37. Final interpretation
Article 59 is short because it establishes a principle rather than a detailed reporting code.
That principle is:
An independent regulator must publicly account for how it used its mandate.
The authority must prepare a genuine annual account of its work, transmit it to relevant democratic institutions and make it publicly and institutionally accessible.
The annual report should allow readers to understand:
- what privacy problems arose;
- what the authority investigated;
- what infringements it found;
- what corrective measures it used;
- how efficiently it handled complaints;
- what cross-border work it performed;
- what emerging risks it identified;
- whether it has adequate resources;
- what reforms may be needed.
Article 59 does not make government or parliament the authority’s superior. It creates transparency without subordination.
The essential distinction is:
Government may ask what the authority did and whether it has the resources to do its work. Government may not tell the authority what conclusion to reach in an individual case.
A report that contains candid statistics, reasoned explanations, enforcement outcomes, institutional limitations and future priorities strengthens both public confidence and regulatory independence. A report that merely lists meetings, celebrates successes and conceals delay may satisfy the form of reporting while undermining its purpose.
In simplest terms, Article 59 requires the supervisory authority to answer four questions every year:
- What did we do?
- What did we find?
- What action did we take?
- What remains to be done?
That is the core of transparent and democratically accountable data protection supervision.