Article 60 - Article 76

Cooperation, Consistency, Enforcement Governance, and Organisational Compliance — a practitioner's guide to Chapter VII of the GDPR.

Executive Overview

GDPR Articles 60–76 comprise Chapter VII of the GDPR and establish the governance architecture through which supervisory authorities cooperate, coordinate investigations, resolve disputes, and ensure consistent enforcement across the European Union. These provisions do not primarily regulate data processing itself; rather, they regulate the regulatory ecosystem that oversees controllers and processors.

Cross-Border Investigations

How cross-border investigations are conducted and which authority takes the lead.

Lead Supervisory Authority

Which supervisory authority becomes the LSA and how binding decisions are made.

Dispute Resolution

How disputes between regulators are resolved and how the EDPB influences outcomes.

Remediation Obligations

How corrective actions must be implemented across all EU establishments.

Section 1

Articles 60–62 – Cooperation Between Supervisory Authorities

Article 60 – Cooperation Between the Lead Supervisory Authority and Other Supervisory Authorities

Scholarly Purpose

Article 60 establishes the GDPR's "One-Stop-Shop" mechanism. It creates a structured cooperation process among the Lead Supervisory Authority (LSA), Concerned Supervisory Authorities (CSAs), and the EDPB when consensus cannot be achieved.

What This Means for Firms

A multinational bank may have headquarters in Ireland, customers in France, operations in Germany, and processing centres in Spain. The Irish DPC may become the Lead Supervisory Authority, but French, German, and Spanish authorities remain involved as Concerned Supervisory Authorities.

Banking Example — AI-Driven Credit Scoring

This escalation pathway illustrates why firms must engage proactively with all Concerned Supervisory Authorities, not only the Lead Supervisory Authority, throughout the lifecycle of a cross-border processing activity.

Required Processes

1

Cross-Border Regulatory Engagement

2

LSA Identification Process

3

Regulatory Inquiry Management

4

Pan-European Remediation Coordination

5

Regulatory Decision Implementation Governance

Articles 61 & 62 – Mutual Assistance and Joint Operations

Article 61

Mutual Assistance

Supervisory authorities must assist one another by sharing information, conducting investigations, providing evidence, and supporting enforcement actions. Firms should expect requests originating from multiple regulators, with information exchanged across authorities and evidence provided in one jurisdiction influencing investigations elsewhere.

Banking Example

A customer complaint is filed in Italy. The lead authority is located in Ireland. The Italian authority gathers local evidence and shares it with the Irish authority, which then incorporates that evidence into its investigation.

Required Processes

  • Regulatory evidence preservation
  • Cross-border document management
  • Regulatory response workflow
  • Centralised investigation repository
Article 62

Joint Operations

Article 62 allows supervisory authorities to conduct joint investigations and enforcement actions. Multiple DPAs may jointly investigate a single firm's processing activities simultaneously.

Banking Implications

Multiple DPAs may jointly investigate:

  • AML monitoring systems
  • Customer analytics
  • Behavioural profiling
  • Fraud monitoring technologies

Required Processes

  • Joint inspection readiness
  • Regulatory interview management
  • Unified evidence production process
  • Coordinated legal response capability
Section 2

Articles 63–67 – The Consistency Mechanism

The consistency mechanism ensures uniform GDPR interpretation across the EU and prevents fragmentation among national authorities. It is one of the most consequential frameworks for multinational organisations.

Article 63 – Consistency Mechanism

Ensures uniform GDPR interpretation across the EU. Prevents fragmentation among national authorities. Organisations must monitor EDPB opinions, binding decisions, and emerging regulatory interpretations.

Illustrative Example

One authority accepts a lawful basis approach. Another authority disagrees. The EDPB intervenes. A harmonised position becomes applicable throughout the EU — potentially overriding the original national decision.

Why Consistency Matters for Firms

The consistency mechanism means that a compliance position accepted by one national authority may subsequently be challenged, revised, or overturned through EDPB intervention. Firms must therefore design compliance programmes that are robust enough to withstand scrutiny from the most demanding supervisory authority in the EU, not merely the most permissive.

Articles 64 & 65 – EDPB Opinions and Dispute Resolution

Article 64

Opinion of the Board

The EDPB may issue opinions on codes of conduct, certification mechanisms, DPIA lists, and cross-border enforcement matters. Firms should treat EDPB opinions as highly influential compliance standards even where they are not formally binding on the organisation directly.

Required Processes

  • Regulatory horizon scanning
  • EDPB monitoring
  • Compliance interpretation governance
Article 65

Dispute Resolution by the Board

Provides binding dispute resolution when supervisory authorities disagree. Article 65 decisions frequently influence fine calculations, scope of investigations, corrective actions, and legal interpretations. The lead authority must revise its position in accordance with the EDPB's binding decision.

Banking Impact

Banks operating in multiple jurisdictions may face expanded investigations, additional remediation obligations, and increased fines as a direct result of Article 65 dispute resolution proceedings.

Articles 66 & 67 – Urgency Procedure and Information Exchange

Article 66

Urgency Procedure

Article 66 allows rapid intervention where immediate action is needed to protect individuals. A supervisory authority may adopt provisional measures with immediate effect in its own territory where urgent action is required.

Banking Example

A bank suffers a severe data breach affecting millions of customers. Immediate action is required. A supervisory authority invokes Article 66, enabling it to act without waiting for the full cooperation procedure under Article 60 to conclude.

Required Processes

  • Incident response
  • Regulatory escalation
  • Crisis governance
  • Emergency communications
Article 67

Exchange of Information

Article 67 facilitates information exchange among supervisory authorities, enabling the Commission to specify arrangements for electronic information exchange between supervisory authorities and between supervisory authorities and the EDPB.

Required Processes

  • Evidence quality assurance
  • Regulatory correspondence governance
  • Single source of truth repositories
Section 3

Articles 68–70 – European Data Protection Board Governance

Articles 68–76 establish the institutional framework of the European Data Protection Board, defining its composition, independence, tasks, and operational procedures. Understanding this framework is essential for firms seeking to anticipate regulatory direction.

Article 68 – The EDPB

Establishes the EDPB as the central GDPR coordination body. The EDPB significantly shapes enforcement priorities, guidance, and interpretation standards across all Member States.

Article 69 – Independence

Ensures EDPB independence from political influence. Organisations cannot rely upon national regulatory preferences if they conflict with EDPB positions. Independence reinforces the authority of EDPB decisions.

Article 70 – Tasks of the Board

The EDPB issues guidelines, publishes recommendations, resolves disputes, and promotes consistent enforcement. EDPB guidance should be incorporated into policies, DPIAs, data governance frameworks, and compliance monitoring programmes.

Articles 71–76 – EDPB Operations, Reporting, and Confidentiality

1

Article 71 – Reports

Annual reporting regarding EDPB activities. A valuable source for enforcement trends, emerging risks, and regulatory focus areas. Firms should review annual EDPB reports as part of their regulatory horizon scanning programme.

2

Article 72 – Procedure

Governs EDPB operational procedures, including voting rules and decision-making processes. Supports the legitimacy and consistency of decisions affecting firms across the EU.

3

Article 73 – Chair

Establishes the EDPB Chair role. Limited direct operational impact on firms but important for governance continuity and the strategic direction of EDPB activities.

4

Article 74 – Tasks of the Chair

Coordination and representation of the Board. Influences the strategic direction of EDPB activities and the prioritisation of enforcement and guidance work.

5

Article 75 – Secretariat

Administrative support for EDPB operations. Supports publication of guidance and decisions relied upon by organisations in designing and maintaining their compliance programmes.

6

Article 76 – Confidentiality

Ensures confidentiality of Board activities and investigations. Firms must respect confidentiality obligations, protect regulator communications, and secure all investigation materials appropriately.

GDPR Articles That Intersect with Articles 60–76

Articles 60–76 do not operate in isolation. They interact with a broad range of substantive and procedural GDPR provisions. Effective compliance requires understanding these intersections.

Substantive Processing Obligations

Articles 5 & 6

Principles relating to processing and lawfulness of processing — foundational to any cross-border investigation.

Article 9

Special category data — frequently the subject of heightened supervisory scrutiny and EDPB guidance.

Articles 12–22

Data subject rights — complaints arising from rights failures frequently trigger cross-border cooperation procedures.

Articles 24 & 25

Controller responsibility and data protection by design and default.

Articles 33–36

Breach notification, DPIAs, and prior consultation — key triggers for regulatory engagement.

Governance and Enforcement Provisions

Articles 28 & 30

Processor management and records of processing activities — essential evidence in cross-border investigations.

Articles 37–39

DPO obligations — the DPO is a key interface with supervisory authorities.

Articles 44–49

International transfers — frequently subject to EDPB opinions and consistency mechanism proceedings.

Articles 55–58

Competence, lead supervisory authority, tasks and powers — directly linked to Articles 60–76 procedures.

Articles 77, 83 & 84

Complaints, administrative fines, and penalties — the ultimate enforcement outcomes of cooperation procedures.

Twenty Cross-Cutting Technical and Organisational Controls

Effective compliance with Articles 60–76 requires a comprehensive suite of technical and organisational measures. The following twenty controls represent the minimum expected capability for a multinational firm subject to the GDPR One-Stop-Shop framework.

Enterprise ROPA Management

Enterprise-wide Record of Processing Activities management.

Regulatory Inquiry Platform

Centralised regulatory inquiry management platform.

Cross-Border Engagement

Cross-border supervisory authority engagement procedure.

Evidence Preservation

Regulatory evidence preservation and legal hold capability.

LSA Determination

Formal Lead Supervisory Authority determination process.

DPIA Governance

Enterprise DPIA governance framework.

Data Inventory & Lineage

Data inventory and lineage management.

Data Classification

Data classification and handling standards.

Privacy-by-Design

Privacy-by-design control framework.

Security-by-Design

Security-by-design engineering standards.

Breach Detection

Enterprise breach detection and escalation process.

Notification Automation

Regulatory notification workflow automation.

Policy Management

Centralised policy management system.

DSR Orchestration

Data subject rights orchestration platform.

Decision Tracking

Regulatory decision tracking and remediation programme.

EDPB Monitoring

Continuous monitoring of EDPB guidance and decisions.

Complaint Management

Cross-border complaint management process.

Audit Readiness

Regulatory audit readiness programme.

Privacy Governance

Executive privacy governance committee.

Compliance Assurance

Independent privacy compliance assurance and testing function.

Advanced Practitioner Teaching Points

The following observations represent the most important strategic insights for practitioners advising multinational organisations on GDPR compliance under Articles 60–76.

Governance, Not Processing

Articles 60–76 are governance and enforcement provisions rather than operational processing provisions. They regulate the regulatory ecosystem itself — the machinery through which supervisory authorities exercise their powers across borders.

The Local Approval Fallacy

The greatest risk for multinational firms is assuming local regulatory approval guarantees EU-wide acceptance. A decision accepted by the Lead Supervisory Authority may be challenged, revised, or overturned through the consistency mechanism and EDPB dispute resolution procedures.

The EDPB as Harmonising Authority

The EDPB increasingly acts as a harmonising authority capable of influencing investigations, interpretations, and enforcement outcomes across all Member States. Modern compliance programmes must be designed around European-wide regulatory expectations rather than solely national requirements.

The Framework for Regulatory Supervision

Banks and financial institutions should view Articles 60–76 as the framework governing regulatory supervision itself. Effective compliance requires not only lawful processing but also demonstrable readiness for cross-border investigations, coordinated regulatory scrutiny, dispute resolution procedures, and EU-wide corrective action implementation.

"Modern compliance programmes must therefore be designed around European-wide regulatory expectations rather than solely national requirements."

17

Articles in Chapter VII

Articles 60–76 covering cooperation, consistency, and EDPB governance.

20

Key Controls

Cross-cutting technical and organisational controls required for compliance.

27

Intersecting Articles

GDPR articles that directly intersect with the Chapter VII governance framework.

Datari Home

The material within this site is provided for general guidance only and does not constitute legal, regulatory, or professional advice. Datari accepts no liability for any actions taken or not taken based on this content. Organisations should seek their own independent advice before making decisions.