HubBroker & Lead Supervisory Authority

The General Data Protection Regulation (GDPR) includes a cooperation mechanism commonly referred to as the One-Stop-Shop.
The One-Stop-Shop mechanism is intended to provide a coordinated supervisory approach where an organisation carries out qualifying cross-border processing of personal data within the European Economic Area (EEA).
When the One-Stop-Shop Applies
The One-Stop-Shop mechanism may apply where personal data processing qualifies as cross-border processing under the GDPR.
Cross-border processing generally includes processing that:
- Takes place in the context of establishments of the same controller or processor in more than one EEA Member State; or
- Takes place through a single establishment in the EEA but substantially affects, or is likely to substantially affect, data subjects in more than one EEA Member State.
Where these conditions are not met, the Lead Supervisory Authority mechanism may not apply.
Determining the Lead Supervisory Authority
An organization does not freely select or appoint its Lead Supervisory Authority.
The applicable Lead Supervisory Authority is determined according to the GDPR rules concerning the organisation's main establishment and the relevant cross-border processing activity.
For a controller, the main establishment will generally be the location of its central administration in the EEA, unless decisions regarding the purposes and means of a particular processing activity are taken and implemented at another establishment.
For a processor, the determination is based on the GDPR rules applicable to the processor's main establishment.
The supervisory authority of the Member State where the relevant main establishment is located will generally act as the Lead Supervisory Authority for qualifying cross-border processing.
Role of the Lead Supervisory Authority
Where the One-Stop-Shop mechanism applies, the Lead Supervisory Authority has primary responsibility for coordinating supervision of the relevant cross-border processing.
Its functions may include:
- Handling or coordinating investigations
- Reviewing complaints relating to cross-border processing
- Coordinating with other concerned supervisory authorities
- Assessing certain personal-data breach notifications
- Exercising supervisory and corrective powers under the GDPR
- Coordinating draft decisions relating to cross-border cases
The Lead Supervisory Authority does not necessarily act alone.
Supervisory authorities in other EEA countries may participate as Concerned Supervisory Authorities where the processing affects establishments or data subjects within their jurisdictions.
The supervisory authorities cooperate through the GDPR cooperation and consistency mechanisms.
Personal Data Breaches
Where HubBroker is required to notify a personal-data breach under the GDPR, the appropriate supervisory authority will be determined according to the circumstances of the processing and the applicable GDPR jurisdictional rules.
Where the One-Stop-Shop mechanism applies to relevant cross-border processing, the Lead Supervisory Authority would normally have the primary coordinating role.
Where HubBroker acts as a Data Processor on behalf of a customer, HubBroker will notify the affected Data Controller of a personal-data breach without undue delay in accordance with applicable GDPR requirements and contractual obligations.
The Data Controller is generally responsible for determining whether notification to a supervisory authority or affected data subjects is required.
HubBroker ApS and the Danish Data Protection Authority
HubBroker ApS is established in Denmark.
Where Denmark constitutes HubBroker's relevant main establishment for a qualifying cross-border processing activity, the Danish Data Protection Agency (Datatilsynet) would normally act as HubBroker's Lead Supervisory Authority for that processing activity under the GDPR One-Stop-Shop mechanism.
The determination should be based on the actual location from which relevant decisions concerning the processing are taken and implemented and should be reviewed if HubBroker's organisational structure or processing arrangements materially change.
Danish Data Protection Agency
Datatilsynet,Denmark.
Current contact information should be obtained directly from the Danish Data Protection Agency's official website to ensure that address and contact details remain up to date.
Complaints and Other Supervisory Authorities
Data subjects retain the right to lodge complaints with a competent supervisory authority.
Where a complaint involves cross-border processing, the Lead Supervisory Authority and other Concerned Supervisory Authorities may cooperate in accordance with the GDPR.
The One-Stop-Shop mechanism therefore provides a coordinated supervisory process; it does not remove the powers or involvement of other competent supervisory authorities.
Review of Lead Supervisory Authority Status
HubBroker should periodically review whether:
- Denmark continues to be the location of its relevant main establishment
- Decisions concerning the purposes and means of relevant processing continue to be taken and implemented in Denmark
- Its processing qualifies as cross-border processing
- Organisational or operational changes affect the applicable supervisory authority
- The applicable regulatory contact information remains current
Category: GDPR
Last date of update: 24.08.2026