CHAPTER VIINDEPENDENT SUPERVISORY AUTHORITIES

Article 58Powers

Official text

(1)Each supervisory authority shall have all of the following investigative powers:

(a)to order the controller and the processor, and, where applicable, the controller’s or the processor’s representative to provide any information it requires for the performance of its tasks;

(b)to carry out investigations in the form of data protection audits;

(c)to carry out a review on certifications issued pursuant to Article 42 (7);

(d)to notify the controller or the processor of an alleged infringement of this Regulation;

(e)to obtain, from the controller and the processor, access to all personal data and to all information necessary for the performance of its tasks;

(f)to obtain access to any premises of the controller and the processor, including to any data processing equipment and means, in accordance with Union or Member State procedural law.

(2)Each supervisory authority shall have all of the following corrective powers:

(a)to issue warnings to a controller or processor that intended processing operations are likely to infringe provisions of this Regulation;

(b)to issue reprimands to a controller or a processor where processing operations have infringed provisions of this Regulation;

(c)to order the controller or the processor to comply with the data subject’s requests to exercise his or her rights pursuant to this Regulation;

(d)to order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period;

(e)to order the controller to communicate a personal data breach to the data subject;

(f)to impose a temporary or definitive limitation including a ban on processing;

(g)to order the rectification or erasure of personal data or restriction of processing pursuant to Articles 16, 17 and 18 and the notification of such actions to recipients to whom the personal data have been disclosed pursuant to Article 17 (2) and Article 19;

(h)to withdraw a certification or to order the certification body to withdraw a certification issued pursuant to Articles 42 and 43, or to order the certification body not to issue certification if the requirements for the certification are not or are no longer met;

(i)to impose an administrative fine pursuant to Article 83, in addition to, or instead of measures referred to in this paragraph, depending on the circumstances of each individual case;

(j)to order the suspension of data flows to a recipient in a third country or to an international organisation.

(3)Each supervisory authority shall have all of the following authorisation and advisory powers:

(a)to advise the controller in accordance with the prior consultation procedure referred to in Article 36;

(b)to issue, on its own initiative or on request, opinions to the national parliament, the Member State government or, in accordance with Member State law, to other institutions and bodies as well as to the public on any issue related to the protection of personal data;

(c)to authorise processing referred to in Article 36 (5), if the law of the Member State requires such prior authorisation;

(d)to issue an opinion and approve draft codes of conduct pursuant to Article 40 (5);

(e)to accredit certification bodies pursuant to Article 43

(f)to issue certifications and approve criteria of certification in accordance with Article 42 (5);

(g)to adopt standard data protection clauses referred to in Article 28 (8) and in point (d) of Article 46 (2);

(h)to authorise contractual clauses referred to in point (a) of Article 46 (3);

(i)to authorise administrative arrangements referred to in point (b) of Article 46 (3);

(j)to approve binding corporate rules pursuant to Article 47.

(4)The exercise of the powers conferred on the supervisory authority pursuant to this Article shall be subject to appropriate safeguards, including effective judicial remedy and due process, set out in Union and Member State law in accordance with the Charter.

(5)Each Member State shall provide by law that its supervisory authority shall have the power to bring infringements of this Regulation to the attention of the judicial authorities and where appropriate, to commence or engage otherwise in legal proceedings, in order to enforce the provisions of this Regulation.

(6)Each Member State may provide by law that its supervisory authority shall have additional powers to those referred to in paragraphs 1, 2 and 3. The exercise of those powers shall not impair the effective operation of Chapter VII.

Commentary

Article 58 gives GDPR supervisory authorities the legal tools needed to perform the tasks listed in Article 57. Article 57 tells an authority what it must do, while Article 58 tells it what it may legally do to investigate, prevent, correct, authorise and litigate.

The Article creates six connected layers of power:

  1. investigative powers;
  2. corrective powers;
  3. authorisation and advisory powers;
  4. procedural safeguards;
  5. powers to bring matters before courts; and
  6. the possibility of additional national powers.

These powers are deliberately broad. A supervisory authority may demand information, inspect databases and premises, order compliance, prohibit processing, suspend international transfers, withdraw certifications and impose administrative fines. At the same time, those powers are not unlimited. They must be exercised lawfully, impartially, fairly, proportionately and subject to effective judicial review. Recital 129 explains that binding measures should be written, clear, reasoned and accompanied by information about the right to an effective remedy.


1. The relationship between tasks, powers and competence

Three ideas must be kept separate:

  • Tasks under Article 57 describe the authority’s responsibilities.
  • Powers under Article 58 describe the legal tools it may use.
  • Competence under Articles 55 and 56 determines when and where the authority may act.

Illustration

A supervisory authority receives a complaint that an employer secretly monitors workers’ emails. Its relevant:

  • task is to handle the complaint and investigate it;
  • power is to order information, inspect systems and issue corrective measures;
  • competence depends on territorial and, where applicable, cross-border rules. Having a power does not mean that an authority may use it in every case. The authority must first be competent and must then exercise the power for a legitimate GDPR purpose.

2. Article 58 as a minimum common enforcement toolkit

Article 58 standardises the principal powers of supervisory authorities across the EEA. A controller should not face an authority in one Member State that can only issue informal recommendations and an authority in another that can inspect systems and impose binding orders.

The GDPR therefore requires each supervisory authority to have the powers listed in paragraphs 1 to 3. These powers arise from the Regulation itself, although their practical exercise may depend on national procedural law, particularly for matters such as:

  • entry into premises;
  • judicial warrants;
  • evidence handling;
  • service of decisions;
  • enforcement of fines;
  • appeals;
  • professional secrecy;
  • procedural deadlines.

Member States may supplement these powers under paragraph 6, but they may not use national law to empty the prescribed GDPR powers of practical effect. The listed powers include information orders, audits, access to data and premises, warnings, reprimands, compliance orders, processing bans, transfer suspensions and fines.

2.1 Powers are not automatic punishments

Article 58 gives the authority a range of possible responses. It does not require the authority to use every power whenever it finds an infringement.

The authority must select a response that is:

  • appropriate;
  • necessary;
  • effective;
  • proportionate;
  • suited to the facts of the case.

In Land Hessen, Case C-768/21, the CJEU held on 26 September 2024 that a supervisory authority is not required to use a corrective power, particularly a fine, in every case where an infringement has occurred. It may refrain where the controller has already taken the necessary measures to end the infringement and prevent recurrence, provided that inaction does not undermine effective GDPR enforcement.

Illustration

An employee accesses one customer’s file without permission. The controller:

  • detects the incident quickly;
  • prevents further access;
  • disciplines the employee;
  • documents the event;
  • improves access controls;
  • demonstrates that the information was not copied or disclosed. The supervisory authority may conclude that no additional corrective measure is needed. The situation would be very different if the controller ignored the incident, retained weak access controls and refused to investigate.

3. Article 58(1): Investigative powers

Investigative powers allow the authority to establish facts before reaching a conclusion.

A fair enforcement process should not begin with the assumption that every allegation is true. The authority must determine:

  • what personal data were involved;
  • who determined the processing;
  • what purpose was pursued;
  • which legal basis was used;
  • what systems were involved;
  • who had access;
  • what safeguards existed;
  • whether individuals suffered or risked harm.

The authority may combine several investigative powers. For example, it may send an information request, perform an audit, inspect databases and visit premises as parts of the same investigation.

Investigative powers are not themselves necessarily findings of guilt. They are evidence-gathering mechanisms.


4. Article 58(1)(a): Ordering information

The authority may order:

  • the controller;
  • the processor; and
  • where applicable, the Article 27 representative

to provide information required for the performance of its tasks.

The words“any information it requires” are broad, but they must be read with the authority’s statutory purpose and the proportionality safeguards in paragraph 4.

An authority may request information concerning:

  • the purposes of processing;
  • legal bases;
  • categories of personal data;
  • categories of data subjects;
  • data recipients;
  • retention periods;
  • access controls;
  • security measures;
  • breach records;
  • processing agreements;
  • data protection impact assessments;
  • legitimate-interest assessments;
  • consent records;
  • privacy notices;
  • international transfers;
  • subprocessor arrangements;
  • data protection officer communications;
  • records of processing activities;
  • main-establishment decision-making.

Illustration

A platform claims that its main establishment is in Ireland and that the Irish authority should be the lead supervisory authority. The authority may require:

  • board minutes;
  • internal delegations;
  • reporting structures;
  • names and locations of decision-makers;
  • documents showing who determines advertising purposes;
  • evidence that the Irish establishment can implement those decisions. The controller’s own statement is not conclusive.

4.1 Information must be relevant

The phrase “for the performance of its tasks” limits the request. The authority should not demand information unrelated to the investigation.

Illustration

If the investigation concerns deletion of customer records, the authority may need:

  • retention schedules;
  • deletion logs;
  • backup policies;
  • system architecture;
  • processor instructions. It would have difficulty justifying a demand for every employee’s private medical history.

4.2 Form and deadline

Information may be supplied through:

  • documents;
  • written explanations;
  • structured questionnaires;
  • database extracts;
  • system demonstrations;
  • technical diagrams;
  • audio or video records;
  • oral hearings where national procedure permits.

The order should specify:

  • what information is required;
  • the relevant investigation;
  • the legal basis;
  • the deadline;
  • the form of response;
  • consequences of non-compliance;
  • available remedies.

An impossibly short deadline may breach proportionality and due process. Conversely, controllers should not use repeated delay requests to frustrate the investigation.

4.3 The Article 27 representative

A non-EEA controller may be required to appoint an EEA representative under Article 27. The representative can be ordered to provide information where applicable.

However, the representative is not automatically the controller, the controller’s main establishment or the person personally liable for every GDPR infringement. Its legal responsibilities must be assessed according to Article 27 and the facts.

4.4 Self-incrimination

The supplied commentary states broadly that a controller may refuse information whenever the response may expose it to sanctions. That is too categorical.

The privilege against self-incrimination may form part of the applicable procedural safeguards, particularly where the investigation can lead to punitive sanctions. But its scope is technically complex. It may protect a person against being forced to provide answers amounting to an admission of wrongdoing, while not necessarily creating a general right to withhold pre-existing business records, processing logs or documents that the organisation is legally required to maintain.

The exact protection depends on:

  • the nature of the person compelled;
  • the nature of the information;
  • whether the material already exists;
  • the punitive character of the proceedings;
  • applicable EU and national procedural law;
  • Charter protections;
  • relevant criminal or administrative case law.

A controller should not assume that invoking “self-incrimination” automatically permits non-cooperation. Article 31 requires cooperation with the supervisory authority, and failure to provide access or comply with an order can itself attract serious consequences under Article 83. Article 58’s powers must nevertheless be exercised consistently with due process under paragraph 4.


5. Article 58(1)(b): Data protection audits

An audit is a structured examination of processing activities and safeguards.

It may cover:

  • governance;
  • lawfulness;
  • transparency;
  • data minimisation;
  • retention;
  • rights handling;
  • security;
  • breach management;
  • processor supervision;
  • international transfers;
  • privacy by design;
  • data protection impact assessments;
  • training;
  • accountability documentation.

An audit may be:

  • comprehensive;
  • focused on one processing operation;
  • sector-wide;
  • remote;
  • on-site;
  • announced;
  • unannounced where national law permits and the circumstances justify it.

Illustration

A hospital claims that access to patient records is limited to treating staff. The authority may audit:

  • user permissions;
  • role assignments;
  • authentication controls;
  • access logs;
  • disciplinary procedures;
  • emergency-access accounts;
  • retention of logs;
  • monitoring of suspicious access;
  • staff training. The point is not merely to examine the written policy. The authority must determine whether the controls work in practice.

5.1 Audit versus information request

An information request usually asks the organisation to provide specified material.

An audit is generally more systematic. It may involve testing the organisation’s claims and comparing documented procedures with actual operations.

Illustration

The controller says: “All personal data are deleted after 30 days.” An information request may ask for the retention policy. An audit may test the application, backups, archive systems and deletion logs to see whether the 30-day rule is genuinely implemented.

5.2 Audit scope and proportionality

An authority should define the audit’s scope with sufficient clarity. A sector-wide audit may be justified where there is evidence of systemic risk, but investigators should avoid collecting excessive information unrelated to the stated purpose.

A small complaint about one marketing email does not ordinarily justify copying every database held by an entire corporate group.

6. Article 58(1)(c): Reviewing certifications

The authority may review certifications granted under Article 42.

Certification is intended to demonstrate that a specified processing operation meets approved criteria. It does not create immunity from investigation.

The authority may examine:

  • whether the certified operation still matches the certified design;
  • whether the organisation continues meeting the criteria;
  • whether relevant material was concealed;
  • whether new subprocessors were introduced;
  • whether security has deteriorated;
  • whether the certification body acted properly.

Illustration

A cloud service is certified for encrypted storage within the EEA. It later adds an unencrypted analytics pipeline and begins transferring logs abroad. The authority may review whether:

  • the certification remains accurate;
  • the new activity falls within its scope;
  • the certification should be withdrawn;
  • the certification body failed in its monitoring. A review does not prejudge the result. The authority must gather evidence and respect the rights of the certificate holder and certification body.

7. Article 58(1)(d): Notification of an alleged infringement

The authority may notify the controller or processor of an alleged infringement.

The word“alleged” is vital. At this stage, the authority has not necessarily made a final finding.

This notification supports procedural fairness by informing the organisation:

  • what conduct is questioned;
  • which GDPR provisions may be relevant;
  • what factual concerns exist;
  • what response or evidence is requested.

Illustration

An authority receives evidence suggesting that an employer uses facial recognition without a valid legal basis. It sends a notice explaining that:

  • Article 6 lawfulness is in question;
  • Article 9 special-category rules may apply;
  • the necessity of biometric attendance is disputed;
  • the employer may submit evidence and legal arguments. The employer may rebut the allegation, correct misunderstandings or voluntarily redesign the processing.

7.1 Allegation is not a reprimand

An Article 58(1)(d) notification differs from a reprimand under Article 58(2)(b).

  • A notification concerns a possible infringement under investigation.
  • A reprimand follows a finding that processing has infringed the GDPR.

Confusing these stages can violate the presumption of impartial investigation and the right to be heard.


8. Article 58(1)(e): Access to personal data and all necessary information

This power is broader and more intrusive than an ordinary information request.

The authority can obtain access to:

  • personal data;
  • internal databases;
  • processing records;
  • system documentation;
  • security configurations;
  • logs;
  • consent records;
  • internal communications relevant to processing;
  • policies;
  • algorithms and decision rules where necessary;
  • processor instructions;
  • transfer documentation.

Illustration

A credit-scoring company claims that it does not use health information. The authority may inspect:

  • input fields;
  • source datasets;
  • model documentation;
  • feature-engineering records;
  • proxy variables;
  • access logs;
  • decision outputs. A policy document alone may not reveal that postcode and pharmacy-purchase data operate as health proxies.

8.1 “All personal data” is not unlimited access

The words “all personal data” must be read with “necessary for the performance of its tasks.”

The authority should access what it reasonably needs. It should also protect the information it obtains through:

  • confidentiality;
  • secure evidence handling;
  • access restrictions;
  • purpose limitation;
  • professional secrecy under Article 54.

The authority does not become free to use inspected data for unrelated political, commercial or personal purposes.

8.2 Data held by processors

The controller cannot avoid investigation by storing information with a processor.

Both controllers and processors are directly subject to the access power. Where the processor holds the relevant data or system records, the authority may obtain access from it, subject to competence and procedural rules.

8.3 Privileged and confidential information

Recital 164 and Article 90 allow Member States to adopt rules reconciling supervisory access with professional or equivalent secrecy obligations.

This may affect:

  • lawyer-client confidentiality;
  • medical secrecy;
  • banking secrecy;
  • journalistic source protection;
  • professional duties of confidence.

Professional secrecy does not necessarily create a complete exemption from data protection supervision. National law should reconcile the competing legal interests without making the authority’s powers ineffective.

Illustration

A law firm processes client files. The authority investigates the firm’s cybersecurity. The firm should not be able to refuse every inquiry merely because legal work is confidential. At the same time, the authority should avoid unnecessary access to privileged legal advice and may use safeguards such as:

  • filtered searches;
  • independent review;
  • redaction;
  • limited access;
  • judicial supervision.

9. Article 58(1)(f): Access to premises, equipment and means

The authority may obtain access to any premises of the controller or processor, including data-processing equipment and means, subject to Union or national procedural law.

Possible locations include:

  • offices;
  • server rooms;
  • archives;
  • data centres;
  • call centres;
  • storage facilities;
  • premises where paper files are kept;
  • locations where processing equipment is operated.

Possible equipment and means include:

  • computers;
  • servers;
  • mobile devices;
  • access-control systems;
  • CCTV equipment;
  • biometric systems;
  • backup media;
  • network devices;
  • filing cabinets containing structured records.

9.1 Access is not unrestricted entry

This provision does not permit investigators to disregard national constitutional protections.

Recital 129 expressly recognises that access to premises may be subject to specific national procedural requirements, including prior judicial authorisation.

Relevant safeguards may include:

  • warrants;
  • defined inspection scope;
  • identification of authorised officials;
  • limits on timing;
  • rights of legal representation;
  • inventory of copied material;
  • rules on sealing or preserving evidence;
  • protection of privileged information;
  • judicial challenge.

9.2 Private homes and remote work

The reference to “any premises” should not be read as automatic authority to enter a private home.

Where business processing occurs from a residence, national law must reconcile:

  • effective supervision;
  • privacy of the home;
  • necessity;
  • proportionality;
  • judicial authorisation.

Illustration

A sole trader operates a health-data service entirely from a home office. The authority may have a legitimate need to inspect the computer used for processing. But entry into the home may require a warrant and a carefully limited inspection. The presence of one business laptop does not justify searching unrelated family rooms or devices.

9.3 Cross-border premises

A French authority cannot ordinarily enter a German data centre under French public powers.

It must use:

  • mutual assistance;
  • joint operations;
  • the Article 60 procedure;
  • cooperation with the German authority.

Article 58 gives substantive powers, while Articles 55, 56 and Chapter VII govern which authority may exercise them and how.


10. Obstruction and non-compliance

A controller or processor should not:

  • conceal documents;
  • destroy logs;
  • provide knowingly misleading information;
  • block lawful system access;
  • ignore binding orders;
  • coach employees to provide false answers.

Non-compliance with an Article 58 order or failure to provide access can trigger the higher Article 83 fine tier, potentially up to €20 million or 4 percent of total worldwide annual turnover for an undertaking, whichever statutory maximum is higher.

That does not remove the organisation’s right to challenge an unlawful order. The lawful response is to use available administrative or judicial remedies, not secretly obstruct investigators.


11. Article 58(2): Corrective powers

Corrective powers allow the authority to remedy an infringement or prevent an intended unlawful operation.

The powers form a graduated toolkit:

  • warning;
  • reprimand;
  • rights-compliance order;
  • general compliance order;
  • breach-communication order;
  • limitation or ban;
  • rectification, erasure or restriction;
  • certification withdrawal;
  • fine;
  • transfer suspension.

They are not arranged as a rigid ladder that must be climbed one step at a time. A serious infringement may justify an immediate prohibition or fine. A minor, corrected infringement may justify a reprimand or, exceptionally, no further measure.

In Land Hessen, the CJEU explained that supervisory authorities retain discretion over the corrective measure but must use that discretion consistently with strong and effective GDPR enforcement. They may refrain from corrective action only where further intervention is unnecessary in the circumstances.


12. Article 58(2)(a): Warnings

A warning concerns intended processing that is likely to infringe the GDPR.

It is preventive rather than retrospective.

Illustration

A company plans to launch a workplace emotion-recognition system. During prior consultation, the authority concludes that:

  • the system will process biometric or health-related inferences;
  • its accuracy is poor;
  • less intrusive methods exist;
  • workers cannot freely consent;
  • safeguards are inadequate. The authority may warn that launching the system as designed is likely to violate the GDPR.

12.1 Warning versus advice

Advice under Article 58(3)(a) helps the controller understand or mitigate risk.

A warning is a stronger regulatory signal that the intended processing is likely unlawful.

A warning should identify:

  • the proposed processing;
  • the suspected legal problem;
  • the factual basis;
  • the measures that may avoid infringement;
  • possible consequences of proceeding.

Although the supplied commentary suggests that a warning could be oral, a formal written warning is normally preferable. Recital 129 expects legally binding measures to be written, clear, reasoned and reviewable.


13. Article 58(2)(b): Reprimands

A reprimand concerns processing that has already infringed the GDPR.

It formally records regulatory disapproval and a finding of infringement.

Illustration

A small organisation sends customer email addresses to the wrong recipient. It reports the incident, secures deletion, updates procedures and trains staff. The authority may issue a reprimand rather than a fine if that response is effective and proportionate.

13.1 A reprimand is not merely informal criticism

A reprimand may have significant consequences:

  • it records the infringement;
  • future repetition may be treated more seriously;
  • it may be published;
  • it may affect certification or procurement;
  • it may be considered in later Article 83 decisions.

The assertion that a reprimand is used only where the “threshold for a fine” is not reached is too narrow. Article 58(2)(i) permits a fine in addition to another measure. A reprimand and a fine may therefore coexist if proportionate.


14. Article 58(2)(c): Ordering compliance with data subject requests

The authority may order compliance with a person’s valid request under the GDPR.

This may concern:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • portability;
  • objection;
  • rights concerning automated decisions.

Illustration

A platform answers an access request by providing only the user’s name and email address, while withholding:

  • profiling categories;
  • inferred interests;
  • advertising recipients;
  • source information;
  • retention information. The authority may order the controller to provide a complete response within a specified period.

14.1 The underlying request must be valid

The authority must first determine whether the right applies.

For example:

  • erasure may be refused where retention is legally necessary;
  • portability applies only under the conditions in Article 20;
  • access may be limited to protect the rights and freedoms of others;
  • objection does not always produce automatic cessation.

The authority may not order a result that the GDPR itself does not require.

14.2 Orders to processors

Paragraph 2(c) refers to controllers and processors. In practice, many data subject rights are primarily obligations of the controller. A processor may nevertheless need to assist, comply with lawful supervisory measures or correct conduct for which it bears direct GDPR responsibility.

The order must accurately reflect the roles of the parties.


15. Article 58(2)(d): General compliance orders

This is one of the broadest corrective powers.

The authority may order a controller or processor to bring processing into compliance:

  • in a specified manner;
  • within a specified period.

Possible orders include:

  • adopting security controls;
  • changing retention periods;
  • appointing a DPO;
  • revising privacy information;
  • concluding a proper processor contract;
  • conducting a DPIA;
  • limiting internal access;
  • redesigning consent;
  • correcting camera angles;
  • stopping secondary use;
  • establishing rights-handling procedures.

Illustration

A hotel stores full passport scans indefinitely. The authority may order it to:

  • identify a valid purpose and legal basis;
  • stop collecting unnecessary copies;
  • delete records exceeding the justified retention period;
  • create a documented retention schedule;
  • report completion within 60 days.

15.1 Specificity

An order must be sufficiently clear to enforce.

A vague direction such as:

“Comply with the GDPR immediately”

may be inadequate because the recipient cannot determine what must change.

The order should identify:

  • affected processing;
  • infringement;
  • required result;
  • deadline;
  • evidence of compliance.

15.2 Outcome versus method

Where several equally effective compliance solutions exist, proportionality may require the authority to specify the result while allowing the controller some freedom over implementation.

[!example] Illustration The authority finds that authentication is inadequate. If several technologies can achieve appropriate security, it may order robust multi-factor authentication or equivalent protection rather than requiring one named vendor without justification. More prescriptive directions may be justified where the organisation has repeatedly failed or where only one measure can effectively address the risk.

16. Article 58(2)(e): Ordering communication of a breach

The authority may order the controller to communicate a personal data breach to affected individuals.

This power is linked to Article 34. Communication is generally required where the breach is likely to result in a high risk to people’s rights and freedoms, unless an Article 34 exception applies.

Illustration

A clinic loses an unencrypted file containing:

  • patient names;
  • diagnoses;
  • medication;
  • contact details. The clinic reports the breach to the authority but decides not to tell patients. The authority may find that the breach presents a high risk and order communication so that patients can:
  • watch for misuse;
  • inform healthcare providers;
  • protect accounts;
  • take other precautions.

16.1 Why the order is directed to the controller

Even if the breach occurred at a processor, the controller normally bears responsibility for communicating with affected individuals. The processor must notify the controller without undue delay under Article 33(2).

The authority’s order should also consider the content and method of communication. A vague notice should not obscure the nature of the risk.


17. Article 58(2)(f): Temporary or definitive limitation, including a ban

This is among the strongest Article 58 powers.

A limitation may restrict:

  • particular data categories;
  • particular purposes;
  • use by specific departments;
  • processing of children’s data;
  • automated decisions;
  • disclosure to certain recipients;
  • retention beyond a period;
  • use of a specific technology.

A ban stops the specified processing entirely.

17.1 Temporary versus definitive measures

A temporary limitation may be appropriate while:

  • facts are investigated;
  • safeguards are implemented;
  • legal uncertainty is resolved;
  • an urgent risk is contained.

A definitive ban may be appropriate where the processing cannot lawfully continue.

Illustration

A company uses facial recognition to identify every person entering a shopping centre without a valid legal basis. If no less intrusive redesign can make the system lawful, a definitive ban may be proportionate. If a security defect can be corrected within two weeks, a temporary suspension may be sufficient.

17.2 Is a ban always a last resort?

A ban is severe and the authority should consider whether a less restrictive measure can achieve compliance.

However, “last resort” should not mean that the authority must first issue every weaker measure.

Illustration

An organisation sells stolen medical records. The authority need not begin with awareness guidance, then a warning, then a reprimand. An immediate prohibition may be the only effective response. Proportionality asks whether a less intrusive measure would be equally effective, not whether every softer power has previously been tried.

17.3 Interim restrictions before a final decision

Temporary restrictions before a final merits decision require special care. They may be justified by urgent and serious risks, but must comply with:

  • legal authority;
  • procedural safeguards;
  • time limits;
  • necessity;
  • proportionality;
  • right to challenge;
  • Article 66 where the case is cross-border and urgent.

A provisional measure should not become an indefinite punishment without a final determination.


18. Article 58(2)(g): Rectification, erasure and restriction

The authority may order:

  • correction of inaccurate data;
  • erasure under Article 17;
  • restriction under Article 18;
  • notification of those actions to recipients under Article 19 and, where applicable, Article 17(2).

Illustration

A credit bureau stores an inaccurate insolvency record and shares it with banks. The authority may order the controller to:

  1. correct or erase the record;
  2. stop using it while accuracy is disputed;
  3. notify banks that received the incorrect information;
  4. provide evidence of completion.

18.1 No prior request is necessarily required

The authority may discover unlawful or inaccurate data during an ex officio investigation. It need not always wait for the affected individual to request erasure first.

18.2 Erasure is not automatic

The conditions and exceptions in Article 17 still apply.

Data may need to be retained for:

  • legal obligations;
  • freedom of expression;
  • public-interest archiving;
  • legal claims;
  • public-health purposes.

The supervisory authority must apply the substantive conditions rather than use Article 58(2)(g) as a free-standing power to erase any data it dislikes.

18.3 Recipient notification

If data have been shared, correction only in the controller’s own system may be inadequate.

The authority can require notification to recipients so they can update their own records. This prevents inaccurate or unlawful data from continuing to circulate.


19. Article 58(2)(h): Certification withdrawal or prevention

The supervisory authority may:

  • withdraw a certification it issued;
  • order the certification body to withdraw a certification;
  • order the body not to issue certification.

The power applies where certification requirements are not or are no longer met.

Illustration

A processor receives certification for strong access controls. It later:

  • gives shared administrator accounts to contractors;
  • stops maintaining logs;
  • conceals incidents;
  • fails repeated audits. The authority may require withdrawal.

19.1 Certification is not permanent

Certification is not a purchased badge that remains valid regardless of later conduct.

It depends upon continued compliance with:

  • certification criteria;
  • monitoring requirements;
  • factual representations;
  • relevant GDPR obligations.

Withdrawal protects the public from relying on an inaccurate assurance.


20. Article 58(2)(i): Administrative fines

The authority may impose an administrative fine under Article 83:

  • instead of another corrective measure; or
  • in addition to another corrective measure.

A fine serves purposes such as:

  • punishment;
  • deterrence;
  • accountability;
  • reinforcement of compliance.

The authority must consider Article 83 factors, including:

  • nature, gravity and duration;
  • number of affected persons;
  • degree of damage;
  • intention or negligence;
  • mitigation;
  • technical and organisational measures;
  • previous infringements;
  • cooperation;
  • categories of data;
  • manner in which the authority learned of the infringement;
  • compliance with earlier measures;
  • codes or certifications;
  • other aggravating or mitigating factors.

20.1 A fine is not mandatory in every case

Land Hessen confirms that an authority need not impose a fine whenever an infringement is found. The authority has structured discretion, but it must ensure effective and strong enforcement.

Illustration

Two controllers commit similar accidental disclosure errors. Controller A:

  • detects the event immediately;
  • informs the authority;
  • protects affected individuals;
  • improves systems;
  • has no prior infringements. Controller B:
  • conceals the breach;
  • misleads investigators;
  • continues insecure processing;
  • has repeated prior violations. Different sanctions are justified.

20.2 Fine plus compliance order

A fine addresses the infringement already committed. A compliance order addresses ongoing or future conduct.

Illustration

A company unlawfully profiles children. The authority may:

  • fine the company for past unlawful processing;
  • order deletion of existing profiles;
  • prohibit future profiling without a valid basis;
  • require changes to the service. These measures are complementary rather than duplicative.

20.3 Judicial review

A fine must be:

  • reasoned;
  • proportionate;
  • based on evidence;
  • imposed through fair procedure;
  • reviewable by a court.

The affected controller or processor may challenge:

  • the finding of infringement;
  • attribution of responsibility;
  • calculation of turnover;
  • aggravating factors;
  • proportionality of the amount;
  • procedural fairness.

21. Article 58(2)(j): Suspension of international data flows

The authority may order suspension of data flows to:

  • a recipient in a third country; or
  • an international organisation.

This power is not limited to situations where a country lacks an adequacy decision.

It may be relevant where:

  • standard contractual clauses are not complied with;
  • supplementary safeguards are insufficient;
  • the recipient cannot provide required protection;
  • government access undermines safeguards;
  • binding corporate rules are breached;
  • an Article 49 derogation is misused;
  • the transfer otherwise violates Chapter V.

Illustration

A European company transfers sensitive employee data under standard contractual clauses. Evidence shows that the overseas recipient:

  • ignores the contractual restrictions;
  • makes unrestricted onward transfers;
  • cannot resist disproportionate government demands;
  • refuses required audits. The authority may suspend the data flow.

21.1 Suspension is not necessarily deletion

Suspension stops the continued transfer. Depending on the facts and other powers, the authority may also require:

  • return of data;
  • deletion abroad;
  • restriction of use;
  • implementation of supplementary measures.

Those additional outcomes require a proper legal basis and a feasible, precise order.

21.2 Transfers and Commission decisions

A national supervisory authority may investigate a complaint about transfers even where a Commission adequacy decision exists. But it cannot itself declare an EU act invalid. If validity is genuinely in question, the issue must reach a national court and potentially the CJEU.


22. Choosing among corrective powers

The authority should consider:

  1. Is the infringement ongoing?
  2. Has it already been remedied?
  3. Is recurrence likely?
  4. What risks exist?
  5. Is the organisation cooperative?
  6. Has it offended before?
  7. What measure will actually achieve compliance?
  8. Would a less intrusive measure work?
  9. Is deterrence required?

10. Is urgent protection necessary?

A severe violation does not automatically require a ban if a targeted order can fully address it. Conversely, a modest fine may be ineffective where unlawful processing produces enormous commercial benefits.

The authority must not choose measures for political popularity or headline impact. It must connect the intervention to the facts and statutory objectives.


23. Article 58(3): Authorisation and advisory powers

Paragraph 3 is preventive and enabling.

It allows the authority to:

  • advise before risky processing begins;
  • issue public opinions;
  • authorise processing where national law requires;
  • approve codes;
  • accredit certification bodies;
  • approve certification criteria;
  • adopt standard clauses;
  • approve tailored transfer safeguards;
  • approve binding corporate rules.

These powers are different from corrective measures because they often operate before an infringement occurs.


24. Article 58(3)(a): Prior consultation advice

Where a DPIA shows a high residual risk, the controller must consult the supervisory authority under Article 36.

The authority may advise on:

  • risk reduction;
  • data minimisation;
  • human oversight;
  • security;
  • transparency;
  • retention;
  • legal basis;
  • necessity and proportionality.

Illustration

An insurer proposes automated analysis of genetic information to price policies. Its DPIA identifies high risks that remain after proposed safeguards. The authority may advise that:

  • certain data should not be used;
  • automated decisions need human review;
  • transparency must improve;
  • the proposed legal basis is insufficient. Advice does not transfer accountability to the authority. The controller remains responsible for its final processing decision.

25. Article 58(3)(b): Opinions to public institutions and the public

The authority may issue opinions:

  • on its own initiative;
  • at the request of parliament;
  • at the request of government;
  • to other institutions;
  • to the public.

Possible subjects include:

  • draft surveillance laws;
  • national identity databases;
  • health-data schemes;
  • facial recognition;
  • AI regulation;
  • election-related data use;
  • workplace monitoring;
  • children’s privacy.

The opinion should be independent. Government cannot require the authority to change its legal conclusion merely because the advice is politically inconvenient.

An opinion is generally advisory rather than a binding prohibition, unless a separate legal power applies.


26. Article 58(3)(c): Prior authorisation under national law

Article 36(5) permits Member States to require prior authorisation for certain processing carried out in the public interest, including social protection and public health.

This power exists only where national law has created the authorisation requirement.

Illustration

National law requires prior authorisation before a public-health body links genetic, hospital and welfare databases. The authority may assess:

  • legal basis;
  • necessity;
  • proportionality;
  • safeguards;
  • access;
  • retention;
  • security;
  • individual rights. It cannot invent a general licensing requirement for all processing if national law does not provide one.

27. Article 58(3)(d): Codes of conduct

The authority may issue an opinion on and approve draft codes under Article 40(5).

Approval requires the code to:

  • comply with the GDPR;
  • contain sufficient safeguards;
  • provide clear commitments;
  • include credible monitoring arrangements where required.

Illustration

An advertising-industry code says members may collect any data “where commercially useful.” The authority should not approve it because it fails to translate GDPR requirements into meaningful safeguards. A properly drafted code might address:

  • profiling limits;
  • children;
  • consent interfaces;
  • sensitive inferences;
  • retention;
  • objections;
  • monitoring.

28. Article 58(3)(e) and (f): Accreditation, certification and criteria

The authority may accredit certification bodies and may issue certifications or approve certification criteria.

National law and Article 43 determine whether accreditation is performed by:

  • the supervisory authority;
  • the national accreditation body;
  • both.

The authority must preserve independence and avoid conflicts.

Illustration

A certification company also sells consultancy services helping applicants pass its own certification. The authority should assess whether that commercial model compromises impartiality. Certification criteria must be:

  • clear;
  • measurable;
  • relevant;
  • technically credible;
  • consistent with the GDPR. Certification does not reduce the controller’s or processor’s responsibility for compliance.

29. Article 58(3)(g): Standard data protection clauses

The authority may adopt standard clauses under:

  • Article 28(8), for controller-processor contracts;
  • Article 46(2)(d), for international transfers.

The clauses can make compliance more accessible and consistent.

Illustration

An authority adopts standard processor clauses addressing:

  • instructions;
  • confidentiality;
  • security;
  • subprocessors;
  • rights assistance;
  • breach support;
  • deletion;
  • audit rights. Using them may satisfy parts of Article 28, but the parties must still complete the relevant details and perform the obligations in practice. Where clauses have EEA-wide implications, the consistency mechanism may require EDPB involvement.

30. Article 58(3)(h): Tailored contractual clauses

The authority may authorise non-standard contractual clauses for international transfers under Article 46(3)(a).

These are used where standard clauses do not fit the proposed arrangement.

Illustration

A research consortium develops a bespoke transfer agreement for long-term international health research. The authority examines:

  • enforceable individual rights;
  • onward transfers;
  • deletion;
  • security;
  • government access;
  • audit;
  • remedies;
  • suspension mechanisms. Authorisation does not guarantee that the transfer will remain lawful forever. Material changes may require reassessment.

31. Article 58(3)(i): Administrative arrangements between public authorities

The authority may authorise provisions in administrative arrangements between public bodies under Article 46(3)(b), provided that they include enforceable and effective rights.

Illustration

An EEA tax authority proposes regular data exchange with a third-country tax authority through a memorandum. The supervisory authority should examine:

  • purpose limitation;
  • categories of data;
  • onward disclosure;
  • retention;
  • security;
  • access and correction;
  • independent redress;
  • enforceability. Calling a document an “administrative arrangement” does not remove the need for effective safeguards.

32. Article 58(3)(j): Binding corporate rules

The authority may approve BCRs under Article 47.

BCRs govern transfers within multinational groups and must be:

  • legally binding;
  • applied throughout the group;
  • enforceable by individuals;
  • supported by training and audits;
  • transparent;
  • backed by complaint and remedy mechanisms.

Illustration

A corporate group wants to centralise customer analytics in several non-EEA countries. The authority should not approve a general promise to “respect privacy.” It should require concrete provisions dealing with:

  • data subjects’ rights;
  • liability;
  • onward transfers;
  • security;
  • government requests;
  • audit;
  • cooperation with supervisory authorities.

33. Article 58(4): Appropriate safeguards, due process and judicial remedy

Paragraph 4 is the constitutional counterweight to the authority’s extensive powers.

Every exercise of Article 58 power must be subject to appropriate safeguards, including:

  • due process;
  • effective judicial remedy;
  • Charter compliance.

Recital 129 expands these safeguards. Powers must be exercised:

  • impartially;
  • fairly;
  • within a reasonable time;
  • appropriately;
  • necessarily;
  • proportionately;
  • with respect for the right to be heard;
  • without unnecessary cost or inconvenience.

Binding decisions should be written, clear, reasoned, dated, signed and accompanied by information about the right to an effective remedy.


34. The right to be heard

Before adopting an adverse individual measure, the authority should normally give the affected person an opportunity to comment on:

  • material allegations;
  • relevant evidence;
  • proposed findings;
  • intended corrective measures.

Illustration

The authority intends to impose a major fine based on system logs supplied by a complainant. The controller should ordinarily receive enough information to:

  • understand the allegation;
  • challenge authenticity;
  • provide context;
  • present mitigating evidence. The right to be heard does not necessarily require disclosure of every confidential document. The authority may protect:
  • whistleblowers;
  • third-party personal data;
  • trade secrets;
  • investigative methods. But it must preserve the essence of the defence.

34.1 Urgent measures

In exceptional urgent cases, immediate temporary action may be justified before a complete hearing, particularly where delay creates serious harm.

Any departure from prior hearing should be:

  • legally authorised;
  • strictly necessary;
  • temporary;
  • followed promptly by an opportunity to be heard;
  • subject to judicial review.

35. Proportionality

A measure is proportionate where it:

  1. pursues a legitimate GDPR objective;
  2. is capable of achieving that objective;
  3. is necessary because no equally effective, less restrictive measure is available;
  4. does not impose an excessive burden relative to the protection achieved.

36. Reasoned decisions

A reasoned decision should explain:

  • relevant facts;
  • evidence;
  • applicable GDPR provisions;
  • legal analysis;
  • finding of infringement;
  • reasons for selecting the measure;
  • deadline;
  • consequences of non-compliance;
  • appeal rights.

Reasons serve several purposes:

  • allow the recipient to understand the decision;
  • permit compliance;
  • permit judicial review;
  • demonstrate impartiality;
  • promote consistency.

A decision merely stating “the GDPR was violated” is not enough for a complex corrective order.


37. Effective judicial remedy

Article 78 provides the GDPR remedy against a legally binding decision of a supervisory authority. The supplied commentary incorrectly refers in places to Article 79. Article 79 principally concerns remedies against controllers or processors.

Courts may review:

  • competence;
  • factual findings;
  • legal interpretation;
  • procedure;
  • proportionality;
  • choice of measure;
  • fine calculation;
  • adequacy of reasons.

The SCHUFA litigation confirmed that supervisory decisions on complaints are subject to full judicial review rather than merely minimal review for obvious error.

Judicial review does not undermine supervisory independence. It ensures that an independent regulator remains subject to law.


38. Article 58(5): Court proceedings

Each Member State must provide by law that its supervisory authority can:

  • bring infringements to the attention of judicial authorities; and
  • where appropriate, commence or participate in legal proceedings.

This paragraph requires national legislation because court structures and procedural standing differ between Member States.

Possible models include:

  • direct authority proceedings;
  • referrals to prosecutors;
  • applications for injunctions;
  • participation in administrative litigation;
  • intervention in civil proceedings;
  • proceedings to enforce unpaid fines;
  • requests for judicial warrants.

Illustration

A controller refuses to comply with an order prohibiting an unlawful surveillance system. The authority may:

  • seek judicial enforcement;
  • ask a court for an injunction;
  • refer obstruction for prosecution where applicable;
  • defend its original order in appeal proceedings. This judicial power complements, rather than replaces, administrative enforcement.

39. Article 58(6): Additional national powers

Member States may give their supervisory authorities additional powers.

Examples

may include:

  • powers to issue enforceable undertakings;
  • powers to impose periodic penalty payments;
  • broader court standing;
  • powers concerning national privacy legislation;
  • powers to order publication of decisions;
  • powers relating to specific public-sector systems. Two limits apply. First, national law may add powers but may not remove the minimum Article 58 toolkit. Second, additional powers must not impair the effective functioning of Chapter VII, which governs European cooperation and consistency.

[!example] Illustration National law gives an authority power to impose a daily penalty until a controller complies with an erasure order. That may strengthen enforcement. But national law should not allow the authority to use that power to bypass the lead-authority procedure and issue conflicting decisions in a cross-border case.

40. Professional secrecy and Article 58 access

Recital 164 recognises the need to reconcile supervisory access with professional secrecy.

This issue frequently arises with:

  • lawyers;
  • doctors;
  • financial institutions;
  • journalists;
  • clergy;
  • regulated professionals.

The correct solution is not an automatic victory for either side.

A blanket secrecy exemption could make sensitive sectors effectively immune from GDPR supervision. Unrestricted authority access could destroy legally protected confidence.

National law may use safeguards such as:

  • prior judicial permission;
  • independent filtering;
  • redaction;
  • closed review;
  • restrictions on further use;
  • separation of privileged and non-privileged material.

The outcome should preserve effective data protection supervision while respecting legitimate secrecy obligations.


41. Practical hierarchy of enforcement responses

Although Article 58 does not establish a mandatory ladder, the following framework helps explain how powers may relate:

Preventive stage

  • advice;
  • opinion;
  • warning;
  • prior authorisation conditions.

Evidence stage

  • information order;
  • audit;
  • access to data;
  • access to premises;
  • certification review.

Corrective stage

  • reprimand;
  • rights-compliance order;
  • general compliance order;
  • breach communication;
  • rectification or erasure;
  • certification withdrawal.

Restrictive stage

  • temporary limitation;
  • definitive ban;
  • transfer suspension.

Punitive and deterrent stage

  • administrative fine;
  • court proceedings;
  • additional penalties under national law.

This is not a compulsory sequence. The authority should select the power or combination suited to the particular risk and infringement.


42. A full practical illustration

Assume that a multinational recruitment platform uses an undisclosed AI model to score job applicants.

The model:

  • collects social-media information;
  • infers health and political characteristics;
  • rejects applicants automatically;
  • affects people in several Member States;
  • transfers profiles to a third-country vendor;
  • has never undergone a DPIA.

The lead supervisory authority may proceed as follows.

Investigation

It may:

  • order information about the model under Article 58(1)(a);
  • audit the processing under paragraph 1(b);
  • notify the company of alleged infringements under paragraph 1(d);
  • obtain access to applicant profiles, source data, model documentation and logs under paragraph 1(e);
  • inspect relevant systems and premises under paragraph 1(f).

Procedural fairness

The company must be told the allegations and given a meaningful opportunity to respond.

Corrective action

Depending on the findings, the authority may:

  • reprimand the company;
  • order it to provide access and explanations to applicants;
  • require a DPIA and human review;
  • prohibit use of sensitive inferences;
  • restrict automated rejection;
  • order deletion of unlawfully obtained social-media data;
  • suspend transfers to the third-country vendor;
  • impose a fine.

Cross-border cooperation

Concerned supervisory authorities must participate through Article 60. The lead authority cannot treat the matter as purely domestic merely because the main establishment is in its Member State.

Judicial review

The platform may challenge the final decision before the competent court. Affected applicants may challenge inadequate supervisory action under Article 78.

This example shows that Article 58 is a connected enforcement system, not a collection of isolated powers.


43. Important corrections and qualifications to the supplied commentary

Several statements in the supplied material require caution.

43.1 Self-incrimination is not a blanket refusal right

Its scope depends on procedural law, the nature of the requested material and relevant Charter protections. It should not be treated as an automatic basis to withhold every document exposing an infringement.

43.2 Premises do not automatically include unrestricted home searches

Access remains subject to national procedural law, constitutional protections, proportionality and, where necessary, judicial authorisation.

43.3 Warnings are not merely casual oral advice

Where a warning produces legal effects, it should comply with the written, reasoned and reviewable form emphasised by Recital 129.

43.4 Reprimands are not available only when a fine threshold is unmet

A reprimand and a fine may be imposed together where proportionate.

43.5 Bans are not always preceded by milder measures

The authority must consider less intrusive alternatives, but an immediate ban may be justified for inherently unlawful or seriously harmful processing.

43.6 Transfer suspension is not limited to lack of adequacy

It can address failures involving standard clauses, BCRs, derogations, supplementary safeguards and other Chapter V requirements.

43.7 Judicial review is under Article 78

Article 79 deals with remedies against controllers and processors, not the ordinary appeal against a supervisory authority’s binding decision.

43.8 Corrective action is not mandatory in every established infringement

The 2024 Land Hessen judgment permits exceptional non-use of corrective powers where the infringement has already been effectively remedied and further intervention is unnecessary.


44. Final synthesis

Article 58 ensures that supervisory authorities are not merely educational institutions or passive complaint recipients.

They can:

  • compel information;
  • audit processing;
  • inspect databases and premises;
  • notify alleged infringements;
  • issue warnings and reprimands;
  • enforce data subject rights;
  • order operational changes;
  • require breach communication;
  • restrict or ban processing;
  • order rectification, erasure and restriction;
  • withdraw certification;
  • impose fines;
  • suspend international transfers;
  • approve codes, clauses, certifications and BCRs;
  • advise lawmakers and controllers;
  • bring matters before courts.

But every power is surrounded by legal discipline.

The authority must act:

  • within its competence;
  • for a legitimate GDPR task;
  • on a sufficient evidential basis;
  • impartially;
  • fairly;
  • within a reasonable time;
  • through clear and reasoned measures;
  • with respect for hearing rights;
  • proportionately;
  • subject to judicial review.

The simplest way to understand Article 58 is:

The supervisory authority may ask, inspect, verify, warn, order, prohibit, fine, authorise and litigate, but it must always explain why its intervention is lawful, necessary and proportionate.

Article 58 therefore balances two equally important principles.

The first is effective enforcement. A regulator without access, inspection, ordering and sanctioning powers could not protect individuals against powerful governments or companies.

The second is the rule of law. A regulator with unlimited and unreviewable powers could itself become a threat to rights.

The GDPR resolves that tension by giving supervisory authorities very strong powers while making their exercise subject to due process, proportionality, reasoned decision-making and effective judicial control.