# What a Data Protection Authority Does — LeakLens Explainer

> A comprehensive breakdown of Data Protection Authorities (DPAs), GDPR enforcement powers, regulatory sanctions, data breach notifications, and civic privacy rights.

## Overview

Data Protection Authorities (DPAs) are independent public supervisory bodies established to enforce data privacy laws, protect personal data rights, and audit corporate or governmental compliance.

## Key Powers of a DPA

1. **Investigative Powers**: Authority to audit corporate databases, request data protection impact assessments (DPIAs), and order access to system logs.
2. **Corrective Powers**: Power to issue warnings, order compliance corrections, impose temporary or definitive bans on data processing, and order data deletion.
3. **Financial Sanctions**: Ability to levy significant administrative fines (e.g., up to €20 million or 4% of global annual turnover under GDPR).
4. **Breach Incident Oversight**: Mandatory 72-hour data breach notification processing and public disclosure audits.

## Civic Privacy Rights & Remediation

When personal data is exposed in a data breach:
- Individuals have the right to file formal complaints with their supervisory DPA.
- DPAs can order organizations to inform affected users directly.
- Independent civic registries like LeakLens provide transparent verification tools to track breach exposures.
