CHAPTER VIINDEPENDENT SUPERVISORY AUTHORITIES

Article 59Activity reports

Official text

Each supervisory authority shall draw up an annual report on its activities, which may include a list of types of infringement notified and types of measures taken in accordance with Article 58 (2). Those reports shall be transmitted to the national parliament, the government and other authorities as designated by Member State law. They shall be made available to the public, to the Commission and to the Board.

Commentary

Article 59 is the final provision in Chapter VI dealing with the internal operation, competence, tasks and powers of national supervisory authorities. Although it contains only a few sentences, it performs an important constitutional function: it requires every supervisory authority to explain publicly, every year, what it has actually done.

The authority must remain independent from government under Article 52, but independence does not mean secrecy or freedom from accountability. Article 59 establishes a structured form of democratic, institutional and public accountability without allowing parliament or government to direct individual investigations or reverse regulatory decisions.


1. The basic purpose of Article 59

Article 59 requires each supervisory authority to:

  1. prepare an annual report on its activities;
  2. transmit the report to parliament, government and any other authorities designated by national law; and
  3. make the report available to the public, the European Commission and the European Data Protection Board.

The report may include:

  • types of GDPR infringements notified to the authority; and
  • types of corrective measures taken under Article 58(2).

The word“shall” makes preparation, transmission and public availability mandatory. The phrase“may include” gives flexibility regarding the listed infringement and enforcement information, but it does not make the entire reporting obligation optional.

In simple terms, Article 59 tells the supervisory authority:

You may investigate independently, decide cases independently and resist political instructions, but once a year you must publicly explain how you used your office, resources and regulatory powers.


2. Why annual reporting matters

A supervisory authority exercises substantial public power. It may:

  • investigate businesses and public bodies;
  • compel production of information;
  • conduct audits;
  • enter premises in accordance with procedural law;
  • order deletion of personal data;
  • prohibit processing;
  • suspend international transfers;
  • withdraw certifications;
  • impose administrative fines.

An institution with such extensive powers must be capable of public explanation and scrutiny.

Annual reports allow the public and democratic institutions to understand:

  • whether the authority is active;
  • what privacy risks are emerging;
  • how many complaints it receives;
  • how long investigations take;
  • which sectors generate the most concern;
  • whether cross-border cooperation is effective;
  • whether the authority has adequate funding;
  • what corrective measures it uses;
  • whether infringements are repeatedly occurring;
  • what legislative reforms may be required.

Article 59 therefore connects three principles:

  1. independence, because the authority decides cases without political direction;
  2. accountability, because it explains how it has performed its mandate;
  3. transparency, because the report must be accessible to the public.

3. Independence and accountability are not opposites

The most important nuance in Article 59 is the distinction between reporting to political institutions and being controlled by political institutions.

A supervisory authority must submit its report to parliament and government. That does not mean that either institution may:

  • order the authority to open an investigation;
  • tell it not to fine a politically important company;
  • reverse its decision;
  • dictate the legal conclusion in a pending complaint;
  • replace its enforcement priorities for political reasons;
  • demand confidential information about an unresolved case without lawful authority.

The CJEU has interpreted complete independence broadly. In Commission v Germany, it explained that supervisory authorities must remain free from direct and indirect external influence so that they can act objectively and impartially. The case arose under the GDPR’s predecessor, but its independence principles remain important for understanding the present institutional system.

At the same time, institutional independence does not prevent the authority from publishing reports, being financially audited, appearing before parliament or having its decisions judicially reviewed.

[!example] Illustration A parliamentary committee asks the authority: “Why did the average time for resolving complaints increase from eight months to fourteen months?” That is legitimate institutional scrutiny. The committee asks: “Why did you fine Company X? Withdraw the fine or we will remove your chairperson.” That is improper interference. Article 59 supports the first form of accountability, not the second.

4. “Each supervisory authority”

The reporting obligation applies to every supervisory authority established under Article 51.

Where a Member State has one national authority, the application is straightforward. Where it has several federal, regional or sectoral authorities, each authority must generally report on its own activities unless national law establishes a compliant consolidated system that still preserves meaningful authority-specific accountability.

Illustration

A federal Member State has:

  • one federal supervisory authority;
  • sixteen regional authorities;
  • two specialised authorities for constitutionally protected sectors. A single two-page national report saying that “the supervisory authorities were active” would not provide meaningful information about how each authority discharged its responsibilities. A better system could involve:
  • individual annual reports from each authority;
  • a consolidated national overview;
  • harmonised statistical categories;
  • separate sections showing the work of each regulator. The words “each supervisory authority” suggest that no authority should disappear from public accountability merely because it operates within a multi-authority structure.

5. “Shall draw up”

To “draw up” a report means more than collecting raw statistics.

The authority must prepare a coherent account of its annual activities. A meaningful report should explain:

  • what the authority did;
  • why it considered certain areas important;
  • what results were achieved;
  • what difficulties arose;
  • how resources were used;
  • what priorities are expected for the next period.

Weak example

“The authority received complaints, conducted investigations and participated in meetings.”

Technically, this describes activity. Substantively, it tells the public almost nothing.

Meaningful example

“The authority received 8,200 complaints, resolved 5,900, transferred 720 through cross-border procedures and closed 1,100 after controllers voluntarily remedied the issue. The median resolution time was seven months. Employment monitoring, direct marketing and delayed access responses were the most frequent subjects.”

The second version allows evaluation of the authority’s effectiveness.

5.1 Report preparation must be independent

Government should not draft, edit or approve the substance of the report in a way that alters the authority’s independent conclusions.

The authority may follow general public-sector requirements concerning:

  • publication format;
  • accessibility;
  • financial presentation;
  • language;
  • document registration.

However, it should retain control over its:

  • legal findings;
  • assessment of enforcement conditions;
  • criticism of legislation;
  • explanation of resource shortages;
  • recommendations for reform.

[!example] Illustration The authority’s report states that a government surveillance programme lacks adequate safeguards. The government may respond publicly or propose different legislation. It should not delete that criticism from the report before publication.

6. Meaning of “annual”

The report must be prepared once every year.

The Article does not prescribe:

  • a calendar year or financial year;
  • a fixed publication date;
  • a maximum delay after year-end;
  • a uniform EU template.

National law may specify those matters.

The annual cycle should nevertheless be regular, predictable and useful. A report published several years after the period it covers would undermine transparency.

Illustration

The authority’s 2025 report is published in March 2026. That is timely enough to inform present oversight. If the 2025 report is published in late 2029, its usefulness for understanding current enforcement, funding and complaint delays is severely reduced. A report may be supplemented by:

  • quarterly statistics;
  • enforcement dashboards;
  • case summaries;
  • strategic plans;
  • thematic investigations;
  • budget reports. Those additional publications are valuable but do not replace the annual report required by Article 59.

7. What period should the report cover?

The reporting period should be clearly identified.

A report should state whether it covers:

  • 1 January to 31 December;
  • a national financial year;
  • another legally defined annual period.

The report should use consistent periods for:

  • complaints;
  • investigations;
  • fines;
  • enforcement actions;
  • staff;
  • expenditure.

Without consistency, year-to-year comparisons may be misleading.

Illustration

The authority reports:

  • complaints received between January and December;
  • fines imposed between April and March;
  • staff numbers as of July;
  • investigations completed over an undefined period. Although all numbers may be individually correct, the report becomes difficult to interpret. Clear methodology is part of meaningful transparency.

8. “A report on its activities”

Article 59 does not exhaustively define the report’s content. This flexibility allows every authority to reflect its:

  • national structure;
  • enforcement environment;
  • workload;
  • regulatory responsibilities;
  • emerging technological issues.

However, the report must concern the authority’s activities. It should provide a reasonably complete picture rather than a carefully selected set of successes.

Relevant content may include the following.

8.1 Complaints

A useful report could state:

  • complaints received;
  • complaints carried forward;
  • complaints resolved;
  • complaints rejected as inadmissible;
  • complaints treated as manifestly unfounded or excessive;
  • average and median handling time;
  • complaints pending beyond specified periods;
  • principal complaint categories;
  • outcomes.

This information helps reveal whether Article 57(1)(f) is being performed effectively.

8.2 Investigations

The report may include:

  • ex officio investigations opened;
  • sectoral audits;
  • on-site inspections;
  • information orders;
  • investigations completed;
  • investigations closed without finding an infringement;
  • continuing major investigations;
  • recurring compliance problems.

8.3 Corrective measures

It may explain how often the authority used:

  • warnings;
  • reprimands;
  • rights-compliance orders;
  • general compliance orders;
  • breach-notification orders;
  • temporary limitations;
  • definitive bans;
  • erasure or rectification orders;
  • certification withdrawals;
  • administrative fines;
  • international-transfer suspensions.

8.4 Advisory and preventive work

It may cover:

  • legislative opinions;
  • consultations with public institutions;
  • guidance documents;
  • public-awareness campaigns;
  • training for SMEs;
  • children’s privacy initiatives;
  • advice following prior consultation;
  • approved codes and certifications.

8.5 European cooperation

It may describe:

  • lead supervisory authority cases;
  • concerned-authority cases;
  • mutual-assistance requests;
  • joint operations;
  • Article 60 procedures;
  • EDPB participation;
  • relevant and reasoned objections;
  • Article 65 dispute-resolution proceedings;
  • Article 66 urgent measures.

8.6 Institutional capacity

It may state:

  • annual budget;
  • number of staff;
  • legal, technical and administrative staffing;
  • vacancies;
  • training;
  • technology expenditure;
  • litigation costs;
  • resource constraints.

The EDPB’s own annual reporting practice illustrates how reports can cover guidance, opinions, binding decisions, enforcement cooperation and international activity. Its annual-report page lists these categories and provides publicly accessible reports. This is the EDPB’s reporting practice rather than a direct Article 59 requirement for national authorities, but it shows the value of structured institutional reporting.


9. “May include” infringement types and corrective measures

Article 59 says that the report may include:

  • a list of types of infringement notified; and
  • types of measures taken under Article 58(2).

The word “may” means these precise lists are not expressly mandatory in every report.

However, that flexibility should not be interpreted as permission to publish an empty or purely ceremonial document.

If the report contains no information about infringements, complaints, investigations, outcomes or corrective activity, it would be difficult to see how it meaningfully reports the authority’s activities.

9.1 Why “types” rather than every case?

The Article refers to types of infringement and measures rather than requiring publication of every case file.

This allows reporting without exposing:

  • personal data;
  • complainant identities;
  • whistleblowers;
  • ongoing investigations;
  • trade secrets;
  • confidential security information;
  • legally privileged material;
  • protected deliberations.

Illustration

The authority may report: “The most frequent infringements concerned delayed responses to access requests, lack of lawful basis for direct marketing, excessive employee monitoring and inadequate security.” It need not identify every individual complainant or publish the full evidence from every investigation.

9.2 Types of Article 58(2) measure

The authority might report:

  • 120 reprimands;
  • 75 compliance orders;
  • 30 erasure orders;
  • 12 temporary restrictions;
  • 4 definitive bans;
  • 45 administrative fines;
  • 2 suspensions of international data flows.

This allows the public to understand the authority’s regulatory approach.

A list containing only total fine revenue would be incomplete because Article 58(2) includes many corrective powers besides fines.


10. “Infringement notified” is potentially ambiguous

The phrase “types of infringement notified” can be read in different ways.

It might refer to infringements:

  • reported to the authority through complaints;
  • discovered through breach notifications;
  • communicated by public bodies;
  • notified to controllers as alleged infringements;
  • formally established by the authority.

A careful report should distinguish these categories.

Illustration

The authority receives 2,000 complaints alleging unlawful direct marketing. Following investigation, it confirms infringements in 600 cases. Reporting “2,000 direct-marketing infringements” would be misleading because allegations and established violations are not the same. A better report would distinguish:

  • allegations received;
  • investigations opened;
  • infringements confirmed;
  • cases still pending;
  • cases closed without infringement.

11. Connection with Article 57(1)(u)

Article 57(1)(u) requires supervisory authorities to keep internal records of:

  • GDPR infringements; and
  • measures taken under Article 58(2).

Article 59 allows those internal records to inform the public annual report.

The two provisions serve different purposes:

  • Article 57(1)(u) supports internal documentation, consistency and institutional memory.
  • Article 59 supports external transparency and accountability.

The annual report should not simply reproduce the complete internal infringement register. Internal records may contain confidential or personal information.

Illustration

The internal record may identify:

  • the controller;
  • the complainant;
  • witnesses;
  • evidence;
  • legal analysis;
  • fine amount;
  • appeal status. The public report may aggregate this into:
  • infringement category;
  • sector;
  • corrective measure;
  • anonymised or summarised case study;
  • overall statistical trend.

12. Quantitative data and qualitative explanation

Statistics are useful, but numbers alone can mislead.

Example

Authority A resolves 10,000 complaints. Authority B resolves 2,000 complaints. It does not necessarily follow that Authority A is five times more effective. Authority A may have closed many simple matters automatically. Authority B may have completed complex investigations into large-scale surveillance affecting millions of people. A meaningful annual report should combine:

  • quantitative indicators; and
  • qualitative explanation. Useful qualitative information includes:
  • major legal issues;
  • significant decisions;
  • systemic investigations;
  • emerging risks;
  • reasons for delays;
  • enforcement strategy;
  • legislative recommendations;
  • lessons from litigation;
  • resource challenges.

12.1 Measuring complaints

Complaint statistics should explain whether a “resolved complaint” includes:

  • withdrawal;
  • informal settlement;
  • transfer to another authority;
  • rejection;
  • final infringement decision;
  • voluntary compliance by the controller.

Without definitions, high closure numbers may conceal weak enforcement.

12.2 Measuring fines

Fine statistics should distinguish:

  • fines imposed;
  • fines final after appeal;
  • fines paid;
  • fines reduced or annulled;
  • fines pending judicial review.

A report that announces €100 million in fines without disclosing that most remain under appeal may produce an incomplete picture.


13. Pending matters and ongoing investigations

An authority should report on unresolved workload without compromising active cases.

Possible information includes:

  • number of pending complaints;
  • age profile of pending files;
  • number pending for more than one, two or three years;
  • number of ongoing cross-border investigations;
  • general reasons for delay;
  • expected procedural stages.

It need not disclose:

  • confidential evidence;
  • planned inspection dates;
  • whistleblower identities;
  • internal legal strategy;
  • material likely to compromise the investigation.

[!example] Illustration A report could state: “At year-end, 2,300 complaints remained pending. Of those, 400 had been open for more than 18 months, primarily because of cross-border coordination, technical forensic work and litigation concerning competence.” This is transparent without revealing case-sensitive details.

14. Reporting on inactivity and failure

An annual report should not be limited to achievements.

Meaningful accountability requires disclosure of:

  • backlogs;
  • failed projects;
  • investigations delayed;
  • judicial annulments;
  • resource shortages;
  • unfilled technical positions;
  • areas where enforcement targets were not met.

Illustration

The authority planned to complete a children’s-app audit but lacked enough technical staff. A candid report should explain:

  • why the audit was delayed;
  • what risk remains;
  • what resources are needed;
  • when the work is expected to resume. Omitting every difficulty can make the report resemble public relations rather than accountability.

15. Reporting judicial outcomes

Supervisory decisions may be challenged in court under Article 78.

A useful report may therefore identify:

  • number of appeals;
  • decisions upheld;
  • decisions annulled;
  • fines reduced;
  • important judicial interpretations;
  • procedural changes adopted following judgments.

This does not weaken the authority. Judicial outcomes can improve future enforcement and promote legal certainty.

Illustration

A court annuls a fine because the authority failed to give the controller a proper opportunity to be heard. The annual report should not conceal the ruling. It could explain:

  • the legal issue;
  • the court’s reasoning;
  • procedural improvements made;
  • whether further appeal is pending.

16. Transmission to the national parliament

The report must be transmitted to the national parliament.

This gives elected representatives information needed to evaluate:

  • whether privacy legislation is effective;
  • whether government programmes respect data protection;
  • whether the authority has sufficient resources;
  • whether further law reform is needed;
  • whether systemic risks are emerging.

Parliament may:

  • debate the report;
  • hold institutional hearings;
  • request clarification;
  • consider legislative changes;
  • examine resource needs.

It must respect the authority’s independence.

Appropriate parliamentary question

“The report shows a four-year complaint backlog. What staffing and procedural reforms are required?”

Inappropriate parliamentary direction

“Do not investigate public hospitals next year because the cases are politically sensitive.”

Article 59 enables scrutiny of institutional performance, not legislative control of individual regulatory judgments.


17. Transmission to the government

The government must also receive the report.

This is important because government may be responsible for:

  • proposing legislation;
  • preparing the state budget;
  • implementing public-administration reforms;
  • managing government-wide cybersecurity;
  • responding to regulatory recommendations.

The government is also a major controller of personal data. Its receipt of the report does not place it above the authority.

Illustration

The report finds recurring security failures in government bodies. The government may respond by:

  • strengthening public-sector security standards;
  • proposing new funding;
  • improving training;
  • amending administrative procedures. It may not instruct the authority to remove the finding because it is embarrassing.

18. Other authorities designated by national law

Member State law may identify additional recipients, such as:

  • regional parliaments;
  • audit institutions;
  • ombuds institutions;
  • constitutional bodies;
  • ministries;
  • judicial councils;
  • national cybersecurity agencies;
  • freedom-of-information bodies.

The phrase allows adaptation to national constitutional structures.

However, additional transmission does not allow those bodies to control the report’s content or interfere with individual cases.

National law should clearly identify:

  • which bodies receive the report;
  • how transmission occurs;
  • whether hearings follow;
  • whether a formal institutional response is required.

19. Making the report available to the public

The report must be publicly available.

Publication on the authority’s website will usually be the most practical method, but public availability should be effective rather than merely theoretical.

A report should ideally be:

  • free to access;
  • easy to locate;
  • downloadable;
  • searchable;
  • accessible to persons with disabilities;
  • available in a stable format;
  • retained in an archive;
  • written or summarised in plain language.

Illustration

The report is technically online but:

  • buried several layers inside an outdated website;
  • available only through an expired link;
  • presented as an inaccessible image scan;
  • removed after one month. That would not reflect meaningful public availability.

19.1 Language

Article 59 does not establish a translation requirement.

At minimum, the report should be available in the relevant national language or languages. An English summary may support:

  • comparison between authorities;
  • EDPB cooperation;
  • academic study;
  • broader public scrutiny.

Translation is especially valuable because the report must also be available to the Commission and EDPB.

19.2 Plain-language summaries

The main report may be technical, but a short public summary can explain:

  • key risks;
  • major decisions;
  • complaint trends;
  • practical rights;
  • priorities.

The summary should not replace the full report.


20. Availability to the European Commission

The report must be made available to the European Commission.

This helps the Commission understand:

  • how the GDPR is being enforced;
  • whether Member States have provided adequate institutions and resources;
  • whether significant enforcement differences exist;
  • whether legislative or infringement action may be necessary;
  • what new regulatory problems are emerging.

Making the report available does not allow the Commission to direct the authority’s individual cases. Article 52 independence continues to apply.

The report may reveal structural issues such as:

  • recurring understaffing;
  • lack of technical expertise;
  • national procedural barriers;
  • failure to provide adequate investigative powers;
  • excessive complaint delays.

These matters may be relevant to the Commission’s role in monitoring EU-law compliance.


21. Availability to the EDPB

The report must also be available to the European Data Protection Board.

This supports:

  • comparison of national enforcement;
  • identification of common trends;
  • development of guidance;
  • consistency of legal interpretation;
  • coordinated enforcement;
  • understanding of resource and staffing conditions.

The EDPB itself publishes annual reports covering guidance, opinions, binding decisions, enforcement cooperation, international cooperation and other institutional activities. Its publicly listed reports include annual publications for successive years.

National reports can provide the underlying information needed to understand:

  • which violations are most common;
  • how national authorities use Article 58;
  • where enforcement gaps remain;
  • whether cross-border cooperation works effectively.

22. Publication is not the same as formal transmission

Article 59 uses two forms of wording:

  • reports shall be transmitted to parliament, government and designated authorities;
  • reports shall be made available to the public, Commission and Board.

Uploading a report to a website may be sufficient for public availability. It may not necessarily fulfil a national legal requirement of formal transmission to parliament or government.

Similarly, best practice would be to notify the Commission and EDPB directly rather than assume that they will discover the report online.

[!example] Illustration The authority publishes its report on its website but never sends it to parliament. The public-availability obligation may be satisfied, but the transmission obligation may remain unfulfilled.

23. Confidentiality and transparency

Article 59 must be reconciled with:

  • Article 54 professional secrecy;
  • personal-data protection;
  • trade secrets;
  • rights of defence;
  • confidentiality of ongoing investigations;
  • whistleblower protection;
  • security of systems.

This does not justify withholding the entire report. Instead, the authority may use:

  • anonymisation;
  • aggregation;
  • redaction;
  • delayed case discussion;
  • thematic summaries;
  • non-confidential versions of decisions.

Illustration

The authority investigates a hospital after an employee confidentially reports sale of patient records. The report may state: “The authority investigated unlawful secondary use of patient data in the healthcare sector and imposed corrective measures.” It should not identify the reporting employee or expose patient records.

23.1 Aggregation can also mislead

Confidentiality should not be used to aggregate information so broadly that meaningful scrutiny becomes impossible.

A report stating only that “some measures were taken against some entities” does not provide useful accountability.

The authority should disclose as much as possible while protecting legitimate confidential interests.


24. Relationship with freedom-of-information law

The annual report is a public document, but access to underlying records may be governed by national freedom-of-information law and applicable exceptions.

Publication of the report does not automatically require disclosure of:

  • every complaint;
  • every internal memorandum;
  • privileged legal advice;
  • confidential evidence;
  • protected personal data;
  • draft decisions;
  • EDPB confidential deliberations.

Conversely, Article 54 professional secrecy should not be used as a blanket excuse to withhold:

  • aggregate statistics;
  • final non-confidential decisions;
  • institutional budgets;
  • staffing information;
  • broad enforcement trends.

A balanced approach distinguishes case confidentiality from institutional accountability.


25. Reports as guidance for controllers and DPOs

An annual report may provide practical value to:

  • controllers;
  • processors;
  • DPOs;
  • lawyers;
  • auditors;
  • public bodies;
  • civil-society organisations.

It can reveal recurring errors, such as:

  • retaining personal data indefinitely;
  • using weak access controls;
  • failing to answer rights requests;
  • relying on invalid consent;
  • conducting employee surveillance without necessity;
  • failing to notify breaches;
  • using deficient processor contracts;
  • making unlawful international transfers.

Illustration

The authority reports that several hotels unlawfully retained full passport copies after check-out. A hotel DPO reading the report should ask:

  • Does our hotel retain passport scans?
  • What is the legal basis?
  • Is the full copy necessary?
  • What is the retention period?
  • Who has access?
  • Can we achieve the purpose with less data? The report therefore promotes preventive compliance beyond the entities directly investigated.

25.1 Reports are not binding law

An annual report is an important interpretive and compliance resource, but it is not automatically equivalent to:

  • the GDPR;
  • a binding court judgment;
  • an individual enforcement order;
  • an EDPB binding decision.

A case summary in a report may omit factual details. Controllers should therefore avoid treating short examples as universal legal rules without considering the full context.


26. Reports as tools for data subjects

Reports may help individuals understand:

  • common privacy violations;
  • available rights;
  • complaint procedures;
  • supervisory priorities;
  • outcomes in similar cases.

Illustration

An employee suspects that workplace CCTV is excessive. The annual report describes earlier cases where cameras continuously monitored workstations. The employee may use that information to:

  • identify relevant rights;
  • raise the issue internally;
  • contact the DPO;
  • lodge a more focused complaint. A plain-language report can therefore increase effective access to rights.

27. Reports as evidence of regulatory effectiveness

Article 59 reports allow year-to-year assessment.

Useful effectiveness indicators include:

  • complaint resolution time;
  • size and age of backlog;
  • number of systemic investigations;
  • compliance with orders;
  • repeat infringement rates;
  • judicial success rate;
  • implementation of legislative advice;
  • public-awareness reach;
  • cross-border case duration;
  • number of unresolved mutual-assistance requests.

However, performance should not be reduced to crude numerical competition.

[!example] Illustration A regulator imposing many small fines is not necessarily more effective than one that uses fewer, highly targeted orders to end systemic unlawful processing. The report should explain outcomes, not merely activity counts.

28. Financial and staffing transparency

Article 59 does not expressly list budget and staff as mandatory content. Nevertheless, this information is highly relevant to Article 52(4), which requires adequate human, technical and financial resources.

A report may explain:

  • approved budget;
  • actual expenditure;
  • staff headcount;
  • legal and technical staffing;
  • recruitment difficulties;
  • vacancies;
  • training;
  • case workload per employee;
  • technology investments.

The EDPB’s annual reporting materials have included information on enforcement cooperation, national cases and, in some years, DPA budget and staff information, illustrating the relevance of capacity data to understanding enforcement.

[!example] Illustration An authority receives 20,000 complaints but has only five investigators. The report should disclose the mismatch. Parliament and government can then consider whether additional resources are required. The report should not be used by government to assess whether the authority made politically desirable decisions. It should be used to assess whether the authority can effectively perform its statutory role.

29. Does Article 59 require named enforcement decisions?

No. Article 59 does not expressly require every controller or processor to be named.

Whether names should be published depends on:

  • national law;
  • procedural fairness;
  • confidentiality;
  • public-interest considerations;
  • whether a decision is final;
  • appeal status;
  • proportionality;
  • the authority’s publication policy.

Arguments for naming

Naming may provide:

  • transparency;
  • deterrence;
  • accountability;
  • practical warnings to the public.

Arguments against naming

Naming may create:

  • disproportionate reputational harm;
  • prejudice during appeal;
  • exposure of individuals;
  • disclosure of trade secrets;
  • misunderstanding of non-final findings.

A balanced report may distinguish:

  • final decisions;
  • decisions under appeal;
  • anonymised examples;
  • significant cases where publication is legally justified.

30. Does failure to mention an infringement invalidate the report?

Article 59 says that the report “may include” a list of infringement types and corrective measures. The absence of such a list does not automatically make the report legally invalid.

However, validity and quality are not identical.

A report may technically exist but still fail to serve its transparency purpose if it contains no substantive information.

[!example] Illustration The authority publishes a one-page document: “During the year, the authority performed its GDPR duties. No further information is provided.” It may be labelled an annual report, but it does not allow any meaningful public or democratic scrutiny. Article 59 should be interpreted according to its effectiveness. A report must be sufficiently substantive to constitute a genuine account of annual activities.

31. Can parliament reject the report?

Article 59 requires transmission. It does not give parliament a GDPR power to approve or reject the report.

National law may provide for:

  • debate;
  • acknowledgement;
  • committee review;
  • recommendations;
  • requests for institutional information.

But a parliamentary vote should not determine whether the authority’s legal findings remain valid.

[!example] Illustration Parliament disagrees with the authority’s criticism of a government database and votes not to “approve” the report. That political disagreement does not cancel the authority’s findings, investigations or enforcement decisions.

32. Can the report be challenged in court?

The annual report itself may contain different kinds of content:

  • statistics;
  • policy statements;
  • summaries of final decisions;
  • recommendations;
  • public criticism;
  • institutional descriptions.

Whether a particular statement is judicially reviewable depends on whether it produces binding legal effects and on applicable national law.

A controller usually challenges the underlying Article 58 decision rather than the report summarising it.

However, if the report:

  • discloses confidential information unlawfully;
  • misidentifies a company;
  • publishes personal data without a legal basis;
  • materially misrepresents a non-final decision.

national remedies may potentially be available.

Article 59 does not give the authority immunity from privacy, confidentiality, defamation or procedural requirements.


33. No specific recital

The supplied text correctly notes that no recital appears to be dedicated solely to Article 59.

That does not leave the Article without interpretive context. Relevant principles can be drawn from:

  • Recital 117 on effective and independent supervisory authorities;
  • Recital 118 on lawful financial monitoring and judicial review;
  • Recital 129 on effective powers, fairness and due process;
  • Article 52 on independence;
  • Article 54 on professional secrecy;
  • Article 57(1)(u) on internal records;
  • Article 58 on corrective measures.

The absence of a dedicated recital makes the Article’s own wording and institutional purpose especially important.


34. A model structure for an Article 59 report

Although the GDPR does not prescribe a template, a robust annual report could contain:

1. Executive summary

A plain-language overview of major activities, risks and results.

2. Institutional information

Mandate, governance, independence, budget, staffing and organisational changes.

3. Complaints

Numbers received, resolved, pending, transferred, rejected and handled through cross-border procedures.

4. Investigations and audits

Ex officio investigations, sector inquiries, audits, inspections and key findings.

5. Article 58 corrective measures

Warnings, reprimands, orders, bans, erasure measures, certification actions, fines and transfer suspensions.

6. Major decisions

Summaries of significant cases, including appeal status.

7. Cross-border cooperation

Lead-authority work, concerned-authority participation, mutual assistance, objections and EDPB procedures.

8. Legislative and administrative advice

Opinions supplied to parliament, government and public bodies.

9. Awareness activities

Public campaigns, children’s initiatives, SME guidance and DPO support.

10. Codes, certifications and transfers

Approved codes, certification criteria, BCRs, standard clauses and transfer authorisations.

11. Technology and commercial developments

AI, biometrics, advertising, connected devices, surveillance and emerging risks.

12. Litigation

Appeals, judicial outcomes and resulting procedural improvements.

13. Performance indicators

Case duration, backlog, resource use and compliance with orders.

14. Future priorities

Planned enforcement, guidance and institutional needs.

15. Statistical annex

Definitions, methodology and detailed tables.

Such a report would transform Article 59 from a formal obligation into a meaningful accountability mechanism.


35. Practical illustration

Assume a supervisory authority had the following year:

  • 12,000 complaints received;
  • 8,500 complaints completed;
  • 2,000 cross-border files;
  • 100 audits;
  • 40 administrative fines;
  • 15 erasure orders;
  • 3 processing bans;
  • 5 major court judgments;
  • a large backlog;
  • difficulty recruiting cybersecurity specialists.

A weak report might announce:

“The authority successfully enforced the GDPR and increased public awareness.”

A meaningful report would explain:

  • what the complaints concerned;
  • how many were upheld;
  • why some remained pending;
  • which sectors were audited;
  • why different corrective powers were selected;
  • whether fines were appealed;
  • how quickly orders were complied with;
  • what technical capacity was missing;
  • what legislative or budgetary support was required.

The point of Article 59 is not merely to celebrate work completed. It is to make the regulator’s actual performance visible.


36. Main grey areas

Article 59 leaves several matters unresolved.

36.1 No uniform reporting template

Different authorities may classify complaints, investigations and sanctions differently, making comparison difficult.

36.2 No express publication deadline

A delayed report may formally satisfy the annual requirement while undermining practical transparency.

36.3 “May include” creates flexibility

The provision does not clearly prescribe minimum enforcement statistics.

36.4 Confidentiality boundaries are not specified

Authorities must balance public accountability with Article 54 secrecy and national rules.

36.5 No express sanction for failure to report

The Article does not state a specific penalty if an authority fails to publish, although the failure may violate EU law and national institutional obligations.

36.6 Multiple-authority states

The GDPR does not detail whether individual, consolidated or both forms of report should be issued.

36.7 Comparability

Differences in terminology, time periods and procedures may make national statistics appear more comparable than they actually are.

These gaps can be addressed through national law, EDPB coordination and sound reporting practice.


37. Final interpretation

Article 59 is short because it establishes a principle rather than a detailed reporting code.

That principle is:

An independent regulator must publicly account for how it used its mandate.

The authority must prepare a genuine annual account of its work, transmit it to relevant democratic institutions and make it publicly and institutionally accessible.

The annual report should allow readers to understand:

  • what privacy problems arose;
  • what the authority investigated;
  • what infringements it found;
  • what corrective measures it used;
  • how efficiently it handled complaints;
  • what cross-border work it performed;
  • what emerging risks it identified;
  • whether it has adequate resources;
  • what reforms may be needed.

Article 59 does not make government or parliament the authority’s superior. It creates transparency without subordination.

The essential distinction is:

Government may ask what the authority did and whether it has the resources to do its work. Government may not tell the authority what conclusion to reach in an individual case.

A report that contains candid statistics, reasoned explanations, enforcement outcomes, institutional limitations and future priorities strengthens both public confidence and regulatory independence. A report that merely lists meetings, celebrates successes and conceals delay may satisfy the form of reporting while undermining its purpose.

In simplest terms, Article 59 requires the supervisory authority to answer four questions every year:

  1. What did we do?
  2. What did we find?
  3. What action did we take?
  4. What remains to be done?

That is the core of transparent and democratically accountable data protection supervision.