·GDPR

The one-stop-shop mechanism: what it means in practice

EU establishment determines lead supervisory authority. The regulatory consequences of that decision are significant and are often not fully understood when the decision is made.

How the mechanism works

Under the GDPR’s one-stop-shop mechanism, companies with EU establishments are supervised primarily by the authority in the country of their main establishment — typically where the EU headquarters is located, or where processing decisions are made. For cross-border cases, this lead authority coordinates with concerned authorities in other member states.

The regulatory authority a company faces for cross-border matters is determined by a structural decision — where to incorporate or locate EU operations — that is almost always made on commercial grounds, without reference to its regulatory implications. That gap is where most jurisdictional exposure originates.

The Irish DPC became lead authority for most major global technology companies not by design, but because those companies chose Dublin for commercial reasons. The regulatory consequence was incidental to the decision.

Authority differences

The DPC, BayLDA, CNIL, and other major authorities operate with different cultures, capacities, and sector expertise. Processing timelines, documentation expectations, and the intensity of scrutiny in specific sectors vary considerably across jurisdictions. These differences are observable in published enforcement records.

Regulatory Reality · 2026 · Observational analysis. Not legal advice.