are likely to be individual companies within the meaning of the GDPR. According to the wording of the law, each individual company represents its own controller. Therefore, applying the one-stop-shop principle to corporate groups is likely prohibited. Whether, and if so how, a lead authority can be determined is therefore still not clearly resolved in many cases.

There is still no "single supervisory authority"

A uniform data protection supervisory authority remains a pipe dream in daily data protection practice, both in Germany and in Europe. The legal situation regarding the jurisdiction of the relevant supervisory authority remains confusing even under the GDPR. Companies should seek expert advice and examine each individual case to determine which authority is actually responsible. Since the GDPR also expands the tasks of the respective data protection authorities, companies have a lot to prepare for in this area.

We answer your questions about supervisory authorities

What is a data protection authority?

Unfortunately, there is still no uniform data protection supervisory authority, as data protection is a multifaceted topic. Therefore, the authorities are divided among the individual federal states.

What are the tasks of the data protection supervisory authority?

Supervisory authorities issue resolutions, guidance, and standards on the subject of data protection. They also monitor compliance with data protection laws and regulations. There are several supervisory authorities throughout Germany and Europe.

Who is the competent supervisory authority for GDPR questions?

The competent nationwide supervisory authority is the Federal Commissioner for Data Protection and Freedom of Information.

How do I find the relevant data protection authority?

Article 37(7) of the GDPR requires you to notify the supervisory authority in your federal state of your DPO's contact details. The best way to do this is to contact your state data protection commissioner.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in