Every member state has at least one supervisory authority (Article 51(1)), each competent on the territory of its own state (Article 55(1)), and a software company with customers across the Union could in principle be answerable to all of them. The Regulation's answer to that is the lead supervisory authority: for cross-border processing, the authority of the company's main establishment or single establishment is the lead, and it is the company's sole interlocutor (Article 56(1) and (6)). This article reads the four articles that decide which authority that is, and the register StandardOS keeps of the authorities themselves, now on the breach clock and on every member-state page.
Cross-border processing: when the question arises
The lead-authority rule applies to cross-border processing, which Article 4(23) defines in two ways: processing in the context of the activities of establishments in more than one member state, or processing in the context of a single establishment that substantially affects, or is likely to substantially affect, data subjects in more than one member state. A SaaS company with one office and customers in six countries is in the second limb: one establishment, people affected in several states. A company with a sales office in a second state is in the first. Either way, there is cross-border processing and Article 56 applies. A company that processes only its own staff's data in one state has none, and its own state's authority is competent under Article 55(1) with no lead-authority question at all.
The main establishment: where the decisions are taken
Article 4(16) defines the main establishment differently for the two roles. For a controller with establishments in more than one state, it is the place of its central administration in the Union, unless the decisions on the purposes and means of processing are taken in another establishment that has the power to have them implemented, in which case that establishment is the main one. For a processor, it is the place of its central administration in the Union, or, if it has none, the establishment where the main processing activities take place. Recital 36 adds the test: the effective and real exercise of management activities determining the main decisions on purposes and means, through stable arrangements; the presence of servers or technical means in a state does not make it a main establishment. So a software company headquartered in one state, with its data centre in a second and its developers in a third, has its main establishment where its management decides what is processed and why, and the second and third states' authorities are supervisory authorities concerned (Article 4(22)), not the lead. Where a company is both controller and processor, recital 36 keeps the lead with the authority of the state where the controller has its main establishment.
The lead authority, and the three ways another one keeps a case
Article 56(1) makes the authority of the main establishment the lead supervisory authority for the cross-border processing, acting under the cooperation procedure of Article 60 with every authority concerned. Article 56(6) makes it the sole interlocutor of the controller or processor for that processing: one authority to notify, one to answer, one that drafts the decision. Article 56(2) is the derogation: any authority is competent to handle a complaint lodged with it, or a possible infringement, if the subject matter relates only to an establishment in its state or substantially affects data subjects only in its state, the local case of recital 127, whose example is the processing of employees' data in the employment context of one state. It informs the lead authority without delay, and the lead has three weeks to decide whether to take the case (Article 56(3)); if it does, the local authority may submit a draft decision the lead must take utmost account of (56(4)), and if it does not, the local authority handles it under Articles 61 and 62 (56(5)). Article 55(2) takes public authorities and bodies acting under Article 6(1)(c) or (e) out of the mechanism entirely: for them the authority of the state concerned is competent and Article 56 does not apply.
No establishment in the Union: no lead authority
A company outside the Union that offers goods or services to people in it, or monitors their behaviour, is under the Regulation by Article 3(2) and must designate a representative in the Union under Article 27(1), in a state where the people whose data it processes are (27(3)). The representative does not create a main establishment, and the one-stop-shop of Article 56 does not apply: recital 122 makes each authority competent for processing carried out by a controller or processor not established in the Union when it targets data subjects residing on its territory. Such a company can therefore be answerable to every authority whose residents it targets, and its breach notification goes to each of them. The free determination says which of the representative and the other duties apply to a given company.
Where the breach notification goes
Article 33(1) has the controller notify the personal data breach to the supervisory authority competent in accordance with Article 55, within 72 hours of becoming aware. For cross-border processing that is the lead authority of Article 56; for a single-state company it is its own authority; for a company with no establishment in the Union it is the authority of each state whose residents are affected. The register StandardOS keeps is the Board's own list of its members: 27 authorities for the 27 member states, and the authorities of Iceland, Liechtenstein and Norway, members for GDPR matters without a vote, 30 rows, each with the name the Board lists and the website it lists first, read on 12 September 2026. The Board notes that competence is split among several authorities in two states, Austria and Germany, and points to the list the Federal Commissioner keeps for the German Länder; a company established in Germany looks its authority up by Land there. Enter the state of the main establishment on the breach clock and the reading names the authority with its address, and the notification written to Article 33(3) carries it under a heading of its own.
What to do with it
The record of processing already asks where the company is established; add one line to it that names the main establishment and the reason, the place of central administration or the establishment that takes the decisions, and the lead authority that follows. That line is what the processor terms a customer sends will ask for, what the impact assessment is addressed to under Article 36 when consultation is needed, and what the breach procedure names as the recipient before anyone is under the clock. StandardOS writes it from the state on the record, and opens the 72-hour clock with the authority already named.