Article 58: Powers
Praxikon tracks Article 58 (Powers) under the GDPR, alongside the EU AI Act, citing the source for every statement.
What does Article 58 govern?
Article 58 lists what a supervisory authority is allowed to do, starting in paragraph 1 with investigative powers: ordering information from the controller and the processor, carrying out audits, and obtaining access to personal data and to premises and equipment. Paragraph 2 gives corrective powers, from a warning and a reprimand to an order to bring processing into compliance, a temporary or definitive ban on processing, an order to erase data, the suspension of data flows to a third country and a fine under Article 83. Paragraph 3 gives authorisation and advisory powers, such as advising in the prior consultation procedure of Article 36 and approving codes of conduct, standard clauses and binding corporate rules under Article 47. Paragraph 4 ensures those powers are used only with appropriate safeguards, including an effective judicial remedy and due process, and paragraphs 5 and 6 let member states provide that the authority can go to court and can receive additional powers. The article exists to make sure supervisory authorities in all member states have the same effective powers, so that the GDPR is enforced equally strongly everywhere (recital 129), each on the territory of its own member state (recital 122).
Key term: Corrective measure: a decision by the supervisory authority that forces an organisation to do or stop doing something, such as a ban on processing or an order to erase data
Directly affects:supervisory authoritycontrollerprocessordata subjectmember state
Praxikon’s reading of the text and the recitals; the official text below prevails.
Official text
Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.
What does this mean for you?
Controller
The supervisory authority can order you to provide any information it needs for its tasks, carry out an audit and request access to personal data and premises (paragraph 1). It can also require you to bring processing into compliance within a set period, to communicate a data breach to data subjects, to stop processing temporarily or definitively, and to suspend data flows to a third country (paragraph 2). Every binding measure comes with safeguards such as an effective judicial remedy (paragraph 4) and must be in writing and state its reasons (recital 129).
Processor
The investigative powers in paragraph 1 apply to you just as much: a processor must also provide information and give access to data and premises. Corrective measures such as a reprimand, an order or a limitation on processing can be imposed on you directly (paragraph 2).
Data Protection Officer
You make sure that information requests from the supervisory authority are answered completely and on time (paragraph 1(a)) and that the organisation knows the possible measures in paragraph 2. In a prior consultation under Article 36 you know that the supervisory authority provides advice on it (paragraph 3(a)).
Data Subject
If an organisation does not comply with your request for, say, access, rectification or erasure, the supervisory authority can order the organisation to do so (paragraph 2(c) and (g)). It can also order that a data breach be communicated to you (paragraph 2(e)).
Compliance checklist
Related recitals
Each supervisory authority should be competent on the territory of its own Member State to exercise the powers and to perform the tasks conferred on it in accordance with this Regulation. This should ...
(129)In order to ensure consistent monitoring and enforcement of this Regulation throughout the Union, the supervisory authorities should have in each Member State the same tasks and effective powers, incl...
Cross-references
Frequently asked questions
Connections
What connects to Article 58 GDPR
Themes where this returns
The counterpart in the other law
Case law
- Reddit's summary proceedings against the DPA over a penalty order and legal privilege dismissed
2026-03-04 · status not established, Rechtbank Den Haag, voorzieningenrechter
- Interim judge suspends DPA penalty order against Northwave: exhaust powers against the hosting provider first
2024-03-26 · final, Rechtbank Midden-Nederland, voorzieningenrechter (zittingsplaats Utrecht)
- Deutsche Wohnen: a fine on a legal person needs no identified natural person, but does require fault
2023-12-05 · final, Hof van Justitie van de EU (Grote kamer), Deutsche Wohnen SE tegen Staatsanwaltschaft Berlin
- Land Hessen: the supervisory authority need not always fine where the organisation already remedied the breach
2024-09-26 · final, Hof van Justitie van de EU (Eerste kamer), TR tegen Land Hessen
- Schrems II: Privacy Shield invalid, transfers under standard clauses only with essentially equivalent protection
2020-07-16 · final, Hof van Justitie van de EU (Grote kamer), Data Protection Commissioner tegen Facebook Ireland Ltd en Maximillian Schrems
- Council of State: DPA could fine DPG Media for routinely demanding ID copies, fine halved to 262,500 euros
2025-09-24 · final, Raad van State, Afdeling bestuursrechtspraak
Guidelines
- Consultation on the Dutch DPA's enforcement policy (April 2026)
2026-04-13 · under consultation, Autoriteit Persoonsgegevens
Enforcement and fines
- Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
2026-02-03 · final, Autoriteit Persoonsgegevens
- Formal warning to the Dutch Minister of Education, Culture and Science not to put the CABR war archive online and searchable
2024-11-26 · final, Autoriteit Persoonsgegevens
Legislation in motion
- Amendment to the Dutch GDPR Implementation Act: DPA must publish GDPR sanctions from 1 September 2026
2026-09-01 · in force, Wetgever (Tweede Kamer) en Autoriteit Persoonsgegevens