CHAPTER VIINDEPENDENT SUPERVISORY AUTHORITIES

Article 54Rules on the establishment of the supervisory authority

Official text

(1)Each Member State shall provide by law for all of the following:

(a)the establishment of each supervisory authority;

(b)the qualifications and eligibility conditions required to be appointed as member of each supervisory authority;

(c)the rules and procedures for the appointment of the member or members of each supervisory authority;

(d)the duration of the term of the member or members of each supervisory authority of no less than four years, except for the first appointment after 24 May 2016, part of which may take place for a shorter period where that is necessary to protect the independence of the supervisory authority by means of a staggered appointment procedure;

(e)whether and, if so, for how many terms the member or members of each supervisory authority is eligible for reappointment;

(f)the conditions governing the obligations of the member or members and staff of each supervisory authority, prohibitions on actions, occupations and benefits incompatible therewith during and after the term of office and rules governing the cessation of employment.

(2)The member or members and the staff of each supervisory authority shall, in accordance with Union or Member State law, be subject to a duty of professional secrecy both during and after their term of office, with regard to any confidential information which has come to their knowledge in the course of the performance of their tasks or exercise of their powers. During their term of office, that duty of professional secrecy shall in particular apply to reporting by natural persons of infringements of this Regulation.

Commentary

Article 54 GDPR turns the broad guarantees found in Articles 51 to 53 into concrete rules that must be written into national law. Its basic message is that the existence, leadership, continuity, integrity and confidentiality of a supervisory authority cannot depend on informal arrangements or changing political preferences.

The Article has two distinct parts. Paragraph 1 tells Member States what institutional matters they must regulate by law. Paragraph 2 imposes professional-secrecy obligations on the authority’s members and staff. Together, these rules support institutional independence while ensuring that supervisory authorities can be trusted with highly sensitive information.

1. Why Article 54 is necessary

The GDPR is a regulation and is therefore directly applicable across the European Union. Nevertheless, it cannot itself create and organise every national supervisory authority in complete detail. Member States have different constitutional structures, public-service systems, appointment procedures and administrative traditions.

Article 54 therefore leaves the organisational details to national law, but it does not give Member States unlimited freedom. National legislation must address every matter listed in Article 54(1), and those national rules must remain compatible with the GDPR’s requirements of independence, competence, transparency and effectiveness. Article 54 forms part of Chapter VI of the GDPR and must be read with Articles 51, 52 and 53.europa+1

A useful way to understand the relationship is:

  • Article 51 says that a supervisory authority must exist.
  • Article 52 says that it must be completely independent.
  • Article 53 establishes minimum conditions concerning its members.
  • Article 54 requires those institutional arrangements to be placed in binding national law.

Simple illustration

Suppose a government announces in a press release: “We have created a Data Protection Commission. The Prime Minister will decide who leads it, how long the leader serves and when the leader may be replaced.” That is not enough. Article 54 requires the central institutional rules to be contained in law. They must not depend merely on political announcements, administrative custom or private arrangements.

2. The significance of the words “provide by law”

Article 54(1) begins by requiring each Member State to provide by law for all the listed matters.

This wording performs several functions.

First, it promotes legal certainty. Members, staff, regulated organisations and the public should be able to determine from legally accessible rules:

  • what the authority is;
  • who may lead it;
  • how members are appointed;
  • how long they serve;
  • whether they may be reappointed;
  • what conduct is prohibited;
  • how their service ends.

Second, legislation is usually more stable and publicly scrutinised than informal executive arrangements. A minister should not be able to change the commissioner’s term, eligibility conditions or conflict rules through a private instruction.

Third, legislation makes judicial review possible. If the government acts outside the statutory framework, the affected person can challenge that action.

“By law” does not necessarily mean that every administrative detail must appear in a single Act of Parliament. Depending on the national legal system, some details may be addressed in valid secondary legislation. However, the essential features affecting independence should be legally prescribed, clear, foreseeable and protected against arbitrary executive alteration.

Illustration

National legislation could establish:

  • the authority’s legal personality;
  • a six-year term for members;
  • the appointing body;
  • dismissal grounds;
  • conflict-of-interest restrictions. Detailed matters such as the format of an application form might be left to administrative regulations. But the government should not be free to change the term from six years to six months through an internal circular.

3. Article 54(1)(a): Establishment of each supervisory authority

National law must formally establish each supervisory authority.

This requirement is particularly important where a Member State has more than one authority. Recital 117 permits multiple authorities to reflect constitutional, organisational and administrative structures. The law should therefore identify every authority and clarify its place within the national system.europa+1

“Establishment” should not be understood as simply giving the authority a name. A meaningful establishing law should normally address matters such as:

  • its legal status;
  • its institutional form;
  • its territorial or sectoral jurisdiction;
  • whether it is a single-member or collegiate body;
  • its relationship with other public institutions;
  • any functions additional to GDPR supervision;
  • continuity of its official acts;
  • coordination with other national supervisory authorities.

Illustration: one national authority

Country A establishes a single national Data Protection Commission responsible for private and public-sector processing throughout the country. Its founding law identifies the Commission, gives it legal status and links its functions to the GDPR.

Illustration: multiple authorities

Country B is a federal state. It creates:

  • one federal authority;
  • several regional authorities;
  • a designated authority representing the country in the EDPB. The national legal framework must clearly establish each authority and organise how their responsibilities fit together.

3.1 Territorial and sectoral division

A Member State may distribute responsibilities territorially or according to sector. For example, it might create different arrangements for federal and regional public bodies.

However, dividing jurisdiction must not produce regulatory gaps.

Illustration

National law says:

  • Authority X supervises private businesses.
  • Authority Y supervises central government.
  • Regional authorities supervise regional government. The law must still explain who supervises entities that perform mixed public-private functions, national companies operating across regions and processing involving several sectors. The authority’s establishment cannot be so vague that a complainant is repeatedly told that every authority lacks jurisdiction.

3.2 Additional functions

A supervisory authority may receive responsibilities beyond GDPR enforcement, such as supervision of freedom-of-information legislation. This is not automatically unlawful.

The additional functions must not:

  • conflict with GDPR duties;
  • create incompatible institutional interests;
  • absorb resources needed for data protection;
  • place the authority under external direction;
  • compromise confidentiality or independence.

Illustration

An authority supervises both privacy and freedom of information. A person asks for access to official documents containing personal data. The same authority may need to balance transparency and privacy. That combination may provide useful expertise, but national law should create clear procedures for managing the two mandates fairly.

4. Article 54(1)(b): Qualifications and eligibility conditions

National law must establish the qualifications and eligibility conditions for appointment as a member.

Article 53(2) already states that each member must have the qualifications, experience and skills required for the role, particularly in personal-data protection. Article 54(1)(b) requires the Member State to translate that general standard into national legal criteria.

Qualifications concern professional competence. They may involve:

  • education;
  • legal knowledge;
  • experience in data protection;
  • regulatory experience;
  • technological understanding;
  • management capabilities.

Eligibility conditions concern whether the person may legally hold the office. They may include:

  • absence of disqualifying conflicts;
  • legal capacity;
  • integrity requirements;
  • compliance with rules governing public office;
  • absence of an incompatible position;
  • any national citizenship or residency condition that is lawful and proportionate.

Illustration

A candidate may be professionally qualified because she is an experienced privacy lawyer. However, she may be temporarily ineligible if she remains a director of a major company that is being investigated by the authority. Another candidate may be free of conflicts but lack the qualifications necessary to direct complex investigations. Absence of a conflict does not prove competence.

4.2 Criteria must not be manipulated

National law must not use eligibility conditions as a disguised mechanism for political exclusion.

Problematic examples

A law may be questionable if it says:

  • only current government officials may be appointed;
  • the member must retain the confidence of the Prime Minister;
  • the government may decide whether a candidate has “appropriate views”;
  • eligibility can be withdrawn whenever the member criticises national policy.

Such conditions may undermine Articles 52 and 53 because they create political dependence.

Criteria should be objective, relevant and foreseeable. They should ensure competence and integrity rather than ideological loyalty.

4.3 Collective expertise is not a substitute for individual fitness

Where an authority has several members, their backgrounds may complement one another. One member may be a lawyer, another a cybersecurity specialist and another an experienced public administrator.

However, Article 53 speaks of each member possessing the required competence. National law should not allow a completely unqualified person to be appointed merely because other board members are experts.

5. Article 54(1)(c): Appointment rules and procedures

Member States must legislate the rules and procedures governing appointment.

This complements Article 53(1), which requires the appointment procedure to be transparent and permits appointment by parliament, government, head of State or an independent body.

The law should clarify:

  • who may nominate candidates;
  • who evaluates them;
  • who makes the final appointment;
  • what documents must be provided;
  • how competence and conflicts are assessed;
  • whether hearings are held;
  • what majority or voting procedure applies;
  • how the appointment is formally published;
  • what occurs if the process fails or is delayed.

5.1 Why procedural detail matters

A law stating only that “the government appoints the commissioner” may satisfy the identity of the appointing body but leave the process insufficiently protected.

A robust framework might require:

  1. publication of the vacancy;
  2. disclosure of eligibility criteria;
  3. assessment by an expert panel;
  4. interviews or hearings;
  5. conflict-of-interest declarations;
  6. publication of the final appointment.

Not every Member State must use precisely these steps. The essential point is that the procedure must be understandable, legally regulated and consistent with Article 53’s transparency requirement.

5.2 Acting appointments

National law should address temporary vacancies. Otherwise, a government might keep an “acting” commissioner in office indefinitely and use the insecurity of that position to influence decisions.

Illustration

The permanent commissioner’s term expires. The deputy automatically becomes acting commissioner for a maximum of six months while a transparent appointment proceeds. That can preserve continuity. By contrast, a politically appointed acting commissioner serves for four years without undergoing the statutory appointment procedure. That may circumvent Articles 53 and 54.

6. Article 54(1)(d): Minimum four-year term

The law must prescribe a term of not less than four years.

A four-year term is a minimum, not an ideal or maximum. Member States may provide longer terms, such as five, six or seven years.

The requirement supports independence by preventing extremely short appointments. A commissioner serving for only a few months would be continuously dependent on the appointing body.

Illustration

A one-year renewable term creates a powerful incentive to please whoever controls renewal. A six-year term provides greater security because the member can make difficult decisions without facing immediate reappointment.

6.1 Can a member serve until retirement?

The supplied Commentary suggests that lifetime service or service until retirement should be excluded because Article 54(1)(e) discusses reappointment.

That conclusion is arguable but should not be treated as certain. Article 54 clearly requires a “duration of the term” of at least four years, which strongly suggests a defined term. A system of service until a predetermined retirement age may raise questions about whether a fixed duration truly exists.

The safer interpretation is that national law should specify a clear and foreseeable period or endpoint. It must not create indefinite service controlled by political discretion.

6.2 The transitional exception after 24 May 2016

Article 54 permits part of the first group appointed after 24 May 2016 to receive shorter terms where necessary to create staggered appointments and protect independence.

This was a transitional device, not a permanent permission to appoint members for fewer than four years.

Illustration

A new five-member authority is established. If every member receives a four-year term beginning on the same date, all positions expire at once. A new government could then replace the whole leadership simultaneously. To avoid that risk, the first appointments might be staggered:

  • Member A: two years;
  • Member B: three years;
  • Members C, D and E: four years. Future appointments would comply with the ordinary minimum. The shorter initial terms are justified by institutional continuity, not convenience.

6.3 Why staggering protects independence

Staggering prevents complete leadership replacement after a single election. It preserves:

  • institutional memory;
  • continuity of investigations;
  • diversity of appointment cycles;
  • stability of enforcement policy.

The exception must be used because it is necessary to protect independence. It should not be used to shorten the term of a politically inconvenient member.

7. Article 54(1)(e): Reappointment

National law must state:

  • whether reappointment is permitted; and
  • if permitted, for how many terms.

The GDPR does not impose one universal model. A Member State may choose:

  • one non-renewable term;
  • one possible reappointment;
  • several reappointments;
  • another clearly regulated system.

7.1 The independence problem created by renewal

Reappointment has advantages. An experienced member understands the authority, ongoing investigations and European cooperation.

But reappointment also produces a risk of anticipatory obedience.

Illustration

A commissioner’s term expires next year. The government will decide whether to renew it. The authority is investigating a politically important state-owned company. Even without an express instruction, the commissioner may soften the investigation to improve the prospect of reappointment. A long, non-renewable term reduces this particular pressure. A renewable term may still be lawful, but the reappointment rules should minimise political dependence.

7.2 Indefinite reappointment

The wording of Article 54 does not expressly prohibit repeated reappointment. Nevertheless, unlimited renewals may amplify dependence on the appointing body.

Safeguards could include:

  • a maximum of two terms;
  • an independent reappointment assessment;
  • objective criteria;
  • transparent procedures;
  • a longer initial term;
  • a prohibition on changing the rules during the member’s mandate.

Reappointment should not be treated as a reward for favourable regulatory outcomes.

8. Article 54(1)(f): Obligations, incompatibilities, benefits and cessation

Paragraph 1(f) requires national law to regulate a broad group of employment and integrity matters for both members and staff.

It covers:

  1. obligations applying to service;
  2. prohibited actions;
  3. incompatible occupations;
  4. incompatible benefits;
  5. restrictions during and after office;
  6. cessation of employment.

This provision is essential because independence can be compromised by private interests just as easily as by government instructions.

8.1 Obligations

National law may impose obligations concerning:

  • integrity;
  • impartiality;
  • disclosure of interests;
  • recusal;
  • confidentiality;
  • proper use of public resources;
  • avoidance of external instructions;
  • cooperation with internal ethics procedures;
  • protection of evidence;
  • reporting of attempted interference.

Illustration

A commissioner’s spouse holds a senior role in a company under investigation. The law may require disclosure and recusal. The purpose is not to accuse the commissioner of wrongdoing. It is to prevent an actual or perceived conflict from compromising confidence in the investigation.

8.2 Incompatible actions

An incompatible action may be a one-time act rather than an ongoing occupation.

Examples

include:

  • accepting confidential assistance from a party to a case;
  • disclosing investigative strategy;
  • intervening in a case involving a personal interest;
  • privately promising a favourable decision;
  • accepting an expensive trip from a regulated company;
  • using non-public information for personal investment. National law should not simply repeat that incompatible conduct is prohibited without providing usable standards and procedures.

8.3 Incompatible occupations

An occupation may be paid or unpaid. The important issue is whether it creates conflicting obligations or dependence.

Likely examples include:

  • serving as director of a regulated company;
  • advising organisations under investigation;
  • lobbying the authority on behalf of industry;
  • representing clients in cases before the authority;
  • holding a political executive role that conflicts with independent regulation.

Teaching or writing may be compatible if it does not interfere with duties, misuse confidential information or create substantial conflicts.

Illustration

A member teaches one university seminar on public law. That is not automatically incompatible. A member simultaneously operates a consultancy advising technology companies on how to resist the authority’s investigations. That is fundamentally different.

8.4 Incompatible benefits

The express reference to benefits is wider than salary.

A benefit may include:

  • gifts;
  • hospitality;
  • travel;
  • loans;
  • discounts;
  • promises of future employment;
  • honorary positions;
  • benefits given to family members;
  • political or professional advancement.

Illustration

A platform offers the commissioner free luxury travel to a conference and privately suggests a board position after retirement. Even if no cash changes hands, these benefits may create actual or perceived influence. National law should address disclosure thresholds, prohibited gifts, return procedures and sanctions.

9. Post-office restrictions and the revolving-door problem

Article 54(1)(f) expressly refers to restrictions during and after the term of office. This means Member States cannot focus only on misconduct while a person is serving.

The revolving-door problem arises when a regulator moves directly into employment with an organisation that the regulator recently supervised.

Illustration

A commissioner leads a major investigation into an advertising platform. One week after leaving office, the commissioner becomes the platform’s head of regulatory strategy. This creates several concerns:

  • confidential knowledge may benefit the company;
  • former colleagues may be lobbied;
  • the commissioner’s earlier decisions may appear influenced by future employment prospects;
  • public confidence in the authority may be damaged. A cooling-off period may therefore be appropriate. However, the GDPR does not prescribe a universal 18-month or 24-month minimum. Any claim that such a period is legally mandatory would go beyond the text. National restrictions should be proportionate. A blanket lifetime prohibition on all privacy-related work could unjustifiably prevent a former member from earning a living. A more balanced system might restrict:
  • employment with entities personally supervised;
  • representation before the authority;
  • use of confidential information;
  • lobbying former colleagues;
  • involvement in specific matters handled during office.

10. Cessation of employment

National law must regulate how the service or employment relationship ends.

For members, these rules must remain consistent with Article 53:

  • expiry of term;
  • resignation;
  • compulsory retirement;
  • dismissal only for serious misconduct or loss of required conditions.

Employment-law language cannot be used to bypass protected tenure.

Illustration

The commissioner is formally described as an employee. The government argues that ordinary employment rules allow termination on three months’ notice without cause. That would undermine Article 53. The label “employee” cannot remove the GDPR’s protection against arbitrary dismissal. For ordinary staff, national law may permit resignation, retirement, redundancy, disciplinary dismissal and other public-service rules. Nevertheless, staff arrangements must not enable an outside ministry to control investigations or remove employees for following the authority’s lawful directions.

11. Article 54(2): Professional secrecy

Paragraph 2 imposes a duty of professional secrecy on both members and staff concerning confidential information obtained through their official functions.

The duty applies:

  • during office or employment;
  • after office or employment;
  • to information learned while performing tasks or exercising powers;
  • particularly to reports of infringements made by natural persons.

Professional secrecy is indispensable because supervisory authorities receive highly sensitive material, including:

  • personal data;
  • health and biometric information;
  • security vulnerabilities;
  • internal corporate documents;
  • trade secrets;
  • legal arguments;
  • details of investigations;
  • identities of complainants;
  • information supplied by whistleblowers.

Without protection, individuals and organisations might be reluctant to cooperate with investigations.

12. Professional secrecy is not an absolute ban on communication

The supplied Commentary describes paragraph 2 as prohibiting disclosure to third parties or the public without prior authorisation. That is too broad if understood literally.

Article 54(2) applies only to confidential information, and disclosure may be lawful where authorised or required by Union or national law.

Examples

may include:

  • sharing information with another supervisory authority under Chapter VII;
  • providing evidence to a competent court;
  • communicating allegations to the investigated party where required by rights of defence;
  • publishing a properly redacted decision;
  • reporting suspected crime to competent authorities;
  • responding to lawful access-to-documents obligations;
  • disclosing information with valid legal authorisation. The correct distinction is between unauthorised disclosure and lawful institutional use.

Illustration

An investigator sends confidential evidence to a concerned supervisory authority through the GDPR cooperation mechanism. That is not an improper public leak. The same investigator sends the evidence to a journalist for personal or political reasons. That is likely a breach of professional secrecy.

13. What is “confidential information”?

Article 54 does not define the term exhaustively.

Information may be confidential because of:

  • its personal nature;
  • commercial sensitivity;
  • investigative sensitivity;
  • legal privilege;
  • national law;
  • security implications;
  • assurances under which it was provided;
  • the risk of harm from disclosure.

The General Court’s Bank Austria Creditanstalt judgment concerned competition proceedings rather than Article 54 GDPR, so its approach is analogous rather than an automatic GDPR definition. That case examined professional secrecy and publication of Commission decisions, including protection of business secrets and other confidential material.europa+1

A commonly used confidentiality analysis asks whether:

  1. the information is known only to a limited number of persons;
  2. disclosure is capable of causing serious harm;
  3. the interest threatened by disclosure is objectively worthy of protection.

This is useful guidance, but Article 54’s context is broader than business secrecy. Information identifying a vulnerable complainant may merit protection even where the harm is not purely commercial.

13.1 Old information

Confidentiality may weaken over time.

A business plan that was commercially sensitive ten years ago may now be publicly known or obsolete. Conversely, a person’s medical information may remain highly sensitive indefinitely.

Therefore, post-office secrecy does not necessarily mean every document remains confidential forever. The obligation lasts as long as the information retains its confidential character or applicable law continues to protect it.

14. Information obtained “in the course” of official work

The duty covers confidential information that comes to a member or staff member through performance of official tasks or exercise of powers.

This includes information received through:

  • complaints;
  • audits;
  • inspections;
  • compulsory information requests;
  • breach notifications;
  • consultations;
  • cross-border cooperation;
  • litigation;
  • internal authority discussions.

Illustration

An investigator learns of a company’s unannounced security vulnerability during an audit. The information is covered. If the same investigator reads a publicly available newspaper report about the company, Article 54 professional secrecy does not make the public article confidential merely because the investigator works for the authority. The source and context of the knowledge matter.

15. Special protection for reports by natural persons

Article 54(2) particularly highlights reports of GDPR infringements made by natural persons.

This includes, depending on the facts:

  • formal complainants;
  • employees reporting unlawful practices;
  • consumers alerting the authority;
  • individuals providing confidential tips;
  • persons reporting misuse of their own data.

The wording reflects the risk of retaliation, intimidation or exposure.

Illustration

An employee reports that a hospital is selling patient information. If the employee’s identity is unnecessarily disclosed to hospital management, the employee may face dismissal or harassment. The authority should protect the identity and the substance of the report as far as legally possible.

15.1 Confidentiality cannot always mean absolute anonymity

An authority may not always be able to keep a complainant’s identity hidden throughout proceedings.

For example:

  • the facts may reveal the complainant’s identity;
  • the investigated party may require sufficient particulars to defend itself;
  • a court may order disclosure;
  • the complainant’s individual claim may be impossible to resolve without identification.

The authority must balance:

  • confidentiality;
  • effective investigation;
  • whistleblower protection;
  • procedural fairness;
  • rights of defence.

It should disclose no more than is necessary and should warn the complainant where identity may need to be revealed.

16. Members and staff after leaving office

The secrecy duty continues after service ends. This prevents former personnel from monetising or publicising information acquired through public office.

Illustration

A former investigator writes a book describing confidential medical records obtained during an unresolved investigation. The fact that the investigator has left the authority does not remove the duty. The continuing duty may also restrict:

  • consulting work based on non-public enforcement information;
  • disclosure to future employers;
  • use of confidential knowledge in litigation;
  • public statements revealing protected case details. However, it should not prevent a former official from using general experience and publicly available knowledge. A former member may say: “Large investigations require strong forensic capacity.” The former member should not reveal:

“Company X’s unreleased system contains the following exploitable vulnerability.”

17. Confidentiality versus transparency

Professional secrecy cannot be used as a blanket excuse for institutional secrecy.

Supervisory authorities are publicly accountable. They may publish:

  • annual reports;
  • enforcement statistics;
  • guidance;
  • final decisions;
  • general descriptions of investigations;
  • financial information;
  • institutional policies.

The challenge is to make the authority’s work visible without exposing protected information.

Illustration

An authority publishes a decision finding that a hospital violated security requirements. It may need to redact:

  • patient names;
  • confidential security details;
  • whistleblower identities;
  • unrelated personal data. But it should not automatically hide the entire decision merely because some portions are confidential. The authority should assess information item by item. Redaction, anonymisation or delayed publication may reconcile transparency and secrecy. The CJEU has recognised in other regulatory contexts that professional secrecy can protect the functioning of supervision, but competing interests such as rights of defence may require careful balancing rather than automatic nondisclosure.europa+1

18. Access to documents and rights of defence

A person affected by an enforcement decision may need access to evidence used against them. Professional secrecy cannot automatically eliminate that right.

The authority may need to balance:

  • the investigated party’s right to understand and answer allegations;
  • the complainant’s privacy;
  • trade secrets;
  • security information;
  • confidentiality of internal deliberations;
  • protection of ongoing investigations.

Possible solutions include:

  • redacted disclosure;
  • confidentiality rings;
  • summaries of sensitive evidence;
  • restricted access by legal advisers;
  • protective court orders;
  • withholding irrelevant confidential material.

The principle is that secrecy should protect legitimate interests, not conceal the basis of coercive state action.

19. Cooperation between supervisory authorities

The Commentary states that professional secrecy does not extend to cooperation under Articles 60, 61, 64 and 65. That wording is misleading.

Confidential information does not lose its protected quality merely because it is shared through cooperation. Rather, Article 54 does not prevent legally authorised sharing between competent authorities.

Illustration

Authority A sends confidential evidence to Authority B in a cross-border case. The transmission is lawful if made under the GDPR cooperation framework. But Authority B must still protect the information. It cannot publish the complete file simply because it received it from another authority. The better conclusion is: Professional secrecy permits necessary authorised institutional sharing, while continuing to protect the information against unauthorised disclosure.

20. Article 339 TFEU and national supervisory authorities

The supplied Commentary says that Article 54’s professional-secrecy obligation “finds its footing” in Article 339 TFEU. That should be treated cautiously.

Article 339 TFEU expressly concerns members of EU institutions, committees, officials and other EU servants. National supervisory-authority personnel are not automatically EU officials merely because they apply the GDPR.

Article 339 and EU regulatory case law may provide useful interpretive context, but Article 54(2) itself is the direct GDPR basis for the secrecy duty of national supervisory-authority members and staff.

Similarly, Article 41 and Article 42 of the Charter and Regulation 1049/2001 primarily concern EU institutions. National access-to-documents questions commonly depend on national law, the GDPR, the Charter where EU law is being implemented and general EU-law principles.

21. Does professional secrecy bind complainants and parties?

Article 54(2), by its wording, directly binds members and staff of the supervisory authority. It does not automatically impose the same professional-secrecy duty on every complainant, controller, processor, witness or lawyer.

However, those persons may be subject to other restrictions arising from:

  • national confidentiality law;
  • court orders;
  • employment obligations;
  • professional ethics;
  • trade-secret law;
  • data protection law;
  • contractual obligations;
  • procedural directions.

Therefore, it would be unsafe to say that parties are always free to disclose everything received from the authority.

Illustration

A complainant receives a redacted public decision. The complainant may generally discuss it, subject to other laws. A company’s lawyer receives confidential documents under a court-ordered confidentiality arrangement. Article 54 may not directly bind the lawyer, but the court order and professional duties do.

22. Practical test for Article 54 compliance

A Member State’s legal framework should answer the following questions clearly.

Institutional establishment

  • Is every supervisory authority formally created by law?
  • Are its legal status and jurisdiction clear?
  • Are gaps and overlaps between multiple authorities addressed?

Membership

  • Are competence and eligibility requirements objective?
  • Is the appointment process legally regulated and transparent?
  • Is the term at least four years?
  • Are renewal rules known in advance?

Integrity

  • Are conflicts, gifts and outside activities regulated?
  • Are post-office risks addressed proportionately?
  • Can members and staff be removed only through lawful procedures?

Confidentiality

  • What information is confidential?
  • Who may access it?
  • When may it lawfully be shared?
  • How are complainants and whistleblowers protected?
  • How are transparency and rights of defence preserved?
  • Do secrecy duties continue after departure?

Article 54 compliance depends on the complete system, not merely whether the national statute copies the Article word for word.

Conclusion

Article 54 is the legal blueprint for constructing a credible supervisory authority. Paragraph 1 requires Member States to place the authority’s institutional foundations in law. The law must establish the body, define member qualifications, regulate appointments, guarantee a term of at least four years, clarify reappointment and create integrity, conflict and cessation rules. Paragraph 2 ensures that the authority can safely receive and investigate sensitive information. Members and staff must protect confidential information during and after service, with particular care for natural persons reporting GDPR infringements. The Article rests on two complementary ideas: The authority must be visible and accountable in its institutional design, but careful and confidential in its investigative work. Too little institutional transparency creates political manipulation. Too little operational confidentiality exposes complainants, personal data, trade secrets and investigations. Conversely, excessive secrecy can conceal poor performance and deny procedural fairness. Article 54 therefore requires balance. National law must be sufficiently detailed to prevent arbitrary control, while professional secrecy must be sufficiently strong to preserve trust without becoming a blanket justification for opacity.