GDPR Learning Hub

Welcome! Here you can read the full GDPR text (only in English).

Article 54 GDPR

Rules on the establishment of the supervisory authority

1.   Each Member State shall provide by law for all of the following:

(a)

the establishment of each supervisory authority;

(b)

the qualifications and eligibility conditions required to be appointed as member of each supervisory authority;

(c)

the rules and procedures for the appointment of the member or members of each supervisory authority;

(d)

the duration of the term of the member or members of each supervisory authority of no less than four years, except for the first appointment after 24 May 2016, part of which may take place for a shorter period where that is necessary to protect the independence of the supervisory authority by means of a staggered appointment procedure;

(e)

whether and, if so, for how many terms the member or members of each supervisory authority is eligible for reappointment;

(f)

the conditions governing the obligations of the member or members and staff of each supervisory authority, prohibitions on actions, occupations and benefits incompatible therewith during and after the term of office and rules governing the cessation of employment.

2.   The member or members and the staff of each supervisory authority shall, in accordance with Union or Member State law, be subject to a duty of professional secrecy both during and after their term of office, with regard to any confidential information which has come to their knowledge in the course of the performance of their tasks or exercise of their powers. During their term of office, that duty of professional secrecy shall in particular apply to reporting by natural persons of infringements of this Regulation.

Suitable recitals

  • Recital 117: Establishment of Supervisory Authorities
  • Recital 121: Independence of the Supervisory Authorities
GDPR Learning Hub Logotype 2024

We teach companies and their employees about the EU General Data Protection Regulation (GDPR). It is an EU regulation that all companies within the EU/EEA must comply with. GDPR is also applicable to companies registered outside of the EU/EEA, if they process personal data that belongs to individuals within the EU/EEA.

Scroll to Top