GDPR Article 77 — complaint to a data protection supervisory authority
- Type
- Public reporting channel
- Place
- European Union — EU/EEA (and UK equivalent)
- Last checked
- 2026-09-22
- Next check due
- 2027-03-21
Ways to reach them
- Submission page
- Homepage
What it does
Complaints from any data subject who considers that processing of their personal data infringes the GDPR. You may complain to the authority in your Member State of habitual residence, your place of work, or the place of the alleged infringement.
Honest assessment
The most battle-tested adjacent route, with a real enforcement record against AI systems (the Italian Garante's ChatGPT actions being the best-known). Its power is the duty to inform you of progress and outcome — a stronger procedural guarantee than Article 85 of the AI Act gives. Its limit is that it only bites where personal data is involved.
How to file
File with the chosen supervisory authority, usually via their online form. Frame the concern in data protection terms — lawful basis, accuracy, transparency, Article 22 automated decision-making — because a concern framed as 'this AI is unsafe' will be rejected as out of scope, while the same facts framed as a data protection issue may be entertained.
Format
Authority-specific form; identify the controller, the processing, the provision breached, and the effect on you.
Timing
Rolling.
What happens after
The supervisory authority must inform the complainant of the progress and outcome of the complaint, and of the possibility of a judicial remedy under Article 78. Without prejudice to other remedies.
What it accepts
Complaints from any data subject who considers that processing of their personal data infringes the GDPR. You may complain to the authority in your Member State of habitual residence, your place of work, or the place of the alleged infringement.
What it does not accept
Concerns that do not involve processing of personal data. This is the key limit for AI safety work: it reaches training data, inference on personal data, profiling, automated decision-making and accuracy of personal data, but not model capability, misuse potential or catastrophic risk.
Operated by
National data protection authorities (EU/EEA); ICO in the UK