Authority Powers for Fundamental Rights Protection
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed because the content specifically addresses the powers and authorities granted to competent authorities to protect fundamental rights in AI systems, including inspection, intervention, and corrective action powers that are not adequately covered by existing topics.
Overview
24 sources · Jul 23, 2026Legal Framework
Authority powers for fundamental rights protection operate at the intersection of the GDPR and the AI Act. Under Article 58(2) GDPR, supervisory authorities wield corrective powers including the ability to impose temporary or definitive processing bans, order suspension of data flows to third countries, and initiate judicial proceedings. Article 58(1) GDPR confers extensive investigative powers to handle complaints and conduct inquiries. These powers are framed as discretionary competencies rather than mandatory obligations — a distinction confirmed by the CJEU and Dutch administrative courts, which have held that Recital 148 GDPR does not compel authorities to sanction every infringement with at minimum a reprimand.
The AI Act reinforces this architecture. Article 20 of the AI Act obliges providers of high-risk AI systems to implement corrective measures and notification duties when systems fail to comply with requirements. Article 27 of the AI Act introduces a fundamental rights impact assessment specific to high-risk AI deployments, requiring organizations to evaluate impacts on rights and freedoms before and during operation. Recital 155 of the AI Act underscores the need for post-market monitoring systems to detect and address emerging risks, including interactions between AI systems and other software or devices.
Article 82(4) GDPR establishes the liability regime underpinning these enforcement powers, ensuring data subjects can exercise rights against any joint controller — a principle that predates the GDPR under the 1995 Data Protection Directive and was affirmed by the Article 29 Working Party in Opinion 1/2010.
Key Developments
The CJEU's ruling in Data Protection Commissioner v. Facebook Ireland Ltd and Maximillian Schrems (C-362/14) established that national supervisory authorities are independently responsible for verifying whether data transfers to third countries comply with EU requirements, regardless of Commission adequacy decisions. The Court emphasized that this responsibility is of paramount importance for fundamental rights protection. Schrems II further reinforced that Article 58(2)(f) and (j) GDPR empower authorities to impose processing bans and suspend data flows when third-country protection is inadequate.
Dutch jurisprudence (ECLI:NL:RVS:2021:1407) clarified that corrective measures under Article 58(2) GDPR constitute a discretionary power, not a duty — meaning authorities may calibrate enforcement responses proportionally rather than mechanically penalizing every violation. A subsequent Dutch case confirmed that complainants cannot compel authorities to adopt specific corrective measures, reinforcing the discretionary nature of enforcement.
Enforcement practice demonstrates the scale of these powers. The Croatian DPA imposed a €4.5 million fine on a telecommunications operator for multiple GDPR violations, while the Spanish DPA has exercised corrective powers even for relatively minor infractions, showing authorities' willingness to act across the full spectrum of non-compliance.
Practical Guidance
Maintain a post-market monitoring system for high-risk AI systems that includes analysis of interactions with other AI systems, devices, and software, as required by Recital 155 of the AI Act and Article 20 of the AI Act. Document corrective actions taken and their outcomes.
Conduct a fundamental rights impact assessment under Article 27 of the AI Act before deploying high-risk AI systems, identifying specific risks to data subject rights and documenting mitigation measures.
Prepare for authority inspections by maintaining an up-to-date processing activity register that can be produced on request, recognizing that supervisory authorities may investigate complaints and exercise corrective powers including processing bans and data flow suspensions under Article 58(2) GDPR.
Establish clear internal escalation procedures for responding to authority inquiries, including designated points of contact for representatives under Article 27 GDPR who must cooperate with supervisory authorities on all compliance measures.
Do not assume proportionality in enforcement will shield non-compliance: while authorities exercise discretion under Article 58(2) GDPR, the Schrems line of cases confirms that authorities must act when fundamental rights are at risk, and complainants' complaints trigger investigative obligations under Article 58(1) GDPR.