EDPB 1/2018
Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation (Annex 2), version 3.0
What it covers
This document explains the purpose and key concepts of certification under Articles 42 and 43 GDPR, the respective roles of supervisory authorities, certification bodies and the EDPB in approving certification criteria, and how certification criteria should be developed and evaluated, and its Annex 2 sets out a target-of-evaluation framework covering GDPR principles, lawfulness, data subject rights and technical measures.
Why it matters
It is the foundational EDPB guidance on how the voluntary GDPR certification mechanism should operate, relevant to anyone designing, approving or relying on a certification scheme or seal.
Refer to it when
- designing certification criteria for a certification scheme
- understanding the approval process for a European Data Protection Seal
- assessing what a certification body may and may not certify
- considering certification as a factor in an administrative fine
Questions this document addresses
- What is the purpose of certification under Articles 42 and 43 GDPR?
- Who approves certification criteria and how?
- What can and cannot be certified under the GDPR?
- How does adherence to certification affect administrative fines?
Topics
- Certification & accreditation
- Supervisory authorities
- Controller & processor
- Administrative fines
Explains how data protection certification mechanisms, seals and marks work under the GDPR and sets out the criteria supervisory authorities and the EDPB use when approving certification criteria. Annex 2 provides the guidance for identifying certification criteria.
Mapped GDPR Articles
Reproduced from official EDPB publications for reference. Not legal advice.