TOTAL: {[ getCartTotalCost() | currencyFilter ]} Update cart for total shopping_basket Checkout


The introduction of the provisions on the data protection certification mechanisms in the EU General Data Protection Regulation in 2016 was welcomed with mixed feelings: high expectations on a new voluntary accountability tool but skepticism at the same time, especially for the client relationship of applicant controllers or processors and certification bodies. Since 2016, the developments on the basis of Articles 42 and 43 of the GDPR have been slower than expected. The European Data Protection Board's guidance on certification and accreditation was published in the third and final version in June 2019. Guidance on certification in the context of data transfers is still expected, despite the recent acknowledgment from the European Council about the usefulness of such transfer mechanisms and the pending cases at the Court of Justice of the European Union (see advocate general opinion Paragraph 342 expressing doubts on the conformity of the Privacy Shield decision with the GDPR).  

At the EU level, there has not been yet a European data protection seal approved by the European Data Protection Board, while at the national level, some developments are now starting to emerge. A comprehensive initiative is coming from the Luxembourg supervisory authority, which developed certification criteria and a "certification mechanism" based on the International Standard on Assurance Engagements, which was originally destined for auditors and accountants. Other pre-GDPR data protection certifications, most of them not yet approved by the national supervisory authorities, are being updated and submitted for approval. Much of the delay is due to the uncertainties of the GDPR articles regarding key aspects of the mechanisms (for example, the difference between seals and marks), in combination with the novelty of certification for the European data protection law that is accompanied with a lack of experience and know-how.

Taking stock of the study conducted by the Tilburg Institute for Law, Technology, and Society and TNO on behalf of Directorate-General Justice and Consumers of the European Commission, but also the EDPB guidelines, let's discuss some truths and myths about certification of Articles 42 and 43.

Myth #1: Certification under the GDPR is voluntary; thus, it bears no legal consequences

While indeed the GDPR certification is voluntary, as explicitly provided in Article 42(3) of the GDPR, meaning that a controller or processor is not obliged to apply for certification, certification is not entirely free from legal consequences. Once a controller or processor applies to an accredited certification body for certification and successfully goes through the certification process, there is a contractual relationship (certification agreement) established between the certification body and the controller/processor. The certification agreement is a legally enforceable agreement that ensures inter alia that the controller/processor continues to fulfill the criteria and requirements of the granted certification throughout its duration. The obligations under the certification agreement are independent to the obligations of the controller/processor to comply with the GDPR, even though some overlap is expected depending on the scope of certification (for example, an obligation to respect the Article 30 record-keeping obligation is likely part of most certifications).

Myth #2: Products, systems and persons can be certified 

As explained in the COM study, the wording of Articles 42(1) and 42(6) determines what is certified under the data protection certification mechanisms: processing activities. In its 1/2018 guidelines, the EDPB clarified that data protection officers are not included in the scope of Article 42. This does not entail that DPO schemes cannot exist (see, for example, the DPO scheme from the Spanish DPA). It means, however, that such schemes are not the accountability instruments of Articles 42/43 and will not be formally taken into account by the SA when it decides to impose a fine to a controller or a processor per Article 83 of the GDPR. When it comes to products and systems, the situation is not as straightforward as with the DPO certification. Products and systems cannot be certified as such for being GDPR compliant, but they are part of the evaluation for awarding the certification for data-processing activities. For example, a processor that has applied to have its data storing certified needs also to show to the certifying entity that its information-security management system provides all the necessary guarantees for a secure data storing. This is where a certification of an information-security management system might be useful but not necessary. This was also explained in an earlier report published by ENISA on "Recommendations for European Data Protection Certification."

Myth #3: GDPR certified means GDPR compliant

This is a common misconception. Once a controller/processor has its processing certified under a data protection certification mechanism, there is still no presumption of conformity with the legal obligations. In other fields, such as the EU legal framework for product safety, when a producer has its product conforming to harmonized standards, it’s presumed they comply with the relevant EU directive.

However, under the GDPR, certification plays a different role: that is to help the controller or processor show to the SA the technical and organizational measures taken to comply with the GDPR legal obligations. The assessment by the certifying body (either a DPA or certification body) that a processing is in line with the certification criteria is not a definite assessment of compliance with the GDPR. Rather, it helps showing that an organization has its "house in order" and dedicated considerable effort and resources for it, which is an element of accountability.

Myth #4: Certification to ISO standards is GDPR certification

Finally, it is important to draw a distinction between certifications on the one hand and ISO standards on the other. Technical and management standards, such as the ones developed by international or European standards organizations, including the well-known information security standard ISO/IEC 27001 or the new ISO/IEC 27701 on the Privacy Information Management Systems, are not necessarily part of a GDPR certification mechanism. Such standards are essentially different in nature: They are directed toward management systems and have a risk-management approach. Nevertheless, such standards can be a very useful building block in a data-protection-certification mechanism, as they are widely used, and the state of the art and conformity experience are potentially important added values to the development of a new data-protection mechanism.

Photo by Emily Morter on Unsplash

Credits: 1

Submit for CPEs


If you want to comment on this post, you need to login.

  • comment Jussi Leppälä • Feb 6, 2020
    Great summary. Thank you!
  • comment Ralph O'Brien • Feb 7, 2020
    Perhaps you could explain your reasoning behind point #4?  We wrote the ISO standards with very much the intention that they could be adopted by the SA and assessed by a competent CB approved by a national accreditation body.  
    Art 42 looks at “Controller and Processor processing operations” ie their management system surrounding personal data.  And the GDPR fully supports a risk management approach, really curious as to the reasoning on what we have all missed as to why ISO standards are somehow excluded?
  • comment Irene Kamara • Apr 9, 2020
    Thanks Jussi Leppälä!
    Thanks for your comments Ralph O'Brien. I explained to you my reasoning on LinkedIn. In brief, I will say here that the risk based approach in the GDPR relating to risks to rights and freedoms of the data subjects is different than risk management, where company risks are primarily taken into account. 
    I have to disagree with your interpretation of Art. 42: processing operations of controllers and processors are linked but not the same to management systems.
    This is clear also in the EDPB guidelines 1/2018 on certification.
    Last, my view that ISO standards are valuable sources of best practices and the SOTA, but not Art. 42 GDPR certification, is also shared by CNIL (which by the way participated in the development of the ISO/IEC 27701). See their recent post, published after I wrote this article:
    "ISO 27701 is a global standard: it is not GDPR specific, nor does it constitute, as such, a GDPR certification instrument as described in Article 42 of the regulation. However, it represents the state of the art in terms of privacy protection and will allow organizations adopting it to increase their maturity and demonstrate an active approach to personal data protection."
  • comment Arya Tripathy • Jan 16, 2021
    Thank you for this great write-up and as I check today, still a lot has to be done in this space. In India, a new law is proposed and expected in 2021, and it also contemplates certification mechanisms. Historically, India has looked for mature jurisdictions to navigate through its sui generis requirements, but looks like it will start with ISO standards.