Skip to main content
Cross-Border Enforcement Coordination TemplateConsent Principles
4 min readFor Data Governance Teams

Cross-Border Enforcement Coordination Template

When a data subject files a complaint against a controller operating across multiple EU member states, your DPA doesn't investigate alone. The GDPR's one-stop-shop mechanism requires coordination between lead and concerned supervisory authorities. But what happens when the investigation involves areas regulated by other EU bodies, like competition law, consumer protection, digital services, or AI governance?

At a meeting in Dublin on 16 and 17 July 2026, the EDPB called for a legal basis to enable cross-regulatory information sharing. This request highlights what enforcement teams already know: modern data protection cases often intersect with other regulatory domains, and the lack of formal information-sharing mechanisms creates friction.

This template provides a structure for documenting cross-regulatory coordination needs in your enforcement files. While it won't create the legal basis the EDPB is requesting, it will help you identify coordination gaps and prepare your team for likely procedural changes.

Purpose of the Template

Use this template when:

  • Your investigation involves practices under multiple EU regulatory frameworks (e.g., GDPR + Digital Services Act, GDPR + AI Act).
  • You're coordinating with a DPA in another member state and discover the case involves their national competition authority or consumer protection regulator.
  • You need to document why your enforcement outcome depends on information held by another regulator.
  • You're preparing internal guidance on when to flag cross-regulatory coordination needs.

The template records coordination attempts, identifies legal barriers to information sharing, and documents the enforcement impact of those barriers. If your jurisdiction implements new cross-regulatory sharing provisions, you'll have a baseline showing where the gaps were.

Prerequisites

Before using this template, confirm:

  1. You've identified the specific regulatory intersection. Specify which provision of which regulation creates the overlap (e.g., Article 22 GDPR automated decision-making + AI Act high-risk system requirements).

  2. You know which regulator holds relevant information. Name the authority, not just the domain. Be specific, like "Agence nationale de la sécurité des systèmes d'information (ANSSI)."

  3. You've documented the enforcement impact. Explain how the information gap affects your ability to assess compliance, calculate penalties, or determine corrective measures.

  4. You've attempted coordination through existing channels. This template documents barriers, so show you tried the available mechanisms first.

The Template

CROSS-REGULATORY COORDINATION LOG
Case Reference: [Your internal case number]
Controller/Processor: [Entity name and establishment location]
Lead DPA: [If cross-border case]
Date Opened: [YYYY-MM-DD]

REGULATORY INTERSECTION
Primary Legal Basis: [e.g., GDPR Article 6(1)(f), Article 9]
Intersecting Framework: [e.g., Digital Services Act Article 24, AI Act Article 10]
Nature of Intersection: [Describe how the frameworks overlap in this case]

INFORMATION NEED
What We Need: [Specific information required]
Why We Need It: [Direct enforcement impact]
Held By: [Specific regulatory authority]
Legal Basis for Their Collection: [If known]

COORDINATION ATTEMPTS
Date: [YYYY-MM-DD]
Method: [Formal request, informal consultation, joint meeting]
Outcome: [Information shared, request declined, partial response]
Barrier Identified: [Legal constraint, procedural gap, resource limitation]

[Repeat for each attempt]

ENFORCEMENT IMPACT ASSESSMENT
Without This Information, We Cannot:
- [Specific enforcement action or determination]
- [Another blocked action]

Workarounds Attempted:
- [Alternative information source]
- [Modified enforcement approach]
- [Result of workaround]

RESOURCE ALLOCATION
Staff Hours Spent on Coordination: [Estimate]
Delay to Investigation Timeline: [Days/weeks]
Impact on Other Cases: [If coordination diverted resources]

RECOMMENDATIONS
For This Case: [How you'll proceed given constraints]
For Future Cases: [Process improvements, legislative needs]
For Policy Development: [What legal basis would help]

Customizing the Template

For joint operations with other DPAs: Track resource-sharing arrangements:

RESOURCE SHARING (Cross-Border Cases)
Resources Offered to LSA:
- Staff: [Number of investigators, specialization]
- Duration: [Weeks/months]
- Coordination mechanism: [How work is divided]

Resources Received from Concerned SAs:
- [Same structure]

Efficiency Gains: [Quantify if possible]

For AI-related cases: Specify:

  • Which AI Act risk category applies (if the system is in scope).
  • Whether you need technical documentation the AI office might hold.
  • Whether training data provenance affects your lawfulness assessment.
  • If the AI system's design decisions impact your ability to assess Data Protection by Design compliance.

For cases involving multiple member states' consumer protection authorities: Note whether the practice also violates unfair commercial practices rules. Consumer protection authorities may have complaint data, test purchases, or enforcement precedents that inform your assessment of whether consent was freely given.

Validation Steps

Before filing this log:

  1. Verify you've cited specific legal provisions. Include article numbers and the specific obligation at issue.

  2. Confirm the enforcement impact is concrete. Ensure there's a clear need for new legislation if required.

  3. Check that you've documented actual barriers, not hypothetical ones. Did you attempt coordination and hit a legal constraint?

  4. Quantify resource impact where possible. The EDPB's call for cross-regulatory sharing connects to resource constraints. Document time spent on coordination.

  5. Review for confidential information. Redact controller-specific details if using the log for training or policy development.

The EDPB's request for a legal basis reflects what enforcement teams face daily: regulatory silos create friction, and that friction has resource costs. This template won't solve the legal gap, but it provides a systematic way to document where coordination fails and why it matters. When the legal framework changes, you'll have the evidence to show which provisions actually help.

You Might Also Like