Without prejudice to other tasks set out under this Regulation, each supervisory authority shall on its territory: … handle complaints lodged by a data subject, or by a body, organisation or association in accordance with Article 80, and investigate, to the extent appropriate, the subject matter of the complaint and inform the complainant of the progress and the outcome of the investigation within a reasonable period, in particular if further investigation or coordination with another supervisory authority is necessary.
Article 57(1)(f) of the GDPR
Supervision of data controllers and data processors is central to the GDPR architecture: DPAs are obliged to handle every complaint lodged with their authority. Some DPAs emphasised that they consider their role to be primarily a supervisory one, and that providing advice should come second – that is, depending on the human, financial and time resources remaining once supervisory duties have been performed. The ability to conduct thorough investigations is a practical precondition to ensure supervision is conducted exhaustively and rigorously. Investigations can be conducted on the DPA’s own initiative (as per Article 57(1)(h) of the GDPR) or following a complaint (as per Article 57(1)(f) of the GDPR). In all cases, DPA experts must be provided with:
- full access to all necessary information (notably, as per Article 30(4) of the GDPR, data controllers and data processors must make records of processing activities available to DPAs upon request);
- the full cooperation of the investigated party in terms of all necessary explanation on the data processing under investigation – as per Article 31 of the GDPR.
More specifically, investigative powers listed in Article 58 of the GDPR include the power to:
- order the controller and the processor to provide any information the DPA requires;
- carry out investigations in the form of data protection audits;
- carry out a review of certifications issued pursuant to Article 42(7);
- notify the controller or the processor of an alleged infringement of the GDPR;
- obtain from the controller and the processor access to all personal data and all information necessary for the DPA to complete its tasks;
- obtain access to any premises of the controller and the processor, including access to any data processing equipment and means.
Given that supervision is a major part of the DPA mandate, several interviewees emphasised how most of their resources are used to handle complaints, to the detriment of other tasks, as discussed in Section 1.1 of this report. Here again, several respondents stressed that the lack of resources was having a negative impact not only on the overall work DPAs can perform, but also on the ultimate objective of ensuring safe processing for personal data upstream.
It would be effective to deal with preventative work; in that way, awareness would be higher and then there should be fewer complaints coming in. We are dealing with trees, instead of the forest.
An EU DPA staff member
Several interviewees highlighted the importance of sanctions in the new supervisory architecture implemented under the GDPR. They feel that the sharp increase in the number of sanctions has led private companies to ‘take data protection seriously’, despite some respondents stating that litigation should always be considered as a last resort, even in cases where a complaint was submitted to them.
The increased level of sanctions is a big change from the 1995 directive to the regulation. This has escalated to the degree to which data protection is taken seriously. Before, the DPA usually had conversations with lower ranking IT staff members, whereas now the DPA meets with the directors of the companies and lawyers.
An EU DPA staff member
When questioned on their experiences and challenges related to the supervisory aspect of their mandate, a large majority of interviewees agreed that the GDPR, on a general basis, provides adequate tools. However, several of them highlighted some critical issues that undermine their overall ability to exercise their investigative powers. Investigating potential data protection breaches remains a complex exercise, and some respondents highlighted that some powers that would help DPAs to conduct their investigations are still missing.
Article 62 of the GDPR allows DPAs to conduct joint operations involving two or more EU DPAs, either joint investigations or joint enforcement measures. For a joint operation to take place, certain conditions need to be fulfilled. Five joint operations were initiated between 2018 and 2023, according to the EDPB’s annual reports [74]
EDPB, Annual Report 2021, 2022, p. 66; EDPB, Annual Report 2020, 2021, pp. 55 and 68; and EPDB, Annual Report 2019, 2020, pp. 29 and 31.
and its contribution to the report on the application of the GDPR under Article 97 [75]
EDPB, Contribution of the EDPB to the report on the application of the GDPR under Article 97, 2023.
.
Joint operations could be a useful tool for DPAs to strengthen mutual learning and understanding of the application of the GDPR, according to some interviewees. A couple of respondents argued that since joint operations are not an established practice, DPAs might not be inclined to resort to them.
Several respondents challenged the practical applicability of joint operations and pointed out five reasons why they are significantly underused.
- A large majority of interviewees claimed that effective implementation of joint operations, including joint investigations, would require the EU to harmonise administrative rules and procedures. At present, DPAs must follow national procedures, which are Member State specific. Procedural challenges may arise concerning admissibility of complaints, which range from formal handwritten or electronically signed submissions in some Member States to less formal email submissions in others. Different administrative deadlines to comply with, and differences in the procedural rights of the complainant, might also hinder effective coordination among DPAs. Generally, national laws do not often permit public officers from other countries or other authorities to participate in on-site inspections, due to confidentiality clauses and non-disclosure obligations.
Even among comparably similar national legal systems, these [joint operations] can be problematic.
An EU DPA staff member
- Multiple interviewees agreed that joint investigations are resource-intensive, in terms of both human and financial resources. They often concern complex cross-border cases, requiring specialist legal knowledge, or sometimes IT expertise. These resources are already under strain at most authorities, as Section 1.1 of this report highlights. Significant financial and staffing constraints do not allow for spare capacity for external endeavours, particularly if this involves redirecting legal or IT experts. One respondent reported an instance when a joint investigation was not initiated for these reasons, and added that there should be a special team of employees for joint investigations.
Speaking about joint investigations, the problem of lack of resources is relevant again. The DPA is a bit reluctant to initiate a joint investigation or participate therein, because such investigations will normally be needed for big cases, and they require a lot of resources. If the DPA joins one joint investigation, it might need to put on hold some national cases. This is something that can benefit more the large DPAs – with more resources.
An EU DPA staff member
If seven people work on investigations in the whole of the country and that is not enough to meet all [national] needs, then it is difficult or impossible to conduct joint investigations outside the country.
An EU DPA staff member
- The employment relationship between the lead DPA and the experts deployed from other DPAs remains unclear, according to one interviewee. National rules and practices might regulate the remuneration of external public officers and their secondment differently, and in the absence of a common approach a memorandum of understanding or other arrangements should be in place before undertaking joint operations.
- Some interviewees mentioned that identifying and using a common work language in joint operations was challenging. Language skills and knowledge might vary among DPA officers, and official documents might be available only in the national language. Interpretation and translation should be provided, although the language of the data subject should be used when delivering decisions.
It is possible to prepare and coordinate a document in English, but then it has to be translated into a national language and presented as a decision from one Member State’s authority. So something as simple as that can influence the decision to cooperate.
An EU DPA staff member
- Some interviewees claimed that there is an imbalance between relatively well-funded DPAs (that have the necessary resources to respond to cross-border cases without seeking the support of other DPAs) and DPAs with fewer resources (that might need support but might find it difficult to get involved because of a lack of resources).
From the perspective of a smaller data protection supervisory authority and a smaller EU Member State, I understand that for the supervisory authorities of Member States that have a much larger role, are bigger, have 10 times as many employees – joint investigations are probably not their priority when they have their own investigations in which they issue fines of hundreds of millions of euros. To put it in simple terms, these (joint investigations) are not high on their priority list. Perhaps they could assign a few employees to handle such cases as part of their activities, in order to enable smaller supervisory bodies, in terms of population and number of employees, to participate more promptly and adequately.
An EU DPA staff member
In addition to these practical difficulties, several interviewees argued that formal ways of cooperating under the GDPR do not lead to swift cooperation schemes, particularly in the framework of joint operations. Formal requirements combined with different interpretations of the GDPR risk prolonging the decision-making process in cross-border cases requiring an urgent response. Some interviewees considered that informal ways of cooperating can deliver better and more timely results. A few cooperation models have been tested in practice, as described in the boxes below.
Joint investigations are difficult in any case as every country is different, it has different companies, etc., so these investigations would never end if DPAs would do it jointly. In small groups it is doable; for example, the Baltic countries have a more similar culture and procedural rules.
An EU DPA staff member
Several interviewees referred to the DPAs’ commitment to fostering joint operations in cross-border cases, as expressed in the ‘Statement on enforcement cooperation’ in April 2022 [76]
EDPB, Statement on enforcement cooperation, 28 April 2022.
. Some suggested that the following could be further explored in the short term, with EDPB support:
- the identification of strategic priorities for cross-border cases when initiating joint operations;
- the collection of information on best practices from initiatives similar to joint operations;
- the development of an example of a joint investigation; the EDPB secretariat could take the initiative to conduct a joint investigation in a Member State to elaborate on the methodology for joint investigations and identify key procedural steps and resource needs;
- the development of training activities; the EDPB secretariat could facilitate training for all DPAs, to develop a common understanding and find a solution for practical issues in joint operations.
Most interviewees supported reform of the GDPR to set out a uniform procedure, binding at the EU level, that harmonises procedures and rules. A few interviewees underlined that ‘binding’ procedural mechanisms may be constitutionally challenging if, for instance, the supervisory authority from one Member State was able to conduct investigations in another Member State without the approval of its authorities.