[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:which-gdpr-supervisory-authority-is-yours-the-main-establishment-the-lead-authority-of-article-56-the-local-cases-and-the-30-authorities-of-the-board":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","which-gdpr-supervisory-authority-is-yours-the-main-establishment-the-lead-authority-of-article-56-the-local-cases-and-the-30-authorities-of-the-board","Which GDPR supervisory authority is yours: the main establishment, the lead authority of Article 56, the local cases, and the 30 authorities of the Board","A software company with customers in several member states deals with one supervisory authority for its cross-border processing: the authority of its main establishment, the lead authority of Article 56(1), its sole interlocutor under Article 56(6). Where that is, what the main establishment means for a controller and for a processor (Article 4(16)), when another authority keeps a local case (Article 56(2)), what a company with no establishment in the Union gets instead (Article 27, recital 122), and where the 72-hour breach notification goes (Article 33(1)). With the 27 authorities and the three EEA ones as the European Data Protection Board lists its members, read on 12 September 2026.","2026-09-12",{"who":10,"when":11,"do":12},"A software company established in the Union that processes personal data of people in more than one member state, as controller of its own customer and employee data and as processor of the data its customers put in the product; and a company with no establishment in the Union that sells to people in it.","From 25 May 2018, the day the Regulation applied, for every controller and processor in scope; the register of authorities is read from the Board's members page on 12 September 2026.","Write down where your central administration in the Union is and whether decisions on purposes and means are taken anywhere else; that place's authority is your lead authority for cross-border processing, the one your breach notification goes to; enter the state on the breach clock and the authority is named with its address.","\nEvery member state has at least one supervisory authority (Article 51(1)), each competent on the territory of its own state (Article 55(1)), and a software company with customers across the Union could in principle be answerable to all of them. The Regulation's answer to that is the lead supervisory authority: for cross-border processing, the authority of the company's main establishment or single establishment is the lead, and it is the company's sole interlocutor (Article 56(1) and (6)). This article reads the four articles that decide which authority that is, and the register StandardOS keeps of the authorities themselves, [now on the breach clock](\u002Fgdpr\u002Fbreach-clock) and on every [member-state page](\u002Fmember-states).\n\n## Cross-border processing: when the question arises\n\nThe lead-authority rule applies to cross-border processing, which Article 4(23) defines in two ways: processing in the context of the activities of establishments in more than one member state, or processing in the context of a single establishment that substantially affects, or is likely to substantially affect, data subjects in more than one member state. A SaaS company with one office and customers in six countries is in the second limb: one establishment, people affected in several states. A company with a sales office in a second state is in the first. Either way, there is cross-border processing and Article 56 applies. A company that processes only its own staff's data in one state has none, and its own state's authority is competent under Article 55(1) with no lead-authority question at all.\n\n## The main establishment: where the decisions are taken\n\nArticle 4(16) defines the main establishment differently for the two roles. For a controller with establishments in more than one state, it is the place of its central administration in the Union, unless the decisions on the purposes and means of processing are taken in another establishment that has the power to have them implemented, in which case that establishment is the main one. For a processor, it is the place of its central administration in the Union, or, if it has none, the establishment where the main processing activities take place. Recital 36 adds the test: the effective and real exercise of management activities determining the main decisions on purposes and means, through stable arrangements; the presence of servers or technical means in a state does not make it a main establishment. So a software company headquartered in one state, with its data centre in a second and its developers in a third, has its main establishment where its management decides what is processed and why, and the second and third states' authorities are supervisory authorities concerned (Article 4(22)), not the lead. Where a company is both controller and processor, recital 36 keeps the lead with the authority of the state where the controller has its main establishment.\n\n## The lead authority, and the three ways another one keeps a case\n\nArticle 56(1) makes the authority of the main establishment the lead supervisory authority for the cross-border processing, acting under the cooperation procedure of Article 60 with every authority concerned. Article 56(6) makes it the sole interlocutor of the controller or processor for that processing: one authority to notify, one to answer, one that drafts the decision. Article 56(2) is the derogation: any authority is competent to handle a complaint lodged with it, or a possible infringement, if the subject matter relates only to an establishment in its state or substantially affects data subjects only in its state, the local case of recital 127, whose example is the processing of employees' data in the employment context of one state. It informs the lead authority without delay, and the lead has three weeks to decide whether to take the case (Article 56(3)); if it does, the local authority may submit a draft decision the lead must take utmost account of (56(4)), and if it does not, the local authority handles it under Articles 61 and 62 (56(5)). Article 55(2) takes public authorities and bodies acting under Article 6(1)(c) or (e) out of the mechanism entirely: for them the authority of the state concerned is competent and Article 56 does not apply.\n\n## No establishment in the Union: no lead authority\n\nA company outside the Union that offers goods or services to people in it, or monitors their behaviour, is under the Regulation by Article 3(2) and must designate a representative in the Union under Article 27(1), in a state where the people whose data it processes are (27(3)). The representative does not create a main establishment, and the one-stop-shop of Article 56 does not apply: recital 122 makes each authority competent for processing carried out by a controller or processor not established in the Union when it targets data subjects residing on its territory. Such a company can therefore be answerable to every authority whose residents it targets, and its breach notification goes to each of them. The [free determination](\u002Fgdpr\u002Fduties) says which of the representative and the other duties apply to a given company.\n\n## Where the breach notification goes\n\nArticle 33(1) has the controller notify the personal data breach to the supervisory authority competent in accordance with Article 55, within 72 hours of becoming aware. For cross-border processing that is the lead authority of Article 56; for a single-state company it is its own authority; for a company with no establishment in the Union it is the authority of each state whose residents are affected. The register StandardOS keeps is the Board's own list of its members: 27 authorities for the 27 member states, and the authorities of Iceland, Liechtenstein and Norway, members for GDPR matters without a vote, 30 rows, each with the name the Board lists and the website it lists first, read on 12 September 2026. The Board notes that competence is split among several authorities in two states, Austria and Germany, and points to the list the Federal Commissioner keeps for the German Länder; a company established in Germany looks its authority up by Land there. Enter the state of the main establishment on the [breach clock](\u002Fgdpr\u002Fbreach-clock) and the reading names the authority with its address, and the notification written to Article 33(3) carries it under a heading of its own.\n\n## What to do with it\n\nThe record of processing already asks where the company is established; add one line to it that names the main establishment and the reason, the place of central administration or the establishment that takes the decisions, and the lead authority that follows. That line is what the [processor terms](\u002Fgdpr\u002Fprocessor-terms) a customer sends will ask for, what the [impact assessment](\u002Fgdpr\u002Fimpact-assessment) is addressed to under Article 36 when consultation is needed, and what the breach procedure names as the recipient before anyone is under the clock. StandardOS writes it from the state on the record, and opens the 72-hour clock with the authority already named.\n",1789383984691]