![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/70e217a4fd3a11d83b945a8dbb8e1fa6.jpeg)
Version1.0 10October2022 AdoptionoftheGuidelines(updatedversionofthe previousguidelinesWP244rev.01adoptedbytheWorking Party29andendorsedbytheEDPBon25May2018)fora targetedpublicconsultation.
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/91b9ed1f035cd7e5b75e81f892248f93.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/9d1f7ef4d924acc53c412e2e2176cb00.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/4499eca8981e1527a0f0c7a6852fa4be.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/453a04d5524ef5db9c5f2263f6dd4a39.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/51defa46e4e83cda5484a1eec9cfc037.jpeg)
TheEuropeanDataProtectionBoard
HavingregardtoArticle70(1)(e)and(l)oftheRegulation2016/679/EUoftheEuropeanParliament andoftheCouncilof27April2016ontheprotectionofnaturalpersonswithregardtotheprocessing ofpersonaldataandonthefreemovementofsuchdata,andrepealingDirective95/46/EC, (hereinafterGDPR),
HavingregardtotheEEAAgreementandinparticulartoAnnexXIandProtocol37thereof,asamended bytheDecisionoftheEEAjointCommitteeNo154/2018of6July20181 ,
HavingregardtoArticle12andArticle22ofitsRulesofProcedure,
HavingregardtotheArticle29WorkingPartyGuidelinesforidentifyingacontrollerorprocessorslead supervisoryauthority,WP244rev.01,
HavingregardtotheEDPBGuidelines07/2020ontheconceptsofcontrollerandprocessorinthe GDPR,
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/c3618e82c54642c3cf62c556125176ef.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/6af0fa9f574fe3b64ececd0655b8a669.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/a055ed99a31a1245cb2d6427647e57d4.jpeg)
HASADOPTEDTHEFOLLOWINGGUIDELINES
0PREFACE
1. On5April2017,theArticle29WorkingPartyadopteditsGuidelinesforidentifyingacontrolleror processorsleadsupervisoryauthority(WP244rev.01)2,whichwereendorsedbytheEuropeanData ProtectionBoard(hereinafterEDPB)atitsfirstPlenarymeeting3.Thisdocumentisaslightlyupdated versionofthoseguidelinesAnyreferencetotheWP29Guidelinesforidentifyingacontrolleror processorsleadsupervisoryauthority(WP244rev.01)should,fromnowon,beinterpretedasa referencetotheseEDPBguidelines.
2. TheEDPBhasnoticedthattherewasaneedforfurtherclarifications,specificallyregardingthenotion ofmainestablishmentinthecontextofjointcontrollershipandtakingintoaccounttheEDPB Guidelines07/2020ontheconceptsofcontrollerandprocessorintheGDPR4 .
3. Theparagraphconcerningthismatterhasbeenrevisedandupdated,whiletherestofthedocument
documents/guidelines/guidelines072020conceptscontrollerandprocessorgdpr_en
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/61d6fe16b955afb104396687086f51d0.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/6e690601fa01469a910ede7f02e89b7f.jpeg)
1.1 Crossborderprocessingofpersonaldata
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/2102e93de065041a667bd61950f63f78.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/94b1614d4610bae628ab4f77cf60996c.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/538e51d32ec6bcd3564d755e2ee81c9c.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/c9271013f3bcacd520b03c656cbfe737.jpeg)
4. Identifyingaleadsupervisoryauthorityisonlyrelevantwhereacontrollerorprocessoriscarryingout thecrossborderprocessingofpersonaldata.Article4(23)GDPRdefinescrossborderprocessingas eitherthe:
processingofpersonaldatawhichtakesplaceinthecontextoftheactivitiesofestablishments inmorethanoneMemberStateofacontrollerorprocessorintheUnionwherethecontrolleror processorisestablishedinmorethanoneMemberState;orthe
processingofpersonaldatawhichtakesplaceinthecontextoftheactivitiesofasingle establishmentofacontrollerorprocessorintheUnionbutwhichsubstantiallyaffectsorislikely tosubstantiallyaffectdatasubjectsinmorethanoneMemberState
5. ThismeansthatwhereanorganisationhasestablishmentsinFranceandRomania,forexample,and theprocessingofpersonaldatatakesplaceinthecontextoftheiractivities,thenthiswillconstitute crossborderprocessing.
6. Alternatively,theorganisationmayonlycarryoutprocessingactivityinthecontextofitsestablishment inFrance.However,iftheactivitysubstantiallyaffects orislikelytosubstantiallyaffect data subjectsinFranceandRomaniathenthiswillalsoconstitutecrossborderprocessing.
1.1.1 Substantiallyaffects
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/604b532384bc24404e8810686a7c3cfb.jpeg)
7. TheGDPRdoesnotdefinesubstantiallyoraffects.Theintentionofthewordingwastoensurethat notallprocessingactivity,withanyeffectandthattakesplacewithinthecontextofasingle establishment,fallswithinthedefinitionofcrossborderprocessing.
8. ThemostrelevantordinaryEnglishmeaningsofsubstantialinclude:ofampleorconsiderableamount orsize;sizeable,fairlylarge,orhavingsolidworthorvalue,ofrealsignificance;solid;weighty, important5 .
9. Themostrelevantmeaningoftheverbaffectistoinfluenceortomakeamaterialimpressionon. Therelatednouneffectmeans,amongstotherthings,aresultoraconsequence6 Thissuggests thatfordataprocessingtoaffectsomeoneitmusthavesomeformofimpactonthem.Processingthat doesnothaveasubstantialeffectonindividualsdoesnotfallwithinthesecondpartofthedefinition ofcrossborderprocessing.However,itwouldfallwithinthefirstpartofthedefinitionwherethe processingofpersonaldatatakesplaceinthecontextoftheactivitiesofestablishmentsinmorethan oneMemberStateofacontrollerorprocessorintheUnion,wherethecontrollerorprocessoris establishedinmorethanoneMemberState.
10. Processingcanbebroughtwithinthesecondpartofthedefinitionifthereisthelikelihoodofa substantialeffect,notjustanactualsubstantialeffect.Notethatlikelytodoesnotmeanthatthere isaremotepossibilityofasubstantialeffect.Thesubstantialeffectmustbemorelikelythannot.On theotherhand,italsomeansthatindividualsdonothavetobeactuallyaffected:thelikelihoodofa substantialeffectissufficienttobringtheprocessingwithinthedefinitionofcrossborderprocessing.
11. Thefactthatadataprocessingoperationmayinvolvetheprocessingofanumber evenalarge numberofindividualspersonaldata,inanumberofMemberStates,doesnotnecessarilymeanthat theprocessinghas,orislikelytohave,asubstantialeffect.Processingthatdoesnothaveasubstantial effectdoesnotconstitutecrossborderprocessingforthepurposesofthesecondpartofthe definition,regardlessofhowmanyindividualsitaffects.
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/c3618e82c54642c3cf62c556125176ef.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/6e690601fa01469a910ede7f02e89b7f.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/6af0fa9f574fe3b64ececd0655b8a669.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/a055ed99a31a1245cb2d6427647e57d4.jpeg)
12. SupervisoryAuthoritieswillinterpretsubstantiallyaffectsonacasebycasebasis.Wewilltakeinto accountthecontextoftheprocessing,thetypeofdata,thepurposeoftheprocessingandfactorssuch aswhethertheprocessing:
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/61d6fe16b955afb104396687086f51d0.jpeg)
o causes,orislikelytocause,damage,lossordistresstoindividuals;
o has,orislikelytohave,anactualeffectintermsoflimitingrightsordenyinganopportunity;
o affects,orislikelytoaffectindividualshealth,wellbeingorpeaceofmind;
o affects,orislikelytoaffect,individualsfinancialoreconomicstatusorcircumstances;
o leavesindividualsopentodiscriminationorunfairtreatment;
o involvestheanalysisofthespecialcategoriesofpersonalorotherintrusivedata,particularlythe personaldataofchildren;
o causes,orislikelytocauseindividualstochangetheirbehaviourinasignificantway;
o hasunlikely,unanticipatedorunwantedconsequencesforindividuals;
o createsembarrassmentorothernegativeoutcomes,includingreputationaldamage;or
o involvestheprocessingofawiderangeofpersonaldata.
asregardsacontrollerwithestablishmentsinmorethanoneMemberState,theplaceofits centraladministrationintheUnion,unlessthedecisionsonthepurposesandmeansofthe processingofpersonaldataaretakeninanotherestablishmentofthecontrollerintheUnionand thelatterestablishmenthasthepowertohavesuchdecisionsimplemented,inwhichcasethe establishmenthavingtakensuchdecisionsistobeconsideredtobethemainestablishment;
asregardsaprocessorwithestablishmentsinmorethanoneMemberState,theplaceofits centraladministrationintheUnion,or,iftheprocessorhasnocentraladministrationinthe Union,theestablishmentoftheprocessorintheUnionwherethemainprocessingactivitiesin thecontextoftheactivitiesofanestablishmentoftheprocessortakeplacetotheextentthat theprocessorissubjecttospecificobligationsunderthisRegulation;
2STEPSTOIDENTIFYTHELEADSUPERVISORYAUTHORITY
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/2e3792ab528c29d0c8c2683c78aac388.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/de84c327194198bb6ddd42edee7cec6a.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/9cbaf97e806e1d68875dfb07db79374f.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/994c372392e0dd91cea36994017e0748.jpeg)
18. Inordertoestablishwherethemainestablishmentis,itisfirstlynecessarytoidentifythecentral administrationofthecontrollerintheEEA,ifanyTheapproachimpliedintheGDPRisthatthecentral administrationintheEUistheplacewheredecisionsaboutthepurposesandmeansoftheprocessing ofpersonaldataaretaken,andthisplacehasthepowertohavesuchdecisionsimplemented.
19. TheessenceoftheleadsupervisoryauthorityprincipleintheGDPRisthatthesupervisionofcross borderprocessingshouldbeledbyonlyonesupervisoryauthorityintheEU.Incaseswheredecisions relatingtodifferentcrossborderprocessingactivitiesaretakenwithintheEUcentraladministration, therewillbeasingleleadsupervisoryauthorityforthevariousdataprocessingactivitiescarriedout bythemultinationalcompany.However,theremaybecaseswhereanestablishmentotherthanthe placeofcentraladministrationmakesautonomousdecisionsconcerningthepurposesandmeansofa specificprocessingactivity.Thismeansthattherecanbesituationswheremorethanonelead supervisoryauthoritycanbeidentified,i.e.incaseswhereamultinationalcompanydecidestohave separatedecisionmakingcentres,indifferentcountries,fordifferentprocessingactivities.
20. Itisworthrecalling,thatwhereamultinationalcompanycentralisesallthedecisionsrelatingtothe purposesandmeansofprocessingactivitiesinoneofitsestablishmentsintheEEA(andthat establishmenthasthepowertoimplementsuchdecisions),onlyoneleadsupervisoryauthoritywillbe identifiedforthemultinational.
21. Inthesesituations,itwillbeessentialforcompaniestoidentifypreciselywherethedecisionson purposeandmeansofprocessingaretaken.Correctidentificationofthemainestablishmentisinthe interestsofcontrollersandprocessorsbecauseitprovidesclarityintermsofwhichsupervisory authoritytheyhavetodealwithinrespectoftheirvariouscompliancedutiesundertheGDPR.These mayinclude,whererelevant,designatingadataprotectionofficerorconsultingforariskyprocessing activitythatthecontrollercannotmitigatebyreasonablemeans.TherelevantprovisionsoftheGDPR areintendedtomakethesecompliancetasksmanageable.
Example1:Afoodretailerhasitsheadquarters(i.e.,itsplaceofcentraladministration)inRotterdam, Netherlands.IthasestablishmentsinvariousotherEEAcountries,whichareincontactwithindividuals there.Allestablishmentsmakeuseofthesamesoftwaretoprocessconsumerspersonaldatafor marketingpurposes.Allthedecisionsaboutthepurposesandmeansoftheprocessingofconsumers personaldataformarketingpurposesaretakenwithinitsRotterdamheadquarters.Thismeansthat
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/27dd14d5f1da0caa8196793299fe641b.jpeg)
thecompanysleadsupervisoryauthorityforthiscrossborderprocessingactivityistheDutch supervisoryauthority.
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/7cbd1b7842765a942b96b977bcc4ed38.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/a02c7bef51515648256e495384f821be.jpeg)
Example2:AbankhasitscorporateheadquartersinFrankfurt,andall8itsbankingprocessingactivities areorganisedfromthere,butitsinsurancedepartmentislocatedinVienna.Iftheestablishmentin Viennahasthepowertodecideonallinsurancedataprocessingactivitiesandtoimplementthese decisionsforthewholeEEA,then,asforeseeninArticle4(16)GDPR,theAustriansupervisoryauthority wouldbetheleadsupervisoryauthorityinrespectofthecrossborderprocessingofpersonaldatafor insurancepurposes,andthecompetentGermansupervisoryauthority(i.e.,theHessensupervisory authority)wouldsupervisetheprocessingofpersonaldataforbankingpurposes,wherevertheclients arelocated9
2.1.1Criteriaforidentifyingacontrollersmainestablishmentincaseswhereitisnotthe placeofitscentraladministrationintheEEA
23. Recital36GDPRisusefulinclarifyingthemainfactorthatshallbeusedtodetermineacontrollers mainestablishmentifthecriterionofthecentraladministrationdoesnotapply.Thisinvolves identifyingwheretheeffectiveandrealexerciseofmanagementactivities,thatdeterminethemain decisionsastothepurposesandmeansofprocessingthroughstablearrangements,takesplace. Recital36GDPRalsoclarifiesthat thepresenceanduseoftechnicalmeansandtechnologiesfor processingpersonaldataorprocessingactivitiesdonot,inthemselves,constituteamainestablishment andarethereforenotdeterminingcriteriaforamainestablishment.
Thecontrolleritselfidentifieswhereitsmainestablishmentisandthereforewhichsupervisory authorityisitsleadsupervisoryauthority.However,thiscanbechallengedbytherespective supervisoryauthorityconcernedafterwards.
Thefactorsbelowareusefulfordeterminingthelocationofacontrollersmainestablishment, accordingtothetermsoftheGDPR,incaseswhereitisnotthelocationofitscentraladministration intheEEA.
o Wherearedecisionsaboutthepurposesandmeansoftheprocessinggivenfinalsignoff?
o Wherearedecisionsaboutbusinessactivitiesthatinvolvedataprocessingmade?
o Wheredoesthepowertohavedecisionsimplementedeffectivelylie?
o WhereistheDirector(orDirectors)withoverallmanagementresponsibilityforthecrossborder processinglocated?
o Whereisthecontrollerorprocessorregisteredasacompany,ifinasingleterritory?
Notethatthisisnotanexhaustivelist.Otherfactorsmayberelevantdependingonthecontrolleror processingactivityinquestion.Ifasupervisoryauthorityhasreasonstodoubtthattheestablishment
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/9341112779cff363be63b631f7d88324.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/ea5da4c3827eec2f3e88263dab4db3d7.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/fe9c5831ba333e7fdc8a65d53ec6d584.jpeg)
Inthecontextofprocessingpersonaldataforbankingpurposes,theEDPBrecognisesthattherearemany differentpurposespursuedbytheseprocessingactivities.However,tosimplifymatters,theEDPBaddressesall ofthemasasinglepurpose.Thesameistrueofprocessingdoneforinsurancepurposes
ItshouldberecalledalsothattheGDPRprovidesforthepossibilityoflocaloversightinspecificcases.See Recital127: Eachsupervisoryauthoritynotactingastheleadsupervisoryauthorityshouldbecompetentto handlelocalcaseswherethecontrollerorprocessorisestablishedinmorethanoneMemberState,butthe subjectmatterofthespecificprocessingconcernsonlyprocessingcarriedoutinasingleMemberStateand involvesonlydatasubjectsinthatsingleMemberState,forexample,wherethesubjectmatterconcernsthe processingofemployees'personaldatainthespecificemploymentcontextofaMemberState. Thisprinciple meansthatthesupervisionofHRdataconnectedtothelocalemploymentcontextcouldfallonseveral supervisoryauthorities.
identifiedbythecontrollerisinrealitythemainestablishmentforthepurposesoftheGDPR,itcan ofcourserequirethecontrollertoprovidetheadditionalinformationnecessaryforittoprovewhere itsmainestablishmentislocated.
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/30eda5d24cb42a0d1b5c37cd964ccfe9.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/d955a91008a67e608e660e5aaefa2795.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/6d6818a604c1960d23f3b3446a248b61.jpeg)
2.1.2Groupsofundertakings
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/86e753962c816d9348557d1860fc1583.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/d9009bd845387ea218c284a476fb815e.jpeg)
establishmentforthegroup,exceptwheredecisionsaboutthepurposesandmeansofprocessingare takenbyanotherestablishment.Theparent,oroperationalheadquartersofthegroupofundertakings intheEEA,islikelytobethemainestablishment,becausethatwouldbetheplaceofitscentral administration.
carriedout,lieswithinthecompanysheadquarters.Insuchcases,determiningthelocationofthe mainestablishmentandthereforewhichsupervisoryauthorityistheleadsupervisoryauthorityis straightforward.However,thedecisionsystemofgroupofcompaniescouldbemorecomplex,giving independentmakingpowersrelatingtocrossborderprocessingtodifferentestablishments.The criteriasetoutaboveshouldhelpgroupsofundertakingstoidentifytheirmainestablishment.
34. ThenotionofmainestablishmentislinkedbyvirtueoftheGDPRtoasinglecontrollerandcannotbe extendedtoajointcontrollershipsituation.Thisiswithoutprejudicetothepossibilityforeachjoint controllertohaveitsownmainestablishment.Inotherwords,themainestablishmentofacontroller cannotbeconsideredasthemainestablishmentofthejointcontrollersfortheprocessingcarriedout undertheirjointcontrol.Therefore,jointcontrollerscannotdesignate(amongtheestablishments wheredecisionsonthepurposesandmeansoftheprocessingaretaken)acommonmain establishmentforbothjointcontrollers.
2.2 Borderlinecases
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/f6aebb6c633fb3464d9d7c1956baa45b.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/d86165bfd4814996ff7c269a72f3c991.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/9b82bdfcd97672c94d7c1e2c4fb64666.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/1f722b35d67f82f6ca86a66e133d93fe.jpeg)
35. Therewillbeborderlineandcomplexsituationswhereitisdifficulttoidentifythemainestablishment ortodeterminewheredecisionsaboutdataprocessingaretaken.Thismightbethecasewherethere iscrossborderprocessingactivityandthecontrollerisestablishedinseveralMemberStates,butthere isnocentraladministrationintheEEAandnoneoftheEEAestablishmentsaretakingdecisionsabout theprocessing(i.e.decisionsaretakenexclusivelyoutsideoftheEEA).
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/c8f0bda8d132164e35def5ee7509f04e.jpeg)
36. Inthecaseabove,thecompanycarryingoutcrossborderprocessingmaybekeentoberegulatedby aleadsupervisoryauthoritytobenefitfromtheonestopshopprinciple.However,theGDPRdoesnot provideasolutionforsituationslikethis.Inthesecircumstances,thecompanyshoulddesignatethe establishmentthathastheauthoritytoimplementdecisionsabouttheprocessingactivityandtotake liabilityfortheprocessing,includinghavingsufficientassets,asitsmainestablishment.Ifthecompany doesnotdesignateamainestablishmentinthisway,itwillnotbepossibletodesignatealead supervisoryauthority.Supervisoryauthoritieswillalwaysbeabletoinvestigatefurtherwherethisis appropriate.
37. TheGDPRdoesnotpermitforumshopping.Ifacompanyclaimstohaveitsmainestablishmentin oneMemberState,butnoeffectiveandrealexerciseofmanagementactivityordecisionmakingover theprocessingofpersonaldatatakesplacethere,therelevantsupervisoryauthorities(orultimately theEDPB12)willdecidewhichsupervisoryauthorityisthelead,usingobjectivecriteriaandlookingat theevidence.Theprocessofdeterminingwherethemainestablishmentismayrequireactiveinquiry andcooperationbythesupervisoryauthorities.Conclusionscannotbebasedsolelyonstatementsby theorganisationunderreview.Theburdenofproofultimatelyfallsoncontrollersandprocessorsto demonstratetotherelevantsupervisoryauthoritieswheretherelevantprocessingdecisionsaretaken andwherethereisthepowertoimplementsuchdecisions.Effectiverecordsofdataprocessingactivity wouldhelpbothorganisationsandsupervisoryauthoritiestodeterminetheleadsupervisory authority.Theleadsupervisoryauthority,orconcernedsupervisoryauthorities,canrebutthe controllersanalysisbasedonanobjectiveexaminationoftherelevantfacts,requestingfurther informationwhererequired.
38. Insomecases,therelevantsupervisoryauthoritieswillaskthecontrollertoprovideclearevidence,in linewithanyEDPBguidelines,ofwhereitsmainestablishmentis,orwheredecisionsaboutaparticular dataprocessingactivityaretaken.Thisevidencewillbegivendueweightandthesupervisory authoritiesinvolvedwillcooperatetodecidewhichoneofthemwilltaketheleadininvestigations. SuchcaseswillonlybereferredtotheEDPBforadecisionunderArticle65(1)(b)GDPRwhere supervisoryauthoritieshaveconflictingviewsintermsofidentifyingtheleadsupervisoryauthority. However,inmostcases,theEDPBexpectsthattherelevantsupervisoryauthoritieswillbeableto agreeamutuallysatisfactorycourseofaction.
Processor
39. TheGDPRalsoofferstheonestopshopsystemforthebenefitofprocessorsthataresubjecttoGDPR andhaveestablishmentsinmorethanoneMemberState.
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/51defa46e4e83cda5484a1eec9cfc037.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/453a04d5524ef5db9c5f2263f6dd4a39.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/9d1f7ef4d924acc53c412e2e2176cb00.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/91b9ed1f035cd7e5b75e81f892248f93.jpeg)
40. Article4(16)(b)GDPRstatesthattheprocessorsmainestablishmentwillbetheplaceofthecentral administrationoftheprocessorintheEUor,ifthereisnocentraladministrationintheEU,the establishmentintheEUwherethemainprocessing(processor)activitiestakeplace.
41. However,accordingtoRecital36GDPR,incasesinvolvingbothacontrollerandaprocessor,the competentleadsupervisoryauthorityshouldbetheleadsupervisoryauthorityforthecontroller.In thissituation,thesupervisoryauthorityoftheprocessorwillbeasupervisoryauthorityconcerned andshouldparticipateinthecooperationprocedure.Thisrulewillonlyapplywherethecontrolleris establishedintheEEAIncaseswherecontrollersaresubjecttotheGDPRonthebasisofitsArticle 3(2),theywillnotbesubjecttotheonestopshopmechanism.Aprocessorforexample,alargecloud serviceprovidermayprovideservicestomultiplecontrollerslocatedindifferentMemberStates.In suchcases,theleadsupervisoryauthoritywillbethesupervisoryauthoritythatiscompetenttoactas leadforthecontroller.Ineffect,thismeansaprocessormayhavetodealwithmultiplesupervisory authorities.
3OTHERRELEVANTISSUES
3.1 Theroleofthesupervisoryauthorityconcerned
42. GDPRArticle4(22)saysthatthe:
supervisoryauthorityconcernedmeansasupervisoryauthoritywhichisconcernedbythe processingofpersonaldatabecause:(a)thecontrollerorprocessorisestablishedontheterritory oftheMemberStateofthatsupervisoryauthority;(b)datasubjectsresidingintheMemberState ofthatsupervisoryauthorityaresubstantiallyaffectedorlikelytobesubstantiallyaffectedbythe processing;or(c)acomplainthasbeenlodgedwiththatsupervisoryauthority.
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/4499eca8981e1527a0f0c7a6852fa4be.jpeg)
43. Theconceptofaconcernedsupervisoryauthorityismeanttoensurethattheleadsupervisory authoritymodeldoesnotpreventothersupervisoryauthoritieshavingasayinhowamatterisdealt withwhen,forexample,individualsresidingoutsidetheleadsupervisoryauthoritysjurisdictionare substantiallyaffectedbyadataprocessingactivity.Intermsoffactor(a)above,thesame considerationsasforidentifyingaleadsupervisoryauthorityapply.Notethatin(b)thedatasubject mustmerelyresideintheMemberStateinquestion;theydonothavetobeacitizenofthatState.It willgenerallybeeasyin(c)todetermineasamatteroffactwhetheraparticularsupervisory authorityhasreceivedacomplaint.
44. Article56,paragraphs(2)and(5)GDPRprovideforaconcernedsupervisoryauthoritytotakearolein dealingwithacasewithoutbeingtheleadsupervisoryauthority.Whenaleadsupervisoryauthority decidesnottohandleacase,theconcernedsupervisoryauthoritythatinformedtheleadsupervisory authorityshallhandleit.ThisisinaccordancewiththeproceduresinArticle61(Mutualassistance) andArticle62(Jointoperationsofsupervisoryauthorities)GDPR.Thismightbethecasewherea marketingcompanywithitsmainestablishmentinParislaunchesaproductthatonlyaffectsdata subjectsresidinginPortugal.Insuchacase,theFrenchandPortuguesesupervisoryauthoritiesmight agreethatitisappropriateforthePortuguesesupervisoryauthoritytotaketheleadindealingwith thematter.Supervisoryauthoritiesmayrequestthatcontrollersprovideinputintermsofclarifying theircorporatearrangements.Giventhattheprocessingactivityhasapurelylocaleffecti.e.on
individualsinPortugaltheFrenchandPortuguesesupervisoryauthoritieshavethediscretionto decidewhichsupervisoryauthorityshoulddealwiththematterinaccordancewithRecital127GDPR
45. TheGDPRrequiresleadandconcernedsupervisoryauthoritiestocooperate,withduerespectfor eachothersviews,toensureamatterisinvestigatedandresolvedtoeachauthorityssatisfaction andwithaneffectiveremedyfordatasubjects.Supervisoryauthoritiesshouldendeavourtoreacha mutuallyacceptablecourseofaction.Theformalconsistencymechanismshouldonlybeinvoked wherecooperationdoesnotreachamutuallyacceptableoutcome.
46. Themutualacceptanceofdecisionscanapplytosubstantiveconclusions,butalsotothecourseof actiondecidedupon,includingenforcementactivity(e.g.fullinvestigationoraninvestigationwith limitedscope).ItcanalsoapplytoadecisionnottohandleacaseinaccordancewiththeGDPR,for examplebecauseofaformalpolicyofprioritisation,orbecausethereareotherconcernedauthorities asdescribedabove.
47. Thedevelopmentofconsensusandgoodwillbetweensupervisoryauthoritiesisessentialtothe successoftheGDPRscooperationandconsistencyprocedures
3.2 Localprocessing
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/51defa46e4e83cda5484a1eec9cfc037.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/453a04d5524ef5db9c5f2263f6dd4a39.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/24ab2c21ac7486886d7e423c0f896753.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/994c372392e0dd91cea36994017e0748.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/27dd14d5f1da0caa8196793299fe641b.jpeg)
48. LocaldataprocessingactivitydoesnotfallwithintheGDPRscooperationandconsistencyprovisions. Supervisoryauthoritieswillrespecteachotherscompetencetodealwithlocaldataprocessingactivity onalocalbasis.Processingcarriedoutbypublicauthoritieswillalwaysbedealtwithonalocalbasis, too.
3.3 CompaniesnotestablishedwithintheEEA
49. TheGDPRscooperationandconsistencymechanismsonlyapplytocontrollerswithanestablishment, orestablishments,withintheEEA.IfacompanydoesnothaveanestablishmentintheEEA,themere presenceofarepresentativeinaMemberStatedoesnottriggertheonestopshopprinciple.This meansthatcontrollerswithoutanyestablishmentintheEEAmustdealwithlocalsupervisory authoritiesineveryMemberStatetheyareactivein,throughtheirlocalrepresentative.
FortheEuropeanDataProtectionBoard
TheChair (AndreaJelinek)
inmorethanoneMemberState.
orprocessorssingleestablishmentintheEEA,but:
State.
establishmentinasingleMemberState.Thisisbylogicthecontrollerorprocessorsmain establishmentbecauseitisitsonlyestablishment.
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/2e3792ab528c29d0c8c2683c78aac388.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/de84c327194198bb6ddd42edee7cec6a.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/9cbaf97e806e1d68875dfb07db79374f.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/994c372392e0dd91cea36994017e0748.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/27dd14d5f1da0caa8196793299fe641b.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/91b9ed1f035cd7e5b75e81f892248f93.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/9d1f7ef4d924acc53c412e2e2176cb00.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/4499eca8981e1527a0f0c7a6852fa4be.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/453a04d5524ef5db9c5f2263f6dd4a39.jpeg)
![](https://assets.isu.pub/document-structure/221031055107-23615f13197235b807cedf0588b58d03/v1/51defa46e4e83cda5484a1eec9cfc037.jpeg)