CHAPTER VIINDEPENDENT SUPERVISORY AUTHORITIES

Article 51Supervisory authority

Official text

(1)Each Member State shall provide for one or more independent public authorities to be responsible for monitoring the application of this Regulation, in order to protect the fundamental rights and freedoms of natural persons in relation to processing and to facilitate the free flow of personal data within the Union (‘supervisory authority’).

(2)Each supervisory authority shall contribute to the consistent application of this Regulation throughout the Union. For that purpose, the supervisory authorities shall cooperate with each other and the Commission in accordance with Chapter VII.

(3)Where more than one supervisory authority is established in a Member State, that Member State shall designate the supervisory authority which is to represent those authorities in the Board and shall set out the mechanism to ensure compliance by the other authorities with the rules relating to the consistency mechanism referred to in Article 63.

(4)Each Member State shall notify to the Commission the provisions of its law which it adopts pursuant to this Chapter, by 25 May 2018 and, without delay, any subsequent amendment affecting them.

Commentary

Article 51 is the institutional starting point of GDPR enforcement. It answers a basic but crucial question: who ensures that governments, companies and other organisations actually comply with the GDPR? Its answer is that every Member State must establish at least one independent public authority with responsibility for monitoring and enforcing the Regulation.

This commentary explains Article 51 and Recitals 117 to 119 in plain language, while highlighting the legal nuances, difficult questions, grey areas and practical consequences. This is an analytical explanation, not legal advice for a specific case.

1. The basic idea behind Article 51

The GDPR does not rely only on individuals bringing cases before courts. It creates specialised public regulators called supervisory authorities, commonly referred to as data protection authorities or DPAs.

Article 4(21) GDPR defines a supervisory authority as an independent public authority established by a Member State under Article 51. Article 51 therefore provides the foundation, while Articles 52 to 59 explain the authority’s independence, organisation, competence, tasks and powers.

The official GDPR text confirms that the Regulation has two connected objectives:

  1. protecting natural persons in relation to the processing of personal data; and
  2. ensuring that personal data can move freely within the Union under a harmonised system.

Simple illustration

Imagine that the GDPR is a set of traffic rules.

  • Controllers and processors are the drivers.
  • Data subjects are the road users whom the rules protect.
  • Courts decide legal disputes when cases reach them.
  • Supervisory authorities are the specialist traffic regulators. They issue guidance, inspect conduct, investigate accidents, respond to complaints and impose corrective measures. Without an independent regulator, the GDPR could exist on paper but remain weak in practice.

2. Article 51 within Chapter VI

Chapter VI is divided broadly into two parts.

Section 1: Independent status

Articles 51 to 54 deal principally with:

  • creation of supervisory authorities;
  • their independence;
  • appointment and qualifications of their members;
  • organisational arrangements;
  • staffing, confidentiality and resources.

Section 2: Competence, tasks and powers

Articles 55 to 59 deal with:

  • which authority is competent;
  • lead supervisory authority arrangements;
  • duties such as complaint handling and public awareness;
  • investigative, corrective, authorisation and advisory powers;
  • annual activity reports.

Article 51 is therefore an enabling and constitutional provision. It does not itself list every power of an authority, but it creates the institutional framework upon which the later provisions operate.

Preventive and retrospective functions

A supervisory authority does not act only after a violation.

Its work is both:

  • preventive, such as issuing guidance, advising legislatures, approving certain instruments, raising awareness and promoting compliant practices; and
  • corrective or retrospective, such as investigating complaints, ordering compliance, restricting processing or imposing administrative fines.

Illustration

A hospital proposes an AI system to prioritise patients. Before implementation, the supervisory authority may issue guidance about transparency, sensitive health data and data protection impact assessments. That is preventive regulation. If the hospital later unlawfully discloses patient files, the authority may investigate and order corrective action. That is retrospective enforcement.

3. Article 51(1): The obligation to establish a supervisory authority

Article 51(1) says that each Member State“shall provide for” one or more supervisory authorities.

The word “shall” creates a binding legal obligation. A Member State cannot decide that ordinary ministries, industry associations or civil courts are sufficient. It must establish at least one qualifying independent public authority.

3.1 One or more authorities

A Member State may create:

  • one national authority;
  • several territorial authorities;
  • separate federal and regional authorities;
  • authorities divided according to public and private sectors;
  • certain specialised authorities where the GDPR permits particular arrangements.

Recital 117 recognises that multiple authorities may be appropriate because Member States have different constitutional, administrative and organisational structures.

Illustration

Country A is centrally governed. It creates one national data protection authority. Country B is a federation. Its constitution gives regional states substantial regulatory autonomy. It establishes regional authorities and a federal authority. Both models can comply with Article 51. The important questions are whether every relevant processing activity falls within a competent authority’s remit and whether the authorities can cooperate effectively.

3.2 A grey area: fragmentation versus local expertise

Multiple authorities may provide:

  • local accessibility;
  • sector-specific expertise;
  • sensitivity to constitutional divisions of power.

However, they may also produce:

  • inconsistent interpretations;
  • uncertainty about jurisdiction;
  • duplicated investigations;
  • slower cross-border cooperation;
  • different enforcement priorities.

Article 51(3) and the consistency mechanism attempt to control these risks. Multiple authorities are permitted, but regulatory fragmentation is not supposed to undermine uniform GDPR protection.

4. The authority must be a public authority

A supervisory authority must be a public body. A Member State cannot contract out the ultimate statutory responsibility for GDPR supervision to a private company, consultancy or industry association.

This does not mean that the authority must perform every supporting activity internally. It may, subject to applicable law and safeguards:

  • procure IT services;
  • obtain expert opinions;
  • commission research;
  • rent premises;
  • use external technical specialists.

But the legally protected decision-making functions must remain with the public authority.

Illustration

A government hires a cybersecurity firm to perform technical testing during an investigation. That may be permissible if proper confidentiality and control safeguards exist. It would be different if the government allowed the firm itself to decide whether a controller violated the GDPR and what sanction should be imposed. That would improperly transfer public regulatory authority to a private body.

4.1 Why public status matters

A supervisory authority may exercise coercive legal powers, including powers to:

  • demand information;
  • conduct investigations;
  • order controllers to comply;
  • prohibit or restrict processing;
  • impose administrative fines.

Such powers require legal authority, accountability, procedural fairness and judicial control. Public-law status helps provide that framework.

5. Independence: the central institutional safeguard

Article 51(1) expressly requires an independent public authority. Article 52 develops this requirement in greater detail, while Recital 117 describes complete independence as essential to protecting individuals.

Independence is not merely a desirable administrative feature. Independent supervision is expressly recognised by Article 8(3) of the EU Charter and Article 16(2) TFEU.

5.1 Independence from whom?

A supervisory authority must be protected against improper influence from:

  • national governments;
  • ministers;
  • political parties;
  • regulated companies;
  • industry groups;
  • other public authorities;
  • private complainants;
  • the European Commission;
  • other supervisory authorities when deciding matters within its own competence.

Independence does not mean that the authority can act arbitrarily. It means that its regulatory judgments must not be directed or distorted by external pressure.

5.2 Functional and structural independence

There are at least two important dimensions.

Functional independence

The authority must be able to perform its tasks and exercise its powers without receiving instructions about how to decide a case.

For example, a minister must not be able to tell the authority:

“Do not investigate this company because it is economically important.”

Structural independence

Formal freedom from instructions may not be enough. The authority also needs structures that prevent indirect influence.

Relevant considerations include:

  • secure terms of office;
  • transparent appointment procedures;
  • protection against arbitrary dismissal;
  • adequate staffing;
  • sufficient funding;
  • control over internal administration;
  • appropriate premises and technical infrastructure;
  • absence of compromising organisational links.

The CJEU’s case law under the GDPR’s predecessor treated indirect influence as a genuine threat. In the Austrian case, concerns included the authority’s administrative integration into the Federal Chancellery, supervision of a key official and the Chancellor’s broad right to information.

Illustration

Suppose a privacy regulator is legally described as “independent,” but:

  • the Justice Minister can dismiss its head at any time;
  • the regulator must obtain ministerial approval before opening important investigations;
  • its budget can be informally withheld when it investigates government departments. The label “independent” would not cure these structural problems.

5.3 Financial oversight is not automatically interference

Recital 118 contains an important qualification. Independence does not mean an absence of accountability. Supervisory authorities may be subject to:

  • auditing of public expenditure;
  • parliamentary budget procedures;
  • anti-corruption controls;
  • procurement requirements;
  • judicial review.

A court may annul an authority’s unlawful decision without violating its independence. Similarly, an auditor may examine whether public money was properly spent.

The key distinction is between:

  • lawful oversight of legality and expenditure, and
  • control over regulatory judgment or case outcomes.

Illustration

An auditor checks whether the authority followed procurement rules when purchasing computers. That is financial oversight. A finance ministry threatens to reduce the authority’s budget unless it stops investigating a state-owned company. That is a threat to independence.

5.4 Independence does not mean unlimited discretion

A supervisory authority remains bound by:

  • the GDPR;
  • the EU Charter;
  • national procedural law, where compatible with EU law;
  • proportionality;
  • equality and non-discrimination;
  • the duty to give reasons;
  • rights of defence;
  • judicial decisions;
  • cooperation and consistency procedures.

It cannot defend an unlawful decision by simply invoking independence.

6. “Monitoring the application” of the GDPR

The authority’s central responsibility is to monitor how the GDPR is applied.

“Monitoring” should be understood broadly. It includes more than passively receiving complaints. It covers activities such as:

  • investigating possible infringements;
  • handling complaints;
  • monitoring technological and commercial developments;
  • issuing guidance;
  • advising governments and legislators;
  • examining codes of conduct;
  • promoting public awareness;
  • conducting audits;
  • cooperating in cross-border matters.

6.1 Monitoring is not the same as acting as everyone’s lawyer

A supervisory authority protects the public interest and individual rights, but it is not simply the personal legal representative of each complainant.

It must investigate and decide independently. A complainant may allege a violation, but the authority must assess:

  • the facts;
  • its jurisdiction;
  • the applicable GDPR provisions;
  • the seriousness of the matter;
  • procedural fairness;
  • appropriate corrective action.

6.2 Priority-setting and resource constraints

A difficult practical issue is whether an authority must investigate every complaint with equal intensity.

The GDPR requires complaint handling, but authorities inevitably have limited staff and budgets. They may need to prioritise systemic, high-risk or particularly serious cases.

However, resource constraints cannot justify:

  • systematic inactivity;
  • ignoring entire classes of complaints;
  • failing to communicate with complainants;
  • allowing cases to remain unresolved indefinitely;
  • refusing to exercise statutory responsibility.

The authority needs a rational and transparent method of case management.

7. The two objectives of Article 51(1)

Article 51 gives supervisory authorities two connected objectives:

  1. protecting fundamental rights and freedoms of natural persons; and
  2. facilitating the free flow of personal data within the Union.

These are not necessarily competing objectives. The GDPR’s basic theory is that a consistently high level of protection creates trust, which enables data to move lawfully across the internal market.

7.1 Protecting fundamental rights and freedoms

Data protection is a fundamental right, but it is not absolute. Supervisory authorities may need to consider other rights, including:

  • privacy;
  • freedom of expression and information;
  • freedom to conduct a business;
  • property rights;
  • access to documents;
  • equality;
  • effective judicial protection.

Illustration: news reporting

A newspaper publishes information about alleged corruption by a senior business executive. The executive demands immediate erasure. The authority cannot reason: “Personal data was published, so it must be deleted.” It must consider the applicable journalistic rules and the balance between data protection, privacy and freedom of expression. Article 85 specifically requires Member States to reconcile data protection with journalistic, academic, artistic and literary expression. National law may therefore create exemptions or derogations from parts of the GDPR, potentially including aspects of Chapter VI where necessary. Important limit Article 85 does not create a general “media exemption” that automatically removes every journalistic activity from all data protection scrutiny. The exact result depends on:

  • the processing purpose;
  • the national implementing law;
  • necessity;
  • proportionality;
  • the particular GDPR provision involved.

7.2 Considering other areas of law

A supervisory authority often has to evaluate other laws to apply the GDPR correctly. This does not necessarily mean that it becomes the final regulator of tax, employment, telecommunications or media law.

Instead, those laws may form part of the GDPR analysis.

Tax-record illustration

A company wants to erase invoices containing customer names after six months. Tax legislation requires the records to be retained for a longer period.

The authority may need to consider the tax requirement when assessing:

  • whether retention is necessary;
  • whether Article 6(1)(c), legal obligation, applies;
  • whether storage complies with Article 5(1)(e);
  • whether the data should be restricted or archived instead of routinely used.

The authority interprets the GDPR in the legal context. It should not simply ignore binding retention legislation.

7.3 The ePrivacy overlap

Electronic communications may fall within both the GDPR and national rules implementing the ePrivacy Directive.

For example, a marketing cookie may raise two separate questions:

  1. Was storing or accessing information on the user’s device lawful under ePrivacy rules?
  2. Was the subsequent processing of personal data lawful under the GDPR?

The competent authorities and available powers may differ under national law. The existence of an ePrivacy issue does not necessarily eliminate the GDPR issue.

8. Only natural persons are directly protected

Article 51 refers to the rights and freedoms of natural persons.

It does not directly protect a company’s data merely because that data is commercially sensitive.

However, business records may contain personal data about natural persons.

Illustration

“Blue River Ltd earned €5 million” is information about a legal entity. “Maria Lopez, sole trader, earned €80,000” may identify a natural person. Similarly, a corporate email address such asjohn.smith@company.eu may be personal data because it identifies an employee, even though it appears in a business context. The authority must examine the substance of the information, not simply whether it is stored in a corporate file.

9. Facilitating the free flow of personal data

The second objective is sometimes misunderstood. Supervisory authorities are not commercial promotion agencies, nor are they required to help companies maximise data transfers.

They facilitate free movement indirectly by ensuring that the GDPR is applied consistently and that data receives reliable protection across the Union.

Illustration

A company in France uses a service provider in Belgium. If both states apply radically different standards to the same processing, cross-border operations become uncertain and expensive. Common GDPR standards reduce that uncertainty. Trust in equivalent protection makes lawful data movement easier.

9.1 Does free flow weaken individual rights?

It should not. Article 1(3) prevents Member States from restricting or prohibiting intra-Union data movement merely for reasons connected with personal-data protection when the GDPR’s harmonised framework governs the matter.

But “free flow” does not legalise unlawful processing. A controller cannot argue:

“Stopping our unlawful profiling would obstruct the internal market.”

The processing must first comply with the GDPR.

9.2 Whose interests must the authority balance?

The provided commentary suggests that supervisory authorities may have to account for the interests of data subjects and processors or controllers.

That proposition must be expressed carefully. The authority must act fairly and proportionately, but it is not required to treat fundamental rights and commercial convenience as automatically equal interests.

The proper approach is:

  1. identify the relevant rights and lawful interests;
  2. establish the applicable GDPR rule;
  3. consider necessity and proportionality where the rule requires it;
  4. choose an effective and proportionate response.

10. Article 51(2): Consistent application throughout the Union

Each supervisory authority must contribute to consistent GDPR application and cooperate with other authorities and the Commission under Chapter VII.

This is a positive duty. An authority cannot focus only on its territory and disregard the European consequences of its decisions.

10.1 “Contribute” requires active participation

The word “contribute” suggests more than avoiding contradiction. It requires active engagement, including:

  • exchanging relevant information;
  • responding to mutual-assistance requests;
  • participating in cross-border procedures;
  • engaging with the European Data Protection Board;
  • identifying divergent legal approaches;
  • using consistency procedures where required;
  • participating in joint operations where appropriate.

Illustration

A platform operates throughout the EU. Complaints arise in six Member States. The authorities should not conduct six disconnected investigations without communicating. Chapter VII provides mechanisms for identifying the lead supervisory authority, involving concerned authorities and working toward a coherent decision.

10.2 Consistency does not mean perfect uniformity in every case

Consistent application does not require identical sanctions in every superficially similar case.

Different outcomes may be justified by differences in:

  • scale;
  • duration;
  • sensitivity of data;
  • number of affected persons;
  • intent or negligence;
  • previous infringements;
  • mitigation;
  • cooperation;
  • national procedural circumstances.

Consistency means applying common legal principles coherently. It does not mean mechanical uniformity without regard to facts.

10.3 Cooperation and independence

The article requires cooperation with both other supervisory authorities and the European Commission. This produces a potential conceptual tension.

If the authority must be completely independent, how can it cooperate with the Commission, a political EU institution?

The answer lies in distinguishing cooperation from direction.

Permissible cooperation may include:

  • exchanging information;
  • participating in institutional procedures;
  • discussing legal consistency;
  • obtaining the Commission’s views where the GDPR permits.

Impermissible influence would arise if the Commission dictated the outcome of an individual enforcement case without a lawful basis.

The duty to cooperate does not convert the Commission into the authority’s political superior.

11. Article 51(3): Multiple authorities within one Member State

Where a Member State has several authorities, it must do two things:

  1. designate the authority that represents them in the European Data Protection Board; and
  2. establish a mechanism ensuring that the other authorities comply with the Article 63 consistency arrangements.

Recital 119 explains that the representative should function as a single contact point so cooperation with the Board, Commission and other authorities remains swift and effective.

11.1 The representative is not necessarily the superior authority

Designation for EDPB representation does not automatically make the representative authority hierarchically superior to every regional or sectoral authority.

Its role may be coordinative rather than managerial.

Illustration

A federal country has ten regional authorities. Regional Authority 4 is competent for a particular company. The designated federal representative communicates the national position to the EDPB. That does not necessarily allow the representative to take over Regional Authority 4’s investigation. The answer depends on the allocation of competence under national law and the GDPR.

11.2 What should the national coordination mechanism cover?

An effective mechanism should address matters such as:

  • internal consultation;
  • allocation of files;
  • information sharing;
  • preparation of national positions;
  • voting or representation in the EDPB;
  • urgent procedures;
  • disagreement resolution;
  • implementation of consistency decisions;
  • confidentiality and secure communication.

A state would not satisfy Article 51(3) merely by naming a representative while leaving the other authorities disconnected.

11.3 Territorial and sectoral authorities

Multiple-authority systems may be based on:

  • territory, such as federal or regional divisions;
  • sector, such as separate public-sector supervision;
  • constitutionally protected institutions;
  • specialised arrangements for religious bodies under Article 91;
  • particular media or broadcasting structures under national law.

Separate religious supervisory authorities are not automatically exempt from GDPR standards. Where Article 91 applies, they must satisfy the conditions established by that provision, including independence requirements.

12. Article 51(4): Notification to the European Commission

Member States had to notify the Commission, by 25 May 2018, of national legal provisions adopted under Chapter VI. They must also notify subsequent amendments without delay.

This is a state-level transparency and oversight obligation.

12.1 What must be notified?

The obligation concerns national rules governing matters such as:

  • establishment of supervisory authorities;
  • appointment and removal procedures;
  • qualifications of members;
  • terms of office;
  • organisational structure;
  • competence;
  • staffing and budget arrangements;
  • confidentiality;
  • multiple-authority coordination.

12.2 Why notification matters

Notification allows the Commission to examine whether national arrangements comply with the GDPR. If a Member State fails to meet EU-law requirements, the Commission may initiate infringement proceedings under Article 258 TFEU.

Historical litigation illustrates the seriousness of independence. The CJEU found problems with Austria’s structural arrangements, and in the Hungarian case it held that prematurely ending the data protection supervisor’s term violated EU-law independence requirements.

12.3 A nuance concerning “inapplicability”

The supplied text states that a violation may result in the national law’s inapplicability. This should not be treated as an automatic consequence of every failure to notify.

Possible consequences depend on:

  • the nature of the national provision;
  • whether the GDPR rule is sufficiently clear, precise and unconditional;
  • primacy of EU law;
  • the procedural setting;
  • whether conforming interpretation is possible;
  • the type of proceedings and parties involved;
  • the remedy sought.

Therefore, the safer conclusion is that defective national law may be challenged, disapplied where EU-law conditions require it, or addressed through infringement proceedings. Non-notification alone should not automatically be equated with universal invalidity.

13. The judicial-capacity exception: an important correction

The supplied commentary contains what appears to be a substantive wording error. It says:

“The SA’s competence does cover the processing of personal data where courts are acting in their judicial capacity.”

Article 55(3) GDPR states the opposite: supervisory authorities shall not be competent to supervise processing operations of courts acting in their judicial capacity.

This exclusion protects judicial independence.

Illustration

If a court processes names, evidence and medical records while deciding a lawsuit, the ordinary supervisory authority cannot supervise that processing in the same manner as it supervises a company. But the exclusion is limited to courts acting in their judicial capacity. It may not necessarily cover every administrative activity of a court, such as:

  • employee payroll;
  • building-access records;
  • staff recruitment;
  • ordinary procurement databases;
  • non-judicial website analytics. The difficult question is whether the particular processing is sufficiently connected to adjudication and judicial decision-making. The institution’s name is not conclusive. The function being performed matters.

14. Accountability and judicial review

Recital 118 confirms that supervisory authorities may be judicially reviewed.

This serves several purposes:

  • protects controllers and processors against unlawful regulatory action;
  • protects complainants against improper rejection or inactivity;
  • ensures consistent interpretation of EU law;
  • reinforces procedural fairness;
  • prevents independence from becoming impunity.

Illustration

An authority imposes a substantial fine but gives no reasons and refuses the company access to essential evidence. A court may review and potentially annul the decision. This does not improperly interfere with the authority’s independence. Judicial review is part of the rule of law.

15. Practical significance of Article 51

Article 51 creates four linked institutional guarantees:

  1. Availability: every Member State must have at least one supervisory authority.
  2. Independence: enforcement must be protected from political and commercial interference.
  3. European consistency: national regulators must cooperate within a common system.
  4. Transparency: Member States must notify the Commission of their institutional laws and amendments.

The article is consequently not a mere administrative provision. It is part of the machinery through which the fundamental right to data protection becomes enforceable.

16. Final synthesis

Article 51 establishes a decentralised but connected European enforcement model.

It is decentralised because Member States create and organise their own authorities and may establish more than one.

It is connected because those authorities must cooperate, participate in European procedures and contribute to consistent interpretation.

It is independent because data protection enforcement cannot depend upon the wishes of governments or regulated industries.

It is nevertheless accountable because independence remains compatible with financial auditing, statutory controls, reasoned decision-making and judicial review.

The most important practical lesson is that Article 51 must never be read alone. It provides the institutional foundation, but the real operation of the system depends on:

  • Article 52 for complete independence;
  • Articles 53 and 54 for membership and establishment rules;
  • Articles 55 and 56 for competence;
  • Articles 57 and 58 for tasks and powers;
  • Articles 60 to 62 for cooperation;
  • Articles 63 to 67 for consistency;
  • Articles 68 to 76 for the EDPB;
  • Articles 77 and 78 for complaints and judicial remedies;
  • Articles 85 and 91 for certain special processing contexts.

In simplest terms, Article 51 says:

Every Member State must create a genuinely independent public privacy regulator. That regulator must protect people, support lawful data movement, cooperate with other European regulators and remain accountable to law rather than political or commercial pressure.

That combination of independence, cooperation, consistency and accountability is the central logic of Article 51.