← Back to Explainers
LEAKLENS EXPLAINER · 2026-07-01

What a Data Protection Authority Actually Does — And What Happens Without One

A comprehensive breakdown of Data Protection Authorities (DPAs), GDPR enforcement powers, regulatory sanctions, data breach notifications, and civic privacy rights.

Overview

Data Protection Authorities (DPAs) are independent public supervisory bodies established to enforce data privacy laws, protect personal data rights, and audit corporate or governmental compliance.

Key Powers of a DPA

  • Investigative Powers: Authority to audit corporate databases, request data protection impact assessments (DPIAs), and order access to system logs.
  • Corrective Powers: Power to issue warnings, order compliance corrections, impose temporary or definitive bans on data processing, and order data deletion.
  • Financial Sanctions: Ability to levy significant administrative fines (e.g., up to €20 million or 4% of global annual turnover under GDPR).
  • Breach Incident Oversight: Mandatory 72-hour data breach notification processing and public disclosure audits.
  • Civic Privacy Rights & Remediation

    When personal data is exposed in a data breach: