← back to the act's dossier

GDPR — Article 56

The article's text

Article 56 Competence of the lead supervisory authority 1. Without prejudice to Article 55, the supervisory authority of the main establishment or of the single establishment of the controller or processor shall be competent to act as lead supervisory authority for the cross-border processing carried out by that controller or processor in accordance with the procedure provided in Article 60. 2. By derogation from paragraph 1, each supervisory authority shall be competent to handle a complaint lodged with it or a possible infringement of this Regulation, if the subject matter relates only to an establishment in its Member State or substantially affects data subjects only in its Member State. relates only to an establishment in its Member State or substantially affects data subjects only in its Member State. 3. In the cases referred to in paragraph 2 of this Article, the supervisory authority shall inform the lead supervisory authority without delay on that matter. Within a period of three weeks after being informed the lead supervisory authority shall decide whether or not it will handle the case in accordance with the procedure provided in Article 60, taking into account whether or
full text
not there is an establishment of the controller or processor in the Member State of which the supervisory authority informed it. is an establishment of the controller or processor in the Member State of which the supervisory authority informed it. 4. Where the lead supervisory authority decides to handle the case, the procedure provided in Article 60 shall apply. The supervisory authority which informed the lead supervisory authority may submit to the lead supervisory authority a draft for a decision. The lead supervisory authority shall take utmost account of that draft when preparing the draft decision referred to in Article 60(3). 5. Where the lead supervisory authority decides not to handle the case, the supervisory authority which informed the lead supervisory authority shall handle it according to Articles 61 and 62. 6. The lead supervisory authority shall be the sole interlocutor of the controller or processor for the cross-border processing carried out by that controller or processor.

Who wrote about this article in the consultations

Filers who named this exact article number in their own text. It is their sentence, not our reading — and not a causal claim.

17
business association
5
NGO
3
ACADEMIC_RESEARCH_INSTITTUTION
2
company
1
non-EU citizen
WhoCountryWhat they wrote
ANITEC-ASSINFORMITin delays with many CSAs seeking to ‘have their say’ and undermine the one‐stop‐shop mechanism and the LSA’s competence under Article 56 of the GDPR. We note that the application of Article 60 is currently being considered as part of the Commis
ZKI e.V.DEichkeit der Zuständigkeit einer federführenden Aufsichtsbehörde sollte nicht auf grenzüberschreitende Verarbeitungsvorgänge gemäß Art. 56 DSGVO beschränkt bleiben, sondern auch auf nationale Verarbeitungsvorgänge Anwendung finden. Letzteres gilt insbesondere i
Bitkom e.V.DEs & Procedures 6 2 Comments on Chapter III – Cooperation under Article 60 of the GDPR Cooperation It is important to maintain the Article 56 competence of the lead supervisory authority (LSA) in its cooperation with Competent Supervisory Authorities (CSAs) as
ITI - Information Technology Industry CouncilUSand reasoned objections (RROs) made by the concerned supervisory authorities (CSAs). Maintaining the competences of the LSA under Article 56 of the GDPR is the most effective method for ensuring the efficient handling of complaints. Maintaining the competences
Hans-Hermann SchildDEegründung, I. Kontext des Vorschlages, Gründe und Ziele des Vor- schlages, S. 1 COM (2023) 348 final. 37 Zum Eintrittsrecht nach Art. 56 Abs. 2 DSGVO siehe Anmerkung Schild, zu Schlussantrag GA Bobeek vom 13.1.2021 – C-645/19, ZD 2021, 203; EuGH, Urteil vom 1
LA POSTEFRte Groupe encourage toutefois la Commission européenne à veiller à ce que le mécanisme de guichet unique, introduit en vertu de l'article 56 du RGPD, soit maintenu et renforcé afin de garantir des conditions de concurrence équitables et la sécurité juridique p
noybATcompetence of the SA The absence of deadline regarding whether a SA considers itself competent delays the procedure (by contrast, Article 56(3) GDPR provides that when a case is transferred by an SA to a LSA, the latter has 3 weeks to confirm whether it will h
Ecommerce EuropeBEwith Article 56(1) GDPR, we sometimes experience that other DPAs approach companies on the basis of Article 56(2) GDPR. More specifically, the respective authorities argue that the case in question is considered as “local” and that they would be competent for
Asociación Española de Economía Digital (Adigital)EScontroller’s main establishment is the only point of contact competent for this controller’s cross-border processing operations (Article 56(1) GDPR). ● In this context, the LSA must cooperate sincerely and effectively with other SAs (Article 63(ff) GDPR). Thi
American Chamber of Commerce to the EU (AmCham EU)BEoperations (Article 56(1) GDPR). In this context, the LSA must cooperate effectively with other SAs (Article 61 GDPR). This harmonised regulatory framework, like the GDPR’s substantive provisions, serves to achieve two goals: the same high level of protection
American Chamber of Commerce in PolandPLcontroller’s main establishment is the only point of contact competent for this controller’s cross-border processing operations (Article 56(1) GDPR). • In this context, the LSA must cooperate sincerely and effectively with other SAs (Article 63(ff) GDPR). Thi
Związek Pracodawców Branży Internetowej IAB PolskaPL, LSA) i jest jedynym punktem kontaktowym właściwym dla transgranicznych operacji przetwarzania danych przez tego administratora (art. 56 ust. 1 RODO). Koncepcja OSS upraszcza firmom transgraniczne prowadzenie działalności i zapewnia pewność prawną i biznesową
ITI - Information Technology Industry CouncilUSthe primacy of Member States’ national laws in this respect. Clarifying SA Competence Under Art. 56(2) GDPR Under Art. 56(2), SAs can handle a complaint “if the subject matter relates only to an establishment in its Member State or substantially affects data s
DOT EuropeBEbasis of Article 56(1) GDPR, without needing to meet further or heightened criteria which are not provided in the GDPR. Another relevant issue that merits clarification is the GDPR provisions on local cases, which can undermine the lead SA concept. Despite the
Polish Confederation LewiatanPLcontroller’s main establishment is the only point of contact competent for this controller’s cross-border processing operations (Article 56(1) GDPR). • In this context, the LSA must cooperate sincerely and effectively with other SAs (Article 63(ff) GDPR).
AmCham SlovenijaSIcontroller’s main establishment is the only point of contact competent for this controller’s cross-border processing operations (Article 56(1) GDPR).  In this context, the LSA must cooperate sincerely and effectively with other SAs (Article 63(ff) GDPR). Thi
CCIA - Computer & Communications Industry AssociationBEonly to an establishment in [the] Member State [of the SA] or substantially affects data subjects only in its Member State” under Article 56(2) GDPR, and to clarify the extent to which SAs are permitted to conduct preliminary assessments for the LSA. We also i
Centre for Information Policy Leadership (CIPL)BEestablishment in the local state or affects individuals in that state only. Where the LSA decides to handle the case pursuant to Article 56(4) of the GDPR, the LSA is not bound by the draft decision prepared by the CSA but shall only “take utmost account of t
European Digital Rights (EDRi)BEder an SA to adopt a decision under Article 66 if the case is not moving fast enough - to order the SAs to adopt a decision under Article 56) - to compensate the complainant for damages if the delay to handle the complaint is not duly justified by the SA.3 Lac
Internet Corporation for Assigned Names and NumbersUSng out cross-border processing. The one-stop shop mechanism needs to be correctly applied taking into account the requirements of Art. 56 (1) GDPR, which stipulates that “the supervisory authority of the main establishment or of the single establishment of the
David ErdosGBing, enforcement and investigatory tasks allocated (GDPR, art. 57) especially in the coordinated area of cross-border processing (art. 56). Where a lead supervisory authority is unable to handle a concern expeditiously then it should be obliged to adopt a faci
EDiMABEtizens’ fundamental rights to data protection and privacy, while allowing business in Europe to thrive and compete. As set out in Art. 56 GDPR, and as confirmed, without reservation by the Commission in past statements, the OSS is a core harmonising EU princip
Open Rights GroupGBns from the Belgian and Irish authorities. At this time the Hungarian DPA is not willing to take further steps. The DPA refers to Article 56.1 of the GDPR which states that the supervisory authority of the main or the single establishment of the controller or
DIGITALEUROPEBEinvestigation and enforcement procedures and promoting consistent interpretation across the EU. 9 Art. 62 GDPR 10 Art. 56 GDPR 7 The reality is that national laws implementing the GDPR have made maximal use of the margin of manoeuvre that the text allowed. Thi
European Publishers CouncilGBwhich are unknown to end-users as they are further down the ad tech funnel. These players may find it preferable – or in 15 GDPR, Article 56(1). 16 European Commission, “The GDPR: new opportunities, new obligations – What every business needs to know about the
Centre for Information Policy Leadership (CIPL)GBto interact with a single regulatory interlocutor in the EU for all cross- border EU data protection-related matters in line with Article 56(6) of the GDPR.8 This is all the more relevant in the context of the COVID-19 crisis where organisations need to react
Computer & Communication Industry Association (CCIA)USseveral Member States; and Joint Statement on the final adoption of the new EU rules for personal data protection (2016); 5 See Article 56(2) GDPR; 6 See Article 51(2) GDPR; CCIA Europe | Rue de la Loi 227, 1040 Brussels | www.ccianet.org | Transparency Reg
ACT | The App AssociationBEraging cooperation between national DPAs. Notably, steps should be taken to avoid certain DPAs acting in conflict with clear GDPR Article 56 policies designating a Lead Authority.
Information Technology Industry CouncilBEies, they will take into consideration the requirements and guidelines of the Lead Authority and follow the procedure outlined in Article 56 of the GDPR. A genuine, strong cooperation among the EU’s DPAs is essential for a coherent application and enforcement

Source: public consultation submissions and position papers. n = 29 mentions; counted as a literal reference to the article number.

Ask about this article →