Dealing with the supervisory authority: what a business must know
Engagement with the data protection supervisory authority often begins unexpectedly — with a subject's complaint or on the authority's own initiative. On this page we explain how the process runs and which deadlines are decisive. One important circumstance first: under the current redaction of the Law on Personal Data Protection, as amended by the law of 17 December 2025, data protection supervision is exercised by the State Audit Service — complaints, inspections and measures therefore occur in the name of that authority.
Examination of an application and its terms
The State Audit Service is obliged to examine a data subject's application concerning data processing and to apply the measures provided for by legislation. Within 10 days of receiving the application the Service takes a decision on the measures to be applied and notifies the applicant. The overall term of examination must not exceed 2 months and may, by a justified decision, be extended by no more than 1 month. The Service may suspend the examination on the ground of demanding additional material — the suspension period is not counted within the term. Before completing the examination the Service may decide on blocking the data, although processing may continue for the protection of vital interests, state security and defence purposes.
Inspection: what an organisation should expect
The State Audit Service may, on its own initiative or on the basis of an interested person's application, inspect a controller; the decision to conduct an inspection is taken by the General Auditor. An inspection entails establishing compliance with the processing principles and the existence of lawful bases; verifying the conformity of security measures and procedures with established requirements; verifying the lawfulness of transfers to another state or international organisation; and verifying compliance with the rules set by the law and other normative acts. The Service may demand a document or information from any institution, natural or legal person — including information containing state, tax, banking, commercial or professional secrets — and enter any institution to inspect documents. Material must be supplied immediately; where retrieval in another structure or processing of a significant volume is required, the term extends to 10 working days and, on a justified request, by a further 10 working days.
The measures the authority applies
On detecting a violation the Service applies one or several measures: demanding rectification of the violation and deficiencies in the form and term it indicates; demanding temporary or permanent cessation of processing where security measures do not meet requirements; demanding cessation of processing and blocking, deletion, destruction or depersonalisation of data where processing is carried out in violation of legislation; demanding cessation of transfers to another state; giving written advice for a minor violation; or imposing administrative liability. Compliance with the measures within the indicated term is mandatory; on non-performance the Service applies to a court, a law-enforcement body or the relevant regulatory institution.
Appealing a decision
A decision of the General Auditor taken as a result of proceedings may be appealed in court under the procedure of the Administrative Offences Code — by the person against whom it was issued, within 1 month of official notification. Where an appeal is brought, the decision is enforced from the moment the court decision enters into legal force. At the same time, a decision of the Service in the field of data protection is mandatory in execution and may be appealed only in court.
How we can help
We represent your interests at every stage of engagement with the supervisory authority: preparing a legal response to an application, supplying materials for an inspection and controlling the deadlines, formulating a response to applied measures, and appealing a decision. Contact us — we will assess your position.
In practical terms, preparation for an inspection proceeds in three directions. First, documentary readiness: the examination of principles, bases, security measures and the lawfulness of transfers rests precisely on the documents the organisation must have in order in advance. Second, deadline management: the terms for supplying material depend on the content of the demand, and the assessment of whether an extension is needed must be made immediately upon receipt, so that the need for it is justified in due time. Third, consistency of position: at all three stages — application, inspection and measures — the same circle of facts must be presented, since contradictory explanations often harm the position more than the violation itself.
One further note for subjects: the law establishes three routes of complaint — the State Audit Service, the court and a superior administrative organ — and the subject may ask the Service to decide on blocking the data before the examination of the application is completed. Knowing these rights matters for business as well: a complaint is foreseeable and its legal dimension can be assessed in advance. Our assistance covers both sides — protecting the rights of the subject and preparing the position of the organisation in supervisory processes.
It should further be noted that the final instrument towards violators is likewise provided by the law: where the Service detects an administrative offence, it draws up a record of the offence and imposes liability in accordance with the procedure established by the Administrative Offences Code. One dispute thus unfolds in three dimensions — supervision, administrative liability and judicial control. Each imposes its own terms and requirements, and steering them simultaneously is precisely a matter of professional support.
