Certification and identifying certification criteria in accordance with Articles 42 and 43 of the GDPR
Guidelines 01/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the GDPR
Section 1.1 Scope of the guidelines
7. These guidelines are limited in scope; they are not a procedural manual for certification in accordance withthe GDPR. The primary aim of these guidelines is to identify overarching requirements and criteria that may be relevant to all types of certification mechanisms issued in accordance with Articles 42 and 43 of the GDPR. To this end, the guidelines:
-
explore the rationale for certification as an accountability tool;
-
explain the key concepts of the certification provisions in Articles 42 and 43; and
-
explain the scope of what can be certified under Articles 42 and 43 and the purpose of certification;
-
facilitate that the outcome of certification is meaningful, unambiguous, as reproducible as possible and comparable regardless of the certifier (comparability).
8. The GDPR allows for a number of ways for Member States and supervisory authorities to implement Articles 42 and 43. The guidelines provide advice on the interpretation and implementation of the provisions in Articles 42 and 43 and will help Member States, supervisory authorities and national accreditation bodies establish a more consistent, harmonised approach for the implementation of certification mechanisms in accordance with the GDPR.
9. The advice contained in the guidelines will be relevant for:
-
competent supervisory authorities and the European Data Protection Board (‘the EDPB’) when approving certification criteria under Article 42(5), Article 58(3)(f) and Article 70(1)(o);
-
certification bodies when drafting and revising certification criteria prior to submission to the competent supervisory authority for approval as per Article 42(5);
-
the EDPB when approving a European Data Protection Seal under Articles 42(5) and 70(1)(o);
-
supervisory authorities, when drafting their own certification criteria;
-
the European Commission, which is empowered to adopt delegated acts for the purpose of specifying the requirements to be taken into account for certification mechanisms under Article 43(8);
-
the EDPB when providing the European Commission with an opinion on the certification requirements in accordance with Article 70(1)(q) and Article 43(8);
-
national accreditation bodies, which will need to take into account certification criteria with a view to the accreditation of certification bodies in accordance with EN-ISO/IEC 17065/2012 and the additional requirements in accordance with Article 43; and
-
controllers and processors when defining their own GDPR compliance strategy and considering certification as a means to demonstrate compliance.