CHAPTER VIINDEPENDENT SUPERVISORY AUTHORITIES

Article 57Tasks

Official text

(1)Without prejudice to other tasks set out under this Regulation, each supervisory authority shall on its territory:

(a)monitor and enforce the application of this Regulation;

(b)promote public awareness and understanding of the risks, rules, safeguards and rights in relation to processing. Activities addressed specifically to children shall receive specific attention;

(c)advise, in accordance with Member State law, the national parliament, the government, and other institutions and bodies on legislative and administrative measures relating to the protection of natural persons’ rights and freedoms with regard to processing;

(d)promote the awareness of controllers and processors of their obligations under this Regulation;

(e)upon request, provide information to any data subject concerning the exercise of their rights under this Regulation and, if appropriate, cooperate with the supervisory authorities in other Member States to that end;

(f)handle complaints lodged by a data subject, or by a body, organisation or association in accordance with Article 80, and investigate, to the extent appropriate, the subject matter of the complaint and inform the complainant of the progress and the outcome of the investigation within a reasonable period, in particular if further investigation or coordination with another supervisory authority is necessary;

(g)cooperate with, including sharing information and provide mutual assistance to, other supervisory authorities with a view to ensuring the consistency of application and enforcement of this Regulation;

(h)conduct investigations on the application of this Regulation, including on the basis of information received from another supervisory authority or other public authority;

(i)monitor relevant developments, insofar as they have an impact on the protection of personal data, in particular the development of information and communication technologies and commercial practices;

(j)adopt standard contractual clauses referred to in Article 28 (8) and in point (d) of Article 46 (2);

(k)establish and maintain a list in relation to the requirement for data protection impact assessment pursuant to Article 35 (4);

(l)give advice on the processing operations referred to in Article 36 (2);

(m)encourage the drawing up of codes of conduct pursuant to Article 40 (1) and provide an opinion and approve such codes of conduct which provide sufficient safeguards, pursuant to Article 40 (5);

(n)encourage the establishment of data protection certification mechanisms and of data protection seals and marks pursuant to Article 42 (1), and approve the criteria of certification pursuant to Article 42 (5);

(o)where applicable, carry out a periodic review of certifications issued in accordance with Article 42 (7);

(p)draft and publish the requirements for accreditation of a body for monitoring codes of conduct pursuant to Article 41 and of a certification body pursuant to Article 43;

(q)conduct the accreditation of a body for monitoring codes of conduct pursuant to Article 41 and of a certification body pursuant to Article 43;

(r)authorise contractual clauses and provisions referred to in Article 46 (3);

(s)approve binding corporate rules pursuant to Article 47;

(t)contribute to the activities of the Board;

(u)keep internal records of infringements of this Regulation and of measures taken in accordance with Article 58 (2); and

(v)fulfil any other tasks related to the protection of personal data.

(2)Each supervisory authority shall facilitate the submission of complaints referred to in point (f) of paragraph 1 by measures such as a complaint submission form which can also be completed electronically, without excluding other means of communication.

(3)The performance of the tasks of each supervisory authority shall be free of charge for the data subject and, where applicable, for the data protection officer.

(4)Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, the supervisory authority may charge a reasonable fee based on administrative costs, or refuse to act on the request. The supervisory authority shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request.

Commentary

Article 57 is the operational job description of every GDPR supervisory authority. Earlier provisions establish the authority, protect its independence and determine its territorial competence. Article 57 explains what that authority must actually do: educate the public, advise government, investigate organisations, handle complaints, cooperate across borders, oversee regulatory mechanisms and maintain effective enforcement.

The provision is unusually detailed. Paragraph 1 contains 22 listed tasks, from points (a) to (v), not 21 as stated in parts of the supplied commentary. Paragraphs 2 to 4 then regulate accessibility, cost and abuse of the authority’s services. These duties are mandatory because the Article repeatedly uses the word“shall.”


1. The overall purpose of Article 57

A supervisory authority is more than a complaints office and more than an enforcement agency. Article 57 gives it several roles simultaneously:

  • regulator;
  • investigator;
  • educator;
  • adviser;
  • complaint handler;
  • cross-border coordinator;
  • approver of compliance mechanisms;
  • observer of technological and commercial developments;
  • institutional contributor to the European Data Protection Board.

These roles are interconnected.

For example, if an authority observes growing use of facial recognition under point (i), it may issue public guidance under point (b), educate controllers under point (d), advise the legislature under point (c), open investigations under point (h), handle affected individuals’ complaints under point (f), and ultimately enforce the GDPR under point (a).

Article 57 therefore creates a complete regulatory cycle:

Observe the problem, explain the law, prevent violations, receive complaints, investigate facts, coordinate with other authorities and enforce compliance.

Recitals 122 and 129 reinforce this design. Supervisory authorities must have equivalent core tasks and effective powers throughout the Union, while exercising those powers impartially, fairly, proportionately and within a reasonable time.


2. “Without prejudice to other tasks”

Article 57(1) begins with the words:

“Without prejudice to other tasks set out under this Regulation.”

This means that the Article 57 list is extensive but not exhaustive. Tasks found elsewhere in the GDPR continue to apply.

Examples

include:

  • preparing annual activity reports under Article 59;
  • participating in the Article 60 cooperation procedure;
  • providing mutual assistance under Article 61;
  • conducting joint operations under Article 62;
  • participating in consistency procedures under Articles 63 to 66;
  • bringing matters before courts where national law provides for this under Article 58(5);
  • supporting international cooperation under Article 50. Point (v), which refers to “any other tasks related to the protection of personal data,” also confirms the list’s open-ended character. This does not mean that an authority can invent unlimited new coercive powers. A task is something the authority is responsible for doing. A power is a legal instrument it can use, such as ordering information or prohibiting processing. Coercive powers require a proper legal basis, principally Article 58 or national law permitted by the GDPR.

3. “Each supervisory authority shall”

The word “shall” makes the Article 57 tasks legal obligations.

An authority is not free to treat complaint handling, public awareness or cooperation as optional. It has discretion over questions such as:

  • how deeply a particular complaint must be investigated;
  • which sectors deserve proactive attention;
  • which educational methods are most effective;
  • how resources should be allocated;
  • which corrective power is proportionate.

However, discretion concerning how to perform a duty is different from discretion concerning whether to perform it at all.

4. “On its territory”

Article 57 links the authority’s tasks to its territorial competence under Articles 55 and 56.

This phrase does not mean that the authority may consider only processing physically performed within national borders. Modern processing may involve:

  • an establishment in one Member State;
  • servers in another state;
  • affected individuals in several states;
  • decision-makers outside the EEA;
  • processors located elsewhere.

Jurisdiction must therefore be determined under Articles 3, 55 and 56.

[!example] Illustration A French authority receives a complaint from a person living in France about a platform whose lead supervisory authority is in Ireland. The French authority may receive the complaint, assist the individual and participate as a supervisory authority concerned. The Irish authority may lead the cross-border procedure. “On its territory” does not require the French authority simply to reject the individual.

5. Article 57(1)(a): Monitor and enforce the GDPR

Point (a) is the authority’s central task. It contains two related but distinct ideas.

5.1 Monitoring

Monitoring means observing, examining and assessing whether controllers and processors comply with the GDPR.

It may include:

  • reviewing regulatory filings and breach notifications;
  • conducting audits;
  • examining a particular sector;
  • inspecting processing systems;
  • studying privacy notices;
  • reviewing security arrangements;
  • monitoring compliance with previous orders;
  • analysing patterns in complaints;
  • reviewing approved certification schemes.

Illustration

The authority notices repeated complaints about supermarkets using facial recognition. It begins a sector-wide inquiry into:

  • the purpose of the systems;
  • the legal basis;
  • the accuracy of facial matching;
  • the treatment of children;
  • retention periods;
  • whether less intrusive measures could achieve the same objective. That is monitoring even before the authority finds a particular infringement.

5.2 Enforcement

Enforcement begins where the authority uses its legal powers to prevent, correct or sanction non-compliance.

Depending on the facts, enforcement may involve:

  • a warning;
  • a reprimand;
  • an order to answer an access request;
  • an order to erase unlawfully held data;
  • restriction or prohibition of processing;
  • suspension of unlawful transfers;
  • withdrawal of certification;
  • an administrative fine.

Monitoring without effective enforcement can become merely observational. Yet enforcement does not mean that every violation automatically requires the largest possible fine. Recital 129 requires every measure to be appropriate, necessary and proportionate to the circumstances.

[!example] Illustration A small charity inadvertently publishes an outdated contact list, immediately removes it and improves its controls. A reprimand and compliance order may be sufficient. A large data broker deliberately continues unlawful profiling after repeated warnings. A prohibition and substantial fine may be necessary. The choice must address the actual infringement and produce compliance.

6. Article 57(1)(b): Public awareness, with special attention to children

The authority must educate the public about:

  • risks associated with processing;
  • applicable legal rules;
  • safeguards;
  • data subject rights.

This task addresses a basic problem. Legal rights are of limited value if people do not understand:

  • when personal data are being collected;
  • what risks arise;
  • what they can ask an organisation to do;
  • where they can complain.

Public-awareness activities may include:

  • plain-language guidance;
  • social-media campaigns;
  • school programmes;
  • videos and webinars;
  • community workshops;
  • template rights requests;
  • multilingual materials;
  • guidance for older people or vulnerable groups;
  • warnings about emerging scams or surveillance practices.

6.1 Special attention to children

Children require specific attention because they may:

  • understand privacy information less easily;
  • underestimate long-term consequences;
  • be more vulnerable to manipulation;
  • use online services intensively;
  • have difficulty distinguishing advertising from ordinary content;
  • lack confidence to exercise rights.

Illustration

An authority publishes a 70-page legal guide about children’s privacy. Technically, the guide discusses children, but it may not effectively educate them. A better approach may include:

  • age-appropriate videos;
  • illustrations;
  • short explanations;
  • school lesson materials;
  • guidance for parents and teachers;
  • simple instructions for reporting cyberbullying or unwanted profiling. “Specific attention” therefore concerns both subject matter and communication method.

6.2 Awareness is not advertising for the authority

Public-awareness work should be accurate, balanced and educational. It should not become self-promotion or political campaigning.

The authority should explain both:

  • the protections available to individuals; and
  • the circumstances in which processing may lawfully occur.

For example, it should not tell people that they always have an unconditional right to erasure. Erasure has exceptions, including where retention remains necessary for a legal obligation or legal claims.


7. Article 57(1)(c): Advice to parliament, government and public bodies

The authority must advise public institutions, in accordance with national law, on legislative and administrative measures affecting personal-data processing.

This is preventive supervision.

The best moment to address privacy problems is often before a law, database or public programme is finalised.

Illustration

A government proposes a national facial-recognition system for railway stations. The supervisory authority may advise on:

  • whether the measure has a sufficiently clear legal basis;
  • necessity and proportionality;
  • categories of persons covered;
  • false-match risks;
  • access controls;
  • retention;
  • independent oversight;
  • children and vulnerable persons;
  • complaint and remedy mechanisms. The legislature may not always be legally bound to accept every recommendation. But advice must be sought where required, considered seriously and given at a time when it can still influence the proposal.

7.1 Advice is not political veto

The authority is an independent expert body, not a second parliament.

It may explain that a proposal conflicts with the GDPR or fundamental rights. It does not ordinarily obtain a general power to prevent parliament from legislating.

Nevertheless, if the law is later applied in a manner governed by the GDPR, the authority or courts may have enforcement and review roles consistent with their competence.

7.2 Timing matters

Consulting the authority after a system has been purchased and the law effectively finalised defeats the preventive purpose.

Meaningful consultation should provide:

  • sufficient information;
  • the draft text;
  • relevant impact assessments;
  • adequate time for analysis;
  • an opportunity for follow-up.

8. Article 57(1)(d): Awareness of controllers and processors

Point (d) focuses on organisations that process personal data.

Supervisory authorities should help controllers and processors understand obligations concerning:

  • privacy notices;
  • lawful bases;
  • security;
  • contracts;
  • breach notification;
  • records of processing;
  • data protection impact assessments;
  • privacy by design;
  • rights requests;
  • international transfers.

Recital 132 indicates that awareness programmes should include measures directed to controllers and processors, particularly micro, small and medium-sized enterprises.

Illustration

A small physiotherapy clinic may not have an in-house lawyer. The authority could publish a practical guide explaining:

  • when patient consent is and is not required;
  • secure appointment communication;
  • access requests;
  • retention;
  • handling medical information;
  • processor contracts with cloud providers.

“Promote awareness” does not require the authority to become every controller’s personal compliance consultant.

The authority may:

  • publish guidance;
  • answer general questions;
  • organise workshops;
  • explain regulatory expectations.

It need not design a company’s processing model or guarantee that a proposed system is lawful.

Illustration

A company asks: “Can you approve our advertising system in advance so that we cannot later be fined?” Point (d) does not require the authority to provide such immunity. Unless a specific approval mechanism applies, the controller retains responsibility for compliance.

9. Article 57(1)(e): Information for data subjects

Upon request, the authority must provide information to a data subject about exercising GDPR rights.

This may cover:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • objection;
  • portability;
  • automated decisions;
  • complaints;
  • judicial remedies;
  • representation under Article 80.

Illustration

A worker believes an employer retains inaccurate absence records. The authority may explain:

  1. how to submit a rectification request;
  2. what information to include;
  3. the controller’s usual response period;
  4. when a complaint may be made;
  5. what supporting documents may be relevant.

The authority provides legal information, not necessarily personalised representation.

9.1 Cross-border cooperation

If the controller is located or led in another Member State, the authority may need to cooperate with another supervisory authority.

A person should not be expected to master the one-stop-shop mechanism before seeking help. The authority should guide the person through the relevant procedure.


10. Article 57(1)(f): Handling complaints

Complaint handling is one of the most important tasks in Article 57.

A complaint may be lodged by:

  • the data subject;
  • an eligible body, organisation or association under Article 80;
  • a body acting on behalf of the individual where the applicable conditions are met.

A complaint is not a casual petition asking the authority to consider policy. It is a mechanism for enforcing rights.

The CJEU stated in the 2023 SCHUFA judgment that supervisory authorities must handle complaints and examine them with all due diligence. It also confirmed that decisions on complaints are subject to full judicial review under Article 78.


10.1 What qualifies as a complaint?

The GDPR does not prescribe one universal technical format.

At minimum, a complaint should make it reasonably possible to understand:

  • who the complainant is;
  • which controller or processor is concerned;
  • what processing is challenged;
  • how the complainant is affected;
  • why the complainant believes the GDPR has been infringed.

National procedural law may specify reasonable admissibility requirements.

However, formalities must not defeat Article 57(2)’s duty to facilitate complaints.

Illustration

A person sends an email saying: “My former employer continues publishing my photograph after I asked it to stop. I attach my request and their reply.” The authority should examine the substance. It should not automatically refuse the matter merely because the person did not quote an Article number or use the official form.

10.2 Complaints are not limited to Chapter III rights

A person may complain about any GDPR violation affecting the processing of their personal data, including:

  • unlawful processing;
  • excessive collection;
  • inadequate security;
  • unlawful disclosure;
  • delayed breach notification;
  • invalid consent;
  • discriminatory profiling;
  • unlawful international transfers.

A complaint need not concern only a rejected access or erasure request.


11. What “handle” means

Handling a complaint covers the whole administrative process:

  1. receiving the submission;
  2. checking whether it sufficiently identifies a GDPR issue;
  3. clarifying missing information where appropriate;
  4. determining territorial competence;
  5. identifying any lead and concerned authorities;
  6. examining evidence;
  7. seeking the controller’s response;
  8. investigating the relevant facts;
  9. deciding whether an infringement occurred;

10. choosing an appropriate measure;

11. informing the complainant;

12. enabling effective judicial review.

An authority cannot satisfy Article 57(1)(f) simply by forwarding the complaint to a general mailbox and recording that it was received.


12. Investigation “to the extent appropriate”

The authority must investigate the subject matter to the extent appropriate.

This wording gives the authority discretion over the investigation’s depth, but it does not authorise inactivity. The authority must examine the factual and legal issues sufficiently to reach a defensible conclusion.

Factors include:

  • seriousness;
  • complexity;
  • quality of submitted evidence;
  • number of affected persons;
  • sensitivity of data;
  • ongoing risk;
  • controller’s cooperation;
  • availability of less intrusive investigative methods;
  • cross-border dimensions.

Illustration: modest investigation

A person complains that a retailer answered an access request five days late. The facts are admitted and documented. The authority may not need a site inspection, forensic imaging or dozens of witness interviews.

Illustration: extensive investigation

A person alleges that a credit-scoring company secretly uses health and location data to deny loans. The authority may need:

  • algorithmic documentation;
  • data-source information;
  • technical audits;
  • model testing;
  • interviews;
  • examination of legal bases;
  • cooperation with other regulators. Appropriateness concerns proportionality, not convenience.

13. Due diligence and enforcement discretion

The authority may have discretion regarding the corrective measure, but not unlimited discretion to ignore an established infringement.

The SCHUFA judgment confirms that the complaint procedure must effectively safeguard the complainant’s rights and that the authority’s decision is subject to full judicial review.

A court may therefore examine:

  • whether the authority identified the correct issues;
  • whether important evidence was ignored;
  • whether the investigation was adequate;
  • whether the legal analysis was correct;
  • whether the selected measure was lawful and proportionate.

[!example] Illustration The authority confirms that a controller unlawfully refused access but closes the case without requiring any response, explanation or correction. It would need to justify why no corrective step was necessary. Independence does not make unreasoned inactivity lawful.

14. Informing the complainant

The authority must inform the complainant about both:

  • progress; and
  • outcome.

A progress update need not disclose confidential investigative material. It should nevertheless provide meaningful information, such as:

  • whether the complaint was admitted;
  • whether competence has been determined;
  • whether another authority is involved;
  • whether further investigation is underway;
  • whether a decision has been delayed and why.

The final communication should ordinarily explain:

  • what was decided;
  • essential reasons;
  • any action taken;
  • available judicial remedy.

A message saying only “the file is closed” would normally be inadequate.


15. “Within a reasonable period”

Article 57 sets no universal final deadline. Reasonableness depends on:

  • the case’s complexity;
  • evidence volume;
  • urgency;
  • cross-border coordination;
  • EDPB involvement;
  • conduct of the parties;
  • potential continuing harm.

Article 78(2) provides an important backstop: where the competent authority does not handle a complaint or does not inform the data subject within three months of its progress or outcome, the person has a right to an effective judicial remedy.

The three-month point does not necessarily require a final decision. It requires at least meaningful communication concerning progress or outcome.

[!example] Illustration A cross-border AI investigation may reasonably take longer than three months. But the authority cannot remain silent for that entire period. A six-year investigation may be difficult to justify unless exceptional complexity and continuous meaningful progress are demonstrated. Resource shortages cannot become a permanent excuse. Article 52(4) requires Member States to provide the authority with resources necessary to perform its tasks effectively.

16. Article 57(1)(g): Cooperation with other authorities

Supervisory authorities must cooperate, share information and provide mutual assistance to achieve consistent GDPR application.

Cooperation may include:

  • identifying the lead authority;
  • sharing complaint files;
  • obtaining evidence;
  • conducting local inspections;
  • translating documents;
  • coordinating legal analysis;
  • preparing joint operations;
  • participating in Article 60 decisions;
  • communicating urgent risks.

Recital 123 makes clear that this cooperation follows directly from the GDPR. No separate treaty between Member States is required.

Illustration

The Austrian authority investigates a service used by Austrian residents, but the relevant server and technical team are in Denmark. The Austrian authority may ask the Danish authority to:

  • inspect the local establishment;
  • obtain system documentation;
  • interview technical staff;
  • preserve evidence. The Danish authority should not treat the request as a favour. Mutual assistance is a GDPR duty, subject to the applicable conditions.

17. Article 57(1)(h): Investigations beyond complaints

Point (h) allows investigations based on information from:

  • another supervisory authority;
  • another public authority;
  • media reports;
  • academic research;
  • civil-society organisations;
  • breach notifications;
  • audits;
  • whistleblowers;
  • the authority’s own monitoring.

This is often called ex officio investigation.

[!example] Illustration Independent researchers report that connected vehicles continuously transmit location, voice recordings and driving behaviour to manufacturers. The authority need not wait for an individual driver to submit a perfectly drafted complaint. It may open a sectoral investigation. Complaint investigations and ex officio investigations may overlap, but they are not identical. If an individual has lodged a complaint, the authority must still respect the complainant’s procedural position and information rights. It should not make those rights disappear merely by relabelling the matter a general inquiry.

18. Article 57(1)(i): Monitoring technological and commercial developments

A modern privacy regulator must understand the systems it supervises.

Relevant developments include:

  • artificial intelligence;
  • facial and voice recognition;
  • connected vehicles;
  • online advertising;
  • data brokerage;
  • location tracking;
  • biometric attendance;
  • cloud infrastructure;
  • blockchain;
  • neurotechnology;
  • health applications;
  • children’s digital services;
  • subscription-or-consent models;
  • privacy-enhancing technologies;
  • encryption and pseudonymisation.

The authority must monitor both harmful and protective technologies.

Illustration

A new system allows retailers to infer pregnancy, illness and financial distress from purchasing patterns. The authority should understand:

  • what inferences are produced;
  • how accurate they are;
  • whether special-category data are involved;
  • how the profiles are used;
  • whether individuals can challenge them. Monitoring should inform guidance, enforcement, legislative advice and DPIA requirements.

19. Article 57(1)(j): Standard contractual clauses

The authority may adopt standard contractual clauses for:

  • controller-processor arrangements under Article 28(8);
  • international-transfer safeguards under Article 46(2)(d).

Standard clauses provide pre-formulated contractual safeguards. They reduce duplication and help organisations use GDPR-compliant terms.

Illustration

Thousands of small controllers use external payroll processors. An authority may adopt standard Article 28 clauses dealing with:

  • documented instructions;
  • confidentiality;
  • security;
  • subprocessors;
  • rights assistance;
  • deletion or return;
  • audits. Adoption does not mean that every organisation can sign the clauses and ignore actual compliance. Parties must follow the terms in practice and adapt applicable details. These instruments may require EDPB consideration through the consistency mechanism to avoid incompatible national clause sets.

20. Article 57(1)(k): DPIA lists

Every authority must establish and maintain a list of processing operations that require a data protection impact assessment under Article 35(4).

A DPIA is required where processing is likely to create a high risk to people’s rights and freedoms.

Possible listed activities may include:

  • large-scale biometric identification;
  • systematic tracking in public places;
  • extensive employee monitoring;
  • large-scale sensitive-data processing;
  • automated decisions producing significant effects;
  • combining datasets in unexpected ways.

The list helps controllers, but it is not exhaustive of all high-risk processing.

Illustration

A processing operation is not mentioned on the authority’s list. The controller concludes that no DPIA is needed. That conclusion may be wrong. Article 35(1)’s general high-risk test still applies. The list identifies mandatory examples rather than creating a safe harbour for every unlisted activity. An authority may also publish a negative list under Article 35(5), but Article 57(1)(k) makes the positive list mandatory.

21. Article 57(1)(l): Prior consultation advice

Where a DPIA shows that processing would result in a high risk unless the controller takes measures to mitigate it, Article 36 requires prior consultation with the authority.

The authority must then give advice.

Illustration

A hospital proposes an AI system that predicts patients’ mental-health crises. Its DPIA identifies:

  • false-positive risks;
  • discriminatory outcomes;
  • large-scale health-data use;
  • limited explainability;
  • serious consequences for patients. The hospital cannot simply document these risks and proceed unchanged. It may need to consult the authority. The authority may recommend:
  • narrower data use;
  • human review;
  • stronger validation;
  • access controls;
  • shorter retention;
  • transparency;
  • independent testing. Prior consultation does not transfer responsibility from the controller to the authority. The controller remains accountable for lawful processing.

22. Article 57(1)(m): Codes of conduct

The authority must encourage the development of sectoral codes of conduct and assess whether proposed codes provide sufficient safeguards.

A useful code translates general GDPR principles into sector-specific practices.

Illustration

A medical-research association develops a code addressing:

  • participant notices;
  • pseudonymisation;
  • secondary research;
  • retention;
  • access requests;
  • data sharing;
  • security;
  • monitoring. The authority should assess whether the code genuinely protects individuals. It should not approve a code merely because the industry prefers it. Approval does not replace the GDPR. Compliance with an approved code may help demonstrate compliance, but it does not legalise processing that violates binding law.

23. Article 57(1)(n): Certification mechanisms, seals and marks

The authority must encourage certification mechanisms and approve certification criteria.

Certification can help demonstrate that a processing operation meets specified standards.

Illustration

A cloud service seeks certification for a secure health-data hosting service. The criteria may assess:

  • encryption;
  • access control;
  • deletion;
  • logging;
  • incident handling;
  • processor obligations;
  • data-subject support. Certification is neither permanent immunity nor proof that every use of the certified service is lawful. A hospital could use a certified cloud platform for an unlawful purpose. Certification concerns the certified processing operations and criteria, not every decision made by every customer.

24. Article 57(1)(o): Periodic review of certification

Where applicable, the authority must periodically review certifications under Article 42(7).

Certification is time-limited and may need renewal. Conditions may change because:

  • the product changes;
  • security weaknesses emerge;
  • subprocessors are added;
  • the legal framework develops;
  • the certified organisation no longer follows its documented controls.

[!example] Illustration A service was certified based on encryption and local data storage. It later introduces a new unencrypted analytics pipeline and transfers information abroad. The authority or certification body should not assume that the prior certificate remains reliable. Review may result in renewal, conditions, suspension or withdrawal.

25. Article 57(1)(p): Accreditation criteria

The authority must draft and publish criteria for accrediting:

  • bodies that monitor codes of conduct under Article 41;
  • certification bodies under Article 43.

Accreditation criteria should examine matters such as:

  • expertise;
  • independence;
  • objectivity;
  • conflict management;
  • procedures;
  • complaint handling;
  • technical capability;
  • confidentiality;
  • financial and organisational stability.

[!example] Illustration An industry association wants to monitor compliance with its own code, but its board is controlled by the largest companies subject to monitoring. The accreditation criteria should address whether the monitoring body can act independently and impose credible corrective measures. Publication is important because candidates must know the standard and the public must understand why a body has been trusted.

26. Article 57(1)(q): Accreditation itself

Point (p) concerns writing the criteria. Point (q) concerns applying those criteria to accredit bodies.

The exact institutional arrangement may vary because Article 43 allows accreditation by the supervisory authority, the national accreditation body, or both, depending on national law.

Illustration

A certification organisation submits evidence of:

  • qualified auditors;
  • independent governance;
  • testing procedures;
  • complaint mechanisms;
  • safeguards against consultancy conflicts. The authority must assess the substance rather than treat accreditation as a registration exercise. Accreditation should be reviewable and withdrawable if the body no longer satisfies the requirements.

27. Article 57(1)(r): Authorising tailored transfer clauses

Article 46(3) permits certain international-transfer safeguards subject to supervisory-authority authorisation, including:

  • contractual clauses between the controller or processor and a recipient in a third country;
  • provisions inserted into administrative arrangements between public authorities that create enforceable and effective rights.

These are tailored clauses, unlike standard clauses adopted generally under Article 46(2).

Illustration

A European research institute wants to transfer sensitive genetic data to an overseas partner under bespoke provisions. The authority must assess whether the proposed arrangement provides:

  • enforceable rights;
  • effective remedies;
  • security;
  • limits on use;
  • onward-transfer controls;
  • appropriate treatment of government-access risks. Authorisation is not a formality. The authority must examine whether the safeguards work in the legal and factual context.

28. Article 57(1)(s): Binding corporate rules

Binding corporate rules, or BCRs, provide an internal framework for transfers within a multinational corporate group or group of enterprises engaged in joint economic activity.

The authority’s approval process checks whether the BCRs are:

  • legally binding;
  • enforceable by data subjects;
  • comprehensive;
  • supported by complaint procedures;
  • subject to audit and training;
  • capable of addressing transfers, security and government-access risks.

[!example] Illustration A multinational group wants to transfer employee and customer data from its EEA companies to affiliates in several third countries. A broad statement that “all companies respect privacy” is insufficient. The BCRs must contain concrete obligations, enforcement structures and rights. Approval does not eliminate the group’s continuing duty to assess whether transfers remain lawful in practice.

29. Article 57(1)(t): Contribution to the EDPB

Every supervisory authority must contribute to the European Data Protection Board.

This may involve:

  • plenary meetings;
  • expert subgroups;
  • guidelines;
  • opinions;
  • urgent procedures;
  • dispute-resolution decisions;
  • consistency reviews;
  • coordinated enforcement;
  • exchange of experience.

This is a substantive task, not ceremonial attendance.

Illustration

The EDPB develops guidance on children’s online services. National authorities may contribute:

  • complaint trends;
  • enforcement experience;
  • technical expertise;
  • national legal context;
  • examples of harmful design. Without active national participation, European consistency would be difficult to achieve.

30. Article 57(1)(u): Internal infringement records

The authority must keep internal records of:

  • GDPR infringements;
  • corrective measures taken under Article 58(2).

These records support:

  • institutional memory;
  • consistency in sanctions;
  • annual reports;
  • strategic planning;
  • identification of repeat offenders;
  • evaluation of enforcement effectiveness;
  • cooperation with other authorities.

Illustration

If separate departments repeatedly investigate the same company, proper records help identify:

  • earlier warnings;
  • prior orders;
  • repeated security failures;
  • whether previous measures were effective. The supplied Commentary suggests that a minimal bullet-point record might be sufficient and that fine amounts need not be included. That is an unduly narrow view. Article 57 does not prescribe the exact fields, but meaningful records should ordinarily include enough information to understand the infringement and response, potentially including:
  • date;
  • controller or processor;
  • relevant provisions;
  • facts;
  • measure;
  • fine where applicable;
  • compliance status;
  • appeal outcome. Internal records must themselves be securely protected because they may contain personal data, confidential information and ongoing investigative details.

31. Article 57(1)(v): Other data-protection tasks

Point (v) is a residual clause covering other tasks related to personal-data protection.

Possible examples include:

  • additional national authorisation functions;
  • privacy research;
  • regulatory cooperation;
  • management of national registers;
  • approved educational initiatives;
  • functions under national legislation compatible with the GDPR.

The clause should not be used to overload the authority with unrelated responsibilities or compromise independence.

Illustration

A Member State gives the supervisory authority responsibility for freedom-of-information oversight. That may be compatible if:

  • conflicts are managed;
  • sufficient resources are provided;
  • privacy responsibilities remain effective;
  • independence is preserved. A government should not assign numerous unrelated duties and then use the resulting workload to excuse failure to handle GDPR complaints.

32. Article 57(2): Facilitating complaint submission

The authority must make complaints easy to submit.

The Article specifically mentions an electronic complaint form but expressly preserves other methods of communication.

A compliant system should not assume that everyone:

  • has internet access;
  • can use electronic signatures;
  • can write in legal language;
  • understands regulator jurisdiction;
  • can upload particular file formats;
  • has no disability.

Useful channels may include:

  • online forms;
  • email;
  • post;
  • accessible telephone support;
  • in-person assistance where appropriate;
  • formats usable with assistive technology.

The CJEU stated in Case C-416/23 that facilitation and free performance of supervisory tasks are intended to enable every data subject to seek enforcement of GDPR rights.

32.1 The official form cannot be the only route

A standard form can improve clarity, but “without excluding other means of communication” prevents rigid form-only systems.

Illustration

A person emails a clear complaint with all essential facts. The authority should not reject it solely because the person failed to copy the information into an online portal. It may reasonably ask for missing details or identity verification where necessary.

32.2 Accessibility and data minimisation

The complaint mechanism should request information necessary to understand and process the case. It should not collect excessive information from complainants.

For example, requiring a full passport copy for every complaint may be disproportionate where identity can be established less intrusively.


33. Article 57(3): Free of charge

The performance of the authority’s tasks must be free for:

  • the data subject; and
  • the data protection officer, where applicable.

This ensures that financial barriers do not prevent enforcement of a fundamental right.

Illustration

An employee asks the authority how to exercise the right of access. The authority cannot charge an advisory fee. A DPO seeks guidance about a prior-consultation process. The authority should not charge the DPO personally for performing the statutory task.

33.1 Controllers and processors

Article 57(3) expressly mentions data subjects and, where applicable, DPOs. It does not create a universal rule that every service for controllers and processors must always be free.

Fees may potentially arise under lawful national systems for matters such as certain accreditation or certification processes. Any fee must be compatible with:

  • the GDPR;
  • effective performance of the authority’s task;
  • proportionality;
  • independence;
  • national law.

An authority cannot convert routine GDPR supervision into a paid consultancy service.


34. Article 57(4): Manifestly unfounded or excessive requests

Paragraph 4 creates a narrow exception.

Where a request is manifestly unfounded or excessive, particularly because of repetition, the authority may:

  • charge a reasonable fee based on administrative costs; or
  • refuse to act.

The authority bears the burden of proving the request’s manifestly unfounded or excessive character.

Because this exception limits access to enforcement, it must be applied carefully.


35. “Request” includes a complaint

The CJEU confirmed on 9 January 2025 in Case C-416/23, Österreichische Datenschutzbehörde v FR, that “request” under Article 57(4) includes complaints under Articles 57(1)(f) and 77(1).

This resolves a textual uncertainty. Paragraph 4 is not limited to requests for general information under point (e). It can apply to complaints, but only when its strict conditions are met.


36. Manifestly unfounded requests

A request may be manifestly unfounded where it plainly lacks any identifiable basis and no reasonable clarification could change that conclusion.

Possible examples include:

  • the facts clearly have no connection to personal-data processing;
  • the complaint concerns only information about a legal entity with no identifiable individual;
  • the authority has already finally decided the identical complaint and no new facts exist;
  • the allegation is demonstrably impossible;
  • the complainant refuses to identify any challenged processing despite reasonable assistance.

“Manifestly” means the absence of foundation should be clear, not merely arguable.

Illustration

A person complains that a restaurant’s soup tastes bad and asks the data protection authority to impose a GDPR fine. No personal-data issue is alleged. That request is plainly outside the authority’s data-protection role. By contrast, a complaint presenting a weak but legally arguable claim is not automatically manifestly unfounded.

37. Excessive requests after Case C-416/23

The 2025 CJEU judgment is crucial.

The Court held that requests cannot be classified as excessive solely because many were submitted during a particular period. The authority must demonstrate an abusive intention, considering all relevant circumstances.

In that case, the individual had reportedly lodged 77 complaints over approximately 20 months. The volume alone was insufficient.

Why number alone is unreliable

A person may submit many legitimate complaints because many controllers have infringed their rights.

Illustration

An individual sends access requests to fifty data brokers. Forty ignore the requests. Filing forty complaints may be burdensome for the authority, but the volume results from forty alleged violations. It does not prove abuse. Repetition becomes more relevant where the person:

  • repeatedly submits the identical claim after a final decision;
  • manufactures disputes with no objective need to protect rights;
  • uses submissions primarily to disrupt the authority;
  • refuses reasonable consolidation while generating needless duplication. The authority must prove abuse rather than infer it from inconvenience.

38. Fee or refusal

Where paragraph 4 applies, the authority may choose between:

  • a reasonable administrative fee; and
  • refusal to act.

The CJEU held that the authority must choose an option that is appropriate, necessary and proportionate. Charging a fee may sometimes interfere less with rights than refusing to act, although the authority is not always required to try a fee first.

[!example] Illustration A person repeatedly asks for copies of the same already provided material for a disruptive purpose. A modest cost-based fee may address the administrative burden. A person repeatedly resubmits an identical, finally rejected complaint without any new facts. Refusal may be more appropriate. The fee cannot be punitive or designed to deter legitimate complaints. It must be based on actual administrative costs.

39. Burden of proof and reasons

The authority bears the burden of demonstrating that the request is manifestly unfounded or excessive.

Its decision should identify:

  • the relevant requests;
  • their pattern;
  • the circumstances indicating abuse;
  • why less restrictive handling would be inadequate;
  • the calculation of any fee;
  • available judicial remedies.

A vague statement that the person is “difficult” or “uses too many resources” is insufficient.

The authority’s own underfunding does not make a legitimate complaint excessive. Member States must provide adequate resources under Article 52(4), and C-416/23 rejected a purely numerical approach to complaint volume.


40. Final synthesis

Article 57 transforms supervisory authorities from nominal institutions into active guardians of data protection.

It requires them to:

  • watch how organisations process data;
  • correct violations;
  • educate the public and children;
  • advise lawmakers;
  • help controllers and processors understand their duties;
  • explain rights to individuals;
  • handle complaints diligently;
  • cooperate across borders;
  • investigate on their own initiative;
  • understand technological and commercial change;
  • oversee contractual, transfer, code and certification mechanisms;
  • contribute to the EDPB;
  • maintain institutional records;
  • perform other legitimate privacy tasks.

Paragraphs 2 to 4 ensure that access to these functions is practical. Complaints must be easy to make and ordinarily free. The abuse exception exists, but it is narrow, fact-specific and controlled by the authority’s burden of proof.

The central distinction throughout Article 57 is between discretion and obligation.

The authority has discretion over:

  • investigative methods;
  • priorities;
  • proportional remedies;
  • format of guidance;
  • allocation of resources.

It does not have discretion to:

  • abandon complaint handling;
  • ignore serious evidence;
  • refuse cooperation;
  • charge ordinary complainants;
  • treat volume alone as abuse;
  • remain inactive without explanation.

In the simplest terms:

Article 57 requires the supervisory authority to educate before problems arise, advise while systems are being designed, investigate when concerns emerge, enforce when violations occur and remain accessible to every person whose rights may have been affected.

That combination of prevention, assistance, investigation and enforcement is what makes the authority a genuine regulator rather than merely a recipient of complaints.