CHAPTER VIICOOPERATION AND CONSISTENCY

Article 60Cooperation between the lead supervisory authority and the other supervisory authorities concerned

Official text

(1)The lead supervisory authority shall cooperate with the other supervisory authorities concerned in accordance with this Article in an endeavour to reach consensus. The lead supervisory authority and the supervisory authorities concerned shall exchange all relevant information with each other.

(2)The lead supervisory authority may request at any time other supervisory authorities concerned to provide mutual assistance pursuant to Article 61 and may conduct joint operations pursuant to Article 62, in particular for carrying out investigations or for monitoring the implementation of a measure concerning a controller or processor established in another Member State.

(3)The lead supervisory authority shall, without delay, communicate the relevant information on the matter to the other supervisory authorities concerned. It shall without delay submit a draft decision to the other supervisory authorities concerned for their opinion and take due account of their views.

(4)Where any of the other supervisory authorities concerned within a period of four weeks after having been consulted in accordance with paragraph 3 of this Article, expresses a relevant and reasoned objection to the draft decision, the lead supervisory authority shall, if it does not follow the relevant and reasoned objection or is of the opinion that the objection is not relevant or reasoned, submit the matter to the consistency mechanism referred to in Article 63.

(5)Where the lead supervisory authority intends to follow the relevant and reasoned objection made, it shall submit to the other supervisory authorities concerned a revised draft decision for their opinion. That revised draft decision shall be subject to the procedure referred to in paragraph 4 within a period of two weeks.

(6)Where none of the other supervisory authorities concerned has objected to the draft decision submitted by the lead supervisory authority within the period referred to in paragraphs 4 and 5, the lead supervisory authority and the supervisory authorities concerned shall be deemed to be in agreement with that draft decision and shall be bound by it.

(7)The lead supervisory authority shall adopt and notify the decision to the main establishment or single establishment of the controller or processor, as the case may be and inform the other supervisory authorities concerned and the Board of the decision in question, including a summary of the relevant facts and grounds. The supervisory authority with which a complaint has been lodged shall inform the complainant on the decision.

(8)By derogation from paragraph 7, where a complaint is dismissed or rejected, the supervisory authority with which the complaint was lodged shall adopt the decision and notify it to the complainant and shall inform the controller thereof.

(9)Where the lead supervisory authority and the supervisory authorities concerned agree to dismiss or reject parts of a complaint and to act on other parts of that complaint, a separate decision shall be adopted for each of those parts of the matter. The lead supervisory authority shall adopt the decision for the part concerning actions in relation to the controller, shall notify it to the main establishment or single establishment of the controller or processor on the territory of its Member State and shall inform the complainant thereof, while the supervisory authority of the complainant shall adopt the decision for the part concerning dismissal or rejection of that complaint, and shall notify it to that complainant and shall inform the controller or processor thereof.

(10)After being notified of the decision of the lead supervisory authority pursuant to paragraphs 7 and 9, the controller or processor shall take the necessary measures to ensure compliance with the decision as regards processing activities in the context of all its establishments in the Union. The controller or processor shall notify the measures taken for complying with the decision to the lead supervisory authority, which shall inform the other supervisory authorities concerned.

(11)Where, in exceptional circumstances, a supervisory authority concerned has reasons to consider that there is an urgent need to act in order to protect the interests of data subjects, the urgency procedure referred to in Article 66 shall apply.

(12)The lead supervisory authority and the other supervisory authorities concerned shall supply the information required under this Article to each other by electronic means, using a standardised format.

Commentary

Article 60 GDPR establishes the principal decision-making procedure for the supervision of cross-border processing under the GDPR. It operates after the lead supervisory authority (“LSA”) has been identified under Article 56(1) GDPR and provides the procedural framework through which the LSA cooperates with the other supervisory authorities concerned (“CSAs”). The provision is therefore central to the GDPR'sone-stop-shop mechanism.

The basic objective is to avoid a situation in which the same cross-border processing activity is investigated and decided differently by several national supervisory authorities. Article 60 instead seeks to produce a coordinated and, as far as possible, uniform outcome. The LSA directs and coordinates the procedure, but the other CSAs remain involved in the decision-making process. The final decision is formally adopted by the LSA, while the views of the other authorities must be taken into account through the cooperation mechanism.

This makes Article 60 different from a conventional administrative procedure conducted entirely by one regulator.

The structure is closer to:

one authority leads + several authorities participate + information is exchanged + consensus is sought + objections are possible + unresolved disputes move to the consistency mechanism.

The provision must therefore be read together with Articles 56, 61, 62, 63, 65 and 66 GDPR. Article 56 determines the authority competent to act as the LSA in cross-border processing. Article 61 provides for mutual assistance, Article 62 concerns joint operations, Article 63 establishes the consistency mechanism, Article 65 provides the dispute-resolution mechanism, and Article 66 addresses urgent circumstances. Article 60 supplies the procedural bridge between these provisions.

The CJEU has also considered the relationship between the lead supervisory authority and the other supervisory authorities in the context of the one-stop-shop mechanism in Facebook Ireland and Others v Gegevensbeschermingsautoriteit, Case C-645/19.


1. The purpose of Article 60: coordinated enforcement in cross-border cases

The starting point is that Article 60 applies to the cooperation procedure following the identification of an LSA under Article 56(1) GDPR. The LSA is the supervisory authority of the main establishment or single establishment of the controller or processor, where the conditions for the one-stop-shop mechanism are met. It assumes the role of directing and coordinating the decision-making procedure.

The purpose of this arrangement is institutional rather than merely administrative.

Suppose a social-media platform has its main establishment in Ireland but processes the personal data of users throughout the Union. A particular processing practice affects individuals in France, Germany, Italy and Spain. If each national authority independently investigated the same processing and reached a different conclusion, the controller could be subject to inconsistent regulatory requirements for the same processing activity.

Article 60 seeks to prevent that result.

The LSA therefore becomes the principal authority responsible for directing the investigation and preparing the decision, while the authorities in the Member States affected by the processing participate as CSAs.

This does not mean that the LSA possesses an unrestricted power to decide the matter without regard to the other authorities. Nor does it mean that every CSA possesses an independent veto over the LSA's proposed decision.

The system deliberately occupies the middle ground.

The LSA leads, but it must cooperate.

The CSAs participate, but they do not automatically replace the LSA.

Consensus is sought, but the GDPR provides a mechanism for resolving disagreement.

This balance is essential to understanding Article 60.



2. Cooperation between the LSA and CSAs

Article 60(1) begins with the requirement that the LSA and the other CSAs cooperate with each other in an endeavour to reach consensus. The cooperation obligation is therefore not something that arises only when the LSA circulates its final draft decision. It informs the decision-making process from the beginning.

Once the LSA becomes aware of its responsibility under Article 56(1), it must take the initiative to identify the other CSAs.

This requires the LSA to understand the relevant processing operation and determine which Member States are affected. Relevant considerations may include the location of affected data subjects and the location of establishments of the controller or processor.

The identification of CSAs is therefore not a purely formal exercise.

The authority must first understand the geographical and substantive dimensions of the processing.

Illustration

A controller established in Member State A operates an online marketplace throughout the Union. A complaint concerns the use of behavioural profiling to target advertisements. The complainant lives in Member State B, while thousands of affected users are located in Member States C, D and E. The LSA cannot simply treat the complaint as a matter concerning the complainant's Member State. It must consider whether the processing itself has a cross-border character and identify the authorities concerned by that processing. The consequence is that the cooperation procedure is designed around theprocessing activity, rather than merely around the location of the person who submitted the complaint.



3. Exchange of all relevant information

Article 60 places particular emphasis on the exchange of information.

After the decision-making group has been constituted, the LSA and the CSAs must exchange relevant information necessary for the decision-making process. Effective cross-border enforcement depends upon each authority having access to the factual and legal material necessary to assess the proposed outcome.

The expression “all relevant information” is important.

The purpose is not simply to give the CSAs the final conclusion reached by the LSA. They must receive sufficient information to understand how the LSA reached that conclusion.

For example, if the LSA concludes that a controller's processing is lawful because it relied upon a particular legal basis under Article 6, the other authorities should have sufficient information about:

  • the processing activity;
  • the purposes of processing;
  • the categories of personal data;
  • the categories of data subjects;
  • the controller's legal arguments;
  • the evidence obtained during the investigation;
  • the relevant national-law considerations; and
  • the proposed corrective measures.

Without that information, the formal opportunity to object would be of limited practical value.

The information-exchange requirement therefore supports the broader principle of participatory decision-making.



4. Information exchange may precede the final identification of the LSA

The cooperation architecture should not be interpreted so narrowly that information sharing becomes impossible merely because the identity of the LSA is still uncertain.

The reference commentary notes that the required exchange of information may take place in any event through the mechanisms provided under Articles 61 and 62 GDPR.

This reflects the practical reality of cross-border investigations.

In a complicated investigation, authorities may initially have incomplete information concerning the controller's establishments, the nature of the processing or the geographical effects of the processing. Waiting for every jurisdictional question to be perfectly resolved before exchanging information could itself frustrate effective enforcement.

The better approach is therefore cooperative from the outset, while the formal competence of the LSA is established.



5. The LSA must endeavour to reach consensus

The obligation to “endeavour to reach consensus” is one of the most important features of Article 60(1).

The LSA is expected to act in a consensus-building manner. The CSAs should receive adequate information and sufficient opportunity to present their legal positions, and those positions should be incorporated into the assessment as far as possible. Recital 125 reinforces this approach by stating that the supervisory authority should closely involve and coordinate the CSAs in the decision-making process.

The word “endeavour”, however, is equally important.

Article 60(1) does not state that the LSA must necessarily achieve consensus.

There is therefore a distinction between:

an obligation to seek consensus

and

an obligation to obtain consensus.

The first exists. The second does not.

This distinction is necessary because disagreement between supervisory authorities is inevitable in complex cross-border cases. If one dissenting authority could prevent the adoption of every decision, the one-stop-shop system could become incapable of producing final outcomes.

Article 60 therefore combines consensus-building with a dispute-resolution mechanism.

Illustration

Suppose the LSA considers that a controller committed one infringement and proposes a corrective order. A CSA believes that the evidence establishes an additional infringement and that a different corrective measure is necessary. The LSA must engage with the CSA's position and attempt to find common ground. But if the disagreement remains, the GDPR does not require the LSA to abandon the procedure indefinitely. Article 60(4), read with Articles 63 and 65, provides a route for resolving the dispute. Thus:Consensus is the preferred outcome. Dispute resolution is the institutional safeguard where consensus fails.



6. Cooperation must begin before the draft decision

A particularly important consequence of the consensus requirement is that the LSA should not wait until the end of the investigation to involve the CSAs.

The source commentary emphasises that the LSA should work towards a consensual approach from the start of the procedure, rather than limiting the involvement of the CSAs to the stage at which a draft decision is circulated.

This matters because a late-stage consultation can become largely artificial.

If the LSA investigates the matter independently for several years, reaches a firm conclusion and then presents a fully developed draft decision to the CSAs, the practical ability of the CSAs to influence the investigation may be considerably reduced.

The cooperation obligation therefore has a substantive procedural dimension.

The LSA should give the other authorities an opportunity to contribute while factual and legal questions are still being developed.



7. Mutual assistance and joint operations

Article 60(2) makes clear that cooperation does not end with the exchange of views. The LSA and CSAs must cooperate in accordance with Articles 61 and 62 GDPR.

This is important because cross-border processing frequently requires evidence or regulatory action in more than one Member State. The LSA may request mutual assistance and may conductjoint operations with other authorities.

Illustration

A multinational company maintains its main establishment in Member State A but has substantial processing operations in Member States B and C. Evidence concerning employee access controls is held in B, while relevant technical logs are maintained in C. The LSA may require assistance from the authorities in B and C to establish facts that cannot conveniently be obtained solely from its own jurisdiction. This demonstrates that Article 60 is not merely about lawyers exchanging submissions between regulators. The cooperation mechanism may involve actual investigative activity.



8. Cooperation continues after the decision

The cooperation obligation does not necessarily end when the final decision has been adopted.

Article 60(2) expressly contemplates cooperation for monitoring the implementation of a measure concerning a controller or processor established in another Member State.

This is practically important.

A regulatory decision may require a controller to alter a processing activity, delete personal data, implement technical measures or change its compliance practices. If the relevant implementation occurs across several Member States, the LSA may need assistance from the other authorities to determine whether the decision has actually been implemented.

The enforcement lifecycle is therefore:

investigation → decision-making → decision → implementation → monitoring.

Article 60 can operate across that entire lifecycle.



9. Communication of relevant information and the draft decision

Article 60(3) establishes the central procedural step.

The LSA must communicate the relevant information on the matter to the other CSAs and, without delay, provide them with a draft decision for their opinion. The LSA must then take their views into “due account”.

Three obligations therefore arise:

  1. communicate the relevant information;
  2. provide the draft decision without delay; and
  3. take the views of the CSAs into due account.

The phrase “due account” does not mean that the LSA must automatically adopt every proposal made by a CSA.

Instead, it requires meaningful consideration.

If a CSA argues that a proposed corrective measure is inadequate, the LSA should assess that argument and explain its treatment of the issue where appropriate.

The obligation would be undermined if the LSA could simply record that a CSA had expressed an opinion without addressing the substance of that opinion.



10. The absence of a fixed deadline for the LSA

An important practical difficulty is that Article 60(3) does not establish a general fixed deadline within which the LSA must complete the investigation and circulate its draft decision.

The reference commentary notes that cross-border procedures can consequently take several years in practice.

This produces an obvious tension.

On the one hand, complex cross-border investigations may genuinely require considerable time. They may involve multiple establishments, large volumes of evidence, technical investigations, submissions by several parties and coordination between several authorities.

On the other hand, prolonged proceedings can adversely affect data subjects and create uncertainty for controllers and processors.

The absence of a general Article 60 deadline therefore gives the LSA procedural flexibility, but it can also contribute to delay.

The “without delay” requirement for the draft decision should accordingly not be interpreted as requiring immediate circulation before the investigation is sufficiently developed. It is better understood as requiring the LSA to proceed without unjustified procedural delay once the draft decision is ready to be submitted.



11. The right of a CSA to object

Article 60(4) provides the principal mechanism through which a CSA can challenge the LSA's proposed approach.

Any CSA may object to the draft decision. However, the objection must be relevant and reasoned. The CSA has four weeks to examine the draft decision and express its objection.

The requirements of relevance and reasoning are cumulative.

A CSA cannot transform the objection procedure into a general political or policy disagreement with the LSA.

The objection must relate to the actual draft decision.



12. What makes an objection “relevant”?

The meaning of “relevant” is particularly important.

Article 4(24) GDPR defines a relevant and reasoned objection as an objection to a draft decision concerning:

  • whether there is an infringement of the GDPR; or
  • whether the envisaged action concerning the controller or processor complies with the GDPR,

and which clearly demonstrates the significance of the risks posed by the draft decision in relation to the fundamental rights and freedoms of data subjects and, where applicable, the free flow of personal data within the Union.

The objection must therefore have a direct connection with the draft decision.

Illustration

The LSA concludes that a controller complied with Article 6 but violated Article 13, and proposes a corrective order. A CSA cannot simply object:

“We believe the LSA should take a stricter approach to privacy enforcement.” That is too abstract. A more relevant objection would be: The LSA's draft decision incorrectly concludes that the controller satisfied Article 6 because the evidence establishes that the alleged legitimate interest was never properly assessed against the rights and freedoms of the data subjects. The second objection directly attacks the legal reasoning contained in the draft decision. The distinction is therefore: general disagreement = insufficient specific challenge to the legal or factual content of the draft decision = potentially relevant. The source commentary expressly states that abstract or broad comments cannot ordinarily qualify as relevant objections.



13. What makes an objection “reasoned”?

Relevance is not enough.

The objection must also be reasoned.

A reasoned objection must explain why an amendment to the draft decision is proposed and identify the alleged legal or factual mistake. It must also demonstrate how correcting that mistake could lead to a different conclusion concerning the existence of an infringement or the action proposed against the controller or processor.

The requirement therefore has a causal structure:

alleged error → explanation → proposed amendment → different legal or factual outcome.

A CSA should provide sound reasoning by reference to legal or factual material. Relevant legal sources may include EU law, applicable national law, guidelines and case law. Factual arguments should identify the facts that allegedly support the alternative conclusion.

The objection should also be coherent, clear, precise and sufficiently detailed.

This is important because the objection is not merely a statement of disagreement. It is an instrument capable of moving the dispute into the Article 65 procedure.



14. An objection should identify the specific deficiency

A CSA should identify the part of the draft decision with which it disagrees.

This may be done by identifying a particular article, paragraph, factual finding, legal conclusion or proposed measure.

For example, if a draft decision finds infringements of Articles 6, 7 and 14 but a CSA disagrees only with the Article 7 finding and believes there is instead an Article 13 infringement, the objection should identify those specific issues.

The purpose is to ensure that the disagreement remains tied to the actual decision.

An objection should therefore not operate as a second, entirely independent investigation unless the circumstances justify identifying an investigative gap.



15. An objection may identify an investigative gap

The objection mechanism is not limited to challenging conclusions based on existing evidence.

In appropriate circumstances, a CSA may identify a failure by the LSA to investigate an essential fact or an issue raised by the complainant or another CSA. The source commentary recognises that such an omission can itself form the basis of a relevant and reasoned objection where the failure affects the proper handling of the complaint or the protection of data-subject rights.

This is significant because an incomplete investigation can produce an incorrect legal conclusion.

Illustration

Suppose a complaint alleges that a controller unlawfully processed location data and health-related information. The LSA investigates the location-data issue but does not examine the health-related data at all. A CSA may argue that the draft decision is deficient because an essential part of the alleged processing was never investigated. The objection is not simply:

“We disagree with the outcome.” It is: “The factual investigation was incomplete, and that omission prevents the draft decision from properly addressing the complaint.” That is a materially different type of objection.



16. Evidence must support the objection

A relevant and reasoned objection should be supported by the facts and evidence available to the CSA.

The source commentary emphasises that the CSA should have regard to the facts and evidence supplied by the LSA and should justify its objection through reference to supporting material. These requirements can apply separately to each specific infringement and provision under consideration.

This creates an important practical discipline.

A CSA should not use the objection procedure to introduce an unsupported conclusion.

Illustration

If the LSA concludes that the controller implemented appropriate technical and organisational measures, a CSA seeking to challenge that conclusion should identify the evidence demonstrating the alleged inadequacy. It might point to:

  • an unaddressed security vulnerability;
  • inadequate access controls;
  • missing safeguards;
  • inconsistent internal documentation; or
  • evidence contradicting the controller's description of its security measures. The stronger the factual foundation, the more capable the objection is of satisfying the “reasoned” requirement.


17. What happens when the LSA does not follow the objection?

Article 60(4) creates a specific consequence where the LSA does not follow a relevant and reasoned objection.

If the LSA does not agree with the objection, or considers that the objection is not relevant or reasoned, the matter is referred to the EDPB under the consistency mechanism, in particular Articles 63 and 65(1)(a).

The significance of this mechanism is substantial.

The LSA cannot simply say:

“The CSA disagrees, but the LSA is in charge.”

Instead, a qualifying disagreement can be escalated.

The EDPB then becomes responsible for resolving the dispute within the framework established by Article 65.

This is one of the principal checks built into the one-stop-shop system.



18. Acceptance of the objection

Article 60(5) addresses the opposite situation.

If the LSA intends to follow one or more relevant and reasoned objections raised by the CSAs, it must submit a revised draft decision to the other CSAs for their opinion. In this second round, the CSAs have two weeks to express their opinion.

The procedure therefore distinguishes between two situations:

Objection rejected: dispute may move to the EDPB.

Objection accepted: revised draft decision is circulated to the CSAs.

The two-week period reflects the fact that the LSA has already accepted the substantive objection and modified its position.



Article 60(6) establishes a particularly important procedural consequence.

If none of the CSAs objects to the draft decision within the applicable period, the LSA and CSAs are deemed to agree with the draft decision and are bound by it. The decision thereby becomes final.

This is a legal fiction.

The GDPR does not require each CSA to issue an affirmative statement saying:

“We agree.”

Instead, failure to object within the prescribed period produces the legal consequence of agreement.

The mechanism serves an important practical purpose.

If every authority were required to provide express approval before a cross-border decision could become final, the procedure could be delayed indefinitely by administrative silence.

The rule therefore balances participation against procedural finality.

It can be stated simply:

silence within the prescribed period is not neutral; Article 60 gives it a legal consequence.



20. Adoption of the final decision

Once the cooperation procedure has produced the final outcome, Article 60(7) provides for formal adoption and notification.

The LSA adopts and notifies the decision to the controller's main establishment or single establishment, as applicable. It must also inform the other CSAs and the EDPB of the decision, including a summary of the relevant facts and grounds. The supervisory authority with which the complaint was lodged must inform the complainant.

This creates a distinction between the authority formally adopting the decision and theauthorities participating in the decision-making process.

The final decision is therefore formally issued by the LSA, but it is the product of the cooperative mechanism involving the other CSAs.



21. The position where the complaint is dismissed or rejected in full

Article 60(8) creates a specific derogation from the ordinary procedure in paragraph 7.

Where a complaint is dismissed or rejected, the supervisory authority with which the complaint was lodged adopts the decision and notifies it to the complainant. The controller is informed of the decision.

The reason for this arrangement is practical.

The complainant ordinarily has a relationship with the authority to which the complaint was submitted. If that authority rejects the complaint, it is therefore appropriate that the authority communicates the decision directly to the complainant.

This also facilitates access to national judicial remedies because the complainant is dealing directly with the authority responsible for the rejection.



22. Partial rejection of a complaint

The position becomes more complicated where the complaint is partly rejected and partly upheld.

Article 60(9) requires separate decisions for the respective parts.

The LSA adopts the decision concerning action against the controller or processor. It notifies that decision to the main or single establishment and informs the complainant.

The supervisory authority with which the complaint was lodged adopts the decision concerning the dismissal or rejection of that part of the complaint and notifies the complainant while informing the controller or processor.

The provision therefore separates two distinct procedural outcomes.

Illustration

A complainant alleges:

  1. unlawful processing;
  2. inadequate transparency; and
  3. failure to honour a data-subject request. Suppose the LSA concludes that the controller violated the transparency requirement but finds no infringement concerning the other two allegations. The decision concerning the infringement and resulting corrective action falls within the LSA's role. The rejection of the remaining parts of the complaint is dealt with by the authority of the complainant. This avoids forcing all aspects of a complaint into a single institutional decision-maker where the GDPR deliberately distributes responsibility between the LSA and the authority with which the complaint was lodged.


23. The decision must be implemented across the Union

Article 60(10) moves the cooperation procedure from decision-making to compliance.

After being notified of the decision under paragraphs 7 and 9, the controller or processor must take the necessary measures to ensure compliance with the decision as regards processing activities in the context of all its establishments in the Union. It must notify the measures taken to the LSA, which then informs the other CSAs.

This is an important consequence of the one-stop-shop mechanism.

The controller cannot ordinarily treat the decision as a purely local obligation applicable only to its main establishment.

Illustration

A controller's main establishment is in Member State A, but the relevant processing occurs through establishments in six other Member States. The LSA orders the controller to change the processing mechanism. The controller cannot simply modify the systems at its headquarters in Member State A while leaving the same unlawful processing untouched in the other establishments. Article 60(10) requires compliance in relation to the relevant processing activities across the Union.



24. The controller must notify the measures taken

The controller or processor does not merely have to implement the decision.

It must also notify the measures taken for complying with the decision to the LSA. The LSA then informs the other CSAs.

This creates a feedback mechanism.

The structure is:

LSA adopts decision → controller implements measures → controller reports compliance → LSA informs CSAs.

The cooperation mechanism therefore continues after the substantive decision because effective enforcement requires verification of implementation.



25. Urgent need to protect data subjects

Article 60(11) recognises that the ordinary cooperation procedure may not always be fast enough.

Where, in exceptional circumstances, a CSA has reasons to consider that there is an urgent need to act in order to protect the interests of data subjects, the urgency procedure under Article 66 GDPR applies.

The words “exceptional circumstances” and “urgent need” are important.

Article 66 is not intended to provide an alternative route whenever a CSA disagrees with the LSA.

There must be an urgency capable of justifying departure from the ordinary Article 60 process.

Illustration

Suppose a controller is operating a processing system that is rapidly exposing highly sensitive personal information of a large number of individuals, and waiting for the ordinary cooperation process could materially increase the harm. In such circumstances, a CSA may have grounds to invoke the urgency mechanism. The distinction is therefore:ordinary disagreement → Article 60 cooperation and, where necessary, Article 65 dispute resolution. exceptional urgent threat to data subjects → Article 66 urgency procedure.



26. Electronic communication and standardised format

Article 60(12) requires the LSA and CSAs to supply the information required under Article 60 to one another by electronic means, using astandardised format.

This may appear administrative, but it has practical importance.

Cross-border cooperation can involve:

  • investigative records;
  • draft decisions;
  • objections;
  • evidence;
  • translations;
  • procedural communications;
  • comments from multiple authorities; and
  • final decisions.

A standardised electronic system facilitates the circulation and preservation of these materials.

The source commentary notes that the Board and DPAs have used the Internal Market Information system for cases involving cross-border components and that standardisation may reduce some of the administrative burdens associated with exchanging documents, although translation and other costs may remain substantial.



27. The procedural importance of standardisation

The standardised communication requirement also supports procedural traceability.

In a complicated Article 60 proceeding, it may become necessary to determine:

  • when a draft decision was circulated;
  • when an objection was submitted;
  • whether the objection was submitted within four weeks;
  • whether the LSA accepted or rejected it;
  • when a revised draft was circulated; and
  • whether the applicable two-week period expired without objection.

Electronic standardisation therefore supports not merely administrative efficiency but the integrity of the procedural record.

This is particularly important because the expiry of the relevant periods can produce legal consequences under Article 60(6).



28. Article 60 and the role of the EDPB

The EDPB does not replace the LSA as the ordinary decision-maker under Article 60.

Its role becomes particularly important where the cooperation process breaks down and a qualifying objection cannot be resolved between the LSA and the CSAs.

Article 60 therefore sits between national supervisory enforcement andUnion-level consistency.

The ordinary model is:

LSA + CSAs → consensus → final decision.

The exceptional disagreement model is:

LSA + CSA disagreement → Article 63/65 → EDPB binding decision.

The EDPB therefore functions as a mechanism for resolving certain inter-authority disputes and ensuring consistency across the Union.



29. Article 60 is a co-decision-making mechanism, but formal adoption remains with one authority

The source commentary describes Article 60 as regulating a co-decision-making procedure. This terminology must nevertheless be understood carefully. The provision does not mean that every CSA formally signs the final decision.

Instead, the CSAs participate in the decision-making process through information exchange, opinions and objections, while the LSA formally adopts the decision.

This distinction is central.

The LSA is not simply an administrative postbox for a decision collectively drafted by every authority. Nor is it an autonomous regulator whose decision is immune from the views of the CSAs.

Its role is one of leadership combined with procedural coordination.

That is why Recital 125 is important: the LSA should closely involve and coordinate the other supervisory authorities concerned in the decision-making process.



30. The relationship between Article 60 and national procedural law

Article 60 does not regulate every procedural question that may arise during a cross-border investigation.

The source commentary notes that, in addition to the GDPR, national procedural rules apply to matters that are not regulated by the GDPR.

This is particularly important because supervisory authorities remain embedded in national administrative and judicial systems.

For example, the GDPR may establish the obligation to cooperate and the procedure for raising an objection, but questions concerning certain aspects of administrative procedure, judicial review or national evidentiary rules may remain governed by national law.

The result is therefore a layered system:

GDPR rules → determine the Union-level cooperation framework.

National procedural law → fills procedural matters not harmonised by the GDPR.

This prevents Article 60 from being interpreted as creating a completely self-contained administrative code.



31. The complaint-based procedure

In a complaint-based investigation, the Article 60 procedure ultimately leads to a decision concerning the complaint.

The source commentary identifies two broad outcomes.

The decision may:

  1. find an infringement of the GDPR and require the infringement to be remedied, thereby granting or partially granting the complaint; or
  2. reject or dismiss the complaint, wholly or partly.

The distinction between these outcomes explains why paragraphs 7, 8 and 9 exist.

The GDPR is therefore not concerned only with the controller's obligations. Article 60 also structures the procedural position of the complainant.



32. Why the “relevant and reasoned objection” standard matters

The relevant-and-reasoned-objection requirement performs two competing functions.

First, it protects the CSAs by giving them a meaningful mechanism to challenge an LSA's proposed approach.

Second, it protects the efficiency of the one-stop-shop mechanism by preventing every disagreement from automatically triggering the EDPB's dispute-resolution machinery.

Without a threshold, a CSA could refer almost any disagreement to the next stage.

The requirement therefore filters objections according to their connection with the draft decision and the quality of the reasoning supporting them.

The objection should identify:

what is wrong + why it is wrong + what should change + why that change matters.

The source commentary expressly states that the objection should indicate the deficient or erroneous part of the draft decision and explain why the proposed amendment would remedy the identified error.



33. Relevant and reasoned are separate requirements

The two concepts should not be collapsed.

An objection may be relevant but insufficiently reasoned.

For example:

“The LSA's proposed corrective measure is inadequate because it does not sufficiently protect data subjects.”

This concerns the draft decision and may therefore be relevant. But without explaining what is inadequate, why it creates a risk, what legal or factual material supports the position, and what alternative measure is required, it may fail to satisfy the reasoning requirement.

Conversely, an objection may contain extensive reasoning but still fail to be relevant if the reasoning concerns a matter unrelated to the draft decision.

Thus:

relevance concerns connection.

reasoning concerns justification.

Both are required.



34. The objection must demonstrate significance

Article 4(24) also requires the objection to clearly demonstrate the significance of the risks posed by the draft decision concerning the fundamental rights and freedoms of data subjects and, where applicable, the free flow of personal data within the Union.

This gives the objection a broader constitutional dimension.

The CSA is not merely required to identify a technical disagreement. It should explain why the proposed decision creates a sufficiently significant risk to justify intervention.

Illustration

Suppose a draft decision imposes a minor administrative correction concerning a limited documentation error. A CSA cannot necessarily transform every disagreement concerning the wording of that correction into an Article 65 dispute. The position becomes materially stronger where the draft decision would permit continued processing affecting millions of data subjects in a manner alleged to violate a fundamental GDPR protection. The significance of the potential risk therefore matters.



35. Article 60 seeks uniformity, not merely administrative cooperation

It would be too narrow to describe Article 60 as a provision requiring DPAs to exchange documents.

Its deeper purpose is consistent enforcement of cross-border processing rules.

The source commentary expressly identifies the ultimate aim of the cooperation procedure as adopting a uniform decision for data processing operations of a cross-border nature.

This is particularly important because controllers operating throughout the Union require a degree of regulatory predictability.

If identical processing were lawful in one Member State but unlawful in another solely because different authorities independently assessed the same operation, the one-stop-shop would fail to achieve its intended function.

Article 60 therefore represents an attempt to reconcile:

decentralised national supervision

with

Union-wide consistency.



36. The tension between speed and participation

Article 60 contains an inherent institutional tension.

Greater participation by CSAs can improve the quality and legitimacy of the decision because authorities directly familiar with the interests of affected data subjects can contribute to the analysis.

But greater participation can also make proceedings slower.

This is particularly significant because the LSA must exchange information, engage with other authorities, prepare a draft decision, consider objections, potentially prepare a revised draft, and coordinate implementation. The source commentary notes that cross-border procedures may in practice extend over several years.

The GDPR therefore attempts to control delay through specific procedural periods, particularly:

  • four weeks for CSAs to raise objections; and
  • two weeks to comment on a revised draft decision.

The LSA itself, however, is not subject to an equivalent general statutory deadline under Article 60(3).

This asymmetry is significant.

The CSAs are placed under defined response periods, while the LSA has greater flexibility in conducting the substantive procedure.



37. Article 60 and protection of data-subject rights

Although Article 60 is primarily an institutional provision, its ultimate justification is the protection of data subjects.

The cooperation mechanism exists because cross-border processing can affect individuals across several jurisdictions. A fragmented enforcement structure could result in inconsistent protection depending upon the Member State in which the individual happens to live.

The requirement that objections demonstrate the significance of risks to the fundamental rights and freedoms of data subjects reinforces this connection.

The procedure should therefore not be understood solely from the perspective of the administrative convenience of regulators.

Its purpose is ultimately protective.

If the cooperation mechanism functions properly, a data subject in one Member State can benefit from an enforcement decision concerning a cross-border processing activity that extends beyond the borders of the Member State in which the complaint was made.



38. Article 60 and accountability of controllers

The cross-border nature of the decision also has consequences for controllers and processors.

A controller operating across the Union cannot assume that the existence of a main establishment in one Member State means that only the regulatory expectations of that Member State matter.

The controller must engage with the substantive requirements of the GDPR throughout its Union-wide processing activities.

Once an Article 60 decision is adopted, Article 60(10) reinforces this by requiring necessary measures to ensure compliance across the Union in relation to the relevant processing activities.

This is an important expression of the GDPR's accountability principle.



39. A practical example of the complete Article 60 procedure

Consider a multinational technology company whose main establishment is in Member State A. It operates a behavioural advertising system throughout the Union.

A data subject in Member State B files a complaint alleging unlawful profiling.

The procedure may develop as follows.

First, the authority in Member State A is identified as the LSA under Article 56.

Second, the LSA identifies the authorities in Member States B, C and D as CSAs because the processing affects data subjects in those jurisdictions.

Third, the LSA and CSAs exchange relevant information concerning the processing.

Fourth, the authorities cooperate through mutual assistance or joint investigative measures where necessary.

Fifth, the LSA prepares a draft decision.

Sixth, the draft decision is circulated to the CSAs for their opinions.

Seventh, the CSAs may raise relevant and reasoned objections within the applicable four-week period.

Eighth, if an objection is accepted, the LSA revises the draft and circulates it again, giving the CSAs two weeks to respond.

Ninth, if a relevant and reasoned objection is not followed, the dispute is referred to the EDPB under the consistency mechanism.

Tenth, once the decision becomes final, the LSA adopts and notifies it.

Eleventh, the controller implements the required measures across its relevant Union establishments.

Twelfth, the controller reports the measures taken to the LSA, which informs the other CSAs.

This example demonstrates why Article 60 is better understood as a complete procedural architecture rather than a simple cooperation clause.



40. The significance of the final decision

The final decision under Article 60 has significance beyond the LSA's Member State.

The controller or processor must ensure compliance across the Union in relation to the relevant processing activities. This is what gives the one-stop-shop system much of its practical value.

At the same time, the complainant's procedural position remains linked to the supervisory authority with which the complaint was lodged, particularly in cases of rejection or dismissal.

Article 60 therefore combines two dimensions:

Union-wide substantive enforcement

with

nationally accessible complaint procedures.

That balance is one of the more sophisticated aspects of the provision.



41. Article 60 does not give the LSA an absolute veto

The institutional position can now be stated more precisely.

The LSA is the authority responsible for directing and coordinating the procedure. It formally adopts the final decision. But its authority is constrained by the obligation to cooperate, exchange relevant information, seek consensus and take the views of the CSAs into due account.

Most importantly, a relevant and reasoned objection that the LSA refuses to follow can trigger the EDPB dispute-resolution mechanism.

Therefore:

LSA leadership ≠ LSA supremacy.

The LSA leads the procedure, but the GDPR embeds mechanisms through which the other authorities can influence and, where necessary, challenge the proposed outcome.



42. Article 60 does not give the CSAs an absolute veto

The opposite proposition is equally important.

The CSAs do not possess an unrestricted veto merely because they disagree with the LSA.

Their objection must satisfy the statutory standard of being relevant and reasoned. Broad, abstract or unsupported disagreement is insufficient.

If the LSA accepts the objection, the draft is revised.

If the LSA rejects a qualifying objection, the matter can proceed to the EDPB.

The CSA therefore has a meaningful procedural power, but that power operates within the architecture of the one-stop-shop rather than independently of it.



43. The importance of procedural fairness

Article 60 also demonstrates that cross-border enforcement is not simply a matter of institutional competence.

The procedural architecture affects the rights of all parties involved.

For the data subject, the mechanism provides a structured route for complaints concerning cross-border processing.

For the controller or processor, it provides a single coordinated decision rather than potentially contradictory national enforcement decisions.

For the CSAs, it provides an opportunity to influence the outcome and challenge deficiencies in the LSA's draft.

For the EDPB, it provides a mechanism for resolving certain disputes and promoting consistency.

The provision therefore distributes procedural functions among several actors while retaining a central coordinating role for the LSA.



44. Overall assessment of Article 60

Article 60 represents one of the clearest examples of the GDPR's attempt to reconcile national regulatory authority with Union-wide consistency.

Before the GDPR, cross-border data protection supervision could be complicated by the territorial structure of national authorities. The one-stop-shop sought to address this by creating an LSA-led mechanism.

But the GDPR did not solve the problem simply by selecting one authority and excluding all others.

Instead, Article 60 creates a more elaborate arrangement:

  • the LSA directs and coordinates;
  • CSAs participate;
  • relevant information is exchanged;
  • consensus is pursued;
  • opinions are considered;
  • objections can be raised;
  • qualifying disagreements can reach the EDPB;
  • final decisions are formally adopted by the LSA;
  • complaints may require specific notification arrangements;
  • implementation extends across relevant Union establishments; and
  • urgent circumstances can activate Article 66.

The provision is consequently both centralising and cooperative.

It centralises decision-making by assigning leadership to one supervisory authority.

At the same time, it decentralises participation by requiring the involvement of authorities concerned in other Member States.



45. Conclusion

Article 60 GDPR should therefore not be understood merely as a provision requiring supervisory authorities to “cooperate”.

Its real function is to establish the decision-making architecture for cross-border GDPR enforcement.

The LSA occupies the central position, but its role is one of coordination rather than unrestricted control. It must identify the CSAs, exchange relevant information, involve them in the procedure, endeavour to reach consensus and submit a draft decision for their opinion. The CSAs, in turn, have a defined opportunity to challenge the draft through relevant and reasoned objections. Where an objection is accepted, the draft decision is revised. Where a relevant and reasoned objection is rejected, the dispute can move to the EDPB's consistency mechanism. Where no objection is raised within the prescribed period, the authorities are deemed to agree with and become bound by the draft decision.

The procedure therefore contains a deliberate sequence:

identify the LSA → identify the CSAs → exchange information → cooperate → seek consensus → circulate draft decision → allow objections → revise or refer the dispute → adopt the final decision → implement the decision across the Union.

The distinction between the LSA and the CSAs is consequently fundamental. The LSA leads, but it must listen. The CSAs participate, but they must substantiate their objections. Consensus is preferred, but disagreement does not paralyse the system. And the EDPB provides the mechanism for resolving qualifying disputes when cooperation alone does not produce agreement.

Article 60 can therefore be reduced to one central proposition:

Cross-border GDPR enforcement is not intended to be a collection of parallel national decisions; it is intended to be a coordinated Union-wide process in which one authority leads, the other concerned authorities participate, and unresolved disagreements are channelled into the consistency mechanism.

That is the essential logic of Article 60.