Lead Supervisory Authority

The Lead-Supervisory-Authority (LSA) is a regulatory body established under the General-Data-Protection-Regulation (GDPR) to streamline the oversight of companies that engage in Cross-Border-Processing. This system is central to the One-Stop-Shop mechanism, which allows organizations to deal with a single primary regulator for their data protection activities across the European-Union.

Identification and Jurisdiction

According to GDPR Article 56, the Lead-Supervisory-Authority is determined by the location of the organization's Main-Establishment. This is typically where the Data-Controller or Data-Processor has its central administration, unless the decisions on the purposes and means of processing are taken elsewhere. The European-Data-Protection-Board (EDPB) provides specific Guidelines on the Lead Supervisory Authority to help businesses identify their relevant regulator.

Cooperation and Consistency

While the Lead-Supervisory-Authority leads investigations, it must coordinate with any Concerned-Supervisory-Authority (CSA). A CSA is an authority that has a stake in the processing because the controller is established in its territory or Data-Subjects in its territory are significantly affected. This collaborative approach is maintained through the Consistency-Mechanism to ensure uniform application of law across all member states.