GuidelinesFinal · v1.0

EDPB 1/2019

Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679, version 2.0

What it covers

These guidelines explain the purpose and benefits of codes of conduct under Articles 40 and 41 GDPR, the admissibility and approval criteria for national and transnational codes, the accreditation requirements for monitoring bodies that oversee compliance, and the procedures for approval, monitoring, and revocation.

Why it matters

It is the primary EDPB reference for organisations or sector bodies wishing to develop, submit or monitor a GDPR code of conduct, and for supervisory authorities assessing such submissions.

Refer to it when

  • drafting a code of conduct for approval
  • assessing whether a code meets GDPR approval criteria
  • seeking accreditation as a monitoring body
  • understanding the transnational code approval process involving the Board

Questions this document addresses

  • What criteria must a code of conduct meet for approval?
  • What is the difference between national and transnational code approval procedures?
  • What accreditation requirements apply to monitoring bodies?
  • What happens when a monitoring body's accreditation is revoked?

Topics

  • Codes of conduct
  • Supervisory authorities

Official EDPB page for this document

Explains how sectoral codes of conduct are drafted, submitted, approved and monitored, the difference between national and transnational codes, and the accreditation requirements for the bodies that monitor compliance with a code.

Inline PDF preview is not supported in this browser. Open the PDF instead.

Mapped GDPR Articles

Reproduced from official EDPB publications for reference. Not legal advice.