Overview —
Who Enforces GDPR?
GDPR is enforced by EU Data Protection Authorities, coordinated by the EDPB to ensure consistent compliance.
Share this article
Who Enforces GDPR?
GDPR is enforced by independent Data Protection Authorities, one in each EU/EEA country — over 30 of them across the network, since some countries like Germany have multiple authorities at the federal and state level. But here's the part most summaries skip: if your company operates in more than one EU country, you don't actually have to deal with all of them. There's a mechanism built specifically to prevent that headache.
What DPAs Actually Do
Each DPA can investigate complaints, run audits, issue fines, and offer compliance guidance. They also coordinate with each other on cross-border cases — which matters a lot once you're operating in more than one country, because that coordination is structured, not informal.
The One-Stop-Shop: Your Real Point of Contact
If your company processes data across multiple EU member states, you generally deal with just one DPA — your "lead supervisory authority," based on wherever your main EU establishment is. That single authority takes the lead on investigations and coordinates with the other countries' DPAs (called "concerned supervisory authorities") rather than you having to respond to each one separately.
Here's how it actually works in practice: your lead authority drafts a decision, shares it with the other relevant DPAs, and if nobody objects, that's the final answer. If DPAs disagree, the case escalates to the European Data Protection Board for a binding resolution. This is a real, structured process — not just "DPAs are nice and cooperate."
One important exception: this one-stop-shop setup doesn't apply if you're a public authority or a private body acting in the public interest. In that case, you only ever deal with your own country's DPA, no matter how many EU countries your processing actually touches.
The European Data Protection Board's Real Role
The EDPB isn't an enforcement body itself — it doesn't fine anyone directly. Its job is keeping enforcement consistent across all the different DPAs, issuing guidance everyone's supposed to follow, and resolving disputes when DPAs can't agree on a cross-border case. Without it, you could end up with conflicting decisions about the exact same processing activity from different countries — which is exactly the inconsistency the one-stop-shop mechanism is designed to prevent.
The Scale of Actual Enforcement
This isn't theoretical. Between May 2018 and early 2026, DPAs collectively issued roughly €7.1 billion in GDPR fines. That number keeps climbing every year — enforcement has gotten more active over time, not less, as DPAs get more resourced and coordinated.
What This Means If You Operate Across Borders
Knowing who your lead supervisory authority actually is — not just "the EU" in some vague sense — matters before anything goes wrong, not after. It determines who you're actually building a relationship with, whose guidance carries the most direct weight for your compliance program, and who you'd be dealing with first if a complaint or investigation comes in. Companies that figure this out only after a problem starts are already behind.
Where This Connects to Other Frameworks
Building consistent governance across jurisdictions matters just as much for ISO 27001 and SOC 2 as it does for GDPR — both expect a coherent program, not patchwork compliance that varies by country. Once you know who your lead DPA is and what they expect, that same governance structure usually does double duty for the other frameworks too.
FAQs
Who enforces GDPR? GDPR is enforced by independent Data Protection Authorities (DPAs), with over 30 across the EU/EEA network — one per country, though some countries like Germany have multiple authorities at the federal and state level. Each DPA can investigate complaints, run audits, issue fines, and provide compliance guidance.
What is a "lead supervisory authority" under GDPR? It's the single DPA responsible for coordinating enforcement when a company processes data across multiple EU member states, based on the location of the company's main EU establishment. This lead authority takes charge of investigations and coordinates with other countries' DPAs, so companies don't have to respond to each one separately.
Do companies operating in multiple EU countries have to deal with every country's DPA? Generally no. Under the "one-stop-shop" mechanism, companies deal primarily with their lead supervisory authority, which coordinates with "concerned supervisory authorities" in other relevant countries. This structured process prevents companies from having to manage separate investigations in every jurisdiction where they operate.
How does the GDPR one-stop-shop mechanism actually work? The lead authority drafts a decision and shares it with other relevant DPAs. If none object, that becomes the final decision. If DPAs disagree, the case escalates to the European Data Protection Board (EDPB) for a binding resolution — a defined process rather than informal cooperation.
Are there exceptions to the one-stop-shop mechanism? Yes. Public authorities and private bodies acting in the public interest don't benefit from the one-stop-shop system. These entities deal only with their own country's DPA, regardless of how many EU countries their data processing actually touches.
What does the European Data Protection Board (EDPB) actually do? The EDPB doesn't issue fines or enforce GDPR directly. Its role is maintaining consistency across DPAs — issuing binding guidance, resolving disputes when DPAs disagree on cross-border cases, and preventing conflicting rulings on the same processing activity across different countries.
How much has been issued in GDPR fines since it took effect? Between May 2018 and early 2026, DPAs collectively issued roughly €7.1 billion in GDPR fines. Enforcement activity has increased over time as DPAs have become better resourced and more coordinated, rather than tapering off.
How do I know which DPA is my company's lead supervisory authority? Your lead supervisory authority is generally determined by the location of your organization's main EU establishment — typically where key decisions about data processing purposes and means are made. Identifying this proactively matters, since it determines who leads any investigation and whose guidance most directly shapes your compliance obligations.
Why does it matter which DPA regulates my company before a problem arises? Knowing your lead authority in advance means you understand whose guidance carries the most weight for your compliance program and who would lead any investigation or complaint response. Companies that only identify this after an issue starts are already at a disadvantage in managing the process.
Does GDPR enforcement structure relate to other compliance frameworks like ISO 27001 or SOC 2? Yes. Both ISO 27001 and SOC 2 expect coherent, consistent governance across jurisdictions rather than fragmented, country-by-country compliance. The same governance structure built around understanding your lead DPA and its expectations typically supports compliance efforts for these other frameworks as well.
In the Spotlight
Start your GDPR compliance journey with DSALTA's complete checklist.
The General Data Protection Regulation (GDPR) is Europe’s core privacy law, shaping how organizations collect, process, and protect the personal data of EU residents. Non-compliance can result in heavy fines, reputational damage, and loss of customer trust.
GDPR can feel complicated with its broad scope and strict requirements, but DSALTA® makes it manageable. With automated evidence collection, continuous monitoring, and AI- driven risk insights, you can maintain compliance without drowning in manual work. Use this checklist to guide your GDPR journey.
Read more about GDPR compliance with DSALTA.
Stop losing deals to compliance.
Get compliant. Keep building.
Join 100s of startups who got audit-ready in days, not months.




