CHAPTER VIICOOPERATION AND CONSISTENCY

Article 67Exchange of information

Official text

The Commission may adopt implementing acts of general scope in order to specify the arrangements for the exchange of information by electronic means between supervisory authorities, and between supervisory authorities and the Board, in particular the standardised format referred to in Article 64.

Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93 (2).

Commentary

Article 67 is a short technical provision, but it supports the entire machinery of cross-border GDPR enforcement. Articles 56 and 60 to 66 require supervisory authorities and the European Data Protection Board to exchange large volumes of information under strict deadlines. Article 67 allows the European Commission to establish uniform technical and procedural arrangements so those exchanges can take place securely, consistently and efficiently.

In the simplest terms:

The earlier Articles explain what supervisory authorities must communicate. Article 67 allows the Commission to standardise how they communicate it electronically.


1. Purpose and position of Article 67

Article 67 appears at the end of Section 2 of Chapter VII, immediately after the provisions governing:

  • one-stop-shop cooperation;
  • mutual assistance;
  • joint operations;
  • consistency opinions;
  • binding dispute resolution;
  • urgent procedures.

These processes depend heavily on communication.

A lead supervisory authority may need to share:

  • complaints;
  • investigation files;
  • technical reports;
  • draft decisions;
  • relevant and reasoned objections;
  • controller submissions;
  • compliance reports;
  • proposed corrective measures.

The EDPB may need to receive:

  • an Article 64 draft decision;
  • the reasons supporting that decision;
  • the views of other authorities;
  • an Article 65 dispute file;
  • an urgent Article 66 request;
  • evidence demonstrating the need for immediate action.

If each authority used its own terminology, file structure, communication channel and deadline-calculation method, European cooperation could become slow and unreliable. Article 67 allows the Commission to specify common electronic arrangements and standardised formats. The provision itself gives the Commission a power to adopt implementing acts of general scope covering electronic exchanges between supervisory authorities and between those authorities and the EDPB.

2. Article 67 is an enabling provision

Article 67 does not itself create a detailed communication system.

It does not specify:

  • which software must be used;
  • what fields a request must contain;
  • how attachments should be labelled;
  • which language must be used;
  • how receipt should be acknowledged;
  • how access rights should be assigned;
  • how long information should be retained.

Instead, it empowers the Commission to address those matters through implementing acts.

This makes Article 67 an enabling provision. The basic duties already appear elsewhere in the GDPR. Article 67 allows uniform practical rules to be adopted without amending the GDPR every time technology or administrative needs change.

Illustration

Article 61 requires a mutual-assistance request to contain the purpose and reasons for the request. Article 67 could support an electronic form containing mandatory fields for:

  • requesting authority;
  • requested authority;
  • legal basis;
  • controller or processor;
  • case reference;
  • purpose;
  • reasons;
  • action requested;
  • urgency;
  • deadline;
  • supporting documents. The implementing act would not create the duty to give reasons. That duty already exists in Article 61. It would standardise how those reasons are recorded and transmitted.

3. Meaning of “the Commission may adopt”

The word“may” means that the Commission is empowered, but not automatically required, to adopt an Article 67 implementing act covering every possible detail.

This must be distinguished from provisions stating that an institution“shall” take a particular action.

The Commission may decide that:

  • existing legislation already provides a suitable electronic system;
  • an existing implementing decision sufficiently supports cooperation;
  • operational details can be handled through the EDPB’s internal procedures;
  • a further implementing act is necessary to correct inconsistency or technological weakness.

The discretion is not unlimited. If a lack of uniform technical rules seriously undermined the effective application of the GDPR, the Commission would need to consider whether exercising the Article 67 power had become necessary to fulfil the Regulation’s objectives.

[!example] Illustration Supervisory authorities use incompatible systems. Draft decisions are routinely lost, objection deadlines cannot be verified and security protections vary significantly. In such circumstances, the Commission could not sensibly treat Article 67 as irrelevant. The purpose of the power is to support effective and consistent GDPR cooperation.

4. What is an implementing act?

An implementing act is a legally recognised EU measure used to establish uniform conditions for implementing an existing binding EU act.

Article 67 does not permit the Commission to rewrite the GDPR. It permits the Commission to establish practical rules necessary to implement the GDPR’s information-exchange duties consistently.

An Article 67 implementing act could address matters such as:

  • electronic submission procedures;
  • standard forms;
  • mandatory metadata;
  • document formats;
  • acknowledgments of receipt;
  • secure transmission;
  • system user roles;
  • case-number structures;
  • notification mechanisms;
  • deadline tracking;
  • translation functions;
  • interoperability;
  • technical audit trails.

It should not create new substantive rules deciding:

  • what constitutes a data protection infringement;
  • when consent is valid;
  • whether an authority is competent;
  • what fine should be imposed;
  • whether an objection is legally correct.

Those matters are governed by the GDPR itself and the institutions legally authorised to interpret and apply it.

5. “Implementing acts of general scope”

The acts contemplated by Article 67 are of general scope. They are not meant to decide how one identified authority must communicate in one individual investigation.

[!example] Illustration A measure stating: “All Article 64 submissions must include a common case reference, a draft decision, a factual summary, supporting reasons and the views of other authorities” would be general in scope. A measure stating: “The Spanish authority must send the evidence in Case X to the French authority by Friday” would not be the type of general implementing act contemplated by Article 67. The general nature promotes equal administrative conditions across the EEA.

6. Persons and institutions covered

Article 67 covers two categories of exchange:

  1. exchanges between supervisory authorities; and
  2. exchanges between supervisory authorities and the EDPB.

6.1 Exchanges between supervisory authorities

These may arise under:

  • Article 56 when identifying the lead supervisory authority;
  • Article 60 cooperation;
  • Article 61 mutual assistance;
  • Article 62 joint operations;
  • implementation monitoring;
  • complaint transfers;
  • communication of relevant evidence.

6.2 Exchanges with the EDPB

These may arise under:

  • Article 64 opinion procedures;
  • Article 65 binding disputes;
  • Article 66 urgent proceedings;
  • EDPB consistency and accountability functions;
  • communication of final national decisions.

Article 67 does not directly regulate communications between:

  • a controller and a supervisory authority;
  • a complainant and the EDPB;
  • a processor and the Commission;
  • an authority and an ordinary national court.

Those communications may be subject to separate provisions and procedures.


7. Why electronic exchange is essential

The GDPR provides short and legally important deadlines.

Examples

include:

  • one month to reply to formal mutual-assistance requests;
  • four weeks for objections to an Article 60 draft decision;
  • two weeks for objections to a revised draft;
  • eight weeks for an ordinary Article 64 opinion;
  • one month for an Article 65 binding decision, subject to extensions;
  • two weeks for an urgent Article 66 opinion or binding decision.

An electronic system helps establish:

  • when information was sent;
  • when it was received;
  • who had access;
  • which version was authoritative;
  • when a deadline began;
  • whether an objection was timely;
  • whether an authority formally invoked a particular procedure.

Illustration

A concerned authority sends a relevant and reasoned objection by ordinary postal mail on the final day of the four-week period. The lead authority receives it one week later and disputes whether the objection was timely. A standard electronic system can record:

  • submission time;
  • receiving authority;
  • legal procedure selected;
  • attached version;
  • electronic acknowledgment. This reduces procedural disputes.

8. Electronic exchange is more than sending email

The phrase “exchange of information by electronic means” should not be understood as merely attaching files to ordinary emails.

A regulatory cooperation system may need:

  • authenticated users;
  • role-based access;
  • encryption;
  • secure storage;
  • version control;
  • protected transmission;
  • automatic acknowledgment;
  • deadline alerts;
  • structured forms;
  • audit logs;
  • controlled deletion;
  • multilingual support.

The information concerned may include:

  • health data;
  • complainant identities;
  • whistleblower information;
  • confidential commercial material;
  • security vulnerabilities;
  • legal submissions;
  • unannounced inspection plans.

Sending such information through unsecured channels could undermine the very rights that supervisory authorities are supposed to protect.


9. The standardised Article 64 format

Article 67 specifically mentions the standardised format referred to in Article 64.

Under Article 64(4), supervisory authorities and the Commission must communicate relevant information to the EDPB electronically and in a standardised format. The information may include:

  • a summary of the facts;
  • the draft decision;
  • the grounds making the measure necessary;
  • views of other supervisory authorities concerned.

Article 67 permits the Commission to specify what that standardised format should look like.

Illustration

A supervisory authority seeks EDPB approval concerning binding corporate rules. A standard form might require:

  • applicant identity;
  • group structure;
  • competent authority;
  • legal basis;
  • type of BCR;
  • entities covered;
  • countries of transfer;
  • enforceability arrangements;
  • liability;
  • complaint mechanism;
  • audit programme;
  • draft national decision;
  • other authorities’ views. Without a standard structure, one authority might submit a complete package while another sends only a short letter and hundreds of unorganised attachments.

A standardised format ensures that authorities provide comparable information. It does not require them to reach the same factual conclusion before the EDPB process begins.

Illustration

France and Germany disagree about whether an online platform processes biometric data. Both use the same form to submit:

  • relevant facts;
  • technical evidence;
  • legal reasoning;
  • proposed outcome. The format is standardised. The positions remain different. The EDPB or the cooperation procedure then resolves the legal disagreement. Standardisation therefore makes disagreement manageable. It does not artificially suppress it.

11. Completeness and mandatory fields

A standardised system may distinguish between:

  • mandatory fields;
  • optional fields;
  • supporting attachments;
  • confidential annexes;
  • translations.

Mandatory fields are particularly important where legal consequences depend on a formal request.

Illustration

For an Article 61 mutual-assistance request, a standard form may require:

  • purpose;
  • reasons;
  • requested measure;
  • competence connection;
  • urgency;
  • controller identity. If the authority leaves the purpose field blank, the requested authority may be unable to assess:
  • competence;
  • legality;
  • proportionality;
  • permitted later use. A well-designed electronic system can prevent submission until essential information is provided. However, technical validation does not guarantee legal sufficiency. An authority may fill every field with vague language. The receiving authority must still evaluate whether the request genuinely meets the GDPR’s requirements.

12. The Internal Market Information System

The Internal Market Information System, or IMI, was selected as the practical platform for GDPR administrative cooperation.

IMI is an internet-based system developed by the European Commission with Member States to support cross-border administrative cooperation and information exchange. The Commission describes IMI as a secure and multilingual tool used across numerous internal-market policy areas.

For GDPR purposes, IMI supports interactions relating to:

  • lead-authority identification;
  • one-stop-shop cases;
  • mutual assistance;
  • joint operations;
  • Article 64 opinions;
  • Article 65 disputes;
  • Article 66 urgency procedures.

The 2018 Commission implementing decision expressly established a pilot project for using IMI to implement GDPR administrative cooperation. It covered cooperation among supervisory authorities under Articles 56 and 60 to 62, and cooperation involving the EDPB and Commission under Articles 64 to 66.


13. Commission Implementing Decision (EU) 2018/743

Commission Implementing Decision (EU) 2018/743, adopted on 16 May 2018, created a pilot project for GDPR administrative cooperation through IMI.

The Decision recognised that the GDPR establishes procedures involving:

  • supervisory authorities;
  • the EDPB;
  • the Commission.

It considered IMI capable of supporting those procedures through a centralised cooperation mechanism. It also contemplated storing information relevant to exchanges and allowing reuse in subsequent processing connected with Articles 56 and 60 to 66.

Illustration

A complaint originally entered into the system may later become relevant to:

  1. identifying the lead authority;
  2. opening an Article 60 procedure;
  3. requesting Article 61 assistance;
  4. preparing an Article 65 dispute file.

Appropriate reuse avoids requiring authorities to upload the same material repeatedly.

Such reuse must still follow the system’s legal purposes, access controls and applicable data-protection protections.


The use of a recognised electronic procedure can have legal consequences.

In the Hamburg-Facebook urgency matter, the EDPB distinguished formal Article 61 mutual assistance from voluntary communications. A voluntary mutual-assistance request did not create the same legal duty to reply as a formal Article 61 request. Consequently, non-response to the voluntary request did not trigger the statutory presumption of urgency under Article 61(8).

This shows that electronic channels are not always interchangeable.

Illustration

Authority A sends an informal IMI message asking Authority B: “Could you share your preliminary thoughts?” Authority B does not answer. That is different from Authority A submitting a formal Article 61 request containing:

  • purpose;
  • reasons;
  • information required;
  • legal basis;
  • deadline. Only the formal request activates the legally prescribed response obligation and the potential consequences of non-response. Article 67 standardisation helps authorities distinguish clearly between:
  • informal consultation;
  • formal legal request;
  • objection;
  • urgent referral;
  • submission of a draft decision.

15. IMI does not replace the GDPR

The software implements the legal procedure. It does not define the law.

Illustration

An IMI form incorrectly allows an authority to select a three-month deadline for an Article 61 response, even though Article 61 requires a response within one month. The software field cannot override the GDPR. Similarly:

  • a system error cannot create competence;
  • a drop-down category cannot make an objection relevant and reasoned;
  • an automatically generated acknowledgment cannot cure an incomplete request;
  • a technical workflow cannot remove the right to be heard. Authorities must interpret the system consistently with the Regulation.

16. Security and confidentiality

Electronic cooperation systems process sensitive regulatory data.

The system should therefore respect principles such as:

  • necessity;
  • purpose limitation;
  • data minimisation;
  • accuracy;
  • storage limitation;
  • confidentiality;
  • accountability.

Security measures may include:

  • strong authentication;
  • least-privilege access;
  • encryption;
  • activity logging;
  • incident response;
  • separation of case roles;
  • secure export controls;
  • periodic access review;
  • backup and recovery procedures.

Illustration

A junior employee responsible only for administrative meeting arrangements should not automatically receive access to:

  • unredacted complaints;
  • confidential evidence;
  • technical vulnerabilities;
  • draft fines;
  • whistleblower identities. Role-based access should reflect operational necessity.

17. Purpose limitation within the system

Information submitted for one cooperation procedure should not be freely used for unrelated purposes.

Illustration

A document is uploaded for an Article 61 investigation concerning security. Another authority wants to use the document in an unrelated employment dispute. Before reuse, the authority should examine:

  • whether the later use falls within the original cooperation purpose;
  • whether another GDPR provision authorises it;
  • whether a fresh request is needed;
  • whether the supplying authority must be informed;
  • whether confidential or third-party information requires protection. The 2018 IMI pilot decision permits relevant data to be reused for subsequent processing in GDPR cooperation procedures, but that does not amount to unlimited reuse for any governmental purpose.

18. Data retention

Article 67 does not itself state how long electronic cooperation records must be retained.

Retention arrangements should distinguish between:

  • active case files;
  • appeal periods;
  • closed decisions;
  • audit logs;
  • duplicates;
  • temporary working documents;
  • material required for the public consistency register.

A system should retain information long enough to support:

  • enforcement;
  • judicial review;
  • accountability;
  • proof of timely compliance;
  • institutional memory.

It should not retain every duplicate and informal document indefinitely without a defined justification.

Illustration

A final Article 65 decision and the national implementing decision may need long-term archival retention because they are legally significant. Temporary duplicate files created during translation may not require the same retention period.

19. Accuracy and correction

A centralised system may spread errors quickly.

Illustration

One authority incorrectly records that a Belgian company’s main establishment is in France. Other authorities rely on that entry, causing the wrong lead authority to be selected. The platform should enable:

  • correction;
  • version history;
  • notification of material changes;
  • identification of the authority making the change;
  • preservation of the original record where legally necessary. A standardised system should improve accuracy, not give inaccurate information an appearance of authority.

20. Access by controllers and complainants

Article 67 governs regulator-to-regulator exchanges. It does not automatically give controllers, processors or complainants direct access to IMI.

Their access rights may arise through:

  • Article 41 of the Charter;
  • rights of defence;
  • Article 78 judicial remedies;
  • national administrative law;
  • public-access rules;
  • data subject access rights, subject to applicable restrictions.

Illustration

A concerned authority uploads an objection arguing that a controller unlawfully processed health data. If the EDPB or lead authority intends to rely on that objection adversely, the controller may need sufficient access to understand and answer it. That does not necessarily mean receiving unrestricted access to the entire IMI file. The authority may need to protect:

  • complainants;
  • whistleblowers;
  • unrelated personal data;
  • confidential deliberations;
  • business secrets. Possible solutions include:
  • redacted copies;
  • summaries;
  • confidentiality arrangements;
  • access to relied-upon documents only.

21. Language and translation

Cross-border cooperation involves many official languages.

A standardised electronic system may support:

  • structured fields that can be translated automatically;
  • common terminology;
  • document-language labels;
  • translation requests;
  • multilingual forms;
  • standard legal phrases.

The EDPB Secretariat may provide necessary translations in Article 64 procedures. A standardised system can help identify which materials require translation and which can remain in the original language.

Illustration

A Spanish authority submits a 200-page technical annex in Spanish. The draft decision is in English, and the disputed evidence appears on ten pages. A proportionate translation approach may involve:

  • translation of the draft;
  • translation of the relevant ten pages;
  • an English summary of the remainder;
  • access to the original for verification. Requiring every document to be translated into every EEA language would impose excessive delay and cost.

22. System outages and alternative communication

Article 67 focuses on electronic means, but any practical framework should deal with outages, cyber incidents and emergencies.

Possible contingency rules include:

  • secure backup channels;
  • emergency encrypted email;
  • telephone notification followed by formal upload;
  • proof of failed submission;
  • extension where a verified system outage prevents filing;
  • later reconciliation with the official record.

[!example] Illustration A concerned authority must submit an Article 60 objection by midnight, but the official system suffers a documented outage. A lawful contingency procedure should allow secure submission through an alternative channel, followed by formal registration once the system is restored. The authority should not casually use ordinary email merely because the secure system is inconvenient. Alternative channels should be exceptional, controlled and recorded.

23. Article 67 and the Commission’s institutional role

The Commission’s role under Article 67 is technical and implementing.

It may specify uniform conditions for communication, but it does not thereby become:

  • the lead supervisory authority;
  • the EDPB;
  • the decision-maker in an Article 65 dispute;
  • the investigator in ordinary complaints.

[!example] Illustration The Commission may prescribe that Article 64 submissions must use a particular electronic form. It cannot use Article 67 to decide that a particular controller infringed Article 6 or must pay a particular fine. The legal boundary is: Article 67 allows the Commission to regulate the communication machinery, not to take over the substantive enforcement function of independent supervisory authorities.

24. Article 93(2) examination procedure

Article 67 states that implementing acts must be adopted under the examination procedure in Article 93(2).

Article 93 refers to Regulation (EU) No 182/2011, which governs how Member States control the Commission’s exercise of implementing powers.

Under the examination procedure, the Commission submits a draft implementing act to a committee composed of Member State representatives. The committee gives an opinion according to the applicable voting rules.

The procedure is used for measures where uniform implementation is important and where Member State oversight of the Commission’s technical rule-making is appropriate.

Recitals 167 and 168 confirm that:

  • implementing powers are conferred on the Commission where the GDPR provides;
  • those powers must follow Regulation 182/2011;
  • the examination procedure applies to arrangements for electronic information exchange among supervisory authorities and the EDPB.

25. Why the examination procedure is appropriate

Electronic cooperation arrangements can affect:

  • national administrative systems;
  • staffing;
  • budgets;
  • cybersecurity;
  • national contact points;
  • official languages;
  • evidence management;
  • legal deadlines.

Member States therefore have a legitimate interest in reviewing the Commission’s proposed arrangements before adoption.

26. Limits on implementing acts

An Article 67 act must remain within the power delegated by the GDPR.

It may specify arrangements and formats. It should not:

  • amend Article 60 objection deadlines;
  • add new grounds for refusing mutual assistance;
  • alter the membership or voting rules of the EDPB;
  • authorise the Commission to decide individual cases;
  • remove confidentiality guarantees;
  • restrict judicial remedies;
  • change the substantive definition of a controller;
  • make a non-binding opinion binding.

[!example] Illustration An implementing act states that an Article 60 objection filed through the system must be submitted within ten days. The GDPR grants four weeks. The implementing act would impermissibly alter the basic legislative rule. Technical standardisation must serve the GDPR, not modify it.

27. Micro, small and medium-sized enterprises

Recital 167 states that the Commission should consider specific measures for micro, small and medium-sized enterprises when exercising implementing powers.

Article 67 mainly concerns communications among public authorities, so its direct effect on SMEs is limited. But cooperative systems may contain information concerning SMEs or influence how quickly cases involving them are handled.

Practical considerations may include:

  • clear terminology;
  • avoiding unnecessary duplicate requests;
  • limiting burdens passed through by authorities;
  • proportionate evidence requirements;
  • efficient complaint handling;
  • reducing conflicting demands from several authorities.

[!example] Illustration Five supervisory authorities separately ask a small processor for the same documentation because their communication system does not show that another authority already obtained it. A well-designed exchange system lets authorities coordinate and reuse lawfully obtained information, reducing unnecessary duplication for the SME.

28. Standardisation and national procedural autonomy

National procedural law continues to apply in areas not fully harmonised by the GDPR.

Article 67 standardisation may regulate how authorities transmit information without eliminating national rules regarding:

  • evidence;
  • professional secrecy;
  • judicial warrants;
  • service of national decisions;
  • access to files;
  • limitation periods;
  • appeals.

Illustration

An Article 67 format may permit an authority to request an on-site inspection. Whether the requested authority may perform the inspection without prior judicial approval remains governed by Article 58, the Charter and applicable national procedural law. The electronic form facilitates the request. It does not supply a missing warrant.

29. Can failure to use the prescribed format invalidate action?

The answer depends on:

  • the wording of the applicable implementing act;
  • the substantive GDPR provision;
  • seriousness of the defect;
  • whether another authority was prejudiced;
  • whether the error can be corrected;
  • whether a statutory consequence depends on formal submission.

A minor formatting defect should not necessarily invalidate an otherwise clear and timely communication.

A failure to use the correct legal channel may be more serious where the GDPR attaches a consequence to a formal request.

Illustration 1: Minor defect

An authority uploads a document in an accepted format but mislabels one annex. The error may be corrected without invalidating the entire process.

[!example] Illustration 2: Material defect An authority relies on the Article 61(8) presumption of urgency even though it never made a formal Article 61 request through the applicable procedure. That defect goes to the legal trigger itself, as illustrated by the Hamburg urgency decision. Form should not defeat substance unnecessarily, but procedural formalities matter where they activate binding rights, duties or deadlines.

30. Evidence and audit trails

A standard system should preserve reliable evidence of procedural action.

Relevant audit information may include:

  • sender;
  • recipient;
  • time;
  • procedure type;
  • documents attached;
  • version;
  • acknowledgment;
  • changes;
  • user access;
  • final status.

Illustration

A lead authority claims that no relevant and reasoned objection was submitted within four weeks. The concerned authority claims that it uploaded the objection on time. A reliable audit trail can show:

  • exact filing time;
  • successful transmission;
  • recipient notification;
  • attachment checksum;
  • subsequent changes. This protects both authorities and affected parties and supports judicial review.

31. Article 67 as administrative infrastructure

Article 67 does not determine privacy rights directly. Nevertheless, weak information infrastructure can cause substantive harm.

Illustration

A complainant alleges unlawful processing of medical data. The complaint is transferred between authorities, but an attachment is lost because they use incompatible systems. The lead authority closes the case because the evidence appears incomplete. The problem appears technical, but the result harms:

  • the complainant’s right to effective handling;
  • the accuracy of the investigation;
  • the consistency of enforcement. Good administrative infrastructure is therefore part of effective fundamental-rights protection.

32. Corrections and qualifications to the supplied commentary

The supplied commentary identifies the importance of IMI correctly, but several points should be expressed carefully.

32.1 Article 67 does not itself name IMI

The GDPR authorises electronic arrangements and standardised formats. The use of IMI arises from the Commission’s implementing decision and the operational framework, not from the literal wording of Article 67.

32.2 The 2018 measure was an IMI pilot decision

Commission Implementing Decision 2018/743 was adopted under the IMI Regulation to pilot GDPR administrative cooperation. It should not be described as though it exhaustively exercised every possible Article 67 implementing power.

32.3 Article 67 covers more than Article 64 submissions

Article 64’s standard format is mentioned specifically, but Article 67’s broader wording covers electronic exchanges:

  • between supervisory authorities;
  • between authorities and the EDPB.

32.4 Use of the wrong channel does not always have the same consequence

Consequences depend upon the legal procedure. A voluntary IMI message and a formal Article 61 request are not equivalent.

32.5 Electronic communication must remain subordinate to substantive law

Software cannot change competence, deadlines, due-process rights or the legal meaning of a GDPR provision.

32.6 Standardisation does not remove professional judgment

Authorities must still decide:

  • relevance;
  • necessity;
  • proportionality;
  • confidentiality;
  • legal sufficiency.

A completed electronic form is not automatically a lawful request.


33. Practical illustration of Article 67 in operation

Assume a French complainant alleges that an online platform led from Ireland unlawfully profiles users across Europe.

Step 1: Case registration

The French authority records the complaint in the electronic cooperation system.

The record identifies:

  • controller;
  • processing;
  • affected states;
  • complaint authority;
  • possible lead authority.

Step 2: Lead-authority identification

The authorities exchange information concerning:

  • the Irish establishment;
  • decision-making;
  • power to implement decisions;
  • affected establishments.

Step 3: Article 60 cooperation

Ireland leads the investigation and shares:

  • controller responses;
  • investigation updates;
  • relevant evidence.

Step 4: Mutual assistance

Ireland formally asks Germany to inspect a technical establishment.

The electronic request records:

  • legal basis;
  • purpose;
  • reasons;
  • action requested;
  • one-month deadline.

Step 5: Draft decision

Ireland circulates a draft through the standardised system.

The platform records:

  • date of circulation;
  • four-week objection deadline;
  • supporting evidence;
  • authorities consulted.

Step 6: Objection

France submits a relevant and reasoned objection electronically.

The system records:

  • disputed paragraphs;
  • legal provisions;
  • evidence;
  • proposed amendment;
  • submission time.

Step 7: Article 65 referral

Ireland does not follow the objection and sends the complete dispute file to the EDPB.

Step 8: EDPB decision

The EDPB adopts a binding decision. The authorities receive it electronically.

Step 9: Final decision and register

Ireland adopts its final national decision and informs the EDPB of notification. The public decisions are then made available through the appropriate consistency register.

Article 67 supports every stage, although it does not decide the legal merits at any stage.


Conclusion

Article 67 provides the technical rule-making foundation for electronic cooperation under the GDPR. It allows the Commission to establish uniform arrangements for:

  • exchanges among supervisory authorities;
  • exchanges between supervisory authorities and the EDPB;
  • standardised Article 64 submissions;
  • secure and traceable electronic procedures. The Commission must exercise this power through implementing acts of general scope adopted under the Article 93(2) examination procedure. In practice, the Internal Market Information System has been used to support the GDPR’s cooperation and consistency procedures. Commission Implementing Decision 2018/743 established the GDPR IMI pilot and recognised the system’s role in exchanges under Articles 56 and 60 to 66. The provision’s deeper significance is that effective European enforcement depends on more than legal powers. It also requires dependable administrative infrastructure. A standardised electronic system can ensure that:
  • the correct authority receives the information;
  • essential fields are completed;
  • deadlines can be verified;
  • files are secure;
  • evidence is traceable;
  • formal and informal procedures are distinguishable;
  • authorities do not repeatedly request the same information;
  • the EDPB receives a complete file.

The simplest summary is:

Article 67 allows the Commission to standardise the digital language and channels through which Europe’s data protection authorities cooperate.

It does not decide cases, create new infringements or alter substantive rights. Its purpose is to make the legal mechanisms in Articles 56 and 60 to 66 work reliably in practice.