While the GDPR is a European regulation, its enforcement is primarily carried out by independent Data Protection Authorities (DPAs) in each member state . These authorities are responsible for monitoring the application of the regulation within their jurisdiction and have the power to investigate complaints, conduct audits, and impose sanctions, including substantial administrative fines. In cases where a company operates in multiple EU countries, the Lead Supervisory Authority concept applies, with the DPA of the company’s main establishment acting as the primary point of contact. A good example of this is the Irish Data Protection Commission (DPC), which has acted as the lead authority for major tech companies in a number of high-profile cases, including an investigation into Meta’s use of personal data for training its AI models . This multi-layered system is designed to ensure that the GDPR is consistently enforced across the entire EU, with national authorities cooperating to protect the rights of all European citizens.