When a GDPR supervisory authority requests cooperation during an investigation or compliance audit, controllers and processors need a structured way to document their assistance and responses. This GDPR Article 31 Supervisory Authority Cooperation Form helps organisations systematically record their cooperation activities, information provided, and compliance measures taken during supervisory authority engagements.
Under Article 31 of the GDPR, controllers and processors must cooperate with supervisory authorities on request, providing information, documentation, and access necessary for investigations. This form template streamlines that process by capturing investigation details, the nature of assistance provided, documentation submitted, and internal compliance measures—creating a clear audit trail that demonstrates good-faith cooperation.
Built for Data Protection Officers, legal teams, compliance managers, and privacy professionals across the EU who need to respond to supervisory authority requests efficiently and transparently. Whether you're handling routine compliance checks, responding to data breach investigations, or participating in cross-border cooperation procedures, this template provides the structure you need.
Paperform's conditional logic automatically adapts the form based on whether you're acting as a controller or processor, the type of investigation, and the nature of assistance requested. You can attach supporting documentation directly to the form, use calculations to track response timelines against legal deadlines, and route submissions to the right stakeholders using Stepper (stepper.io) workflows that notify legal counsel, update compliance logs, and trigger follow-up actions automatically.
For organisations managing multiple entities or client data protection matters, Paperform's Agency+ features let you deploy separate forms for each legal entity while maintaining centralised oversight. Combined with SOC 2 Type II compliance and EU data residency options, you can trust that your supervisory authority cooperation records meet the same high standards you're being audited against.
Turn regulatory cooperation from a reactive scramble into a documented, repeatable process—and demonstrate your commitment to GDPR compliance at every stage of the supervisory relationship.
Notify data subjects of privacy policy changes and collect updated consent in compliance with GDPR requirements. Ensure transparent communication and maintain regulatory compliance.
Comprehensive GDPR compliance documentation form for data controllers to record policies, procedures, training records, and audit results demonstrating accountability under EU data protection law.
Notify customers of business ownership transfer and obtain consent for data processing continuity under new data controller, with clear opt-out rights per GDPR requirements.
A comprehensive form for multinational groups to apply for Binding Corporate Rules (BCR) approval, enabling compliant intra-group personal data transfers across borders under GDPR requirements.
A comprehensive GDPR-compliant agreement form for joint controllers to document shared data processing responsibilities, allocate obligations, and ensure transparent compliance under Article 26 of the GDPR.
A comprehensive form for documenting personal data processing activities and data flows across systems to maintain Article 30 GDPR Records of Processing Activities (RoPA) compliance.
Log and track data deletion activities, responsible parties, and compliance with GDPR retention schedules. Maintain a comprehensive audit trail for regulatory oversight and internal accountability.
A GDPR Article 37 compliant form for notifying supervisory authorities and documenting Data Protection Officer appointments, including contact details and responsibilities.
Allow data subjects to formally object to processing based on legitimate interests under GDPR Article 21, with space to specify compelling grounds and personal circumstances.
A comprehensive GDPR-compliant form for verifying and processing customer data anonymization requests, ensuring technical feasibility and permanent de-identification under EU data protection regulations.
Structured assessment form to evaluate data breaches and determine if notification to supervisory authority is required under GDPR Article 33 within 72 hours.
A comprehensive tracking form for Data Protection Officers to log and monitor GDPR data subject access requests (DSARs), including request type, priority, response times, and compliance metrics for regulatory reporting.