Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: EN
- General data protection
Basic legislative acts
- GDPR regulation
Article 55 Competence
Summary What does Article 55 of the GDPR regulation say?
This article establishes the territorial scope of each supervisory authority's competence.
As a companion to Article 56, which deals with cross-border processing and the "lead supervisory authority" mechanism, Article 55 sets the default rule: each supervisory authority operates within its own Member State.
It also carves out two notable exceptions to this general principle — one expanding competence in specific processing contexts, and one explicitly limiting it in relation to the judiciary.
Important points:
- Each supervisory authority is competent only within the territory of its own Member State.
- Where processing is carried out by public authorities or private bodies under Article 6(1)(c) or (e), the supervisory authority of that Member State is competent and the lead authority mechanism under Article 56 does not apply.
- Supervisory authorities have no competence to supervise courts when those courts are acting in their judicial capacity.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Each supervisory authority shall be competent for the performance of the tasks assigned to and the exercise of the powers conferred on it in accordance with this Regulation on the territory of its own Member State.
Where processing is carried out by public authorities or private bodies acting on the basis of point (c) or (e) of Article 6(1), the supervisory authority of the Member State concerned shall be competent. In such cases Article 56 does not apply.
Supervisory authorities shall not be competent to supervise processing operations of courts acting in their judicial capacity.
Relevant recitals
Recital 20 Judicial independence in court processing
While this Regulation applies, inter alia, to the activities of courts and other judicial authorities, Union or Member State law could specify the processing operations and processing procedures in relation to the processing of personal data by courts and other judicial authorities. The competence of the supervisory authorities should not cover the processing of personal data when courts are acting in their judicial capacity, in order to safeguard the independence of the judiciary in the performance of its judicial tasks, including decision-making. It should be possible to entrust supervision of such data processing operations to specific bodies within the judicial system of the Member State, which should, in particular ensure compliance with the rules of this Regulation, enhance awareness among members of the judiciary of their obligations under this Regulation and handle complaints in relation to such data processing operations.
Recital 122 Territorial competence of authorities
Each supervisory authority should be competent on the territory of its own Member State to exercise the powers and to perform the tasks conferred on it in accordance with this Regulation. This should cover in particular the processing in the context of the activities of an establishment of the controller or processor on the territory of its own Member State, the processing of personal data carried out by public authorities or private bodies acting in the public interest, processing affecting data subjects on its territory or processing carried out by a controller or processor not established in the Union when targeting data subjects residing on its territory. This should include handling complaints lodged by a data subject, conducting investigations on the application of this Regulation and promoting public awareness of the risks, rules, safeguards and rights in relation to the processing of personal data.
Recital 128 One-stop-shop excludes public bodies
The rules on the lead supervisory authority and the one-stop-shop mechanism should not apply where the processing is carried out by public authorities or private bodies in the public interest. In such cases the only supervisory authority competent to exercise the powers conferred to it in accordance with this Regulation should be the supervisory authority of the Member State where the public authority or private body is established.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
processing
Definition
controller
Definition
processor
Definition
supervisory authority
Definition
personal data