EU establishment determines lead supervisory authority. The regulatory consequences of that decision are significant and are often not fully understood when the decision is made.
Under the GDPR’s one-stop-shop mechanism, companies with EU establishments are supervised primarily by the authority in the country of their main establishment — typically where the EU headquarters is located, or where processing decisions are made. For cross-border cases, this lead authority coordinates with concerned authorities in other member states.
The regulatory authority a company faces for cross-border matters is determined by a structural decision — where to incorporate or locate EU operations — that is almost always made on commercial grounds, without reference to its regulatory implications. That gap is where most jurisdictional exposure originates.
The Irish DPC became lead authority for most major global technology companies not by design, but because those companies chose Dublin for commercial reasons. The regulatory consequence was incidental to the decision.
The DPC, BayLDA, CNIL, and other major authorities operate with different cultures, capacities, and sector expertise. Processing timelines, documentation expectations, and the intensity of scrutiny in specific sectors vary considerably across jurisdictions. These differences are observable in published enforcement records.