Supervisory Authority
A supervisory authority is an independent public regulator that a country sets up to make sure organisations follow data protection law. It monitors compliance, receives notifications of personal data breaches, investigates complaints, and oversees how the rules are applied. Under the EU General Data Protection Regulation (GDPR), each Member State provides for one or more of these authorities.
Under the EU GDPR, a supervisory authority is an independent public authority that a Member State is required to establish to monitor the application of the Regulation within its jurisdiction (Art. 51 GDPR). Its functions generally include supervising compliance through investigative and corrective powers, receiving and handling personal data breach notifications, and investigating complaints from data subjects. The term is often used interchangeably with 'data protection authority' (DPA). Note that the specific composition, powers, competence, and cooperation mechanisms of supervisory authorities are governed by additional GDPR provisions not detailed here; equivalent bodies under other regimes (for example, the UK GDPR's regulator or authorities under other national laws) operate under their own instruments and may differ in scope and powers. This entry does not cover the mechanics of cross-border cooperation, the one-stop-shop mechanism, or the calculation of administrative fines.
Why it matters
Supervisory authorities are the primary point of contact between organisations and the enforcement machinery of data protection law. Under the EU GDPR, each Member State is required to provide for one or more independent public authorities responsible for monitoring the application of the Regulation within their jurisdiction. For a controller or processor, understanding which authority is competent and what powers it holds is foundational to operational compliance: these bodies receive personal data breach notifications, investigate complaints from data subjects, and supervise compliance through investigative and corrective powers. Failure to engage with a supervisory authority appropriately, for example, in the context of a notifiable breach, can compound the underlying compliance exposure.
The independence of a supervisory authority is a defining characteristic rather than an incidental one. As an independent public regulator, it is intended to act without external influence, which shapes how organisations should approach interactions with it: engagement should be treated as a regulatory relationship grounded in demonstrable evidence of compliance, not as a negotiation. Because accountability under GDPR generally requires that organisations be able to demonstrate compliance, the way a controller responds to inquiries, complaints, or breach investigations often turns on the quality of the records and evidence it can produce.
It is important not to assume that the supervisory authority concept is uniform across regimes. The term as defined here originates in the EU GDPR framework, and equivalent bodies under other instruments, such as the UK GDPR's regulator or authorities established under other national laws, operate under their own legal instruments and may differ in composition, scope, and powers. Treating all such regulators as interchangeable can lead to incorrect assumptions about jurisdiction, competence, and the specific obligations owed to each.
Who it's relevant to
Inside SA
Common questions
Answers to the questions practitioners most commonly ask about SA.