EDPB 4/2018
Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the Regulation (Annex 1), version 3.0
What it covers
These guidelines, including their Annex 1, interpret Article 43 GDPR on the accreditation of certification bodies, covering the two accreditation routes, the role of Member States, supervisory authorities and national accreditation bodies, and the detailed legal, structural, resource, process and management system requirements certification bodies must meet.
Why it matters
It is the reference for national accreditation bodies, supervisory authorities and certification bodies establishing a harmonised, GDPR-compliant accreditation scheme under Article 43.
Refer to it when
- setting up or assessing an accreditation scheme for certification bodies
- determining whether a supervisory authority may act as a certification body
- reviewing a certification body's impartiality, resource or complaints-handling arrangements
- understanding the additional requirements a supervisory authority may impose on accreditation
Questions this document addresses
- What are the two routes for accrediting a certification body under Article 43(1)?
- What additional requirements can a supervisory authority impose on accreditation?
- What structural and resource requirements must a certification body satisfy?
- How must a certification body manage impartiality, complaints and withdrawal of certification?
Topics
- Certification & accreditation
- Supervisory authorities
- Controller & processor
Sets out the requirements supervisory authorities apply when accrediting certification bodies that issue GDPR certifications, including independence, expertise and complaint-handling requirements. Annex 1 contains the accreditation requirements template.
Mapped GDPR Articles
Reproduced from official EDPB publications for reference. Not legal advice.