National and regional Data Protection Authorities (DPAs), also known as supervisory authorities, are responsible for the monitoring and consistency of GDPR application. Each Member State has at least one supervisory authority.12 However, while France, Hungary and Italy have only one supervisory authority, Germany and Spain have regional authorities in addition to a central authority. This is a consequence of their federal or devolved constitutional structure. Consequently, competences are then split between central and regional authorities.
DPAs act as enforcers, ombudsmen, auditors, consultants to policy advisors, negotiators and educators.13 The latter role concerns raising public awareness and understanding of the risks, rules, safeguards and rights in relation to the processing of personal data. To this end, DPAs, individually or jointly (e.g. as the European Data Protection Board), issue authoritative guidance on GDPR concepts and provisions.
Some guidance has been addressed to SMEs specifically. Based on the information provided by the STAR II interviews with DPAs as well as desktop research of all EU DPA websites, it appears that slightly fewer than one-third of EU DPAs currently provide GDPR guidance that is specifically tailored to SMEs. Upon the last review, this included the DPAs from Belgium (Autorité de protection des données - Gegevensbeschermingsautoriteit),14 France
