Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: EN

Article 55 Competence


Summary What does Article 55 of the GDPR regulation say?

This article establishes the territorial scope of each supervisory authority's competence.

As a companion to Article 56, which deals with cross-border processing and the "lead supervisory authority" mechanism, Article 55 sets the default rule: each supervisory authority operates within its own Member State.

It also carves out two notable exceptions to this general principle — one expanding competence in specific processing contexts, and one explicitly limiting it in relation to the judiciary.

Important points:

  • Each supervisory authority is competent only within the territory of its own Member State.
  • Where processing is carried out by public authorities or private bodies under Article 6(1)(c) or (e), the supervisory authority of that Member State is competent and the lead authority mechanism under Article 56 does not apply.
  • Supervisory authorities have no competence to supervise courts when those courts are acting in their judicial capacity.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Each supervisory authority shall be competent for the performance of the tasks assigned to and the exercise of the powers conferred on it in accordance with this Regulation on the territory of its own Member State.

    1. Where processing is carried out by public authorities or private bodies acting on the basis of point (c) or (e) of Article 6(1), the supervisory authority of the Member State concerned shall be competent. In such cases Article 56 does not apply.

    1. Supervisory authorities shall not be competent to supervise processing operations of courts acting in their judicial capacity.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod