CHAPTER VIINDEPENDENT SUPERVISORY AUTHORITIES

Article 55Competence

Official text

(1)Each supervisory authority shall be competent for the performance of the tasks assigned to and the exercise of the powers conferred on it in accordance with this Regulation on the territory of its own Member State.

(2)Where processing is carried out by public authorities or private bodies acting on the basis of point (c) or (e) of Article 6 (1), the supervisory authority of the Member State concerned shall be competent. In such cases Article 56 does not apply.

(3)Supervisory authorities shall not be competent to supervise processing operations of courts acting in their judicial capacity.

Commentary

Article 55 answers a foundational enforcement question: which supervisory authority is legally entitled to deal with a particular processing operation? Its three paragraphs establish the general territorial rule, a special rule for public-authority and public-interest processing, and an exclusion protecting courts when they act judicially.

The Article is best understood as a rule about regulatory competence, not merely geography. It determines which authority may receive complaints, investigate facts, demand information, make findings, issue orders and impose sanctions. It must be read together with Articles 3, 4(23), 51, 56, 60 to 62 and 77 GDPR. The official text and recitals show that Article 55 creates the ordinary national competence rule, while Article 56 reallocates responsibility in qualifying cross-border cases.europa+1

1. What “competence” means

In ordinary language, “competence” can mean ability or expertise. In Article 55, it means legal authority or jurisdiction.

A supervisory authority may be competent to:

  • receive and examine a complaint;
  • investigate a controller or processor;
  • order production of information;
  • carry out an audit;
  • issue warnings or reprimands;
  • order compliance;
  • restrict or prohibit processing;
  • impose an administrative fine;
  • participate in cross-border cooperation;
  • give advice or promote public awareness.

However, four different questions must be kept separate:

  1. Does the GDPR apply to the processing?

This is principally an Article 2 and Article 3 question.

  1. Which supervisory authority is competent?

This is principally an Articles 55 and 56 question.

  1. Which authority takes the lead in a cross-border case?

This is an Article 56 and Article 60 question.

  1. Which substantive national law applies?

This may depend on the particular national GDPR provision and relevant conflict-of-laws considerations.

These issues influence one another, but they are not interchangeable.

Illustration

A Canadian company targets customers in France, Germany and Italy. Article 3(2) may bring the relevant processing within the GDPR. That does not automatically identify one lead supervisory authority. Since the company has no EU establishment, it may not benefit from the ordinary one-stop-shop arrangement based on a “main establishment.” Each territorially connected authority may have competence within the GDPR framework. Thus: GDPR applicability tells us whether EU data protection rules reach the processing. Competence tells us which regulator may act.

2. Structure of Article 55

Article 55 contains three rules:

Paragraph 1: General territorial competence

Every supervisory authority is competent to perform its GDPR tasks and exercise its GDPR powers on the territory of its Member State.

Paragraph 2: Public authorities and processing under Article 6(1)(c) or (e)

The supervisory authority of the Member State concerned remains competent, and the lead-authority mechanism under Article 56 does not apply.

Paragraph 3: Courts acting judicially

The ordinary supervisory authority cannot supervise processing operations of courts acting in their judicial capacity.

The first rule is general. The next two modify it for particular institutional situations.

3. Article 55(1): General territorial competence

Article 55(1) provides that each supervisory authority is competent:

for the performance of the tasks assigned to it and the exercise of the powers conferred on it under the GDPR, on the territory of its own Member State.

The authority’s tasks appear primarily in Article 57. Its powers appear primarily in Article 58.

Article 55 does not itself create every task and power. Rather, it identifies the territorial space within which those tasks and powers belong to a particular authority.

3.1 Why competence is territorial

A supervisory authority is a national public authority. Public enforcement powers are ordinarily exercised within the territory of the state that legally created the authority.

This reflects state sovereignty. A French authority may inspect premises in France in accordance with applicable procedural law. It cannot independently enter premises in Spain and conduct a compulsory search as if it were a Spanish public body.

Illustration

A controller has offices in Paris and Madrid. The French supervisory authority may use its national investigative powers at the Paris office. If evidence must be physically obtained from the Madrid office, it normally needs cooperation from the Spanish authority under Articles 61 or 62. This does not mean that GDPR enforcement stops at national borders. It means that cross-border enforcement is organised through legal cooperation rather than unilateral action by one national authority on another state’s territory.

4. Territory does not mean the location of the server

A common mistake is to identify competence solely by asking where the data is stored.

The location of a server may be relevant to an investigation, but it is not the only or necessarily decisive connecting factor. Recital 122 identifies several territorial links, including:

  • processing in the context of activities of an establishment in the Member State;
  • processing by public authorities or private bodies acting in the public interest;
  • processing affecting people on the territory;
  • targeting residents by a controller or processor not established in the Union.

The broad approach reflects modern digital processing, where the controller, operational team, customers, affected individuals and servers may all be in different countries.europa+1

Illustration

A Polish company makes decisions about customer profiling in Warsaw. Its cloud server is in Finland, its processor is in Ireland, and its customers are mainly in Poland. Finland does not automatically become the central regulatory jurisdiction merely because the server is physically located there. The processing must be analysed in relation to establishments, decision-making, effects and the cross-border rules.

5. The connection with Article 3 GDPR

Article 3 determines the GDPR’s territorial scope through two main routes:

  1. processing in the context of an EU establishment; and
  2. certain targeting or monitoring by an organisation outside the EU.

The EDPB’s territorial-scope guidance confirms that Article 3 uses an “establishment” criterion and a “targeting” criterion. It also distinguishes the GDPR’s territorial scope from the older Directive’s function of determining national applicable law.europa+1

Article 55 then helps identify the competent national supervisory authority.

A useful sequence

A regulator should normally ask:

  1. Does the activity involve personal-data processing?
  2. Does the GDPR apply territorially?
  3. What connection exists with the authority’s Member State?
  4. Is the processing cross-border under Article 4(23)?
  5. Does Article 56 designate a lead authority?
  6. Does Article 55(2) exclude Article 56?
  7. Does Article 55(3) remove ordinary supervisory competence because a court is acting judicially?

6. Competence based on an establishment

An “establishment” does not necessarily require incorporation, a subsidiary or a formally registered branch. EU case law interprets establishment functionally. Real and effective activity through stable arrangements may be enough, even if the activity is relatively limited.

In Weltimmo, the CJEU considered whether a company registered in Slovakia had a sufficient Hungarian establishment in connection with a property website directed at Hungary. The Court held that real and effective activity through stable arrangements, even minimal activity, could support application of the relevant Member State’s data protection framework under the former Directive.europa+1

Illustration

A company is incorporated in Country A, but it:

  • operates a website dedicated to properties in Country B;
  • uses Country B’s language;
  • has a representative in Country B;
  • pursues local debts there;
  • conducts sustained local commercial activity. The absence of a formally incorporated subsidiary in Country B does not necessarily prevent the existence of an establishment there.

6.1 Mere website accessibility is insufficient

At the other extreme, the fact that a website can be opened from a Member State does not by itself create an establishment there.

Illustration

A small Japanese shop has a general website in Japanese. A person in Belgium happens to visit it. That fact alone does not show that the shop has a Belgian establishment or intentionally targets the Belgian market. Relevant indicators of targeting may include delivery to EU countries, EU-focused advertising, local currencies, local-language marketing, references to EU customers and country-specific domain names. No single factor is necessarily decisive.europa+1

7. The lesson from Weltimmo

Weltimmo was decided under Directive 95/46 rather than the GDPR, so it must not be treated as though it directly interpreted the present one-stop-shop system. Nevertheless, its reasoning remains helpful for understanding:

  • the broad concept of establishment;
  • the distinction between investigating a matter and exercising coercive powers abroad;
  • the territorial character of national enforcement powers;
  • the need for cooperation between national authorities.

The CJEU held that an authority could investigate a complaint involving a company registered in another Member State, but its effective powers of intervention could be exercised only within its own territory where another Member State’s law and authority were competent.europa+1

Important qualification

The supplied Commentary suggests that a supervisory authority’s decision can never be enforced in another Member State. That is too absolute.

A national authority cannot simply exercise public power inside another state as if no border existed. However, the GDPR’s cooperation and consistency mechanisms are specifically designed to give cross-border decisions coordinated effect. A lead authority may adopt a decision through Article 60, while concerned authorities participate and take steps required in their respective territories.

The better statement is:

A supervisory authority cannot unilaterally exercise coercive state powers on the territory of another Member State, but GDPR procedures may produce cross-border regulatory consequences through cooperation and coordinated enforcement.

8. Purely national cases

The simplest Article 55 case involves:

  • one controller;
  • one establishment;
  • one Member State;
  • people affected in that state;
  • no substantial cross-border element.

Illustration

A local Polish medical clinic processes Polish patients’ records entirely through its Polish operations. A patient complains to the Polish supervisory authority. The Polish authority is competent to handle the complaint, investigate the clinic and use Article 58 powers according to the GDPR and applicable Polish procedural law. The complainant’s nationality is not normally decisive. Residence, the location of processing activities and effects, and the controller’s establishment are often more relevant.

Illustration

A Hungarian citizen lives in Poland and complains about a Polish employer’s processing of employee records. The fact that the employee is Hungarian does not shift the case automatically to the Hungarian authority. The processing is connected to the Polish establishment and Polish employment relationship.

9. Cross-border processing and Article 56

Article 55 gives the starting point, but Article 56 may reallocate primary responsibility when there is cross-border processing.

Article 4(23) defines cross-border processing in two broad situations:

  1. processing occurs in the context of activities of establishments in more than one Member State; or
  2. processing occurs in one establishment but substantially affects, or is likely substantially to affect, people in more than one Member State.

The phrase is “likely to substantially affect,” not “sustainably affect.”

Illustration

A social-media company has establishments in Ireland, France and Germany. Its central Irish establishment determines the purposes and essential means of a Europe-wide profiling system. Several authorities may be “concerned supervisory authorities,” but Article 56 may make the Irish authority the lead supervisory authority. The lead authority does not act entirely alone. Article 60 requires cooperation with the concerned authorities.

9.1 Article 55 competence is not erased by the lead authority

The one-stop shop does not mean that every non-lead authority becomes irrelevant.

A concerned authority may:

  • receive complaints;
  • share evidence;
  • raise relevant and reasoned objections;
  • participate in the Article 60 procedure;
  • handle certain local matters under Article 56(2);
  • take urgent provisional measures under Article 66 where the conditions are met.

Thus, one-stop-shop coordination is not the same as exclusive isolation of all authority in one regulator.

10. Transnational cases that may not satisfy Article 4(23)

Not every case containing a foreign element qualifies as “cross-border processing.”

Illustration

A French controller processes the information of one German tourist in relation to a one-off hotel stay. A server copy happens to be stored in Belgium. The case has transnational features, but it does not automatically follow that the processing substantially affects data subjects in several Member States or is conducted through establishments in several states. Even where Article 56 does not apply, authorities may still need mutual assistance under Article 61 or joint operations under Article 62. The practical distinction is:

  • Article 56 allocates leadership in qualifying cross-border processing.
  • Articles 61 and 62 support cooperation whenever assistance is needed for effective supervision.

11. Controllers outside the EU

Recital 122 indicates that a national authority may be competent where a non-EU controller or processor targets persons residing on its territory.

Illustration

A United States-based application has no EU establishment but deliberately offers a French-language behavioural-tracking service to users in France and Spain. The French and Spanish authorities may each have territorial connections to affected users. Since the controller has no EU main establishment, the ordinary one-stop-shop mechanism is generally unavailable.

11.1 The Article 27 representative is not a main establishment

A non-EU controller may be required to appoint an EU representative under Article 27. That representative provides a point of contact, but appointing one does not transform the representative into the controller’s “main establishment.”

Nor should it be assumed that the representative automatically bears full substantive liability merely because the controller is outside the Union.

11.2 Enforcement difficulty

Legal competence and practical enforcement are different questions.

A supervisory authority may have jurisdiction over a non-EU company but face difficulty enforcing a fine if the company has:

  • no EU establishment;
  • no EU assets;
  • no effective representative;
  • no presence in a cooperating third country.

Possible tools may include cooperation with foreign authorities, action against EU-based processing operations, restrictions on unlawful transfers and other legally available measures. Article 55 establishes competence, but it does not magically eliminate international enforcement obstacles.

12. “Tasks” and “powers” under Article 55(1)

Article 55 deliberately refers to both tasks and powers.

Tasks

Tasks include:

  • handling complaints;
  • monitoring GDPR application;
  • raising public awareness;
  • advising public institutions;
  • promoting controller awareness;
  • cooperating with other authorities;
  • monitoring developments affecting personal-data protection.

Powers

Powers include:

  • ordering information;
  • conducting investigations and audits;
  • obtaining access to data and premises;
  • issuing warnings and reprimands;
  • ordering compliance;
  • restricting or prohibiting processing;
  • imposing fines;
  • granting or withdrawing authorisations.

The distinction matters because an authority may sometimes be able to perform a non-coercive task even where direct use of coercive powers abroad requires cooperation.

Illustration

A national authority may provide information to a resident and receive the resident’s complaint. If the necessary evidence is held in another Member State, the authority may need the assistance of the authority situated there before compulsory access can occur.

13. Multiple supervisory authorities within one state

Article 55(1) says that each authority is competent on the territory of its Member State. This does not necessarily mean that every authority in a multi-authority country has competence over every matter nationwide.

National law may distribute jurisdiction:

  • territorially;
  • federally;
  • regionally;
  • according to public and private sectors;
  • according to constitutionally protected sectors.

Illustration

A federal state has sixteen regional authorities and one federal authority. Article 55 does not automatically give every regional authority jurisdiction over all sixteen regions. National law determines their internal allocation, subject to the GDPR’s requirements that supervision remain complete, effective and coordinated. A complainant should not be left without a competent authority because national rules create gaps or endless referrals.

14. Competence is not the same as applicable national law

The GDPR permits or requires Member States to make more specific rules in areas such as:

  • employment processing under Article 88;
  • journalistic expression under Article 85;
  • official documents under Article 86;
  • special-category data;
  • professional secrecy;
  • national identification numbers.

A lead authority may occasionally need to consider the national law of another Member State when assessing processing affecting that state.

Illustration

A multinational employer centrally manages employee data from Country A, but employees work in Country B under specific national employment-data rules adopted under Article 88. If Country A’s authority is the lead authority, it cannot necessarily ignore Country B’s valid national rules merely because it leads the procedure. Article 55 determines regulatory competence. It does not contain a complete conflict-of-laws code resolving every question about national implementing legislation.

15. Article 55(2): Public authorities, legal obligations and public-interest functions

Paragraph 2 creates a special rule:

Where processing is carried out by public authorities, or by private bodies acting on the basis of Article 6(1)(c) or Article 6(1)(e), the supervisory authority of the Member State concerned is competent. Article 56 does not apply.

The two legal bases are:

  • Article 6(1)(c): processing necessary for compliance with a legal obligation;
  • Article 6(1)(e): processing necessary for a task carried out in the public interest or in the exercise of official authority.

Recital 128 explains that the lead-supervisory-authority and one-stop-shop rules should not apply to public authorities or private bodies acting in the public interest. The competent authority should be that of the Member State where the public authority or private body is established.europa+1

15.1 Why Article 56 is excluded

Public-law obligations are closely connected with the legal system of the Member State that creates them.

It would be institutionally awkward for a foreign supervisory authority to become the lead regulator of:

  • another country’s tax authority;
  • another country’s municipality;
  • another country’s social-security administration;
  • processing required by another country’s public law.

The local authority is better positioned to understand the statutory duty, public function and constitutional context.

16. What counts as a public authority?

The GDPR does not provide one universal definition for every Member State.

Likely examples include:

  • ministries;
  • municipalities;
  • tax administrations;
  • public hospitals acting under statutory functions;
  • public universities carrying out public tasks;
  • social-security bodies;
  • regulatory agencies;
  • administrative authorities.

However, public ownership alone may not always be decisive.

Illustration

A company is wholly owned by the state but sells ordinary telecommunications services in competition with private companies. For its ordinary commercial customer processing, it may operate more like a commercial undertaking than a public authority exercising statutory power. The precise classification depends on its legal status, function and the particular processing operation. This shows why Article 55(2) must be applied operation by operation, not entity by entity in the abstract.

17. Public authorities may perform commercial processing

A public body can conduct different activities under different legal bases.

Illustration

A public university:

  1. maintains legally required student records under Article 6(1)(c);
  2. awards public qualifications under Article 6(1)(e);
  3. sells conference tickets under Article 6(1)(b);
  4. sends optional alumni marketing based on consent.

The first two operations clearly fit the public-law rationale of Article 55(2). The commercial or consensual activities require separate analysis.

One organisation may therefore come under different competence pathways for different processing operations.

This prevents a public body from claiming that every commercial activity receives special treatment simply because the organisation has public status.

18. Private bodies under Article 6(1)(c) or (e)

Article 55(2) also applies to private bodies when the relevant processing is based on a legal obligation or public-interest/official-authority basis.

Examples

may include:

  • a private provider administering a statutory public service;
  • a company retaining records because national law requires it;
  • an airline transmitting passenger information under legislation;
  • a regulated professional performing a legally assigned public function;
  • a private hospital carrying out a statutory public-health task.

Illustration

An airline processes passenger names for two separate purposes:

  1. selling and managing tickets under the contract with passengers;
  2. transmitting passenger information to national authorities under a statutory obligation.

The commercial booking system may fall within the normal cross-border rules. The legally required transmission may fall within Article 55(2).

The same data may therefore be processed:

  • by the same organisation;
  • at the same time;
  • for different purposes;
  • under different legal bases;
  • under different competence arrangements.

That is not contradictory. GDPR analysis is processing-specific.

19. The meaning of “Member State concerned”

The relevant state is normally the state whose public authority or public-law framework underlies the processing. Recital 128 refers to the state where the public authority or private body is established.

Illustration

A German private company must retain particular records because German public law imposes that obligation. The fact that some affected customers live in Austria does not automatically make the Austrian authority the lead regulator of that legally mandated processing. However, the exact result may become complicated where:

  • several national legal obligations apply;
  • the body has public functions in several states;
  • different establishments perform separate statutory tasks;
  • the operation combines legal-obligation and commercial purposes. In difficult cases, the authority must identify:
  1. the specific processing operation;
  2. its actual purpose;
  3. the correct Article 6 legal basis;
  4. the law creating the obligation or task;
  5. the establishment carrying out that function;
  6. whether another operation should be separated for competence purposes.

20. A controller cannot manipulate competence by choosing Article 6(1)(c) or (e)

Article 55(2) applies only if the legal basis is valid in substance.

A company cannot avoid the one-stop shop merely by labelling ordinary commercial processing as a “legal obligation.” Equally, it cannot obtain one-stop-shop treatment by falsely describing a statutory public task as contractual processing.

Illustration

A private parking operator says that profiling every customer for advertising is necessary to perform a public-interest parking function. The authority must ask whether the advertising profile is genuinely necessary for the statutory task. If it is merely commercial reuse, Article 6(1)(e) and Article 55(2) may not apply. Purpose, necessity and the legal source of authority must be examined rather than accepted from the controller’s privacy notice.

21. Article 55(3): Courts acting in their judicial capacity

Paragraph 3 states:

Supervisory authorities shall not be competent to supervise processing operations of courts acting in their judicial capacity.

This is not an exemption from the GDPR itself. It is an exclusion from the competence of the ordinary supervisory authority.

Recital 20 explains that the purpose is to protect judicial independence, including judicial decision-making. It also states that Member States may entrust supervision to specific bodies within the judicial system that promote compliance, raise awareness and handle complaints.europa+1

21.1 Why the exclusion exists

A data protection authority should not be able to use regulatory powers to influence:

  • what evidence a judge considers;
  • how a case file is organised;
  • what information appears in a judgment;
  • whether a hearing is public;
  • how judicial deliberation occurs;
  • how courts communicate about proceedings.

Illustration

A supervisory authority orders a judge to remove evidence from a pending criminal or civil case because it considers the evidence excessive. Such an order could directly interfere with adjudication. Article 55(3) prevents the ordinary regulator from supervising the court’s judicial processing in that manner.

22. “Courts” does not automatically mean every judicial institution

The text expressly refers to courts. It should not automatically be expanded to every organisation connected with justice.

Possible distinctions include:

  • courts;
  • prosecutors;
  • police;
  • ministries of justice;
  • court-appointed experts;
  • lawyers;
  • bailiffs;
  • administrative tribunals;
  • judicial councils.

Prosecutors and law-enforcement authorities may be governed partly by Directive (EU) 2016/680 rather than the GDPR when processing for criminal-law enforcement purposes. Their supervision must be analysed under the applicable instrument and national law.

The supplied Commentary’s statement that prosecutors are “obviously” covered by Article 55(3) is too broad. Prosecutorial status varies between Member States, and Article 55(3) specifically uses the word “courts.” A separate legal analysis is necessary.

23. The key phrase: “acting in their judicial capacity”

The exclusion is functional, not merely institutional.

A court performs both:

  • judicial activities; and
  • ordinary administrative activities.

Only the former fall within Article 55(3).

Judicial examples

  • managing evidence in a pending case;
  • recording hearings;
  • maintaining judicial case files;
  • drafting and issuing judgments;
  • deciding access to court materials;
  • communicating judicial proceedings in a manner connected with adjudication.

Administrative examples

  • staff payroll;
  • recruitment;
  • employee attendance records;
  • procurement;
  • building-access systems;
  • canteen administration;
  • ordinary IT asset records;
  • non-judicial marketing or website analytics.

Illustration

The court processes a witness’s medical history as evidence in a lawsuit. That is closely connected to the judicial function. The same court processes a job applicant’s CV for a clerical position. That is employment administration and is ordinarily not protected from supervisory-authority competence by Article 55(3).

24. The CJEU’s broad functional interpretation

In X and Z v Autoriteit Persoonsgegevens, Case C-245/20, a court made documents from judicial proceedings temporarily available to journalists so they could report on the hearing. The CJEU held that this fell within the court’s judicial capacity for Article 55(3).europa+1

The decision is important because judicial capacity is not confined to the judge’s final deliberation or judgment. It can extend to processing connected with how proceedings are conducted and communicated where external supervisory control could influence judicial independence.

The relevant question is not simply:

“Was the information processed inside a courthouse?”

Instead, the question is:

“Was the processing part of judicial activity, and could supervision by the ordinary data protection authority directly or indirectly influence judicial independence?”

Illustration

Giving accredited journalists temporary access to selected court documents may form part of a court’s policy for ensuring accurate reporting of proceedings. Even though the activity involves public communication rather than deciding the merits, it may still be judicial in character.

25. Article 55(3) does not create a privacy-free zone

Courts remain subject to the GDPR where it applies. The exclusion concerns the identity of the supervisor, not the existence of legal duties.

Courts must still consider matters such as:

  • lawfulness;
  • purpose limitation;
  • data minimisation;
  • accuracy;
  • retention;
  • security;
  • transparency, subject to applicable restrictions;
  • rights of affected persons, subject to judicial rules and lawful limitations.

Recital 20 encourages supervision through specialised bodies within the judicial system.

Illustration

A judicial council or dedicated judicial data protection body may:

  • receive complaints;
  • issue internal guidance;
  • audit court systems;
  • train judges and staff;
  • examine security incidents;
  • recommend corrective action. Such a system protects privacy while avoiding executive interference in adjudication.

26. Difficult boundary cases involving courts

Court websites

Publishing judgments may form part of judicial activity. However, unrelated analytics, advertising cookies or recruitment portals may be administrative.

CCTV in courthouses

CCTV used for building security may be administrative. Recording introduced as courtroom evidence or as an official hearing record may be judicial.

Court communications

A press release explaining a judgment may be judicially connected. A promotional campaign recruiting administrative staff is likely not.

Case-management software

Processing within a system used to allocate cases, store evidence and issue judgments may be judicial. Procurement and payroll records for the software provider are administrative.

The correct approach is not to classify the court as wholly exempt. Each processing operation must be examined by purpose and function.

27. Key corrections and cautions in the supplied Commentary

Several points require careful qualification:

First, territorial competence is not simply physical location

Server location is not decisive. Establishment, effects, targeting and cross-border arrangements must all be considered.

Second, Article 55 does not itself determine applicable national law

Competence and substantive applicable law are separate questions.

Third, one authority’s foreign enforcement power is not absolutely nonexistent

It cannot exercise coercive sovereignty unilaterally abroad, but GDPR cooperation can produce coordinated cross-border decisions and enforcement.

Fourth, Weltimmo predates the GDPR

It remains persuasive for establishment and territorial enforcement principles, but it arose under Directive 95/46 and must be applied carefully within the GDPR’s newer one-stop-shop structure.europa+1

Fifth, Article 55(2) requires operation-specific analysis

A public or private body may conduct different processing operations under contract, consent, legal obligation and public-interest bases.

Sixth, prosecutors are not automatically “courts”

Their status and applicable supervision require separate analysis under the GDPR, the Law Enforcement Directive and national law.

Seventh, judicial processing remains regulated

Article 55(3) removes ordinary supervisory-authority competence, not GDPR applicability.

28. A practical competence checklist

For any real case, the analysis should proceed in this order:

Step 1: Identify the processing

Do not examine the organisation only at a general level. Identify the precise collection, use, sharing, retention or deletion operation.

Step 2: Identify the actors

Determine the controller, joint controllers, processors and establishments involved.

Step 3: Confirm GDPR territorial scope

Apply Article 3’s establishment or targeting criteria.

Step 4: Identify territorial connections

Consider establishments, affected persons, targeting, public functions and where enforcement steps must occur.

Step 5: Assess cross-border processing

Apply Article 4(23).

Step 6: Check Article 56

Determine whether a lead supervisory authority and concerned authorities exist.

Step 7: Check Article 55(2)

Ask whether the operation is performed by a public authority or by a private body under Article 6(1)(c) or (e).

Step 8: Check Article 55(3)

Ask whether a court performs the operation in its judicial capacity.

Step 9: Identify cooperation needs

Determine whether Articles 60, 61, 62 or 66 are relevant.

Step 10: Separate competence from applicable law

Identify any national provisions that must be applied to the substance of the processing.

Conclusion

Article 55 establishes the ordinary map of GDPR regulatory authority. Paragraph 1 gives each supervisory authority competence on the territory of its Member State, but that territorial principle must accommodate digital processing, broad concepts of establishment, targeting of EU residents and mandatory cross-border cooperation. Paragraph 2 keeps public-authority processing and processing under national legal obligations or public-interest powers under the supervision of the Member State concerned. It prevents the one-stop shop from making a foreign regulator the principal supervisor of another state’s public administration or statutory functions. Paragraph 3 protects judicial independence by preventing ordinary supervisory authorities from supervising courts when they act judicially. It does not exempt courts from data protection law. It redirects supervision away from the ordinary regulator and toward appropriate judicial oversight arrangements. In the simplest terms: Article 55 says that a national data protection authority regulates within its own national sphere; cross-border business processing may be coordinated through a lead authority; national public functions stay with the relevant national regulator; and judicial decision-making is supervised in a way that does not compromise the independence of courts. The most important lesson is that competence must be determined processing by processing. The identity of the organisation, the location of the server or the nationality of the complainant can never, by themselves, answer the entire Article 55 question.