Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Powers of Supervisory Authorities (Art. 58)
Courses Guides Blog Resources News
Français English Nederlands
Fiche 50/54 Part 5 — Operational Obligations & Sanctions Intermediate Reviewed 2026-08-23

Powers of Supervisory Authorities (Art. 58)

Supervisory authorities (such as the DPA/APD in Belgium or CNIL in France) hold investigative, corrective, and advisory powers, enabling comprehensive inspection, enforcement, and penalisation.

Open in interactive reader
⚖️ Binding Standard (Art. 58) 🇧🇪 Belgian DPA Act 03/12/2017

Powers of Supervisory Authorities (Art. 58)

⚡ In 30 seconds

Article 58 equips DPAs with sweeping enforcement instruments, ranging from simple information requests to total bans on data processing activities.

Inspections & Inquiries

Authorities can conduct unannounced on-site audits, written documentary inspections, hearings, or digital remote sweeps. Controllers and processors are legally obliged to cooperate actively.

Corrective Measures

Prior to or alongside financial fines, authorities can order compliance with data subject rights, mandate rectifications or erasures, or order temporary or permanent processing bans.

⚡ Key Takeaways
  • Investigative powers: full access to premises, equipment, infrastructure, and processed data (on-site or remote audits).
  • Corrective powers: warnings, reprimands, orders to comply, temporary or definitive processing bans, and administrative fines.
  • Supervisory bodies act on their own initiative or following complaints lodged by data subjects or associations.
⚠️ Common Pitfall

Refusing or delaying cooperation during an authority inspection; obstructing a supervisory investigation constitutes a directly punishable violation.

🛠️ Practical Action

Draft and formalise an internal supervisory inspection response protocol (reception, designated legal and IT contacts, dedicated conference room).

⚖️ Official sources: Art. 58 GDPR · Recitals 129–133 · Belgian DPA Act 03/12/2017 ✓ Last legal review: 23 August 2026

✓ Key takeaways

  • Investigative powers: full access to premises, equipment, infrastructure, and processed data (on-site or remote audits).
  • Corrective powers: warnings, reprimands, orders to comply, temporary or definitive processing bans, and administrative fines.
  • Supervisory bodies act on their own initiative or following complaints lodged by data subjects or associations.

⚠ Common pitfall: Refusing or delaying cooperation during an authority inspection; obstructing a supervisory investigation constitutes a directly punishable violation.

→ Actionable practice: Draft and formalise an internal supervisory inspection response protocol (reception, designated legal and IT contacts, dedicated conference room).

← Compliance Audit & Continuous Action Plan Administrative Fines & Sanctions (Art. 83) →