• Courses
      • Executive Management Courses
      • Global Series of National Privacy Laws
      • Netherlands Privacy Academy (in Dutch)
      • Caribbean Data Protection Academy
    • Resources
    • Join GADPPRO ACADEMY
      • Join GADPPRO Academy as an Official Partner
      • Become an Official GADPPRO Training Entity
      • Join the GADPPRO Business Academy
      • Secretariat & International Training Centre
      • Contact Us
    •  
      • RegisterLog in
    Privacad GADPPRO Academy
      • Courses
        • Executive Management Courses
        • Global Series of National Privacy Laws
        • Netherlands Privacy Academy (in Dutch)
        • Caribbean Data Protection Academy
      • Resources
      • Join GADPPRO ACADEMY
        • Join GADPPRO Academy as an Official Partner
        • Become an Official GADPPRO Training Entity
        • Join the GADPPRO Business Academy
        • Secretariat & International Training Centre
        • Contact Us
      •  
        • RegisterLog in

      Blog

      Certification and identifying certification criteria in accordance with Articles 42 and 43 of the GDPR

      • Categories Blog, Business, Design / Branding, Free Data Protection Resources, Uncategorized
      • Date November 6, 2020

      Guidelines 01/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the GDPR

      Section 2.2  Supervisory Authority’s further tasks regarding certification

      24. In Member States where certification bodies become active, the supervisory authority has the power and task irrespective of its own activities:

      • to assess a certification scheme’s criteria and make a draft decision (Article 42(5));

      • to communicate to the Board the draft decision when it intends to approve the criteria for certification (Article 64(1)(c), 64(7)) and consider the Board’s opinion (Article 64(1)(c) and 70(1)(t));

      • to approve the criteria for certification (Article 58(3)(f)) before accreditation and certification can take place (Article 42(5) and 43(2)(b));

      • to publish the certification criteria (Article 43(6);

      • to act as competent authority for EU wide certification schemes, which may result in an EDPB approved European Data Protection Seals (Articles 42(5) and Article 70(1)(o); and

      • to order a certification body (a) not to issue certification or (b) to withdraw certification where the requirements for certification (certification procedures or criteria) are not or are no longer met (Article 58(2)(h).

      25. The GPDR tasks the supervisory authority with approving certification criteria but not with developing criteria. In order to approve certification criteria under Article 42(5), a supervisory authority should have a clear understanding of what to expect, specifically in terms of scope and content for demonstrating compliance with the GDPR and with regard to its task to monitor and enforce the application of the regulation. The annex provides guidance to ensure a harmonized approach when assessing criteria for the purpose of approval.

      26. Article 43(1) requires certification bodies to inform their supervisory authority before issuing or renewing certifications to allow the competent supervisory authority to exercise its corrective powers under point (h) of Article 58(2). Additionally, Article 43(5) also requires certification bodies to provide the competent supervisory authority with the reasons for granting or withdrawing the requested certification. Although the GDPR allows for supervisory authorities to determine how to receive, acknowledge, review and deal with this information operationally (for example, this could include technological solutions to enable reporting by certification bodies), a process and criteria to process the information and reports provided on each successful certification project by the certification body according to Article 43(1) may be put in place. On the basis of this information, the supervisory authority can exercise its power to order the certification body to withdraw or not issue a certification (Article 58(2)(h)) and to monitor and enforce the application of the requirements and criteria of certification under the GDPR (Article 57(1)(a) and 58(2)(h)). This will support a harmonized approach and comparability in certification by different certification bodies and that information about an organisation’s certification status is known by supervisory authorities.

      • Share:
      User Avatar
      Richard V

      Previous post

      Certification and identifying certification criteria in accordance with Articles 42 and 43 of the GDPR
      November 6, 2020

      Next post

      Certification and identifying certification criteria in accordance with Articles 42 and 43 of the GDPR
      November 6, 2020

      You may also like

      Children Safety Encryption www.privacad.com
      Apple’s New Step to Protect Child Abuse via Encryption Feature
      20 August, 2021
      DNA Technology and Privacy www.privacad.com
      DNA Technology Regulation Bill and Violation of Privacy for Minority Groups
      19 August, 2021
      www.privacad.com
      India accuses Twitter of not complying with new IT rules
      18 August, 2021

      Search

      Categories

      • Blog
      • Business
      • Design / Branding
      • Free Data Protection Resources
      • Nederlandse Privacy Academie
      • Uncategorized
      Facebook-f Linkedin-in

      © Privacad 2020

      For all your questions about courses

      students@privacad.com

      For all your questions about Privacad for business

      info@privacad.com

      Links

      • Courses
      • Become a GADPPRO Academy Official Training Entity
      • Resources
      • Free Data Protection Resources
      • Blog
      • Profile
      • Students Stewards Network (SSN)

      Support

      • Privacy Policy
      • Terms of Use
      • FAQs
      • Contact

      © GADPPRO Academy | Privacad 2023

      GADPPRO Academy 2023

      Login with your site account

      Lost your password?

      Not a member yet? Register now

      Register a new account

      Are you a member? Login now