EU regulatory register · GDPR
Article 58Powers
CELEX 32016R0679 · Read on 2026-08-18 · Chapter VI
Official text
Read from the EU Publications Office for this CELEX number. The wording stands as published; nothing here is rewritten or summarised.
1. Each supervisory authority shall have all of the following investigative powers:
(a)
to order the controller and the processor, and, where applicable, the controller's or the processor's representative to provide any information it requires for the performance of its tasks;
(b)
to carry out investigations in the form of data protection audits;
(c)
to carry out a review on certifications issued pursuant to Article 42(7);
(d)
to notify the controller or the processor of an alleged infringement of this Regulation;
(e)
to obtain, from the controller and the processor, access to all personal data and to all information necessary for the performance of its tasks;
(f)
to obtain access to any premises of the controller and the processor, including to any data processing equipment and means, in accordance with Union or Member State procedural law.
2. Each supervisory authority shall have all of the following corrective powers:
The article continues in the official text.
Other articles in this chapter
Judgments of the Court of Justice
3 decisions
- C-768/21Court of Justice of the European Union
TR v Land Hessen
Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(a) and (f) – Tasks of the supervisory authority – Article 58(2) – Corrective powers – Administrative fine – Discretion of the supervisory authority – Limits.
- C-46/23Court of Justice of the European Union
Budapest Főváros IV. Kerület Újpest Önkormányzat Polgármesteri Hivatala v Nemzeti Adatvédelmi és Információszabadság Hatóság
Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 58(2)(d) and (g) – Powers of the supervisory authority of a Member State – Paragraph 17(1) – Right to erasure (‘right to be forgotten’) – Erasure of unlawfully processed personal data – Power of the national supervisory authority to order the controller or processor to erase those data without a prior request from the data subject.
- C-807/21Court of Justice of the European Union
Deutsche Wohnen SE v Staatsanwaltschaft Berlin
Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Article 58(2) – Powers of supervisory authorities to apply corrective measures – Article 83 – Imposition of administrative fines on a legal person – Conditions – Discretion of the Member States – Requirement that the infringement be intentional or negligent.
The text is quoted from the official source and is not legal advice. A national court reads the language version that binds in its jurisdiction.
Verifiable trust signals
- Six fixed blocks, one source per line
- No sentence written by a language model
- Engine version and read date on every answer
- No customer data, no documents, no advice
- Model card and audit published under the EU AI Act