This guide helps decide whether GDPR one-stop-shop routing is available, which establishment anchors the lead supervisory authority, and what evidence should support that position.
Focused on main establishment, cross-border processing, Article 56 competence, Article 60 cooperation, and evidence records that avoid unsupported national-procedure assumptions.
Use the GDPR only for cross-border processing carried out by a controller or processor with a qualifying main establishment or single establishment in the Union. The organisation cannot choose its regulator. It must identify the processing-specific decision-making establishment, document why Article 56 points to that supervisory authority, identify the other supervisory authorities concerned, and prepare for the Article 60 cooperation procedure.
1
Section 1
When GDPR one-stop-shop routing is available
Start with the processing activity, not the corporate group. GDPR Article 4(23) treats processing as cross-border when it is carried out in the context of establishments in more than one Member State, or when processing in one Member State substantially affects or is likely to substantially affect data subjects in more than one Member State.
Article 56 connects that cross-border processing to the supervisory authority of the controller's or processor's main establishment or single establishment. A company subject to the GDPR only because Article 3(2) applies, but with no establishment in the Union, cannot use an Article 27 representative to create a main establishment and does not receive routing.
Article 55(2) is another limit: Article 56 does not apply when public authorities process personal data or when private bodies process it on the basis of Article 6(1)(c) or (e). The supervisory authority of the Member State concerned is competent for that processing.
Identify the specific processing operation, product, data flow, or incident before naming a lead authority.
Record each Union establishment involved in deciding or carrying out the processing.
Separate cross-border processing evidence from unrelated multinational presence.
List Member States where data subjects are substantially affected or likely to be substantially affected.
Stop the analysis if there is no qualifying Union establishment or Article 55(2) applies; then identify the competent national authority or authorities for the actual processing.
For a controller with establishments in more than one Member State, GDPR Article 4(16) points first to the place of central administration in the Union. That changes if decisions on the purposes and means of the processing are taken in another Union establishment and that establishment has power to implement those decisions.
The central-administration presumption depends on that establishment making the decisions on the purposes and means of the processing and having power to implement them. If those decisions are taken outside the Union and no Union establishment takes and can implement them, the controller has no main establishment in the Union for that processing. Formal designation, headquarters paperwork, or a convenient contact point does not supply the missing decision-making facts.
For a processor with establishments in more than one Member State, the main establishment is its central administration in the Union. If there is no central administration in the Union, Article 4(16) points to the Union establishment where the processor's main processing activities take place, to the extent the processor is subject to specific GDPR obligations. A controller and its processor must each assess their own role and establishment facts.
Keep signed governance records, decision minutes, reporting lines, role descriptions, and approvals showing where purposes and means are decided for this processing activity.
Keep implementation evidence showing that the same establishment can direct and secure implementation across the relevant Union establishments.
For processors, document the Union central administration or the Union establishment carrying out the main processing activities.
Do not treat a sales office, representative, group headquarters, or local contact point as the main establishment unless the Article 4(16) facts support it.
Reassess the position when decision rights, reporting lines, establishments, processing purposes, or implementation power change.
Article 56(1) makes the supervisory authority of the main establishment or single establishment competent to act as lead supervisory authority for cross-border processing, using the Article 60 cooperation procedure.
Article 56 also preserves local competence for complaints or possible infringements that relate only to an establishment in one Member State or substantially affect data subjects only in that Member State. In those cases, the local supervisory authority informs the lead authority, and the lead authority has three weeks to decide whether it will handle the case under Article 60. A lead authority is therefore not exclusive for every GDPR issue involving the organisation.
Record the proposed lead supervisory authority and the Article 4(16) facts supporting it.
Identify supervisory authorities concerned because a controller or processor is established in their Member State, data subjects there are substantially affected or likely to be substantially affected, or a complaint was lodged there.
When Article 56(2) may apply, preserve the local-establishment or local-effect facts separately from the lead-authority analysis.
If the lead supervisory authority handles an Article 56(2) matter, Article 60 applies; if it declines, the local supervisory authority handles that matter under Articles 61 and 62.
Treat the proposed authority as a reasoned position, not a self-certified outcome; supervisory authorities can examine and dispute the establishment facts.
Article 60 is a cooperation procedure between the lead supervisory authority and the other supervisory authorities concerned. The lead authority must exchange relevant information, submit draft decisions for opinion, and take the views of concerned authorities into account.
A concerned authority has four weeks to make a relevant and reasoned objection to the first draft decision and two weeks for a revised draft. If the lead authority does not follow an objection it considers relevant and reasoned, the matter goes to the consistency mechanism. Those periods are authority-to-authority steps, not a promised deadline for resolving the whole case.
The record should anticipate more than one authority's involvement. Preserve the facts, establishments, affected Member States, complaint locations, processing descriptions, and compliance measures needed for the draft-decision process and implementation across Union establishments.
Maintain a single processing fact record that can be shared consistently across concerned authorities.
Track which establishments and Member States the decision would cover.
Record remedial measures in a form that can be implemented across all relevant Union establishments.
Track draft decisions, concerned-authority views, objections, revisions, final notices, and measures taken to comply.
Do not promise a fixed Article 60 case timeline; the GDPR specifies objection periods but no single end-to-end duration.
Use this checklist when opening a new market, changing a processing model, responding to a complaint, or preparing a breach route for cross-border processing. It records an auditable lead-authority position without adding unsupported national-procedure claims.
If a fact is uncertain, mark it as unresolved instead of selecting a convenient authority. Name the missing governance, establishment, affected-data-subject, public-authority, lawful-basis, or complaint-location evidence and assign an owner to obtain it.
Does having customers in several EU Member States automatically create a GDPR lead supervisory authority?
No. Customer location alone does not identify a lead authority. The processing must meet Article 4(23)'s cross-border test, and Article 56 must attach that processing to a qualifying main establishment or single establishment in the Union.
Can the company choose the most convenient supervisory authority?
No. The lead supervisory authority follows the GDPR facts: the main establishment or single establishment for the relevant cross-border processing, subject to Article 56 mechanics.
What should be saved as evidence?
Save the processing description, controller or processor role, Union establishment map, decision and implementation records, Article 4(16) main-establishment analysis, Article 4(23) cross-border-processing analysis, Article 55(2) exclusion check, concerned-authority list, complaint locations, and Article 60 cooperation records.
Does an EU representative give a non-EU controller access to the ?
No. An Article 27 representative is distinct from an establishment and does not create a main establishment. If a controller has no establishment in the Union, it cannot obtain routing through its representative, even when Article 3(2) makes the GDPR applicable.
Processing operation is described with controller or processor role, establishments involved, and affected data-subject Member States.
Cross-border processing analysis is tied to Article 4(23), not only to customer geography or group structure.
Main establishment analysis is tied to Article 4(16) facts about central administration, purpose-and-means decisions, implementation power, or processor main processing activities.
Exclusion check confirms that a qualifying Union establishment exists and that Article 55(2) does not remove the processing from Article 56.
Lead supervisory authority, concerned supervisory authorities, and any Article 56(2) local-case facts are recorded separately.
Article 60 evidence pack includes facts, measures, decision owners, affected establishments, and implementation records for all relevant Union establishments.
Sorena can help turn the Article 4, Article 56, and Article 60 checks on this page into owner assignments, evidence requests, and reusable regulator-routing records.
EDPB opinion explaining that a controller's Union central administration qualifies only when it makes decisions on purposes and means and can have them implemented, and that the controller bears the burden of proving the relevant facts.