Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: FR

Article 55 Compétence


Summary What does Article 55 of the GDPR regulation say?

This article establishes the territorial scope of each supervisory authority's competence.

As a companion to Article 56, which deals with cross-border processing and the "lead supervisory authority" mechanism, Article 55 sets the default rule: each supervisory authority operates within its own Member State.

It also carves out two notable exceptions to this general principle — one expanding competence in specific processing contexts, and one explicitly limiting it in relation to the judiciary.

Important points:

  • Each supervisory authority is competent only within the territory of its own Member State.
  • Where processing is carried out by public authorities or private bodies under Article 6(1)(c) or (e), the supervisory authority of that Member State is competent and the lead authority mechanism under Article 56 does not apply.
  • Supervisory authorities have no competence to supervise courts when those courts are acting in their judicial capacity.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Chaque autorité de contrôle est compétente pour exercer les missions et les pouvoirs dont elle est investie conformément au présent règlement sur le territoire de l'État membre dont elle relève.

    1. Lorsque le traitement est effectué par des autorités publiques ou des organismes privés agissant sur la base de l'article 6, paragraphe 1, point c) ou e), l'autorité de contrôle de l'État membre concerné est compétente. Dans ce cas, l'article 56 n'est pas applicable.

    1. Les autorités de contrôle ne sont pas compétentes pour contrôler les opérations de traitement effectuées par les juridictions dans l'exercice de leur fonction juridictionnelle.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod