The classic trap
Recital 117 establishes a founding principle: the independence of supervisory authorities. In practice, many organisations underestimate what this entails: the Luxembourg CNPD is not a mere administrative contact, it holds investigation, correction and sanction powers that it exercises without receiving instructions from any government or other actor. The classic trap consists in believing that ministerial lobbying or a political argument can influence an ongoing procedure, or in presuming that the French CNIL would have jurisdiction over a Luxembourg-based processing operation.
Mapping your competent authorities: a more subtle exercise than it seems
The independence of authorities combined with the possibility for a Member State to designate several (see Germany with one authority per Land) requires a rigorous mapping:
- Identify your lead supervisory authority per article 56 (main establishment in the EU).
- List the concerned authorities in each country where you have data subjects or a secondary establishment.
- Distinguish GDPR authorities (CNPD, CNIL, APD/GBA) from sectoral authorities (CSSF for finance in Luxembourg, ILR for telecoms, ILNAS for digital trust).
- Anticipate the cooperation mechanism (article 60) and consistency mechanism (article 63): a complaint filed in Paris can escalate to the CNPD as lead authority.
- Document operational contact points (DPO contact, breach notification form, average response times) for each relevant authority.
How Luxgap automates this risk
Our Luxgap Authority Compass turns the jungle of European authorities into a living map that designates, in real time, who to contact, within which deadline and with which form, for each processing operation and each scenario (breach, complaint, advice request, prior consultation). The tool combines your article 30 register, the geolocation of your data subjects detected in your systems (CRM, ERP, M365 Entra ID) and the up-to-date EDPB database of territorial and sectoral competences to produce an enforceable matrix.
- Automatically detects your main establishment within the meaning of article 4(16) by analysing your real processing decisions (Azure logs, Odoo, Salesforce) and not your statutory declarations.
- Calculates for each processing the exhaustive list of concerned authorities and designates the lead authority with written justification.
- Pre-fills breach notification forms (CNPD, CNIL, APD/GBA, BfDI, Garante) with your register data, respecting the linguistic and technical specificities of each portal.
- Alerts on jurisdiction changes (reorganisation, opening of a subsidiary, hosting migration) that would alter your lead authority.
- Generates a timestamped PDF report, enforceable during a CNPD audit, demonstrating that you have identified and documented your competent authorities in line with articles 55 to 60.
Available as a complement to a Luxgap DPO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real mapping, with a free 48-hour blank audit to validate your current lead authorities before any commitment.