Skip to content

Supervisory Authority

Definition

The national data protection regulator responsible for enforcing GDPR in a given EU member state, such as the UK Information Commissioner's Office (post-Brexit), the Irish Data Protection Commission, or the French CNIL. Controllers must notify the relevant supervisory authority within 72 hours of becoming aware of a notifiable breach.

Field
GDPR, data protection compliance
Role
National regulator enforcing GDPR in an EU member state
Examples
UK ICO, Irish DPC, French CNIL
Breach notification window
72 hours from becoming aware

Common questions

Which supervisory authority does a controller notify if it operates across several EU countries?+

Under the GDPR one-stop-shop mechanism, a controller with establishments in multiple member states generally notifies the lead supervisory authority in the country of its main establishment, which then coordinates with the other authorities affected rather than the controller notifying each one separately.

What happens if a controller misses the 72-hour breach notification window?+

A late notification does not excuse the obligation, and the controller must explain the delay when it does notify. Supervisory authorities can treat unjustified delay as an aggravating factor when deciding on fines, alongside the severity and handling of the breach itself.

Related terms

Controller
The natural or legal person, authority, agency, or other body that determines the purposes and means of processing personal data. The controller...
Covered Entity / Business Associate
Terms used in the US HIPAA framework. Covered entities are healthcare providers, health plans, and healthcare clearinghouses. Business Associates are contractors that...
Data Fiduciary
The term used in India's Digital Personal Data Protection Act 2023 for an entity that determines the purpose and means of processing...
Data Protection Impact Assessment (DPIA)
A structured risk assessment required under Article 35 before any processing that is likely to result in high risk to individuals' rights...
Lawful Basis
One of the six conditions listed in Article 6 that must be satisfied before personal data may be processed. The controller must...
Notification Trigger
The threshold condition that activates a legal notification obligation. Under GDPR the trigger is any personal data breach that poses a risk...
Personal Data Breach
Under GDPR, a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal...
Processor
A natural or legal person that processes personal data on behalf of the controller. Processors are directly bound by certain GDPR obligations...
Record of Processing Activities (ROPA)
The inventory of processing operations required under Article 30. It documents the purposes, data categories, recipients, retention periods, and security measures for...
Safe Harbour (Encryption)
A provision in many breach notification frameworks that exempts organisations from individual notification obligations if the breached data was encrypted and the...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.