CHAPTER VIIIREMEDIES, LIABILITY AND PENALTIES

Article 77Right to lodge a complaint with a supervisory authority

Official text

(1)Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation.

(2)The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78.

Commentary

Article 77 is one of the GDPR’s central enforcement provisions for individuals. It gives a person a direct, accessible and generally free route to ask an independent supervisory authority to investigate processing of their personal data that they consider unlawful.

In simple terms:

If a person believes that an organisation has mishandled their personal data, they may complain to a data protection authority. They do not have to prove the entire case before complaining, and they do not lose their other legal remedies by choosing the complaint route.

Article 77 must be read together with:

  • Article 57, which requires supervisory authorities to handle complaints;
  • Article 58, which gives them investigative and corrective powers;
  • Article 60, which governs cross-border complaints;
  • Article 78, which provides judicial remedies against supervisory authorities;
  • Article 79, which permits direct court proceedings against controllers and processors;
  • Article 80, which permits certain non-profit bodies to represent data subjects;
  • Article 82, which provides a right to compensation where its conditions are satisfied.

The official text creates both a right to complain and a corresponding duty to inform the complainant about progress, outcome and judicial remedies.


1. Article 77 is a formal legal remedy, not an informal suggestion box

A complaint under Article 77 is not merely a request asking a regulator to consider whether a privacy issue is interesting. It activates a legal procedure intended to safeguard the complainant’s rights and interests.

The CJEU has repeatedly treated the Article 77 complaint mechanism as an important element of effective GDPR enforcement. A supervisory authority must handle an admissible complaint with appropriate diligence, investigate it to the extent suitable for the case and adopt an outcome capable of judicial review. The complaint procedure is therefore different from a general petition, tip-off or policy suggestion.

Illustration

A person writes: “Your authority should look generally at the privacy practices of social-media companies.” That may be a useful regulatory tip, but it does not necessarily amount to an Article 77 complaint because the person has not alleged processing of their own personal data. Now compare: “This platform generated political and health-related profiles about me, refused to tell me the source of the data and continues to use those profiles for advertising.” This is an Article 77 complaint because the individual alleges that personal data relating to them have been processed in breach of the GDPR. The distinction matters because an Article 77 complainant has procedural rights, including:

  • handling of the complaint;
  • information about progress;
  • information about the outcome;
  • access to an Article 78 judicial remedy.

A person who merely gives the authority a general market tip may not enjoy the same procedural position.


2. The complainant must be a “data subject”

Article 77 gives the right to every data subject.

A data subject is an identified or identifiable natural person to whom the personal data relate. The right is therefore not confined to:

  • citizens of the European Union;
  • adults;
  • consumers;
  • employees;
  • residents with a permanent address.

A person may be a data subject regardless of nationality if the relevant processing falls within the GDPR’s scope.

Illustration

An Indian national staying temporarily in France uses a service covered by the GDPR. The service unlawfully discloses that person’s location data. The person may be entitled to complain even though they are not an EU citizen. The central questions are:

  1. Are they a natural person?
  2. Do the personal data relate to them?
  3. Does the disputed processing fall within the GDPR?

Companies, associations and public authorities are not themselves data subjects under the GDPR.

Illustration

A company cannot generally lodge an Article 77 complaint merely because processing damaged its commercial reputation. But a company director may complain personally if the disputed data concern:

  • their name;
  • work email;
  • personal conduct;
  • financial details;
  • professional evaluation;
  • communications. The distinction is between information about the company and information relating to an identifiable human being.

2.2 Children and persons represented by others

Children are data subjects and may have Article 77 rights. Depending on age, capacity and national procedural law, a complaint may be filed:

  • by the child;
  • through a parent or guardian;
  • through a properly mandated representative;
  • through an eligible Article 80 organisation.

The complaint procedure should remain practically accessible and should not create unnecessary formal barriers for vulnerable data subjects.


3. The complaint must concern personal data “relating to” the complainant

Article 77 is not a general actio popularis allowing any person to challenge any GDPR violation affecting somebody else.

The complaint must concern processing of personal data relating to the complainant.

Illustration

A person reads that a hospital may have unlawfully disclosed another patient’s medical record. The person may report that matter to the authority, but they cannot necessarily claim the full status of an Article 77 complainant unless their own personal data or legal interests under the GDPR are involved. By contrast, if the leaked database may include their own patient record, they can complain even if they do not yet possess definitive evidence that their individual file was accessed.

3.1 The complainant does not need perfect proof at the beginning

A person will often lack access to the controller’s internal systems. Requiring complete proof before allowing a complaint would make the remedy ineffective.

A reasonable complaint should identify, so far as possible:

  • the organisation involved;
  • the processing complained of;
  • the person’s connection with the data;
  • what allegedly happened;
  • why it may infringe the GDPR;
  • relevant communications or supporting materials.

The supervisory authority may then use its Article 58 powers to obtain evidence that the individual cannot access.

Illustration

A job applicant suspects that an employer used an undisclosed automated scoring system because the applicant received an instant rejection after submitting disability-related information. The applicant may not know:

  • the algorithm;
  • data sources;
  • score;
  • vendor;
  • internal decision logic. The complaint can explain the circumstances and request investigation. It would defeat Article 77 if the authority demanded disclosure of internal algorithmic evidence that only the controller possesses.

4. “If the data subject considers” that the GDPR was infringed

The wording is intentionally complainant-friendly. It does not say that the person may complain only after proving an infringement.

The person must genuinely allege facts capable of showing that processing concerning them may violate the GDPR.

This creates a lower threshold than the final merits determination.

Illustration

A controller refuses an access request, saying: “We do not provide copies of customer data.” The data subject may reasonably consider that Article 15 has been infringed and complain. The authority may later discover that:

  • no personal data were held;
  • an exemption applied;
  • the request was not properly authenticated;
  • the controller actually provided a lawful response. The complaint may fail on the merits, but that does not mean it was inadmissible when lodged.

4.1 Purely hypothetical concerns are different

Article 77 should not require an authority to resolve abstract questions disconnected from actual or sufficiently imminent processing.

Illustration

A person says: “A company might be created one day and might process my data unlawfully.” That is too hypothetical. But if an existing organisation announces that it will publish the complainant’s name and medical information next week, the risk is concrete and imminent. InNADA Austria, decided on 14 July 2026, the CJEU held that Article 77 can apply where unlawful processing has not yet occurred but is not purely hypothetical and there are specific indications that it is imminent or will occur in the near future. The case concerned proposed online publication of information relating to anti-doping violations. The practical principle is: Article 77 is preventive as well as corrective. A person does not always have to wait until the privacy harm has occurred.

5. The complaint can concern the whole GDPR, not only Chapter III rights

Article 77 refers broadly to processing that infringes“this Regulation.”

It is not confined to violations of:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • objection;
  • portability.

A person may complain about other GDPR obligations where the disputed processing relates to them.

Examples

include:

  • absence of a lawful basis under Article 6;
  • unlawful special-category processing under Article 9;
  • lack of transparency;
  • excessive collection;
  • unlawful retention;
  • inadequate security;
  • unlawful international transfer;
  • failure to apply privacy by design;
  • an invalid joint-controller arrangement;
  • non-compliant processing records where relevant to the complainant’s processing;
  • failure to notify a high-risk breach.

Illustration

A hospital gives the patient access to their record but stores the record without adequate security. The patient’s Article 15 right may have been respected, but the patient may still complain about:

  • Article 5(1)(f);
  • Article 24;
  • Article 25;
  • Article 32. The complaint route protects compliance with the Regulation as a whole where the person’s own data are involved.

6. A complaint may concern past, ongoing or imminent processing

The most natural cases involve ongoing processing, but Article 77 is not limited to data currently being processed.

6.1 Past processing

Illustration

A company unlawfully disclosed the person’s financial data last year and later deleted the file. Deletion does not erase the past infringement. The person may still complain about:

  • unlawful disclosure;
  • inadequate security;
  • excessive retention;
  • breach notification;
  • failure to inform the individual.

6.2 Ongoing processing

Illustration

A platform continues using the person’s location data for advertising after a valid objection. The complaint may seek an investigation and corrective action stopping the continued use.

6.3 Imminent processing

[!example] Illustration A sports body formally decides that it will publish an athlete’s name, sanction and underlying information online in seven days. Following NADA Austria, the individual need not necessarily wait for publication where the proposed processing is specific and imminent rather than speculative.

7. No general requirement to approach the controller first

Article 77 does not expressly require the individual to complain to the controller before contacting the supervisory authority.

A national procedure should not automatically reject a complaint solely because the person did not first send an informal complaint to the organisation.

However, the nature of a particular allegation may require some prior interaction.

Access illustration

A person alleges that a controller failed to comply with Article 15, but the person never made an access request.

It may be impossible to establish a refusal or delay where the underlying right was never exercised.

Security illustration

A person discovers that a public website displays their passport.

They do not need to negotiate with the controller before asking the authority to intervene, especially if immediate protection is needed.

The correct approach is not:

“Every complaint requires prior contact.”

It is:

“Ask whether the alleged infringement logically depends on the person having exercised a right or made a request first.”

Prior contact may also be practically useful because the controller may:

  • correct the problem quickly;
  • clarify a misunderstanding;
  • provide evidence;
  • create a written record.

But convenience should not become an unlawful admissibility barrier.


8. Complaints should be easy to submit

Recital 141 states that authorities should facilitate complaints, including by providing electronic complaint forms, without excluding other means of communication.

The purpose is accessibility, not procedural trap-setting.

A supervisory authority may reasonably request information such as:

  • complainant identity and contact details;
  • controller or processor;
  • description of the issue;
  • relevant dates;
  • data involved;
  • documents;
  • requested outcome;
  • information on related proceedings.

But an authority should not insist that an unrepresented person:

  • identify every correct GDPR provision;
  • draft formal legal pleadings;
  • prove the complete case;
  • use technical terminology;
  • calculate jurisdiction perfectly.

Illustration

A person writes: “My former employer shared my medical certificate with all employees, and I want this investigated.” The person has not cited Articles 5, 6, 9 or 32. The authority should understand the substance rather than reject the complaint because the individual did not identify the precise provisions. Forms improve completeness, but they should not exclude:

  • email;
  • post;
  • accessible digital tools;
  • assistance for disabilities;
  • other legally permitted channels.

9. Complaints are generally free

Article 57(3) requires the supervisory authority’s tasks for data subjects to be performed free of charge, subject to Article 57(4).

The general principle is therefore that a person should not have to pay a filing fee simply to exercise Article 77.

This is important because the complaint mechanism is intended to provide accessible protection without requiring the person to finance litigation.

9.1 Manifestly unfounded or excessive complaints

Article 57(4) allows an authority, where requests are manifestly unfounded or excessive, particularly because of repetitive character, to:

  • charge a reasonable fee based on administrative costs; or
  • refuse to act.

The authority bears the burden of demonstrating the manifestly unfounded or excessive character.

In Österreichische Datenschutzbehörde, Case C-416/23, decided on 9 January 2025, the CJEU confirmed that Article 57(4) can cover Article 77 complaints, but the number of complaints alone is insufficient. The authority must demonstrate abusive intent before treating them as excessive.

Illustration

A person files seventy genuine complaints because seventy unrelated controllers failed to answer lawful access requests. The number is large, but that fact alone does not establish abuse. Compare a person who files hundreds of substantially identical complaints:

  • without genuine concern for data protection;
  • to harass staff;
  • to create costs;
  • to obtain fees or leverage;
  • while concealing that the issue has already been fully resolved. That pattern may support an abuse finding, but the authority must examine the evidence and justify its choice between a fee and refusal. The authority cannot use Article 57(4) as a workload-management shortcut.

10. Where may the complaint be lodged?

Article 77 says that a complaint may be lodged with a supervisory authority,“in particular” in the Member State of the complainant’s:

  • habitual residence;
  • place of work;
  • place of the alleged infringement.

The words “in particular” identify practical and protected connecting points.

The safest course is normally to use one of those authorities, because that authority will clearly have a meaningful relationship with the complainant or disputed processing.

The supplied commentary’s claim that a person may lodge a complaint with absolutely any EEA supervisory authority regardless of location is too broad. Article 77 is designed to offer convenient access, not unrestricted regulator shopping wholly disconnected from the person or processing.


11. Habitual residence

Habitual residence is a factual concept. It normally refers to the place where the person has an established centre of life, not merely:

  • nationality;
  • formal registration;
  • temporary hotel stay;
  • brief visit.

Relevant circumstances may include:

  • duration and regularity of residence;
  • family life;
  • housing;
  • employment;
  • social connections;
  • intention and factual stability.

Illustration

A German citizen has lived and worked in France for four years. France is likely the person’s habitual residence even though the person remains a German national. This option is especially valuable because the person can usually:

  • use a familiar language;
  • contact a nearby authority;
  • rely on domestic procedural support;
  • challenge the authority locally under Article 78 where appropriate.

12. Place of work

A data subject may complain in the Member State where they work.

The text does not expressly require the disputed processing to concern their employment.

[!example] Illustration A person lives in Belgium, works in Luxembourg and complains about a Spanish travel platform. Article 77 indicates that the Luxembourgish authority is an available forum based on the person’s place of work, even though the complaint does not concern the employer. The purpose is accessibility. A person should not be forced to deal only with the authority where the controller has its headquarters. For remote workers, cross-border commuters or people with several workplaces, identifying the relevant place may require a factual assessment of where work is habitually carried out.

13. Place of the alleged infringement

A complaint may also be lodged where the alleged infringement occurred.

This connection may be useful where:

  • the physical processing took place there;
  • a CCTV system is located there;
  • the local establishment made the decision;
  • evidence or witnesses are there;
  • the disclosure occurred there;
  • the processing substantially affects people there.

Illustration

A hotel in Italy unlawfully scans and retains the passport of a guest who lives in Sweden and works in Denmark. The person may have complaint options connected with:

  • Swedish habitual residence;
  • Danish place of work;
  • Italian place of the alleged infringement. The individual is not necessarily required to identify the authority that will ultimately act as lead authority. The supervisory authorities must operate the competence and cooperation mechanisms.

14. Filing authority and deciding authority may differ

In a cross-border case, the authority receiving the complaint may not be the authority that leads the investigation.

The one-stop-shop system may involve:

  • a lead supervisory authority under Article 56;
  • one or more concerned supervisory authorities;
  • the authority with which the complaint was lodged;
  • cooperation under Article 60;
  • possible Article 65 dispute resolution.

Illustration

A French resident complains to the French authority about a platform whose main establishment is in Ireland. The French authority may:

  1. receive and assess the complaint;
  2. identify cross-border processing;
  3. communicate it through the cooperation system;
  4. become a concerned supervisory authority;
  5. remain the complainant’s accessible point of contact.

The Irish authority may act as lead authority in relation to the controller.

The French complainant should not be told:

“You must refile everything in Ireland.”

The purpose of Article 77 is to let the individual complain locally while the authorities coordinate behind the scenes.


15. Local complaint does not necessarily mean local application of different law

All the authorities are applying the GDPR, although national procedural rules may differ within EU-law limits.

A complainant’s choice of accessible authority should not produce arbitrary differences in the substantive GDPR standard.

16. The authority has a duty to handle the complaint

Article 57(1)(f) requires supervisory authorities to handle Article 77 complaints, investigate the subject matter to the extent appropriate and inform the complainant of progress and outcome within a reasonable period.

The authority cannot treat every complaint as discretionary correspondence.

The CJEU’s SCHUFA judgment emphasised that an Article 77 complaint is designed to protect the data subject effectively. Supervisory authorities possess broad investigative powers, and where an infringement is found, they must react appropriately to remedy it using suitable Article 58 powers. The resulting complaint decision is subject to full judicial review.

16.1 Appropriate extent of investigation

Not every complaint requires the same investigation.

A simple complaint may be resolved by:

  • checking correspondence;
  • obtaining the controller’s explanation;
  • examining one policy;
  • confirming deletion.

A complex case may require:

  • technical audit;
  • access to systems;
  • interviews;
  • cooperation with other authorities;
  • expert analysis;
  • examination of source code;
  • inspection of contracts;
  • international-transfer analysis.

[!example] Illustration A person alleges that an email was sent to the wrong recipient. The key facts are admitted and the recipient deleted it immediately. A proportionate inquiry may be limited. A person alleges that a national facial-recognition system systematically misidentifies minority groups and makes automated policing decisions. A much deeper investigation may be required. Recital 141 expressly says that the investigation should be carried out, subject to judicial review, to the extent appropriate in the specific case.

17. The authority does not act merely as the complainant’s lawyer

The supervisory authority must be independent and objective.

It does not have to accept every legal characterisation made by the complainant.

Illustration

The complainant says: “This is an Article 9 violation.” The authority may conclude that:

  • the data are not special-category data;
  • another GDPR provision was infringed;
  • no infringement occurred;
  • further evidence is required. The authority’s obligation is to examine the substance fairly and act within its statutory powers. However, independence does not permit superficial dismissal. The authority must give enough reasoning to allow the complainant and a reviewing court to understand the outcome.

18. Corrective action after an infringement

Where an infringement is found, the supervisory authority must consider an appropriate response.

Article 58(2) provides measures including:

  • warning;
  • reprimand;
  • compliance order;
  • order to honour rights;
  • rectification or erasure;
  • restriction;
  • processing prohibition;
  • suspension of data flows;
  • administrative fine.

The authority retains judgment regarding the suitable measure, but its action must ensure full and effective GDPR enforcement.

Illustration

A controller answered an access request three days late because of a one-off administrative error and corrected its procedure. A reprimand may be sufficient. Another controller intentionally sells medical data, continues after warnings and refuses deletion. A stronger combination may be necessary:

  • prohibition;
  • deletion;
  • compliance order;
  • fine. The complainant does not necessarily have a right to demand a particular fine. They do have a right to lawful, diligent handling and an outcome capable of judicial review.

19. Article 77 does not itself award compensation

A supervisory authority may investigate and use corrective powers, but Article 77 is not the normal route for obtaining damages.

Compensation is governed by Article 82 and the applicable court procedure.

Illustration

A data breach causes identity theft and financial loss. The person may:

  • complain under Article 77 to obtain regulatory investigation and corrective action;
  • sue under Article 79 and Article 82 for compensation;
  • use both routes concurrently, subject to lawful national coordination rules. A fine imposed by the authority is generally paid to the state, not transferred automatically to the complainant. This distinction should be made clear so that individuals do not assume that a successful complaint automatically produces damages.

20. “Without prejudice to any other administrative or judicial remedy”

These opening words preserve parallel remedies.

A complainant may potentially:

  • complain under Article 77;
  • challenge the authority under Article 78;
  • sue the controller or processor under Article 79;
  • claim compensation under Article 82;
  • use another available administrative remedy.

In BE v Nemzeti Adatvédelmi és Információszabadság Hatóság, Case C-132/21, the CJEU held that the Article 77 and 78 remedies, on one hand, and the Article 79 court remedy, on the other, may be exercised concurrently and independently. Member States must coordinate them consistently with effectiveness, equivalent treatment and Article 47 of the Charter.

Illustration

A controller refuses erasure. The person may simultaneously:

  1. complain to the supervisory authority;
  2. ask a civil court to order erasure;
  3. claim compensation if legally recoverable damage occurred.

The court does not automatically have to wait for the authority, and the authority does not automatically lose jurisdiction because the court case exists.


21. A supervisory authority cannot reject solely because a court case exists

The CJEU clarified this issue further in Datenschutzbehörde, Case C-414/24, decided on 18 June 2026.

The Court held that Articles 77(1) and 79(1) preclude a supervisory authority from rejecting an Article 77 complaint solely because court proceedings concerning the same subject matter have already been brought under Article 79.

Illustration

A patient asks a company to erase an online medical profile. The patient:

  • sues the company in civil court;
  • also complains to the data protection authority. The authority cannot say: “Because you went to court first, you no longer have an Article 77 right.” That would undermine the concurrent and independent structure chosen by the GDPR.

21.1 Coordination remains possible

Concurrent remedies create a risk of inconsistent findings.

National law may adopt coordination mechanisms, so long as those mechanisms do not make EU rights practically impossible or excessively difficult.

Possible mechanisms may include:

  • information exchange;
  • procedural stays;
  • consideration of a final judgment;
  • case-management rules;
  • res judicata principles;
  • referral to the CJEU where necessary.

But coordination cannot become disguised abolition of one remedy.

Illustration

The authority temporarily stays one narrow issue because a court is about to decide the identical legal question. That may be defensible if:

  • the stay is proportionate;
  • the complaint remains alive;
  • urgent protection is not needed;
  • the person retains effective remedies;
  • the authority does not simply refuse its statutory role. A blanket rule that the first forum chosen permanently excludes the other is inconsistent with the CJEU’s approach.

22. National procedural autonomy

The GDPR does not regulate every procedural detail of the complaint.

Member States may determine matters such as:

  • form;
  • language;
  • identification;
  • representation;
  • evidence;
  • hearings;
  • deadlines;
  • appeals;
  • service of decisions;
  • limitation periods;
  • coordination with court proceedings.

But national autonomy is constrained by EU law.

22.1 Principle of equivalence

GDPR complaints must not be treated less favourably than comparable domestic claims.

Illustration

Domestic consumer complaints may be filed electronically without notarisation, while GDPR complaints require an expensive notarised filing. That difference may violate equivalence unless objectively justified.

22.2 Principle of effectiveness

National rules must not make GDPR rights practically impossible or excessively difficult.

Illustration

A national rule requires an Article 77 complaint to be filed within twenty-four hours of discovering the processing. That period would likely make the right excessively difficult to exercise.

22.3 Effective judicial protection

Procedures must respect Article 47 of the Charter, including effective access to a court.

The CJEU has emphasised that concurrent GDPR remedies must be coordinated in a way that preserves effective protection and consistent application.


23. Limitation periods

Article 77 itself establishes no express limitation period.

Member States may apply procedural time limits if they comply with:

  • equivalence;
  • effectiveness;
  • legal certainty;
  • effective judicial protection.

The fairness of a limitation period may depend on:

  • when it begins;
  • whether the infringement is continuing;
  • whether the person knew or could reasonably know of it;
  • whether the authority contributed to delay;
  • whether vulnerable individuals are involved.

[!example] Illustration A controller secretly profiles a person for six years. The person discovers it only after obtaining an access response. A national time limit starting from the hidden processing date might expire before the person could possibly know of the infringement. Such a rule could undermine effectiveness. By contrast, a reasonable period beginning when the person knew or should reasonably have known may be compatible with EU law. Continuing processing also raises a separate question. Each day of unlawful retention or use may represent an ongoing situation rather than a completed historical event.

24. Representation under Article 80

A data subject may mandate an eligible non-profit organisation to:

  • lodge the Article 77 complaint;
  • exercise Article 78 remedies;
  • bring Article 79 proceedings;
  • pursue compensation where national law permits the representative to do so.

The organisation must satisfy Article 80 requirements, including:

  • non-profit character;
  • proper constitution under Member State law;
  • public-interest objectives;
  • activity in protecting data subject rights and freedoms.

Illustration

A person affected by an inaccessible algorithmic credit system may authorise a digital-rights organisation to complain on their behalf. This can help where the individual lacks:

  • legal knowledge;
  • resources;
  • technical expertise;
  • confidence to confront a large controller. Article 80(2) also allows Member States to permit certain representative actions without an individual mandate where its conditions are met. That broader representative route depends on national implementation.

25. Article 77 and information duties of controllers

Controllers must tell data subjects about their right to complain in several contexts, including:

  • Article 13 privacy information;
  • Article 14 privacy information;
  • Article 15 access responses;
  • certain communications restricting or refusing rights.

The information should include the possibility of contacting a supervisory authority.

Illustration

A privacy notice states: “If you have concerns, contact our customer service team. Its decision is final.” That is misleading because the controller cannot eliminate the person’s Article 77 right. A good notice should explain:

  • the right to complain;
  • the relevant authority or how it can be located;
  • that internal contact does not remove external remedies.

26. Article 77(2): Duty to inform about progress

The authority with which the complaint was lodged must inform the complainant about progress.

This duty prevents a complaint from disappearing into an administrative black hole.

Progress information may include:

  • acknowledgment of receipt;
  • request for further information;
  • admissibility status;
  • transfer to a lead authority;
  • identification of a cross-border procedure;
  • opening of an investigation;
  • communication with the controller;
  • expected next steps;
  • delay or extension;
  • coordination with another authority;
  • closure or preliminary resolution.

Recital 141 states that the complainant should be informed within a reasonable period and should receive intermediate information where further investigation or coordination is needed.


27. The three-month safeguard

Article 78(2) provides a judicial remedy where the competent supervisory authority:

  • does not handle the complaint; or
  • does not inform the data subject within three months about progress or outcome.

This does not mean that every investigation must be completed within three months.

It means that the complainant should not remain uninformed beyond that point without access to judicial protection.

Illustration

A complex cross-border case requires twelve months. The authority need not necessarily finish within three months, but it should provide meaningful information such as:

  • the complaint has been accepted;
  • a lead authority has been identified;
  • the controller has been contacted;
  • technical examination is ongoing;
  • further coordination is required. A bare automated acknowledgment may be insufficient if nothing more is communicated for an extended period.

27.1 Does the GDPR require updates every three months?

The text does not expressly impose a mechanical recurring three-month update in every case.

The stronger legal position is:

  • silence for three months activates the Article 78(2) remedy;
  • Recital 141 requires intermediate information where further investigation or coordination is needed;
  • updates must occur within a reasonable period based on circumstances;
  • prolonged cases normally require meaningful periodic communication.

The supplied commentary goes too far by converting the three-month judicial-remedy trigger into an automatic statutory duty to send a report every three months in every case.

Good administration may support regular three-month updates, but that is not the exact wording of Article 77 or Article 78.


28. What counts as meaningful progress information?

Progress information need not disclose every investigative detail.

The authority may need to protect:

  • confidentiality;
  • investigation strategy;
  • the controller’s rights;
  • whistleblowers;
  • trade secrets;
  • cooperation among authorities.

But the information should be sufficient to tell the complainant that the case is genuinely being handled.

Weak update

“Your complaint remains under consideration.”

Repeated without further information for two years, this may become inadequate.

Better update

“Your complaint was accepted on 12 January. It concerns cross-border processing. The Irish authority has been identified provisionally as lead authority. The controller supplied a response on 15 March. The authorities are now examining the lawful basis and retention issues. We expect to provide a further update by June.”

The second update proves meaningful activity while avoiding disclosure of confidential evidence.


29. Duty to inform about the outcome

The complainant must also be told the outcome.

Possible outcomes include:

  • complaint upheld;
  • complaint partly upheld;
  • complaint rejected;
  • complaint dismissed as inadmissible;
  • infringement found but already remedied;
  • settlement or amicable resolution;
  • transfer to another competent authority;
  • corrective measures ordered;
  • no infringement established.

The outcome should contain enough information to understand:

  • what was alleged;
  • what was investigated;
  • central factual findings;
  • legal reasoning;
  • disposition;
  • available judicial remedy.

Illustration

An authority sends: “Your complaint is closed.” That is unlikely to be enough where the complainant cannot tell:

  • whether it was rejected;
  • whether the controller complied;
  • whether an infringement was found;
  • whether the authority considered the evidence;
  • what may be challenged. The level of detail may vary, but the information must allow effective Article 78 review.

30. Full judicial review of complaint decisions

In the SCHUFA judgment, the CJEU held that a supervisory authority’s complaint decision is subject to full judicial review.

The authority is not simply providing a non-reviewable policy opinion. A court must be able to examine the relevant legal and factual questions within the scope of the action.

Illustration

The supervisory authority dismisses a complaint by accepting the controller’s assertion that retaining insolvency data for three years is lawful. The reviewing court may examine:

  • applicable GDPR provisions;
  • lawfulness;
  • necessity;
  • balancing of interests;
  • retention;
  • evidence;
  • adequacy of the authority’s investigation. It is not confined merely to asking whether the authority acted irrationally in an extreme sense. This full review is why the authority’s final reasoning must be sufficiently clear.

31. Information about Article 78 remedies

Article 77(2) expressly requires information about the possibility of a judicial remedy under Article 78.

A useful remedy notice should identify, according to applicable law:

  • right to challenge the decision;
  • competent court;
  • filing period;
  • form;
  • whether representation is required;
  • relevant procedural information.

Illustration

The authority rejects a complaint but does not mention that the person has only one month to challenge it. The omission may seriously prejudice the right to effective judicial protection. Whether the omission suspends or extends the national appeal period depends on applicable procedural law and the principles of effectiveness and equivalence. But the authority has plainly failed to perform the Article 77(2) information duty properly.

31.1 Inaction remedies

Good practice also supports informing the complainant that Article 78(2) provides a judicial remedy where:

  • the authority does not handle the complaint; or
  • no progress or outcome information is given within three months.

It would be odd to tell individuals about judicial remedies only after a final decision while leaving them unaware of the remedy against silence.


32. Communication in cross-border cases

The authority with which the complaint was lodged remains responsible for informing the complainant, even where another authority acts as lead.

Illustration

A complainant files in France. Ireland becomes lead authority. The French authority should remain the accessible local channel and provide information received through the cooperation mechanism. The complainant should not have to:

  • identify the Irish case officer;
  • communicate in another language;
  • understand the entire Article 60 procedure;
  • repeatedly contact several authorities. This local-contact function is part of the practical value of Article 77.

32.1 Final decisions in mixed outcomes

Article 60 contains special rules where:

  • the complaint is upheld;
  • rejected in full;
  • partly upheld and partly rejected.

Where the complaint is rejected, the authority with which it was lodged generally adopts and notifies the rejection decision. Where action is taken against the controller, the lead authority adopts the relevant decision and the complainant is informed through the cooperation framework.

These rules preserve:

  • local judicial access for the rejected complaint;
  • coherent cross-border action against the controller.

33. Complaints may reveal systemic violations

An individual complaint can expose a wider GDPR problem.

Illustration

One employee complains that an employer unlawfully recorded biometric attendance data. The authority discovers that the same system affects ten thousand workers. The investigation may expand beyond the complainant’s individual record to examine:

  • lawful basis;
  • special-category data;
  • necessity;
  • retention;
  • vendor access;
  • security;
  • transparency;
  • DPIA. The CJEU has recognised that Article 77 complaints play an important role in bringing infringements to supervisory authorities’ attention and thereby support a high and consistent level of protection. In the excessive-complaint judgment, the Court’s approach reinforced that genuine complaints cannot be disregarded merely because one person submits many of them. The complainant’s individual remedy and the authority’s public enforcement role therefore overlap.

34. Withdrawal and amicable resolution

A complainant may later:

  • withdraw;
  • settle with the controller;
  • obtain the requested access or erasure;
  • lose interest.

National procedure determines the precise effect, but withdrawal does not necessarily require the authority to ignore a serious systemic infringement.

Illustration

A company deletes one complainant’s data after the authority asks questions, but evidence shows that it unlawfully retains millions of other records. The personal dispute may be resolved, yet the authority may continue an own-initiative investigation in the public interest. The authority should distinguish:

  • closure of the Article 77 individual complaint;
  • continuation of general supervisory enforcement. This distinction should be explained to the complainant.

35. Complaints and anonymous reporting

Article 77 normally requires identifying a data subject whose data are involved. Fully anonymous allegations may be difficult to treat as formal complaints because the authority cannot verify:

  • identity;
  • relation to the data;
  • representation;
  • desired outcome;
  • entitlement to procedural rights.

But an anonymous report may still serve as:

  • a tip;
  • a breach report;
  • evidence supporting an own-initiative inquiry;
  • a whistleblower disclosure.

Illustration

An anonymous employee reports that a hospital sells patient data. The authority may investigate even if the employee cannot be recognised as an Article 77 complainant. If a patient later identifies themselves and alleges that their own data were sold, they may exercise the formal Article 77 right. Authorities should not confuse:

  • admissibility as a personal complaint;
  • usefulness as regulatory intelligence.

36. The complainant’s procedural participation

The precise procedural rights depend partly on national law, but EU principles may require an effective opportunity to participate.

Potential rights include:

  • acknowledgment;
  • opportunity to clarify the complaint;
  • submission of evidence;
  • response to adverse factual assumptions;
  • reasonable access to relevant file material;
  • reasoned outcome;
  • judicial remedy.

These rights must be balanced against:

  • controller confidentiality;
  • third-party personal data;
  • trade secrets;
  • investigative secrecy;
  • professional privilege.

37. What Article 77 does not guarantee

Article 77 is powerful, but it does not guarantee:

  • that the complainant will win;
  • that the authority will impose a fine;
  • that the exact remedy requested will be ordered;
  • that the investigation will finish within three months;
  • that every internal document will be disclosed;
  • that compensation will be awarded;
  • that the complainant directs the entire investigation.

What it does guarantee is a legally meaningful route to:

  • submit the complaint;
  • have it handled diligently;
  • receive progress information;
  • receive an outcome;
  • obtain information about judicial remedies;
  • challenge the authority’s decision or inaction.

38. Detailed end-to-end illustration

Assume that a person living in France uses a fitness application operated by a company whose main EEA establishment is in Ireland.

The person discovers that the app:

  • inferred pregnancy;
  • shared the inference with advertisers;
  • retained precise location data;
  • ignored an access request;
  • may transfer data to a third country.

Step 1: Complaint

The person files with the French authority because France is the habitual residence.

The complaint contains:

  • account details;
  • screenshots;
  • access request;
  • unanswered emails;
  • advertising evidence;
  • privacy notice.

The person need not prove the internal transfer chain.

Step 2: Initial assessment

The French authority confirms receipt and determines that the complaint concerns cross-border processing.

It identifies the potential Irish lead authority and communicates through the cooperation mechanism.

Step 3: Progress information

The French authority informs the complainant that:

  • the case is cross-border;
  • Ireland is acting as lead;
  • French and other authorities are concerned;
  • the controller has been asked for information.

Step 4: Investigation

The authorities examine:

  • Article 6 lawful basis;
  • Article 9 health-data inference;
  • Articles 12 and 15 access compliance;
  • Article 5 retention;
  • Articles 44 to 49 transfers;
  • Article 32 security.

Step 5: Draft decision

The Irish authority finds only an access violation.

France objects that:

  • pregnancy inference concerns health data;
  • Article 9 was not addressed;
  • advertising disclosure lacked lawful basis;
  • location retention was excessive.

If the objection is relevant and reasoned and Ireland does not follow it, the dispute may go to the EDPB under Article 65.

Step 6: Final outcome

Following the European process, the final decision may:

  • find additional infringements;
  • order cessation of advertising use;
  • order deletion;
  • require access;
  • impose a fine.

Step 7: Notification and remedy

The complainant receives the outcome through the appropriate authority and is told:

  • which findings succeeded;
  • which were rejected;
  • corrective measures;
  • how and when to seek Article 78 judicial review.

Step 8: Parallel compensation claim

The complainant may separately pursue an Article 82 compensation claim before a competent court if the legal conditions are met.

The authority cannot reject the complaint solely because that civil action exists.


39. Corrections and qualifications to the supplied commentary

Several propositions in the supplied material should be refined.

39.1 A complaint does not normally require ongoing processing

Past infringements and specifically imminent processing may also support Article 77. The 2026 NADA Austria judgment confirms the preventive dimension where processing is imminent and not purely hypothetical.

39.2 The person does not need to establish the infringement before filing

They must make a sufficiently comprehensible allegation that their personal data are or will be processed incompatibly with the GDPR.

39.3 Complaints are not restricted to Chapter III

Article 77 refers to any infringement of the Regulation connected with processing of the complainant’s personal data.

39.4 Filing with absolutely any EEA authority is too broad a reading

The Article protects filing particularly at habitual residence, workplace or place of infringement. A meaningful jurisdictional connection remains important.

39.5 A court action does not extinguish the complaint right

The remedies are concurrent and independent. The 2026 CJEU judgment confirms that a supervisory authority cannot reject solely because an Article 79 proceeding on the same matter already exists.

39.6 A stay may sometimes be permissible, but not automatically

Any coordination rule must respect effectiveness, equivalence, urgent protection and the independence of the remedies.

39.7 Many complaints do not alone prove excessiveness

Abusive intent must be demonstrated under the 2025 CJEU judgment.

39.8 Three months is not a universal deadline for completing the investigation

It triggers the Article 78(2) remedy where no progress or outcome information is supplied.

39.9 The GDPR does not expressly require automatic updates every three months

It requires information within a reasonable period and intermediate information where further investigation or coordination is necessary.

39.10 An Article 77 complaint does not automatically produce compensation

Compensation requires an Article 82 claim satisfying its separate conditions.

Conclusion

Article 77 gives every data subject an accessible administrative remedy against suspected GDPR violations involving their personal data. The individual may complain particularly in the Member State of:

  • habitual residence;
  • place of work;
  • place of the alleged infringement. The person need not:
  • prove the complete case in advance;
  • know which authority will ultimately lead;
  • cite the correct GDPR provision;
  • abandon parallel judicial remedies;
  • pay an ordinary filing fee;
  • wait for specifically imminent unlawful processing to occur. The complaint must nevertheless concern processing of personal data relating to that person. Article 77 is not ordinarily a general public-interest action for challenging processing affecting only strangers. Once a complaint is filed, the supervisory authority must:
  • handle it diligently;
  • investigate to the extent appropriate;
  • cooperate with other authorities where necessary;
  • use suitable corrective powers if an infringement is found;
  • inform the complainant about progress;
  • communicate the outcome;
  • explain the possibility of Article 78 judicial review.

The complaint right coexists with:

  • court proceedings against the controller or processor;
  • judicial review of the supervisory authority;
  • compensation claims;
  • representative action under Article 80.

The CJEU’s modern case law strengthens this remedial structure:

  • Article 77 and Article 79 remedies may operate concurrently and independently.
  • A complaint cannot be rejected solely because a court proceeding concerning the same subject matter already exists.
  • An authority’s complaint decision is subject to full judicial review.
  • Numerous complaints are not excessive merely because of their number; abusive intent must be demonstrated.
  • An Article 77 complaint may address sufficiently specific and imminent processing before the threatened publication or use occurs.

The essential balance is:

The threshold for lodging a complaint is deliberately accessible, but the authority remains responsible for objective investigation and proportionate enforcement. The complainant is entitled to an effective procedure, not an automatic victory or a guaranteed fine.

In the simplest possible terms:

A person who reasonably believes that their personal data have been mishandled may ask an independent data protection authority to investigate. The authority must take the complaint seriously, keep the person informed, explain the result and make judicial review possible.