# Who Does What in European Data Protection and AI Governance?

Canonical URL: https://xpertdpo.com/european-data-protection-ai-governance-institutions-guide/

Content type: Article

Published: 2026-08-06T15:12:26+01:00

Updated: 2026-08-06T20:59:45+01:00

Author: Philipa Jane Farley, Head of Legal and Operations

Summary: A practical map of the European institutions that shape, supervise and enforce data protection and AI rules, and how their responsibilities connect.

## Article

*This article accompanies **Hour 1: Global Privacy Law Updates** in our full-day CPD programme on XpertAcademy. Completion of the full one-hour session, including the related learning materials, contributes to the one-hour CPD certificate issued for that session. [Access CPD Event A: Full-Day Regulatory Privacy Training](https://xpertacademy.com/cpd-event-a-regulatory/).*

 European data protection and AI governance can look like an alphabet of overlapping bodies: the European Commission, EDPB, EDPS, national supervisory authorities, AI Office, AI Board and CJEU, among others.

 They do not all make rules, and they do not all enforce them. Some supervise organisations directly. Some coordinate national authorities. Some advise, investigate, interpret or decide disputes. The boundaries matter because they determine where guidance comes from, who can take action and which legal question is actually being answered.

 This guide is designed for DPOs, privacy and compliance leaders, and those building a working understanding of European governance for qualifications such as CIPP/E or AIGP. Its purpose is not to memorise an organisation chart. It is to make the system usable.

### Start with the EU institutions that make legislation

 The European Commission normally proposes EU legislation. The European Parliament and the Council of the European Union then act as co-legislators through the relevant legislative process. The Commission also adopts some delegated and implementing acts where the legislation gives it that power.

 This distinction helps when reading regulatory news. A Commission proposal is not yet law. A political agreement is an important step, but the final legal text still matters. Once an instrument has been adopted, its entry-into-force and application provisions determine when obligations bite.

 For operational teams, the source hierarchy should therefore be clear: the enacted law on EUR-Lex is the primary legal text. Commission pages, regulator guidance and expert commentary can make it intelligible, but they should not silently replace it.

> "The EU has announced" is not a reliable compliance date. Teams need to know whether they are looking at a proposal, an adopted act, guidance or an enforcement decision.

### National supervisory authorities enforce the GDPR locally

 Each EU and EEA state has one or more independent data protection supervisory authorities. They monitor and enforce the GDPR within their competence, handle complaints, conduct investigations, issue corrective measures and advise on data protection matters.

 For cross-border processing, the GDPR's cooperation and consistency mechanisms can bring several authorities into the same matter. The lead supervisory authority model is important, but it does not mean that every issue involving a multinational organisation automatically belongs only to the authority where the organisation has its headquarters. The establishment, decision-making arrangements, processing facts and nature of the complaint still need to be considered.

 The practical starting point for an organisation is its relevant national supervisory authority or authorities. In Ireland, for example, that is the Data Protection Commission. Our analysis of the [DPC Annual Report 2025](https://xpertdpo.com/dpc-annual-report-2025-dpo-privacy-governance/) considers the operational signals coming from national supervision.

### The EDPB drives consistency under the GDPR

 The [European Data Protection Board](https://www.edpb.europa.eu/about-edpb/tasks-and-duties_en) is an independent EU body made up principally of the heads of national supervisory authorities and the EDPS. It helps ensure consistent application of the GDPR and the Law Enforcement Directive across the EEA.

 Its work includes guidelines, recommendations and best-practice materials; consistency opinions; advice to the European Commission; and binding decisions in certain cross-border disputes between supervisory authorities. The EDPB does not usually replace the national authority as the frontline investigator of an organisation.

 Guidelines are highly influential but must be read with their status in mind. Draft guidelines are open to consultation. Final guidelines state the Board's interpretation but are not legislation. Binding dispute decisions perform a different function again.

 The EDPB's [Annual Report 2025](https://xpertdpo.com/edpb-annual-report-for-2025/) is therefore best read as a map of consistency work and regulatory direction, not as the activity report of a single EU-wide enforcement authority.

### The EDPS supervises EU institutions

 The [European Data Protection Supervisor](https://www.edps.europa.eu/about/about-us_en) is the independent data protection authority for EU institutions, bodies, offices and agencies. Its main data protection framework is Regulation (EU) 2018/1725.

 The EDPS directly supervises EU bodies, investigates and audits their processing, handles relevant complaints and advises the EU institutions on legislation and policy affecting data protection. It also participates in the EDPB.

 The EDPS is therefore both a supervisor in its own jurisdiction and an influential institutional adviser. It should not be confused with the EDPB, and it is not the ordinary supervisory authority for private organisations operating across the EU. Our separate review of the [EDPS Annual Report 2025](https://xpertdpo.com/edps-annual-report-2025-dpo-ai-governance/) explains why its work still provides valuable signals for corporate governance.

### The CJEU gives authoritative interpretations of EU law

 The Court of Justice of the European Union (CJEU) ensures that EU law is interpreted and applied consistently. National courts can refer questions about the interpretation or validity of EU law through the preliminary-ruling procedure. The CJEU also hears direct actions within its jurisdiction.

 This is why important privacy principles may be shaped by judgments arising from national disputes. Regulator guidance can explain how an authority understands the law, but a CJEU judgment is authoritative on the point of EU law it decides.

 For DPOs, case names matter less than the operational rule that follows. A mature legal-update process should identify which processing, contracts, notices, transfer arrangements or rights-handling decisions are affected, and whether the judgment changes a settled organisational position.

### Who governs and enforces the AI Act?

 At EU level, the European AI Office sits within the European Commission. It supports implementation of the AI Act and directly supervises and enforces the rules for providers of general-purpose AI models. Following the 2026 AI Omnibus amendments, its remit also covers a defined subset of AI systems based on those models.

 The Commission has additional responsibilities under the Act, including implementation measures, guidance, coordination and support for innovation. The AI Office is therefore important, but it is not the sole EU regulator for every AI system.

 Most AI-system supervision is carried out at Member State level by national competent authorities. Before deciding which authority or obligation matters, organisations must understand the system, sector and their own role as provider, deployer, importer, distributor or product manufacturer. Our [AI Act role-mapping guide](https://xpertdpo.com/ai-act-role-mapping-provider-deployer-importer-and-distributor/) provides a practical route through that first classification.

 At national level, Member States designate competent authorities. Market surveillance authorities supervise and enforce compliance for AI systems, including prohibited practices and high-risk requirements. Notifying authorities are responsible for bodies carrying out third-party conformity assessment.

 The national structure may involve more than one authority, especially where existing sector regulators are used. Each Member State must also identify a single point of contact. Organisations should not assume that the data protection authority will automatically be the general AI Act market surveillance authority in every country.

 Fundamental-rights authorities, including data protection and equality bodies, have specific information and cooperation rights where AI systems may affect the rights they protect. This makes cross-regulatory working a feature of the system, not an exceptional event.

> One AI use case can attract several regulators without those regulators enforcing the same rule.

 Coordination is provided by the European Artificial Intelligence Board, which is composed of representatives from the Member States. It advises and assists the Commission and Member States and supports consistent implementation and cooperation.

 The AI Board is supported by the AI Office, which acts as its secretariat. The EDPS participates as an observer. The Board can shape common approaches and recommendations, but organisations should not describe it as the authority that ordinarily investigates and fines providers or deployers.

 Two further bodies provide expert and stakeholder input. The Scientific Panel consists of independent experts with a particular role in relation to general-purpose AI risks and evaluation. The Advisory Forum brings perspectives from industry, civil society, academia and other stakeholders.

 These bodies influence implementation. They do not erase the legal responsibilities of the Commission, AI Office or national authorities.

### Where does the EDPB fit with the AI Act?

 The EDPB does not enforce the AI Act as such. Its mandate remains centred on consistent application of EU data protection law. National data protection authorities likewise enforce data protection law when personal data is processed through AI systems.

 The overlap is nevertheless substantial. Training data, prompts, monitoring, biometric processing, automated decisions, transparency, purpose limitation, rights and security can all engage the GDPR. An AI Act classification does not determine GDPR compliance, and a DPIA does not determine AI Act compliance.

 That is why organisations should connect assessments without treating them as interchangeable. Each instrument should retain its own legal test, accountable owner and conclusion even where the underlying evidence is shared.

### A usable way to read the governance map

 When a new opinion, guideline, judgment or enforcement announcement appears, ask five questions.

1. **Who issued it?** Identify the institution and its legal mandate.
2. **What kind of instrument is it?** Legislation, draft guidance, final guidance, opinion, decision, judgment or policy statement.
3. **Who is directly affected?** EU institutions, national authorities, providers, deployers, controllers, processors or a particular sector.
4. **Is it binding?** If so, on whom and from when? If not, what weight should it carry?
5. **What changes operationally?** Identify the affected owner, process, evidence and decision.

 This simple discipline prevents two common errors: treating every EU publication as immediately binding, and dismissing non-legislative material that gives a clear warning about future scrutiny.

 For example, suppose an organisation introduces an AI recruitment-screening system across several Member States. The national AI market surveillance authority may examine the system's AI Act classification and controls. A data protection authority may examine applicant data, transparency, legal basis, DPIA and automated decision-making. An equality body may consider discriminatory effects. The EDPB or AI Board may shape consistent approaches, while a later CJEU judgment could clarify the governing EU law. The organisation therefore needs one verified factual record, but separate legal analyses and accountable responses for each regime.

### The XpertDPO view

 European governance is layered by design. Different institutions make law, supervise different actors, coordinate authorities, provide expertise and interpret legal questions. That can be frustrating, but the answer is not to pretend that one body owns the entire privacy and AI landscape.

 For DPOs and compliance leaders, the practical objective is a governance map tied to the organisation's own activities. It should identify relevant laws, authorities, sectors, establishments and escalation routes. It should also show where evidence can be reused and where a separate legal test or accountable decision is required.

> A useful governance map does not merely name the institutions. It tells the organisation who must act when a real issue arrives.

 XpertDPO supports in-house teams through [DPO support](https://xpertdpo.com/dpo-support/), including regulatory interpretation, decision review and the design of evidence-led privacy and AI governance arrangements.

### What This Means for CPD

 For Event A Hour 1, learners should be able to distinguish the institutions that make EU law, interpret it, coordinate regulators and supervise organisations. The practical test is whether they can identify the issuer, legal mandate, status and operational significance of a new European development before advising the organisation.

 This article is intended to support the learning covered in Hour 1 of our XpertAcademy CPD programme. The relevant CPD certificate is issued for completion of the full one-hour session on XpertAcademy, rather than for reading this article on its own. [Return to CPD Event A: Full-Day Regulatory Privacy Training](https://xpertacademy.com/cpd-event-a-regulatory/).

### Sources

- European Commission, [How EU law is made](https://european-union.europa.eu/institutions-law-budget/law/how-eu-policy-decided_en)
- EDPB, [Tasks and duties](https://www.edpb.europa.eu/about-edpb/tasks-and-duties_en)
- EDPS, [About the EDPS](https://www.edps.europa.eu/about/about-us_en)
- CJEU, [About the Court of Justice of the European Union](https://curia.europa.eu/site/jcms/d2_5390/en/about-the-court-of-justice-of-the-eu)
- European Commission, [Governance and enforcement of the AI Act](https://digital-strategy.ec.europa.eu/en/policies/ai-act-governance-and-enforcement)
- European Commission, [Market surveillance authorities under the AI Act](https://digital-strategy.ec.europa.eu/en/policies/market-surveillance-authorities-under-ai-act)
- European Commission, [AI Board](https://digital-strategy.ec.europa.eu/en/policies/ai-board)

## General Information Only

This article is provided for general information and does not constitute legal, regulatory, or professional advice. Data protection obligations depend on the specific facts, context, and jurisdiction involved. You should not rely on this content as a substitute for advice tailored to your organisation.

If you would like support with a specific issue, please contact us: https://xpertdpo.com/contact/
