As a data controller or data processor you are as a rule to be in contact with only one member state's supervisory authority, the so-called "lead supervisory authority". If you for example suffer a personal data breach that affects your activities in several member states, you only need to report it to your lead supervisory authority. The lead supervisory authority then coordinates investigations that concern other supervisory authorities.
Your lead supervisory authority is where you have your main activities
To know which supervisory authority is your lead supervisory authority you need to determine where your main or only activities are carried out.
If you are a data controller, your main or only establishment is:
where you have your central administration (head office) unless the decisions concerning the purposes and means of the personal data processing are taken at another establishment within the Union and that establishment can have such decisions implemented. If so, that establishment is your main establishment.
If you are a data processor, your main or only establishment is:
where you have your central administration (head office) or, if you do not have any central administration within the Union, your establishment in the Union where the main personal data processing is carried out.
If both data controllers and data processors are involved in the personal data processing, the controller's lead supervisory authority is also the lead supervisory authority for the data processor.
Also note that you can have different lead supervisory authorities for different instances of personal data processing if you decide the purposes and means of personal data processing in different places in the European Union. When you begin a new instance of personal data processing, it is therefore important that you assess which supervisory authority will be your lead supervisory authority.
Consider whether it is possible to allow an establishment to take decisions regarding several different instances of personal data processing. You will then not need to be in contact with several different supervisory authorities for different instances of personal data processing.