Cooperation, Consistency, Enforcement Governance, and Organisational Compliance — a practitioner's guide to Chapter VII of the GDPR.
GDPR Articles 60–76 comprise Chapter VII of the GDPR and establish the governance architecture through which supervisory authorities cooperate, coordinate investigations, resolve disputes, and ensure consistent enforcement across the European Union. These provisions do not primarily regulate data processing itself; rather, they regulate the regulatory ecosystem that oversees controllers and processors.
How cross-border investigations are conducted and which authority takes the lead.
Which supervisory authority becomes the LSA and how binding decisions are made.
How disputes between regulators are resolved and how the EDPB influences outcomes.
How corrective actions must be implemented across all EU establishments.
Article 60 establishes the GDPR's "One-Stop-Shop" mechanism. It creates a structured cooperation process among the Lead Supervisory Authority (LSA), Concerned Supervisory Authorities (CSAs), and the EDPB when consensus cannot be achieved.
A multinational bank may have headquarters in Ireland, customers in France, operations in Germany, and processing centres in Spain. The Irish DPC may become the Lead Supervisory Authority, but French, German, and Spanish authorities remain involved as Concerned Supervisory Authorities.
This escalation pathway illustrates why firms must engage proactively with all Concerned Supervisory Authorities, not only the Lead Supervisory Authority, throughout the lifecycle of a cross-border processing activity.
Supervisory authorities must assist one another by sharing information, conducting investigations, providing evidence, and supporting enforcement actions. Firms should expect requests originating from multiple regulators, with information exchanged across authorities and evidence provided in one jurisdiction influencing investigations elsewhere.
A customer complaint is filed in Italy. The lead authority is located in Ireland. The Italian authority gathers local evidence and shares it with the Irish authority, which then incorporates that evidence into its investigation.
Article 62 allows supervisory authorities to conduct joint investigations and enforcement actions. Multiple DPAs may jointly investigate a single firm's processing activities simultaneously.
Multiple DPAs may jointly investigate:
The consistency mechanism ensures uniform GDPR interpretation across the EU and prevents fragmentation among national authorities. It is one of the most consequential frameworks for multinational organisations.
Ensures uniform GDPR interpretation across the EU. Prevents fragmentation among national authorities. Organisations must monitor EDPB opinions, binding decisions, and emerging regulatory interpretations.
One authority accepts a lawful basis approach. Another authority disagrees. The EDPB intervenes. A harmonised position becomes applicable throughout the EU — potentially overriding the original national decision.
The consistency mechanism means that a compliance position accepted by one national authority may subsequently be challenged, revised, or overturned through EDPB intervention. Firms must therefore design compliance programmes that are robust enough to withstand scrutiny from the most demanding supervisory authority in the EU, not merely the most permissive.

The EDPB may issue opinions on codes of conduct, certification mechanisms, DPIA lists, and cross-border enforcement matters. Firms should treat EDPB opinions as highly influential compliance standards even where they are not formally binding on the organisation directly.
Provides binding dispute resolution when supervisory authorities disagree. Article 65 decisions frequently influence fine calculations, scope of investigations, corrective actions, and legal interpretations. The lead authority must revise its position in accordance with the EDPB's binding decision.
Banks operating in multiple jurisdictions may face expanded investigations, additional remediation obligations, and increased fines as a direct result of Article 65 dispute resolution proceedings.
Article 66 allows rapid intervention where immediate action is needed to protect individuals. A supervisory authority may adopt provisional measures with immediate effect in its own territory where urgent action is required.
A bank suffers a severe data breach affecting millions of customers. Immediate action is required. A supervisory authority invokes Article 66, enabling it to act without waiting for the full cooperation procedure under Article 60 to conclude.
Article 67 facilitates information exchange among supervisory authorities, enabling the Commission to specify arrangements for electronic information exchange between supervisory authorities and between supervisory authorities and the EDPB.
Articles 68–76 establish the institutional framework of the European Data Protection Board, defining its composition, independence, tasks, and operational procedures. Understanding this framework is essential for firms seeking to anticipate regulatory direction.
Establishes the EDPB as the central GDPR coordination body. The EDPB significantly shapes enforcement priorities, guidance, and interpretation standards across all Member States.
Ensures EDPB independence from political influence. Organisations cannot rely upon national regulatory preferences if they conflict with EDPB positions. Independence reinforces the authority of EDPB decisions.
The EDPB issues guidelines, publishes recommendations, resolves disputes, and promotes consistent enforcement. EDPB guidance should be incorporated into policies, DPIAs, data governance frameworks, and compliance monitoring programmes.
Annual reporting regarding EDPB activities. A valuable source for enforcement trends, emerging risks, and regulatory focus areas. Firms should review annual EDPB reports as part of their regulatory horizon scanning programme.
Governs EDPB operational procedures, including voting rules and decision-making processes. Supports the legitimacy and consistency of decisions affecting firms across the EU.
Establishes the EDPB Chair role. Limited direct operational impact on firms but important for governance continuity and the strategic direction of EDPB activities.
Coordination and representation of the Board. Influences the strategic direction of EDPB activities and the prioritisation of enforcement and guidance work.
Administrative support for EDPB operations. Supports publication of guidance and decisions relied upon by organisations in designing and maintaining their compliance programmes.
Ensures confidentiality of Board activities and investigations. Firms must respect confidentiality obligations, protect regulator communications, and secure all investigation materials appropriately.
Articles 60–76 do not operate in isolation. They interact with a broad range of substantive and procedural GDPR provisions. Effective compliance requires understanding these intersections.
Principles relating to processing and lawfulness of processing — foundational to any cross-border investigation.
Special category data — frequently the subject of heightened supervisory scrutiny and EDPB guidance.
Data subject rights — complaints arising from rights failures frequently trigger cross-border cooperation procedures.
Controller responsibility and data protection by design and default.
Breach notification, DPIAs, and prior consultation — key triggers for regulatory engagement.
Processor management and records of processing activities — essential evidence in cross-border investigations.
DPO obligations — the DPO is a key interface with supervisory authorities.
International transfers — frequently subject to EDPB opinions and consistency mechanism proceedings.
Competence, lead supervisory authority, tasks and powers — directly linked to Articles 60–76 procedures.
Complaints, administrative fines, and penalties — the ultimate enforcement outcomes of cooperation procedures.
Effective compliance with Articles 60–76 requires a comprehensive suite of technical and organisational measures. The following twenty controls represent the minimum expected capability for a multinational firm subject to the GDPR One-Stop-Shop framework.
Enterprise-wide Record of Processing Activities management.
Centralised regulatory inquiry management platform.
Cross-border supervisory authority engagement procedure.
Regulatory evidence preservation and legal hold capability.
Formal Lead Supervisory Authority determination process.
Enterprise DPIA governance framework.
Data inventory and lineage management.
Data classification and handling standards.
Privacy-by-design control framework.
Security-by-design engineering standards.
Enterprise breach detection and escalation process.
Regulatory notification workflow automation.
Centralised policy management system.
Data subject rights orchestration platform.
Regulatory decision tracking and remediation programme.
Continuous monitoring of EDPB guidance and decisions.
Cross-border complaint management process.
Regulatory audit readiness programme.
Executive privacy governance committee.
Independent privacy compliance assurance and testing function.
The following observations represent the most important strategic insights for practitioners advising multinational organisations on GDPR compliance under Articles 60–76.
Articles 60–76 are governance and enforcement provisions rather than operational processing provisions. They regulate the regulatory ecosystem itself — the machinery through which supervisory authorities exercise their powers across borders.
The greatest risk for multinational firms is assuming local regulatory approval guarantees EU-wide acceptance. A decision accepted by the Lead Supervisory Authority may be challenged, revised, or overturned through the consistency mechanism and EDPB dispute resolution procedures.
The EDPB increasingly acts as a harmonising authority capable of influencing investigations, interpretations, and enforcement outcomes across all Member States. Modern compliance programmes must be designed around European-wide regulatory expectations rather than solely national requirements.
Banks and financial institutions should view Articles 60–76 as the framework governing regulatory supervision itself. Effective compliance requires not only lawful processing but also demonstrable readiness for cross-border investigations, coordinated regulatory scrutiny, dispute resolution procedures, and EU-wide corrective action implementation.
"Modern compliance programmes must therefore be designed around European-wide regulatory expectations rather than solely national requirements."
Articles 60–76 covering cooperation, consistency, and EDPB governance.
Cross-cutting technical and organisational controls required for compliance.
GDPR articles that directly intersect with the Chapter VII governance framework.
The material within this site is provided for general guidance only and does not constitute legal, regulatory, or professional advice. Datari accepts no liability for any actions taken or not taken based on this content. Organisations should seek their own independent advice before making decisions.
Article 60 - Article 76