CHAPTER VIICOOPERATION AND CONSISTENCY

Article 61Mutual assistance

Official text

(1)Supervisory authorities shall provide each other with relevant information and mutual assistance in order to implement and apply this Regulation in a consistent manner, and shall put in place measures for effective cooperation with one another. Mutual assistance shall cover, in particular, information requests and supervisory measures, such as requests to carry out prior authorisations and consultations, inspections and investigations.

(2)Each supervisory authority shall take all appropriate measures required to reply to a request of another supervisory authority without undue delay and no later than one month after receiving the request. Such measures may include, in particular, the transmission of relevant information on the conduct of an investigation.

(3)Requests for assistance shall contain all the necessary information, including the purpose of and reasons for the request. Information exchanged shall be used only for the purpose for which it was requested.

(4)The requested supervisory authority shall not refuse to comply with the request unless:

(a)it is not competent for the subject-matter of the request or for the measures it is requested to execute; or

(b)compliance with the request would infringe this Regulation or Union or Member State law to which the supervisory authority receiving the request is subject.

(5)The requested supervisory authority shall inform the requesting supervisory authority of the results or, as the case may be, of the progress of the measures taken in order to respond to the request. The requested supervisory authority shall provide reasons for any refusal to comply with a request pursuant to paragraph 4.

(6)Requested supervisory authorities shall, as a rule, supply the information requested by other supervisory authorities by electronic means, using a standardised format.

(7)Requested supervisory authorities shall not charge a fee for any action taken by them pursuant to a request for mutual assistance. Supervisory authorities may agree on rules to indemnify each other for specific expenditure arising from the provision of mutual assistance in exceptional circumstances.

(8)Where a supervisory authority does not provide the information referred to in paragraph 5 of this Article within one month of receiving the request of another supervisory authority, the requesting supervisory authority may adopt a provisional measure on the territory of its Member State in accordance with Article 55 (1). In that case, the urgent need to act under Article 66 (1) shall be presumed to be met and require an urgent binding decision from the Board pursuant to Article 66 (2).

(9)The Commission may, by means of implementing acts, specify the format and procedures for mutual assistance referred to in this Article and the arrangements for the exchange of information by electronic means between supervisory authorities, and between supervisory authorities and the Board, in particular the standardised format referred to in paragraph 6 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93 (2).

Commentary

Article 61 creates the practical machinery through which national data protection authorities help one another. It recognises a simple reality: personal-data processing may cross national borders, but each supervisory authority normally exercises its compulsory public powers only within its own Member State.

The Article therefore establishes a binding system of regulator-to-regulator assistance. One authority may ask another to obtain information, inspect premises, conduct an investigation, undertake a prior consultation or perform another supervisory measure within the requested authority’s territory. The requested authority must normally act promptly, free of charge and through secure electronic channels. It may refuse only on two narrowly defined legal grounds.


1. The central purpose of Article 61

The GDPR creates national supervisory authorities, but it seeks a consistent level of protection throughout the EEA. That objective would fail if every authority could act effectively only where all evidence, systems, establishments and affected persons were located in its own country.

Consider a simple example.

A French authority receives a complaint from French users about an online service. The controller’s main establishment is in the Netherlands, its technical team is in Germany, the relevant servers are in Denmark and its processor is in Ireland.

The French authority cannot enter the German office or inspect the Danish data centre by exercising French public powers abroad. Instead, the GDPR provides a cooperation architecture:

  • Article 60 coordinates cross-border decisions under the one-stop shop;
  • Article 61 allows authorities to request assistance from one another;
  • Article 62 allows joint operations;
  • Articles 63 to 65 provide consistency and dispute-resolution mechanisms;
  • Article 66 permits urgent provisional action.

Article 61 is thus the legal bridge between national territorial powers and Europe-wide GDPR enforcement. Its text requires authorities to exchange relevant information, provide mutual assistance, reply within one month, give reasons for refusals, normally communicate electronically and provide assistance without charging one another.


2. Mutual assistance is not optional diplomacy

Article 61 does not establish a voluntary network in which authorities may help one another when convenient. It uses mandatory language:

Supervisory authorities “shall” provide one another with relevant information and mutual assistance.

The requested authority is therefore subject to a legal duty. It cannot refuse merely because:

  • the request creates work;
  • it considers another case more important;
  • it disagrees with the requesting authority’s legal strategy;
  • the controller is economically important in its country;
  • the two authorities have institutional disagreements;
  • the request concerns a politically sensitive public body;
  • translation or technical investigation will be inconvenient.

The two permitted grounds for refusal are stated in paragraph 4 and are deliberately narrow:

  1. lack of competence; or
  2. unlawfulness of compliance.

This mandatory character reflects Recital 123, under which cooperation follows directly from the GDPR without any separate agreement between Member States. Authorities do not need a bilateral treaty before helping each other.

3. Article 61 and the independence of supervisory authorities

Each supervisory authority remains independent under Article 52. Mutual assistance does not place the requested authority under the hierarchical control of the requesting authority.

The requesting authority may identify what information or action it requires, but the requested authority:

  • exercises powers under the law applicable to it;
  • follows its own lawful procedural requirements;
  • determines how to carry out the requested measure;
  • remains responsible for the legality of its actions;
  • may refuse if it lacks competence or if compliance would be unlawful.

Illustration

The Spanish authority asks the German authority to enter a company’s German premises without notice and copy all devices. German procedural law requires prior judicial authorisation for that type of entry. The German authority is not required to ignore German law. It may:

  • seek the required judicial authorisation;
  • ask Spain for further supporting material;
  • narrow the proposed inspection;
  • use a less intrusive lawful measure;
  • refuse the specific execution method if it would be unlawful. Mutual assistance requires sincere cooperation, not blind obedience.

4. Relationship between Articles 60, 61 and 62

These provisions have related but different functions.

Article 60: Coordinated decision-making

Article 60 governs cooperation between the lead supervisory authority and supervisory authorities concerned in a cross-border case. It covers information exchange, draft decisions, objections, EDPB dispute resolution and adoption of the final decision.

Article 61: Specific assistance

Article 61 normally involves one authority asking another for information or for a defined supervisory measure.

Article 62: Joint operations

Article 62 enables authorities to conduct an operation together, such as a joint investigation or coordinated inspection.

Illustration

The Dutch authority is the lead authority in an investigation. It may use:

  • Article 60 to involve the French and German authorities in the European decision-making process;
  • Article 61 to ask France to interview employees at a French establishment;
  • Article 62 to establish a joint Dutch-German technical inspection team. The mechanisms may operate together. Article 60(2) expressly permits the lead authority to request Article 61 mutual assistance and conduct Article 62 joint operations.

4.1 Article 61 is not confined to one-stop-shop cases

The wording of Article 61 is not limited to relationships between a lead authority and concerned authorities.

It may apply whenever assistance is needed to implement and apply the GDPR consistently, including situations involving:

  • uncertainty about the lead authority;
  • transnational evidence that does not amount to cross-border processing under Article 4(23);
  • assistance with a purely national investigation where evidence happens to be in another country;
  • implementation of an already adopted measure;
  • verification of a controller’s representations;
  • supervisory cooperation outside a formal complaint.

[!example] Illustration An Austrian controller processes only Austrian customers’ data, so the main case is national. Its processor stores relevant security logs in Denmark. The Austrian authority may request Danish assistance even though the underlying processing is not necessarily a one-stop-shop case.

5. Article 61(1): Relevant information and mutual assistance

Paragraph 1 imposes three connected obligations:

  1. authorities must provide relevant information;
  2. authorities must provide mutual assistance;
  3. authorities must establish measures for effective cooperation.

The objective is consistent implementation and application of the GDPR.

The supplied commentary observes a possible linguistic question concerning the words “information and mutual assistance.” The better interpretation is that the two obligations are complementary.

Information exchange may itself be a form of assistance. But mutual assistance is broader because it may require actual supervisory action, such as:

  • interviewing witnesses;
  • inspecting premises;
  • obtaining system records;
  • conducting an audit;
  • seeking a judicial warrant;
  • verifying compliance with an order.

[!example] Illustration Authority A asks Authority B whether a controller has previously been investigated. If Authority B provides the relevant decision and case status, the assistance consists largely of information. If Authority A asks Authority B to inspect the controller’s local server room, Authority B must do more than forward documents. It must consider and, where lawful, execute a supervisory measure.

6. What counts as “relevant information”?

Information is relevant where it has a reasonable connection with:

  • the authority’s competence;
  • the processing operation;
  • the alleged infringement;
  • the identity or role of a controller or processor;
  • the affected data subjects;
  • the appropriate investigation;
  • the proposed corrective measure;
  • implementation of a decision.

Examples

include:

  • complaints;
  • audit findings;
  • breach notifications;
  • technical reports;
  • controller submissions;
  • legal-basis assessments;
  • retention policies;
  • processing agreements;
  • previous enforcement decisions;
  • information about the main establishment;
  • evidence concerning the scale of affected persons;
  • records showing compliance with an order.

Illustration

A Polish authority investigates whether an application tracks users without consent. The Swedish authority has already audited the same application. The Swedish authority’s findings concerning:

  • tracking technologies;
  • consent design;
  • data recipients;
  • retention;
  • technical identifiers may be relevant. An unrelated Swedish tax dispute involving the company’s building lease would ordinarily not be relevant.

6.1 Relevance is assessed functionally

Authorities should not define relevance so narrowly that cooperation becomes ineffective.

Information may be relevant even though it does not conclusively prove an infringement. For example, it may:

  • identify a witness;
  • contradict a controller’s statement;
  • reveal another affected country;
  • indicate that further investigation is required;
  • show that the processing has changed.

Conversely, the requesting authority should not demand the entire institutional archive of another authority without explaining the connection to the case.


7. “Put in place measures for effective cooperation”

Paragraph 1 requires more than case-by-case goodwill. Authorities must build practical systems that make cooperation work.

Appropriate measures may include:

  • designated contact points;
  • trained cooperation teams;
  • secure electronic systems;
  • case-tracking procedures;
  • escalation mechanisms;
  • translation arrangements;
  • internal deadlines;
  • templates for requests and responses;
  • processes for approving joint investigative action;
  • secure handling of confidential evidence;
  • methods for identifying the correct national or regional authority.

Illustration

An authority receives an urgent assistance request, but:

  • no one monitors the cooperation inbox;
  • the request is not registered;
  • staff cannot identify the responsible department;
  • nobody records the one-month deadline. That authority has not merely mishandled one file. It may also have failed to establish effective cooperation measures as required by paragraph 1.

7.1 Multiple authorities within one Member State

Recital 119 is particularly relevant where a Member State has several supervisory authorities. National law should create mechanisms ensuring their effective participation and designate a single contact point for smooth cooperation with other authorities, the EDPB and the Commission.

[!example] Illustration A federal state has regional authorities with different territorial jurisdictions. A Portuguese authority should not have to send the same request to sixteen regional offices hoping that one accepts competence. The Member State should provide a functioning contact-point system that routes the request promptly to the appropriate authority. A contact point does not necessarily replace the substantively competent authority. Its purpose is to ensure that requests do not disappear within a complex national structure.

8. Types of mutual assistance expressly mentioned

Article 61(1) gives a non-exhaustive list:

  • information requests;
  • prior authorisations;
  • consultations;
  • inspections;
  • investigations.

The phrase “in particular” means other appropriate assistance may also be covered.

8.1 Information requests

Authority A may ask Authority B for:

  • records from an existing case;
  • information obtained from a local controller;
  • details of previous measures;
  • confirmation of an establishment;
  • technical or legal information.

8.2 Prior authorisations

A cross-border processing arrangement may require a prior authorisation, such as certain bespoke transfer safeguards. Another authority may need local information before the authorising authority can decide.

8.3 Consultations

An authority may seek another authority’s factual or legal input, particularly where a proposed processing operation affects several Member States.

8.4 Inspections

The requested authority may be asked to inspect:

  • offices;
  • systems;
  • data centres;
  • physical registers;
  • CCTV equipment;
  • security mechanisms.

Any inspection must comply with Article 58 and applicable procedural law.

8.5 Investigations

The requested authority may conduct:

  • interviews;
  • document collection;
  • technical tests;
  • audits;
  • verification of local practices;
  • examination of a processor or establishment.

9. The list is non-exhaustive

Other forms of mutual assistance may include:

  • serving a regulatory notice;
  • confirming whether an order was implemented;
  • preserving evidence;
  • locating a controller or processor;
  • identifying the correct establishment;
  • checking whether local users received breach notifications;
  • verifying deletion;
  • obtaining public records;
  • providing translation support;
  • facilitating contact with another competent public authority.

Illustration

A lead authority orders a multinational company to delete profiles throughout the EEA. It asks local authorities to verify that:

  • deleted profiles no longer appear in local systems;
  • the old processing interface has been disabled;
  • local establishments no longer generate new profiles. That verification is a natural form of mutual assistance even though “compliance verification” is not separately listed in paragraph 1.

10. Article 61(2): Duty to take appropriate measures

The requested authority must take all appropriate measures required to reply.

This does not mean that it must always perform exactly the act worded by the requester. It must determine what lawful and appropriate action will produce a useful response.

Possible steps include:

  • checking competence;
  • seeking clarification;
  • examining existing records;
  • contacting the controller;
  • issuing an information order;
  • conducting an inspection;
  • consulting another domestic authority;
  • obtaining judicial authorisation;
  • transmitting relevant investigation information;
  • giving a reasoned status update.

Illustration

The French authority requests copies of access logs from an establishment in Italy. The Italian authority discovers that the logs are held by an Italian processor. Appropriate measures may involve:

  1. sending a lawful information order to the processor;
  2. verifying the completeness of the logs;
  3. redacting irrelevant third-party data where necessary;
  4. securely transmitting the relevant material to France.

Merely confirming receipt of the request would not ordinarily be enough.


11. “Without undue delay” and the one-month maximum

The authority must reply:

  • without undue delay; and
  • no later than one month after receiving the request.

These are cumulative standards.

The one-month period is the outer limit for a response under paragraph 5. It is not a licence to wait a full month where the matter can be answered immediately.

Illustration

The requested authority already possesses the relevant final decision. It can send it securely within two days. Waiting until the last day of the month without reason may conflict with “without undue delay.” By contrast, an on-site forensic inspection may not be completed within one month. In that situation, the requested authority must provide a meaningful progress update within the month.

11.1 What must happen within the month?

The text should be read with paragraph 5.

Within one month, the requested authority should provide:

  • the result, where the measure is complete; or
  • meaningful information about progress and measures taken, where work continues; or
  • a reasoned refusal under paragraph 4.

The requested authority is not always required to complete a complex investigation within one month. But it cannot remain silent.

11.2 When does the month begin?

The period begins when the request is received by the competent requested authority through the recognised cooperation channel.

Practical questions may arise where:

  • the request is sent to the wrong authority;
  • the request lacks necessary information;
  • a technical attachment is unreadable;
  • competence must be allocated within a federal system.

Good cooperation requires the receiving contact point to flag the problem promptly rather than wait until the deadline expires.

If essential information is missing, the requested authority should seek clarification immediately. Whether the formal deadline is affected may depend on applicable procedural rules and the severity of the deficiency. An authority should not deliberately create uncertainty by treating a clearly understandable request as incomplete.


12. A receipt acknowledgment is not necessarily a substantive reply

The supplied commentary incorrectly links electronic acknowledgment to paragraph 7. Electronic communication is governed by paragraph 6. Paragraph 7 concerns fees.

More importantly, a message stating:

“Your request has been received”

does not normally satisfy paragraph 5 if no results, progress information or reasoned refusal follow within the month.

A proper progress response should explain:

  • what measure has been taken;
  • what remains outstanding;
  • any legal or practical obstacle;
  • the expected next stage;
  • whether further information is needed.

Adequate example

“The authority issued an information order on 10 March. The controller responded on 22 March. Technical review is underway, and the verified logs are expected to be transmitted by 15 April.”

Inadequate example

“The request is being processed.”

The second message supplies too little information to allow the requesting authority to assess the position.


13. “All appropriate measures” does not require unlawful action

The requested authority must remain within:

  • Article 58 powers;
  • its territorial competence;
  • national procedural safeguards;
  • the Charter;
  • professional-secrecy rules;
  • rights of defence;
  • judicial-warrant requirements.

Illustration

The requesting authority asks for a secret night-time search of a lawyer’s home office. The requested authority must consider:

  • whether it is competent;
  • whether lawful access powers exist;
  • whether a warrant is required;
  • whether legal privilege applies;
  • whether the scope is proportionate;
  • whether a less intrusive method is available. Mutual assistance cannot convert an unlawful measure into a lawful one.

14. Article 61(3): Content of the request

A valid request must contain all information necessary for the requested authority to act, including:

  • the purpose of the request;
  • the reasons for the request.

A well-framed request should ordinarily identify:

  • requesting authority;
  • case reference;
  • controller or processor;
  • relevant processing operation;
  • factual background;
  • suspected GDPR provisions;
  • requested information or measure;
  • why the requested authority is competent;
  • desired timeframe;
  • urgency;
  • confidentiality requirements;
  • how the result will be used.

Illustration

of a poor request “Please investigate Company X and send us everything.” This request does not specify:

  • the processing involved;
  • suspected infringement;
  • information sought;
  • purpose;
  • connection with the requested state.

Illustration

of a proper request “We are investigating whether Company X unlawfully retains applicants’ biometric templates after recruitment. Its German establishment operates the relevant server. Please obtain the retention configuration, deletion logs for the previous 12 months and the local administrator’s written explanation. The material is required to determine compliance with Articles 5(1)(e), 6 and 17.” The second request allows the German authority to act lawfully and efficiently.


15. Why purpose and reasons must be stated

Purpose and reasons allow the requested authority to verify:

  • relevance;
  • necessity;
  • competence;
  • proportionality;
  • legality;
  • appropriate investigative method;
  • permitted later use.

They also protect the controller, processor and affected individuals against unexplained regulatory fishing expeditions.

Illustration

An authority requests the entire customer database of a multinational retailer. The requested authority cannot assess proportionality unless it knows whether the investigation concerns:

  • one access request;
  • a security breach;
  • discriminatory profiling;
  • systemic unlawful retention. The same database request might be unnecessary in the first case but potentially relevant in the third or fourth.

16. Purpose limitation on exchanged information

Paragraph 3 states that exchanged information may be used only for the requested purpose.

This creates a regulator-to-regulator purpose-limitation rule.

Illustration

The Danish authority supplies technical logs to the Austrian authority for an investigation into whether account access was unauthorised. The Austrian authority should not later use the logs for:

  • an unrelated employee-disciplinary investigation;
  • publication in a public report;
  • a commercial research project;
  • disclosure to the media without a further lawful basis and appropriate cooperation.

16.1 Purpose must not be defined too narrowly

The “purpose” should reflect the legitimate scope of the investigation.

If information is requested to examine the lawfulness and security of a particular profiling system, it may be used for:

  • factual findings;
  • legal analysis;
  • corrective measures;
  • fine assessment;
  • judicial defence of the decision;
  • monitoring compliance with the outcome.

These are connected parts of the same regulatory purpose.

16.2 New infringement discovered incidentally

Suppose exchanged material reveals a separate serious violation.

The receiving authority should not simply repurpose the material silently.

Appropriate steps may include:

  • notifying the supplying authority;
  • seeking permission or a fresh request;
  • opening a separate ex officio investigation;
  • collecting the evidence independently;
  • considering whether another legal duty authorises or requires action.

[!example] Illustration Logs supplied to investigate unlawful advertising reveal an unreported breach exposing health data. The receiving authority should coordinate with the supplying authority and use the proper procedural route. Purpose limitation should not force regulators to ignore serious harm, but it requires lawful and transparent handling of the new issue.

17. Article 61(4): Exhaustive refusal grounds

The authority may refuse only where:

  1. it is not competent for the subject matter or requested measures; or
  2. compliance would infringe the GDPR, EU law or applicable Member State law.

The phrase “shall not refuse unless” signals an exhaustive list. Member States should not create additional refusal grounds such as:

  • resource inconvenience;
  • political sensitivity;
  • disagreement with the requesting authority;
  • lack of a bilateral arrangement;
  • commercial importance of the investigated entity.

The statutory text confirms these two refusal grounds and requires a reasoned refusal.


18. Paragraph 4(a): Lack of competence

The requested authority may lack competence because:

  • the controller has no relevant establishment in its territory;
  • the data-processing operation is outside its territorial remit;
  • another domestic supervisory authority is competent;
  • the measure concerns a court acting in its judicial capacity;
  • the requested act falls under another legal regime;
  • the authority lacks the particular power under applicable law.

Illustration

The French authority asks a German regional authority to inspect an establishment located outside that regional authority’s jurisdiction. The requested authority may refuse because it lacks territorial competence. Sincere cooperation would normally require it to indicate the competent German authority or route the request through the national contact point.

18.1 Subject-matter competence and measure competence

These are distinct.

An authority may be competent for the investigation’s subject matter but not for the particular requested measure.

[!example] Illustration The authority may supervise the controller but may not itself authorise entry into a private home. A court may need to issue the warrant. The authority should not necessarily reject the entire request. It may explain the lawful procedure and take the steps within its power.

19. Paragraph 4(b): Compliance would be unlawful

The requested authority may refuse where execution would violate:

  • the GDPR;
  • other EU law;
  • applicable Member State law.

Examples

may include:

  • unlawful disclosure of privileged material;
  • absence of a required judicial authorisation;
  • disproportionate access to irrelevant personal data;
  • violation of criminal-procedure secrecy;
  • unlawful interference with judicial independence;
  • breach of protected journalistic sources;
  • execution of a measure prohibited by applicable national procedural law.

Illustration

The requesting authority asks for all patient records held by a local hospital, although the investigation concerns one employee’s access to one file. The requested authority may conclude that wholesale disclosure would violate necessity, proportionality or secrecy rules. It should consider whether a narrower disclosure can satisfy the legitimate purpose.

19.1 National law cannot undermine EU cooperation

Paragraph 4(b) recognises applicable national law, but Member States cannot enact or invoke national rules that make Article 61 cooperation ineffective.

[!example] Illustration A national rule states: “The supervisory authority may never share information with another EEA authority.” Such a rule would conflict directly with Article 61 and could not lawfully justify refusal. National law may regulate how assistance is carried out. It may not abolish the EU duty.

20. Partial compliance and alternative measures

Paragraph 4 is often presented as a yes-or-no decision, but proportional cooperation may support partial execution.

Illustration

A request seeks ten categories of documents. Two are protected by legal privilege, while eight can lawfully be disclosed. The requested authority should ordinarily:

  • provide the eight permissible categories;
  • explain why the two protected categories cannot be supplied;
  • consider redaction or an alternative form of access;
  • identify any judicial procedure that might resolve the issue. A total refusal would be difficult to justify where most of the request can lawfully be fulfilled.

21. Article 61(5): Results, progress and reasoned refusal

The requested authority must inform the requesting authority of:

  • the result; or
  • progress of the measures taken.

If it refuses, it must give reasons.

21.1 Result

A result may include:

  • requested documents;
  • inspection report;
  • witness statement;
  • confirmation of compliance;
  • finding that no relevant records exist;
  • technical analysis;
  • outcome of a prior consultation;
  • evidence that the establishment has closed.

21.2 Progress

Where the final result is unavailable, the progress update should identify concrete steps.

Illustration

“A judicial warrant was requested on 4 May, granted on 11 May, and the inspection is scheduled for 19 May. The final report is expected within two weeks after inspection.” That is meaningful progress information.

21.3 Reasons for refusal

A reasoned refusal should specify:

  • the relevant paragraph 4 ground;
  • material facts;
  • legal provision;
  • why compliance would exceed competence or violate law;
  • whether partial compliance is possible;
  • whether another authority is competent;
  • possible steps for reformulating the request.

Inadequate refusal

“We cannot assist because of domestic law.”

Adequate refusal

“The requested inspection concerns judicial case files held by a court acting in its judicial capacity. Under Article 55(3) and section X of national law, this authority lacks competence. The competent judicial oversight body is Y.”


22. Must the requested authority disclose ongoing investigation information?

Paragraph 2 expressly recognises that assistance may include transmission of relevant information concerning the conduct of an investigation.

However, the authority should consider:

  • confidentiality;
  • rights of defence;
  • integrity of the investigation;
  • risks of evidence destruction;
  • whistleblower protection;
  • restrictions under applicable law.

[!example] Illustration The requested authority is conducting a covert inspection and immediate disclosure would alert the controller. It may be lawful to provide a limited progress update rather than disclose planned operational details. It should explain the constraint sufficiently without compromising the investigation.

23. Article 61(6): Electronic means and standardised format

As a rule, information should be supplied:

  • electronically; and
  • through a standardised format.

“As a rule” allows exceptions. Urgent information may initially be provided by:

  • telephone;
  • secure video communication;
  • another rapid channel.

The information should then ordinarily be formally recorded through the recognised electronic system.

23.1 Why electronic standardisation matters

Cross-border cooperation involves:

  • numerous authorities;
  • procedural deadlines;
  • large evidence files;
  • multiple languages;
  • confidentiality;
  • audit trails.

Standardised electronic communication helps record:

  • sending and receipt dates;
  • requesting and requested authorities;
  • purpose;
  • legal basis;
  • urgency;
  • attachments;
  • response;
  • refusal;
  • deadline.

23.2 Security

Electronic communication should be:

  • authenticated;
  • encrypted where appropriate;
  • access-controlled;
  • logged;
  • protected against alteration;
  • limited to authorised personnel.

Authorities may exchange highly sensitive material, including:

  • health data;
  • security vulnerabilities;
  • complainant identities;
  • trade secrets;
  • investigation plans.

Ordinary unencrypted email may not be appropriate for all material.

23.3 Standard format is not a mere box-ticking exercise

The form should contain enough substance to permit lawful execution.

An authority cannot satisfy paragraph 3 merely by selecting:

“Purpose: GDPR investigation”

from a drop-down menu while failing to explain what is being investigated and why the measure is required.

24. Article 61(7): No fees

The requested authority normally cannot charge the requesting authority for assistance.

This avoids a system in which regulators invoice one another for every:

  • document search;
  • email;
  • inspection;
  • interview;
  • legal analysis.

Such billing could deter cooperation and create unnecessary administration.

[!example] Illustration The Spanish authority asks Portugal to verify whether a Portuguese establishment changed its retention system. Portugal cannot make action conditional upon payment of a routine inspection fee.

25. Exceptional indemnification of specific expenditure

Authorities may agree on rules for reimbursement of specific costs in exceptional circumstances.

Possible examples include:

  • expensive external forensic experts;
  • specialist laboratory testing;
  • unusual interpretation services;
  • extensive travel;
  • extraordinary data recovery;
  • a large-scale coordinated technical operation.

Three limitations matter.

First, exceptional costs should not become routine fees.

Second, the authorities should agree on reimbursement rules.

Third, cost discussions should not delay urgent protection.

[!example] Illustration A regulator needs a specialist to reverse-engineer a complex biometric system. The expert’s cost is far beyond ordinary investigation expenses. The authorities may agree that the requesting authority will reimburse part of that specific expenditure. This is different from charging for ordinary staff time.

26. Article 61(8): Consequences of silence

Paragraph 8 provides a strong response where the requested authority fails to provide the paragraph 5 information within one month.

The requesting authority may:

  1. adopt a provisional measure within its own Member State under Article 55(1);
  2. rely on a statutory presumption that urgent action is necessary under Article 66(1); and
  3. seek an urgent binding EDPB decision under Article 66(2).

This provision prevents one authority’s silence from paralysing protection.

The text links the failure to respond with a territorial provisional measure and presumed urgency.


27. What triggers paragraph 8?

Paragraph 8 is triggered where the requested authority does not provide:

  • results; or
  • progress information

within one month.

It is therefore directed at non-response, not necessarily failure to complete the requested investigation.

Illustration

Authority B cannot finish an inspection within one month but sends a detailed progress update on day 20. Paragraph 8 should not be triggered merely because the final report remains pending. If Authority B provides no result, progress update or reasoned refusal by the deadline, paragraph 8 becomes relevant.

27.1 A meaningless response may not be enough

An authority should not be able to avoid paragraph 8 by sending a one-line message:

“Your request is under consideration.”

A purely formal communication containing no meaningful progress may fail to satisfy paragraph 5.

The requesting authority should nevertheless act carefully before invoking provisional powers, especially where there is a genuine dispute about whether the response was sufficient.


28. Provisional measures are territorial

The requesting authority may adopt a provisional measure only on the territory of its own Member State under Article 55(1).

Possible measures include:

  • temporary restriction;
  • temporary ban;
  • order directed to a local establishment;
  • temporary suspension of a local operation;
  • another interim measure permitted by Article 58 and national law.

Illustration

The French authority asks another authority for urgent security information but receives no response. It may temporarily restrict the relevant processing in France. It does not automatically obtain power to impose a permanent EEA-wide ban. Territorial limitation respects:

  • national competence;
  • the lead-authority structure;
  • the temporary nature of emergency intervention.

29. Presumed urgency

Ordinarily, Article 66 requires the authority to demonstrate exceptional circumstances and urgent need.

Under Article 61(8), the absence of a timely mutual-assistance response means urgency is presumed.

The logic is practical:

  • information needed to assess the risk has not been provided;
  • delay may leave people unprotected;
  • the requesting authority should not be paralysed by another regulator’s silence.

However, the presumption does not mean that any unreasonable or unrelated measure becomes lawful.

The provisional measure must still be:

  • within territorial competence;
  • appropriate;
  • necessary;
  • proportionate;
  • procedurally lawful;
  • subject to judicial review.

[!example] Illustration The request concerned retention of marketing email logs. Silence does not automatically justify shutting down every service of the controller. The emergency response must remain connected to the risk underlying the request.

30. Urgent binding EDPB decision

Article 61(8) states that an urgent binding decision from the Board under Article 66(2) is required.

This is a notable difference from the broader wording of Article 66(2), under which an authority may request an urgent opinion or an urgent binding decision.

Under paragraph 8, the statutory route points specifically toward a binding Board decision.

The EDPB can then assess the urgent European dimension and prevent a provisional national measure from developing into uncontrolled fragmented enforcement.


31. What if the requested authority replies after paragraph 8 is triggered?

A late response does not necessarily make every interim step disappear automatically.

The authorities and EDPB should consider:

  • whether the new information removes the urgency;
  • whether the provisional measure remains necessary;
  • whether it should be modified or withdrawn;
  • whether the original request is now fulfilled;
  • whether failure to cooperate requires institutional follow-up.

[!example] Illustration The requesting authority temporarily suspends a tracking operation after one month of silence. Two days later, the requested authority supplies evidence that the system has already been disabled and the risk has ended. The requesting authority should reassess whether its provisional measure remains necessary. Emergency powers should not continue after their factual justification disappears.

32. Article 61(9): Commission implementing acts

The Commission may adopt implementing acts specifying:

  • mutual-assistance formats;
  • procedures;
  • electronic information-exchange arrangements;
  • communication between authorities and the EDPB;
  • standardised formats under paragraph 6.

These implementing acts must follow the Article 93(2) examination procedure.

Paragraph 9 gives the Commission a power, not necessarily an obligation to regulate every operational detail.

The purpose is administrative uniformity. Standard procedures can reduce:

  • uncertainty about required fields;
  • missing information;
  • divergent electronic systems;
  • deadline disputes;
  • incompatible case categories.

Implementing acts cannot rewrite the substantive rights and duties in Article 61. For example, they cannot create new refusal grounds beyond paragraph 4.


33. Article 61 and professional secrecy

Information exchanged under Article 61 remains subject to professional secrecy under Article 54.

This matters because assistance files may contain:

  • personal data;
  • allegations;
  • trade secrets;
  • security documentation;
  • legal submissions;
  • sensitive whistleblower information;
  • draft enforcement positions.

The receiving authority should:

  • use the information only for the stated purpose;
  • limit internal access;
  • secure the information;
  • observe applicable confidentiality classifications;
  • avoid unauthorised publication;
  • respect rights of defence.

[!example] Illustration Authority A supplies Authority B with a confidential cybersecurity report identifying an unpatched vulnerability. Authority B should not publish the report merely because the information was shared under a mandatory cooperation mechanism.

34. Article 61 and the rights of the controller or processor

Article 61 directly governs relations between authorities, but its operation may affect controllers and processors.

The requested authority may use Article 58 to:

  • demand information;
  • inspect premises;
  • obtain access to data;
  • interview staff;
  • review certifications.

The controller or processor retains procedural safeguards, including:

  • clear legal basis;
  • proportionality;
  • right to be heard where applicable;
  • protection of privileged information;
  • effective judicial remedy;
  • national procedural protections.

The requesting authority cannot use Article 61 to evade safeguards that would apply if it acted itself.

[!example] Illustration Authority A lacks evidence to justify a broad inspection. It asks Authority B to conduct the same inspection without disclosing the weakness of the factual basis. Authority B must independently ensure that its exercise of public powers is lawful. Article 61 is not a mechanism for regulatory laundering.

35. Article 61 and complainants

A complainant does not normally submit an Article 61 request. The request is made by one supervisory authority to another.

However, mutual assistance may be essential to effective complaint handling.

Illustration

A Greek complainant alleges that a German processor holds inaccurate employment data. The Greek authority may need German assistance to:

  • confirm the processor’s role;
  • obtain records;
  • verify the controller’s instructions;
  • inspect the local establishment. The complainant should receive appropriate progress information under Article 57 and Article 77, but need not receive every confidential communication between the authorities. If mutual-assistance delay prevents meaningful complaint handling, remedies against supervisory inaction under Article 78 may become relevant.

36. Article 61 and the lead supervisory authority

Where there is an Article 60 case, the lead authority will often be the requesting authority. But it is not the only authority capable of requesting assistance.

A concerned authority may require information from:

  • the lead authority;
  • another concerned authority;
  • an authority holding relevant local evidence.

The Article 60 duty to exchange relevant information and Article 61’s formal mutual-assistance procedure complement one another.

[!example] Illustration The French authority needs evidence held by the Portuguese authority to formulate its comments on a Dutch lead authority’s draft. France may use the appropriate cooperation channels rather than relying entirely on the lead authority to collect every item. Authorities should avoid duplicative requests and coordinate through the lead authority where doing so improves efficiency.

37. Mutual assistance before the lead authority is identified

A cross-border case may begin with uncertainty about:

  • the controller;
  • main establishment;
  • decision-making location;
  • affected states;
  • processor relationships.

Article 61 may help resolve those questions.

Illustration

A company claims its main establishment is in Luxembourg. French and Belgian authorities suspect that all decisions are taken in Belgium. An authority may request:

  • corporate governance documents;
  • records of decision-making;
  • information about executive locations;
  • evidence of implementation power. Mutual assistance can therefore determine the cooperation structure itself.

38. Mutual assistance after the final decision

Paragraph 1 is not confined to investigation. Authorities may assist with enforcement and compliance monitoring.

Illustration

A final decision requires a social network to stop using a particular dark-pattern consent interface throughout the EEA. Concerned authorities may check:

  • local-language versions;
  • mobile applications;
  • logged-out users;
  • children’s accounts;
  • local subsidiaries. They can report non-compliance to the lead authority, which may take further corrective action. A cross-border decision is only effective if it is implemented in practice across the affected operations.

39. Difference between refusal and inability to complete on time

These situations should not be confused.

Refusal

The authority decides that paragraph 4 permits it not to comply.

It must give reasons.

Delayed completion

The authority accepts the request but cannot finish the measure within one month.

It must provide progress information.

Need for clarification

The authority cannot act because essential information is missing.

It should request clarification promptly.

Practical impossibility

The subject or evidence may no longer exist.

The authority should explain the steps taken and the result rather than simply remain silent.

Illustration

The authority attempts to inspect an establishment but discovers that it closed six months earlier. This is not necessarily a refusal. The authority may report:

  • closure date;
  • records located;
  • successor entity;
  • whether another authority or processor holds the evidence.

40. Can workload justify delay or refusal?

Ordinary workload does not appear among paragraph 4’s refusal grounds.

An authority should organise its work to meet mandatory EU cooperation duties.

Exceptional resource pressure may affect how quickly a complex measure is completed, but the authority must still:

  • acknowledge the request;
  • prioritise appropriately;
  • provide progress information;
  • explain delay;
  • seek practical solutions.

A Member State’s persistent underfunding of its authority may also raise issues under Article 52(4), which requires adequate human, technical and financial resources.

Authorities should not use resource shortages as a permanent reason to render Article 61 ineffective.


41. Good-faith cooperation and corrective clarification

A poorly drafted request should not automatically lead to adversarial refusal.

Sincere cooperation may require the requested authority to ask:

  • Which processing operation is involved?
  • Which period should be examined?
  • Is a full database needed or would a sample suffice?
  • Which urgency exists?
  • Does the requesting authority need evidence or merely confirmation?
  • Is another domestic authority competent?

[!example] Illustration A request asks for “all records relating to Company Y.” The requested authority could reject it as insufficiently precise. A more cooperative response would be: “Please identify the relevant processing operation, time period and categories of documents. Our authority can execute a targeted request once those details are supplied.” This preserves both effectiveness and proportionality.

42. Potential abuse of mutual assistance

Although Article 61 is mandatory, requests should not be used:

  • to evade local procedural safeguards;
  • to overwhelm another authority;
  • to conduct fishing expeditions;
  • to obtain information for unrelated purposes;
  • to create parallel investigations that undermine Article 60;
  • to pressure another authority politically.

The requested authority may not invent an “abuse” refusal ground. But it can examine whether:

  • the request contains necessary information;
  • the proposed measure is within competence;
  • execution would be lawful;
  • the requested information is relevant;
  • proportionality is respected.

An overbroad or unlawful request may need narrowing or may fall within paragraph 4(b).


43. Example: Cross-border employee monitoring

A company’s main establishment is in the Netherlands. Its French subsidiary uses biometric attendance.

A French employee complains to the French authority. The Dutch authority leads the broader case.

The Dutch authority asks France to:

  • inspect the biometric device;
  • obtain the enrolment procedure;
  • interview the local HR manager;
  • examine deletion settings;
  • identify affected employees.

The request states:

  • the alleged infringement;
  • relevant GDPR provisions;
  • purpose of the investigation;
  • information required;
  • confidentiality status.

France must:

  1. check competence;
  2. register the request;
  3. take appropriate measures;
  4. reply without undue delay;
  5. provide results or meaningful progress within one month;
  6. use secure electronic communication;
  7. avoid charging routine fees.

If French law requires judicial approval for a particular access measure, France must follow that law.

France later supplies the inspection report. The Netherlands may use it only for the stated investigation and connected enforcement purposes.


44. Example: Lawful refusal

The Austrian authority asks another supervisory authority to obtain documents from a court’s pending case file.

The requested authority concludes that:

  • the requested processing is performed by a court acting in its judicial capacity;
  • Article 55(3) excludes ordinary supervisory-authority competence;
  • a judicial oversight body has jurisdiction.

The authority may refuse under Article 61(4)(a).

A proper response should:

  • identify the competence issue;
  • cite the legal basis;
  • explain the judicial nature of the processing;
  • identify the appropriate body if possible.

It should not merely say:

“This matter is sensitive.”


45. Example: Unlawful scope but partial assistance possible

The Irish authority asks the German authority to copy every email of 2,000 employees to determine whether one manager unlawfully disclosed a customer file.

The German authority concludes that the request is disproportionate and would unlawfully disclose vast amounts of unrelated data.

Instead of total refusal, it proposes:

  • targeted searches;
  • a limited date range;
  • specified custodians;
  • independent filtering;
  • extraction of relevant communications only.

This approach respects Article 61 while ensuring that the executed measure remains lawful and proportionate.


46. Example: Silence and emergency action

The Belgian authority receives evidence that a platform publicly exposes users’ medical information.

It asks the lead authority for:

  • confirmation of the breach;
  • technical details;
  • mitigation status;
  • affected persons.

No result or progress information is supplied within one month.

Belgium may:

  • adopt a temporary territorial restriction in Belgium;
  • rely on the presumed urgent need under Article 66(1);
  • request an urgent binding EDPB decision under Article 66(2).

Belgium still must ensure that the measure:

  • addresses the specific risk;
  • is temporary;
  • is proportionate;
  • applies within its territory;
  • respects due process;
  • is reviewable.

Article 61(8) protects against paralysis, not against the normal rule of law.


47. Corrections and qualifications to the supplied commentary

Several points in the supplied commentary require refinement.

47.1 Information and mutual assistance are not alternatives

They are complementary obligations. Information exchange may be one form of mutual assistance, while supervisory measures are another.

47.2 Paragraph 6, not paragraph 7, governs electronic communication

Paragraph 7 addresses the no-fee rule and exceptional cost indemnification.

47.3 One month does not necessarily require completion

A complex inspection may continue beyond one month. The authority must provide results where available or meaningful progress information.

47.4 Domestic law is not an unlimited refusal tool

Domestic law may regulate lawful execution, but it must comply with EU law and cannot nullify Article 61.

47.5 Purpose limitation should be taken seriously

Information cannot simply be reused for unrelated aims. A new issue may require further coordination, a new request or an independent investigation.

47.6 Silence creates a provisional route, not permanent national competence

Paragraph 8 permits territorial provisional measures and urgent EDPB action. It does not allow the requesting authority to take permanent control of the whole cross-border case.

47.7 An acknowledgment is not necessarily a compliant response

Paragraph 5 requires results or meaningful progress, not merely confirmation of receipt.

47.8 Refusal should be as narrow as possible

Where partial execution or an alternative lawful measure is available, sincere cooperation generally favours that approach over total refusal.


48. Practical checklist for the requesting authority

Before sending a request, the authority should ask:

Competence and routing

  • Which authority is competent?
  • Is there a national contact point?
  • Is Article 60, 61 or 62 the appropriate route?
  • Is the case urgent?

Scope

  • What exact information or measure is needed?
  • Why is it relevant?
  • Is the request proportionate?
  • Is a narrower measure sufficient?

Content

  • Is the controller or processor clearly identified?
  • Is the processing operation explained?
  • Are the purpose and reasons stated?
  • Are relevant legal provisions identified?
  • Is the desired deadline explained?
  • Are supporting documents attached?

Use and confidentiality

  • How will the information be used?
  • Does it contain sensitive or privileged content?
  • What security classification is necessary?
  • Is translation required?

Follow-up

  • Has receipt been confirmed?
  • Has meaningful progress been provided?
  • Has the one-month deadline expired?
  • Is paragraph 8 action justified?

49. Practical checklist for the requested authority

Upon receiving a request, the authority should ask:

Triage

  • When was the request received?
  • Has it been registered?
  • Who owns the response?
  • What is the one-month deadline?
  • Is the authority competent?
  • Does it possess the requested power?
  • Is judicial authorisation required?
  • Would compliance violate EU or national law?
  • Are secrecy or privilege safeguards required?

Sufficiency

  • Is the purpose clear?
  • Are reasons supplied?
  • Is the controller correctly identified?
  • Is clarification needed?

Execution

  • What appropriate measures are required?
  • Can existing information answer the request?
  • Is an information order, audit or inspection needed?
  • Can part of the request be completed immediately?

Communication

  • Can a result be provided now?
  • If not, what meaningful progress can be reported?
  • If refusal is necessary, are full reasons given?
  • Can another competent authority be identified?

Closure

  • Was the information transmitted securely?
  • Was the purpose limitation recorded?
  • Were exceptional costs agreed?
  • Is further monitoring required?

Conclusion

Article 61 ensures that national boundaries do not become enforcement barriers. It requires supervisory authorities to:

  • share relevant information;
  • perform supervisory measures for one another;
  • establish effective cooperation systems;
  • respond without undue delay;
  • provide results or meaningful progress within one month;
  • use information only for the stated purpose;
  • refuse only for lack of competence or legal impossibility;
  • explain any refusal;
  • communicate electronically in standardised form;
  • provide routine assistance free of charge;
  • support provisional territorial action where silence creates urgency. The Article balances four concerns. First, effectiveness: one authority must be able to obtain evidence and action from another state. Second, consistency: all authorities should apply the same GDPR through a connected system. Third, legality: the requested authority remains bound by competence, procedural law, professional secrecy and proportionality. Fourth, urgency: an authority’s silence must not leave individuals unprotected.

In the simplest terms:

Article 61 says that one data protection authority cannot tell another, “That evidence is in our country, so your investigation must stop.” It must either help promptly or explain a narrow and lawful reason why it cannot.

The system depends upon mutual trust, but it does not rely on trust alone. It creates concrete duties, a one-month response requirement, limited grounds for refusal and an emergency consequence where assistance is not provided. That is what turns a collection of national regulators into an integrated European enforcement network.