One-stop-shop mechanism and lead supervisory authority
The one-stop-shop mechanism is the system under which a controller or processor engaged in cross-border processing within the EU deals primarily with one supervisory authority, the lead supervisory authority, which is the authority of the Member State where the organisation has its main establishment or its single establishment (Art. 56(1) GDPR). The lead authority is the sole interlocutor for that processing and coordinates its decisions with the other authorities concerned under the cooperation procedure of Art. 60.
Concerned supervisory authorities are those in Member States where the organisation has other establishments, where data subjects are substantially affected, or where a complaint was lodged (Art. 4(22)). The lead authority prepares a draft decision, the concerned authorities may raise relevant and reasoned objections, and unresolved disputes are settled by a binding decision of the EDPB under the consistency mechanism (Art. 65), as in the Meta, WhatsApp and TikTok cases handled by the Irish Data Protection Commission. Exceptions allow a local authority to handle purely local cases (Art. 56(2)) and urgent measures (Art. 66). The 2025 GDPR procedural regulation aims to streamline cross-border enforcement.
The mechanism only benefits organisations with an establishment in the EU. A sponsor or HealthTech company established solely outside the Union, even one that has appointed an Art. 27 Data Protection Representative, has no lead authority and is subject to the jurisdiction of every supervisory authority in whose territory it processes data, which multiplies regulatory exposure across the Member States where it recruits patients or has users. Groups with an EU headquarters should therefore document their main establishment carefully, since the choice of lead authority determines the regulator, the language and the enforcement culture they will face. Note that the one-stop shop does not extend to the UK or Switzerland.
