Cross-border processing
Cross-border processing means either the processing of personal data that takes place in the context of the activities of establishments in more than one Member State of a controller or processor established in more than one Member State, or processing that takes place in the context of the activities of a single establishment but substantially affects, or is likely to substantially affect, data subjects in more than one Member State (Art. 4(23) GDPR).
The concept is the trigger for the one-stop-shop mechanism under Art. 56: an organisation engaged in cross-border processing deals primarily with the supervisory authority of its main establishment as lead authority, which coordinates with the other concerned authorities through the cooperation and consistency procedures of Chapter VII.
A multinational sponsor running a trial in several EU countries from an Irish or Dutch headquarters is a typical case. Note that cross-border processing is a different concept from an international data transfer to a third country under Chapter V: the former concerns where processing happens within the EU and which regulator is competent, the latter concerns data leaving the EEA. Organisations with no EU establishment cannot benefit from the one-stop shop and remain subject to every concerned authority, which is one reason to appoint a Data Protection Representative and to centralise EU compliance.
