EDPB 1/2019
Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679, version 2.0
What it covers
These guidelines explain the purpose and benefits of codes of conduct under Articles 40 and 41 GDPR, the admissibility and approval criteria for national and transnational codes, the accreditation requirements for monitoring bodies that oversee compliance, and the procedures for approval, monitoring, and revocation.
Why it matters
It is the primary EDPB reference for organisations or sector bodies wishing to develop, submit or monitor a GDPR code of conduct, and for supervisory authorities assessing such submissions.
Refer to it when
- drafting a code of conduct for approval
- assessing whether a code meets GDPR approval criteria
- seeking accreditation as a monitoring body
- understanding the transnational code approval process involving the Board
Questions this document addresses
- What criteria must a code of conduct meet for approval?
- What is the difference between national and transnational code approval procedures?
- What accreditation requirements apply to monitoring bodies?
- What happens when a monitoring body's accreditation is revoked?
Topics
- Codes of conduct
- Supervisory authorities
Explains how sectoral codes of conduct are drafted, submitted, approved and monitored, the difference between national and transnational codes, and the accreditation requirements for the bodies that monitor compliance with a code.
Mapped GDPR Articles
Reproduced from official EDPB publications for reference. Not legal advice.