5. Are there limits?
Yes.
The request must be connected to the authority's lawful functions and must operate within the broader framework of EU law, proportionality, procedural fairness, confidentiality, privilege and fundamental rights.
The most important practical lesson is therefore this:
Article 31 should never be treated as a simple "answer the regulator" provision. It is the intersection between GDPR accountability, supervisory powers, regulatory procedure and fundamental rights.
For controllers and processors, the safest compliance posture is to maintain a regulatory-readiness system before an investigation ever begins. That means knowing who owns the response, where the evidence is located, how the DPO and legal team coordinate, how processors will cooperate, how privileged material is handled, how deadlines are managed, and how factual accuracy is verified.
For legal analysis, the key is to read Article 31 together with Articles 30, 39, 51-58 and 83, rather than treating it as a standalone duty. Article 31 supplies the general cooperation obligation; Article 57 defines the regulatory mission; Article 58 supplies much of the concrete investigative machinery; and Article 83 gives non-compliance with Article 31 real enforcement consequences.
The most difficult unresolved territory concerns the precise boundary between mandatory cooperation and fundamental procedural rights, particularly the privilege against self-incrimination. That issue prevents Article 31 from being understood as an unlimited power to compel an undertaking to build the case against itself. At the same time, that limitation cannot be converted into a general licence to obstruct regulatory investigations.
In practical terms, the ideal response to a supervisory-authority request is therefore:
verify → identify legal basis → scope → preserve → collect → reconcile → assess privilege/confidentiality → identify fundamental-rights issues → respond completely and accurately → preserve the response record.
That is the operational meaning of Article 31 within the GDPR's broader accountability and enforcement architecture.
Article 32 is one of the most operationally important provisions in the GDPR because it converts the abstract principle of integrity and confidentiality into a concrete, risk-based security obligation. Its central idea is not that an organisation must make personal data absolutely secure. Rather, it must be able to show that it hasidentified the security risks created by its processing and implemented measures proportionate to those risks, while continuously testing whether those measures remain effective.
Below is a detailed commentary that goes beyond merely restating the provision and examines the difficult interpretive questions, practical implications, examples, grey areas, compliance strategy, and the relationship of Article 32 with Articles 5, 24, 25, 28, 33, 34 and 35.