Supervisory Authority
Definition
The national data protection regulator responsible for enforcing GDPR in a given EU member state, such as the UK Information Commissioner's Office (post-Brexit), the Irish Data Protection Commission, or the French CNIL. Controllers must notify the relevant supervisory authority within 72 hours of becoming aware of a notifiable breach.
- Field
- GDPR, data protection compliance
- Role
- National regulator enforcing GDPR in an EU member state
- Examples
- UK ICO, Irish DPC, French CNIL
- Breach notification window
- 72 hours from becoming aware
Common questions
Which supervisory authority does a controller notify if it operates across several EU countries?+
Under the GDPR one-stop-shop mechanism, a controller with establishments in multiple member states generally notifies the lead supervisory authority in the country of its main establishment, which then coordinates with the other authorities affected rather than the controller notifying each one separately.
What happens if a controller misses the 72-hour breach notification window?+
A late notification does not excuse the obligation, and the controller must explain the delay when it does notify. Supervisory authorities can treat unjustified delay as an aggravating factor when deciding on fines, alongside the severity and handling of the breach itself.
Related terms
- Controller
- The natural or legal person, authority, agency, or other body that determines the purposes and means of processing personal data. The controller...
- Covered Entity / Business Associate
- Terms used in the US HIPAA framework. Covered entities are healthcare providers, health plans, and healthcare clearinghouses. Business Associates are contractors that...
- Data Fiduciary
- The term used in India's Digital Personal Data Protection Act 2023 for an entity that determines the purpose and means of processing...
- Data Protection Impact Assessment (DPIA)
- A structured risk assessment required under Article 35 before any processing that is likely to result in high risk to individuals' rights...
- Lawful Basis
- One of the six conditions listed in Article 6 that must be satisfied before personal data may be processed. The controller must...
- Notification Trigger
- The threshold condition that activates a legal notification obligation. Under GDPR the trigger is any personal data breach that poses a risk...
- Personal Data Breach
- Under GDPR, a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal...
- Processor
- A natural or legal person that processes personal data on behalf of the controller. Processors are directly bound by certain GDPR obligations...
- Record of Processing Activities (ROPA)
- The inventory of processing operations required under Article 30. It documents the purposes, data categories, recipients, retention periods, and security measures for...
- Safe Harbour (Encryption)
- A provision in many breach notification frameworks that exempts organisations from individual notification obligations if the breached data was encrypted and the...
Explained in these topics
- Breach Notification Laws and Obligations
- GDPR: Core Principles and Audit ObligationsThe independent national authority responsible for monitoring the application of the GDPR in its member state. Examples include the UK Information Commissioner...