A complaint concerns cross-border processing by a pan-EU SaaS whose main establishment is in one Member State. How should supervisory competence typically be approached under the one-stop-shop model?
Select an answer to reveal the explanation.
Short Explanation
One-stop-shop is like having a lead project manager for a multi-country job, while other site managers still get a say. For cross-border SaaS processing, the lead SA tied to the main establishment runs point with concerned SAs cooperating.
Full Explanation
For cross-border processing, the GDPR one-stop-shop mechanism generally designates a lead supervisory authority based on the controller's or processor's main establishment, cooperating with concerned supervisory authorities. Municipal mayors and the EDPS (for EU institutions) are not the default enforcers for private pan-EU SaaS. Language count does not dismiss complaints.