CHAPTER IVCONTROLLER AND PROCESSOR

Article 41Monitoring of approved codes of conduct

Official text

(1)Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58, the monitoring of compliance with a code of conduct pursuant to Article 40 may be carried out by a body which has an appropriate level of expertise in relation to the subject-matter of the code and is accredited for that purpose by the competent supervisory authority.

(2)A body as referred to in paragraph 1 may be accredited to monitor compliance with a code of conduct where that body has:

(a)demonstrated its independence and expertise in relation to the subject-matter of the code to the satisfaction of the competent supervisory authority;

(b)established procedures which allow it to assess the eligibility of controllers and processors concerned to apply the code, to monitor their compliance with its provisions and to periodically review its operation;

(c)established procedures and structures to handle complaints about infringements of the code or the manner in which the code has been, or is being, implemented by a controller or processor, and to make those procedures and structures transparent to data subjects and the public; and

(d)demonstrated to the satisfaction of the competent supervisory authority that its tasks and duties do not result in a conflict of interests.

(3)The competent supervisory authority shall submit the draft requirements for accreditation of a body as referred to in paragraph 1 of this Article to the Board pursuant to the consistency mechanism referred to in Article 63.

(4)Without prejudice to the tasks and powers of the competent supervisory authority and the provisions of Chapter VIII, a body as referred to in paragraph 1 of this Article shall, subject to appropriate safeguards, take appropriate action in cases of infringement of the code by a controller or processor, including suspension or exclusion of the controller or processor concerned from the code. It shall inform the competent supervisory authority of such actions and the reasons for taking them.

(5)The competent supervisory authority shall revoke the accreditation of a body as referred to in paragraph 1 if the requirements for accreditation are not, or are no longer, met or where actions taken by the body infringe this Regulation.

(6)This Article shall not apply to processing carried out by public authorities and bodies.

Commentary

At a glance

FunctionMonitoring adherence to an approved code of conduct
Monitoring bodyAccredited by the competent supervisory authority; must be independent and expert
PowersAssess eligibility, monitor, suspend or exclude members, report infringements
LimitDoes not replace the powers of the supervisory authority

Article 41 is the provision that gives practical credibility to Article 40.

Article 40 allows sectors to develop Codes of Conduct that explain how GDPR requirements should operate in a particular processing environment. But a Code would have limited value if an organisation could simply sign up to it and then decide for itself whether it was complying.

Article 41 addresses that problem by establishing the concept of a Monitoring Body.

The basic architecture is therefore:

Article 40 → creates the Code framework

Article 41 → creates the mechanism for monitoring adherence to that Code

The Monitoring Body is therefore not another general GDPR regulator. Its role is much more specific: it monitors whether organisations that have undertaken to follow a particular Code are actually following that Code.

This distinction is extremely important.

Suppose an association representing online advertising companies develops an approved Code dealing with behavioural advertising, transparency, profiling and data-subject rights.

A company joins that Code.

The Monitoring Body may then examine whether that company is complying with the Code's requirements, for example, whether its profiling disclosures actually satisfy the Code, whether its complaint mechanism operates properly, and whether it has implemented the security and governance measures required by the Code.

But the Monitoring Body does not suddenly become the company's general GDPR regulator.

That remains the role of the competent supervisory authority.

What is the Monitoring Body?

The Monitoring Body is the organisation responsible for monitoring compliance with the Code of Conduct by those controllers and processors that have undertaken to apply it.

The GDPR deliberately does not prescribe one particular organisational model.

The Monitoring Body may therefore be structured in different ways, provided that it satisfies the relevant requirements concerning independence, expertise, procedures and accreditation.

The EDPB has recognised that a Monitoring Body could, depending on the circumstances, be an external body or aninternal body, including an appropriately structured internal committee or department.

This flexibility is important because sectors differ substantially.

A large international industry may have the resources to establish an independent external monitoring organisation.

A smaller, specialised sector might establish a dedicated internal structure.

But the word "internal" should not be misunderstood.

An internal Monitoring Body cannot simply be another department controlled by the very organisations it is supposed to monitor.

Its independence must still be demonstrated to the satisfaction of the competent supervisory authority.

The Monitoring Body does not monitor everyone

This is a subtle but important limitation.

The Monitoring Body's responsibility is tied to the scope of the particular Code.

It monitors organisations that:

  1. fall within the Code's scope; and

  2. have undertaken to adhere to it.

It is therefore not a general-purpose privacy inspector.

Example

Suppose a banking Code deals with:

  • customer data;
  • fraud detection;
  • data retention;
  • customer rights; and

  • security.

A Monitoring Body established for that Code does not automatically become responsible for monitoring every GDPR obligation of every participating bank.

If a bank has a completely unrelated processing activity outside the Code's scope, the Monitoring Body's role does not automatically expand to that activity.

The supplied commentary specifically emphasises that the Monitoring Body's responsibility is limited by the scope of the Code.

This prevents Article 41 from being interpreted as creating a parallel data-protection regulator for the entire sector.

The phrase "without prejudice to the tasks and powers of the competent supervisory authority"

This is arguably one of the most important phrases in Article 41.

It prevents the Monitoring Body from displacing the statutory authority of the DPA.

The DPA continues to exercise its powers under the GDPR, particularly its tasks and investigative and corrective powers under Articles 57 and 58.

In other words:

==Monitoring Body = Code compliance==

==DPA = GDPR enforcement==

The two systems can operate simultaneously.

Example

Suppose an advertising company joins an approved advertising Code. The Monitoring Body discovers that the company is not following the Code's requirements concerning transparency. The Monitoring Body may take action under the Code. But if the same conduct also amounts to a violation of the GDPR, the competent DPA can independently investigate the matter.

The company cannot argue:

"The Monitoring Body is already dealing with this, so the DPA has no jurisdiction."

That would fundamentally misunderstand Article 41.

Monitoring is not merely an optional courtesy

There is an interesting point arising from the wording of Article 41(1).

The provision uses language suggesting that compliance monitoring "may" be carried out by a Monitoring Body.

Taken in isolation, this could create the impression that monitoring is optional.

But Article 40(4) is important here.

Article 40 requires an approved Code to contain mechanisms enabling the Monitoring Body to carry out mandatory monitoring of compliance.

The EDPB framework therefore treats the existence of a Monitoring Body as an essential part of an admissible Code.

So the better understanding is:

Participation in a Code may be voluntary, but once the Code is structured around Article 41 monitoring, compliance with the Code is subject to mandatory monitoring.

This distinction is easy to miss.

Example

A company can generally choose: "I will join this Code." But after joining, it cannot say: "I joined voluntarily, so the Monitoring Body cannot inspect my compliance."

The voluntary element concerns adherence.

It does not eliminate the monitoring mechanism attached to that adherence.

Accreditation: why is it necessary?

The Monitoring Body itself must be accredited by the competent supervisory authority.

This is another important safeguard.

Imagine that the Code Owner is an industry association.

That association creates a Code and then appoints its own friendly committee to decide whether its members comply.

There would immediately be a credibility problem.

The companies being monitored could potentially influence the people responsible for monitoring them.

Article 41 therefore introduces an accreditation process.

The competent DPA must be satisfied that the Monitoring Body possesses the characteristics necessary to perform its role properly.

The accreditation is tied to the particular Code.

A Monitoring Body can potentially be accredited for more than one Code, but it must satisfy the requirements applicable to each accreditation.

Accreditation is not a generic "GDPR licence"

This distinction is worth emphasising.

Accreditation under Article 41 does not mean:

"This organisation has been certified by the EU as a general GDPR compliance authority."

Its accreditation is connected to its role as the Monitoring Body for a particular Code.

Example

Suppose a body is accredited to monitor: a Code for cloud-service providers. That does not automatically mean that the same body is competent to monitor: a Code concerning healthcare organisations.

The second Code could involve very different:

  • processing risks;

  • sectoral expertise;

  • technical requirements;

  • data categories;

  • compliance procedures.

The body would therefore need to satisfy the relevant accreditation requirements for that Code as well.

Independence, the first major requirement

The Monitoring Body must demonstrate its independence to the satisfaction of the competent DPA.

This is more than simply saying:

"We are independent."

The organisational arrangements must make independence credible.

The EDPB discussion identifies issues such as:

  • independent funding;

  • independence in appointment of staff;

  • separate reporting structures;

  • informational barriers;

  • independent decision-making;

  • organisational separation;

  • ability to impose sanctions without interference.

The underlying concern is straightforward:

Can the Monitoring Body realistically take action against a powerful Code member when necessary?

If the answer is no, the monitoring mechanism loses credibility.

Why funding can affect independence

Consider an industry association representing 500 companies.

It creates a Code.

It also creates a Monitoring Body.

The Monitoring Body's entire budget comes from the companies it monitors, and the largest companies can threaten to withdraw funding whenever the Monitoring Body investigates them.

Technically, the Monitoring Body may have a separate name and office.

But its practical independence could still be questionable.

This is why the EDPB considers financial arrangements relevant to demonstrating independence.

The issue is not that funding by Code members is automatically prohibited.

The question is whether the funding structure creates a realistic risk of influence.

Independence in appointment

The same principle applies to personnel.

Suppose the CEO of the Code Owner personally appoints the head of the Monitoring Body and can remove that person whenever the Monitoring Body takes action against a major member.

That arrangement creates an obvious independence concern.

The Monitoring Body needs sufficient organisational protection to make decisions without fear that exercising its responsibilities will result in retaliation.

The EDPB specifically refers to independent appointment arrangements and separate reporting structures as possible ways of demonstrating independence.

Internal Monitoring Bodies are not automatically prohibited

This is an important nuance.

Independence does not necessarily require the Monitoring Body to be a completely separate legal entity.

The EDPB allows flexibility concerning whether the body is internal or external.

Therefore, the argument:

"It is an internal body, so it can never be independent."

is too simplistic.

The real question is whether sufficient safeguards exist to ensure impartiality.

Example

An industry association might create an internal monitoring unit with:

  • separate management;
  • independent reporting;
  • ring-fenced funding;
  • separate decision-making;

  • protected staff;

  • no ability for monitored members to interfere with investigations.

That could potentially satisfy the independence requirement, subject to the competent DPA's assessment.

Independence is ultimately assessed by the DPA

The GDPR does not provide a mathematical independence test.

There is no universal formula such as:

"The Monitoring Body must have 100% independent funding."

Instead, the question is whether the Monitoring Body demonstrates independence to the satisfaction of the competent supervisory authority.

The DPA therefore has significant evaluative responsibility.

The EDPB guidance helps harmonise the approach, but the exact assessment must take account of the circumstances and sector.

Expertise, independence alone is not enough

A Monitoring Body could be completely independent and still be unsuitable if it does not understand the sector.

Article 41 therefore also requires an appropriate level of expertise in the subject matter covered by the Code.

The Monitoring Body should understand both:

  1. data-protection law; and

  2. the particular sector and processing activities covered by the Code.

The EDPB approach looks at matters such as:

  • knowledge of the relevant sector;

  • previous experience in that sector;

  • understanding of the applicable data-protection law;

  • experience with compliance monitoring.

Why sectoral expertise matters

Imagine a Code for hospitals dealing with medical records.

A Monitoring Body may have excellent general GDPR lawyers but no understanding of:

  • clinical workflows;

  • electronic health-record systems;

  • emergency access;

  • healthcare professionals' access requirements;

  • medical confidentiality;

  • research environments.

Its ability to assess actual compliance could therefore be limited.

Similarly, a Monitoring Body for online advertising needs to understand technologies such as:

  • tracking;

  • profiling;

  • advertising identifiers;

  • real-time bidding;

  • audience segmentation.

Legal knowledge without operational knowledge may not be enough.

Expertise does not mean that every employee must be an expert

The requirement concerns the Monitoring Body as an organisation.

It does not necessarily mean that every employee must possess deep expertise in every aspect of the sector.

A Monitoring Body could have:

  • privacy lawyers;

  • technical specialists;

  • sector experts;

  • auditors;

  • investigators.

The overall institutional capability is what matters.

Example

For a cybersecurity Code, the Monitoring Body might combine:

  • GDPR lawyers;
  • information-security specialists;
  • auditors;
  • incident-response professionals.

That multidisciplinary composition may be far more useful than having only lawyers.

Expertise must evolve

There is another practical implication.

Expertise cannot necessarily be treated as something established once and then permanently satisfied.

Technology and processing practices change.

Suppose a Code originally concerned traditional financial services.

Five years later, participating organisations extensively use:

  • AI;

  • behavioural analytics;

  • automated decision-making;

  • biometric authentication.

The Monitoring Body must remain capable of understanding these developments if they fall within the Code's scope.

Otherwise, its expertise may become outdated.

Established procedures and structures

The Monitoring Body must have appropriate procedures and structures for dealing with complaints and infringements.

This is essential because monitoring cannot depend entirely on ad hoc decisions.

The Monitoring Body should have a predictable process for:

  • receiving complaints;

  • assessing them;

  • investigating;

  • communicating with the relevant parties;

  • reaching decisions;

  • taking corrective measures;

  • documenting outcomes.

The EDPB specifically identifies established procedures and structures as one of the core areas for accreditation.

Complaint handling is a substantive function

Complaints are not merely administrative correspondence.

Suppose a consumer believes that a company participating in an approved Code has:

  • ignored its rights;

  • failed to provide required information;

  • breached the Code's security standards;

  • used data in a way prohibited by the Code.

The Monitoring Body must have a mechanism through which the complaint can be properly considered.

This requires sufficient resources and powers to investigate and, where appropriate, take corrective action.

Complaints can come from data subjects

The framework is particularly significant because it is not designed solely around relationships between industry participants.

Data subjects need to be able to understand:

  • how complaints can be made;

  • where they should be submitted;

  • what happens after submission;

  • what the Monitoring Body can do.

The complaint-handling procedures therefore need to be transparent to data subjects and the general public.

Example

Suppose a consumer believes an online retailer participating in a Code has violated a Code requirement. The consumer should not have to discover an obscure internal process. There should be a publicly accessible mechanism explaining how to complain.

What can the Monitoring Body do after finding a violation?

Article 41 contemplates the Monitoring Body taking appropriate action when a controller or processor infringes the Code.

The possible actions can include:

  • warnings;

  • requiring corrective action;

  • requiring training;

  • formal notices;

  • temporary suspension;

  • exclusion from the Code.

The EDPB discussion describes corrective measures ranging from remedial measures to suspension and definitive exclusion, depending on the seriousness of the infringement.

The important principle is proportionality.

A minor procedural deficiency should not necessarily result in immediate exclusion.

A serious or repeated breach may justify much stronger action.

Suspension versus exclusion

These are not the same.

Suspension

The organisation temporarily loses its status as a Code participant until the problem is corrected.

Exclusion

The organisation is removed from the Code.

Example

Suppose a company fails to update one of its internal procedures despite repeated reminders. A Monitoring Body might initially require corrective action. If the company refuses to comply, temporary suspension could follow. If the company continues to disregard the Code or commits a serious violation, exclusion may become appropriate.

This graduated approach makes the monitoring framework more credible.

The purpose of corrective action

Corrective measures should not simply be punitive.

The EDPB approach emphasises stopping the infringement and preventing recurrence.

This distinction matters.

Suppose a company repeatedly mishandles data-subject requests because its employees have not been properly trained.

Simply issuing a fine-like sanction may not solve the underlying problem.

A requirement to:

  • retrain employees;

  • redesign the request-handling process;

  • implement supervisory review;

may be more effective.

The objective is therefore compliance improvement, not merely punishment.

Conflict of interest

The Monitoring Body must also demonstrate that its functions and duties do not result in a conflict of interest.

This is related to independence but is not identical to it.

Independence asks:

Can the Monitoring Body act without external influence?

Conflict of interest asks:

Does the Monitoring Body have interests or relationships that compromise, or appear capable of compromising, its ability to perform its monitoring role impartially?

The EDPB therefore expects safeguards preventing the Monitoring Body from engaging in incompatible activities or relationships.

Example

of a conflict of interest Imagine a Monitoring Body is responsible for assessing whether a company complies with a cybersecurity Code. At the same time, the Monitoring Body sells cybersecurity consulting services to the same company. It might:

  1. advise the company on what controls to implement; and then
  2. decide whether those same controls satisfy the Code. That creates an obvious conflict. The Monitoring Body would effectively be assessing its own advice. A credible accreditation framework therefore needs safeguards against such situations.

Independence and conflict of interest can overlap

The two requirements are closely connected but should not be collapsed into one.

A Monitoring Body might be structurally independent but still have a conflict.

For example, it may be organisationally separate from the Code Owner but simultaneously provide commercial consulting services to organisations it monitors.

Conversely, an internal body might have no obvious commercial conflict but still lack sufficient independence because its management can interfere with investigations.

Both dimensions therefore need to be assessed.

Resources must be adequate

A Monitoring Body cannot effectively monitor hundreds of organisations if it has:

  • two employees;

  • inadequate funding;

  • no technical specialists;

  • no investigative capacity.

The EDPB therefore emphasises that resources should be proportionate to:

  • the expected number and size of Code members;

  • the complexity of processing;

  • the degree of risk involved.

This is an important operational requirement.

Example

Monitoring 15 small companies conducting relatively low-risk processing is very different from monitoring 500 multinational companies processing sensitive data at massive scale. The monitoring infrastructure should reflect that difference.

The Monitoring Body must be capable of reviewing the Code itself

This is a particularly interesting aspect of Article 41.

The Monitoring Body does not merely monitor Code members.

It must also have procedures for reviewing the Code.

Why?

Because the Code may become outdated.

The EDPB indicates that the review should consider the Code's continuing relevance, including developments in:

  • the sector;

  • industry practices;

  • technology;

  • GDPR application.

Why Code review matters

Consider a Code for mobile-app developers drafted in 2019.

At that time, the sector may have had relatively limited use of certain technologies.

By 2026, developers may be using:

  • AI assistants;

  • behavioural analytics;

  • sophisticated profiling;

  • biometric features;

  • cross-platform tracking.

If the Code never changes, it could become disconnected from actual processing practices.

The review mechanism allows the Code to evolve.

Review does not mean rewriting the Code every year

The requirement should not be understood as requiring constant amendments.

The point is that the Monitoring Body should have a credible review process capable of identifying when change is necessary.

For example, the process could trigger review when:

  • major technological developments occur;

  • legislation changes;

  • significant regulatory guidance is issued;

  • recurring complaints reveal a weakness;

  • monitoring repeatedly identifies the same compliance problem.

The important issue is institutional capability.

Transparency of complaint procedures

The Monitoring Body's procedures and structures must be transparent to:

  • data subjects; and

  • the general public.

This has an important accountability function.

People should be able to understand:

  • how to complain;

  • what the Monitoring Body does;

  • what kinds of Code violations it handles;

  • how complaints are processed;

  • what outcomes may be available.

The EDPB specifically links this requirement to publicly accessible complaint-handling processes.

Communication with the supervisory authority

The Monitoring Body must maintain appropriate communication with the competent DPA.

This reflects the fact that the Monitoring Body is not operating in a regulatory vacuum.

For example, if a Monitoring Body:

  • discovers serious Code violations;

  • suspends a major participant;

  • excludes an organisation;

  • identifies systemic problems;

the competent DPA needs to be appropriately informed.

Article 41(4) expressly requires the Monitoring Body to inform the competent DPA when it takes appropriate action following a Code infringement.

Why must the DPA be informed?

Because the DPA has broader powers than the Monitoring Body.

Suppose a Monitoring Body discovers that a company's conduct violates both:

  • the Code; and

  • the GDPR.

The Monitoring Body can address the Code violation.

The DPA may need to determine whether regulatory action under the GDPR is appropriate.

Information sharing therefore prevents the two systems from operating in isolation.

Review mechanism

The Monitoring Body must also have a mechanism for reviewing whether the Code continues to achieve its purpose.

This is different from investigating individual companies.

There are therefore two different forms of review:

Member-level review

"Is Company X complying with the Code?"

Code-level review

"Is the Code itself still relevant and effective?"

Both are important.

The EDPB identifies legal status as another relevant area in accreditation criteria.

The Monitoring Body needs an appropriate legal and organisational structure capable of carrying out its responsibilities.

The GDPR does not prescribe one universal corporate form.

The relevant question is whether the chosen structure enables the Monitoring Body to:

  • operate independently;

  • maintain appropriate procedures;

  • handle complaints;

  • make decisions;

  • communicate with the DPA;

  • exercise its monitoring responsibilities effectively.

The role of the competent DPA in accreditation

The competent DPA does not simply decide informally whether a Monitoring Body appears trustworthy.

Article 41 establishes a structured accreditation process.

The DPA must establish criteria for accreditation.

Those draft criteria are submitted to the EDPB through the consistency mechanism.

The EDPB then gives an opinion on those criteria under Article 64.

This is important because it promotes greater consistency between Member States.

Why does the EDPB review the accreditation criteria?

Without coordination, different DPAs could potentially establish radically different standards.

Imagine:

DPA A: requires extremely strict independence safeguards.

DPA B: accepts very weak independence safeguards.

Two substantially similar Monitoring Bodies could therefore receive completely different treatment depending on the Member State.

The EDPB's role helps promote a more harmonised approach.

The supplied material identifies eight principal areas reflected in the EDPB approach:

  • independence;

  • conflicts of interest;

  • expertise;

  • procedures and structures;

  • transparent complaints handling;

  • communication with the DPA;

  • review mechanisms; and

  • legal status.

But harmonisation does not mean identical criteria

This is a subtle point.

The EDPB helps ensure consistency, but the accreditation criteria cannot be completely detached from the relevant sector.

A Monitoring Body for:

healthcare

may require different expertise from one monitoring:

online advertising.

Similarly, a Code dealing with:

low-risk business contact information

may require different resources from one dealing with:

large-scale sensitive-data processing.

The supplied material therefore notes that the level of detail in accreditation criteria necessarily has to take account of the specific Code and sector.

What happens when a Code member violates the Code?

This is where Article 41 becomes operational.

Suppose a company has undertaken to follow an approved Code.

The Monitoring Body discovers that the company has:

  • failed to follow a mandatory Code procedure;

  • repeatedly ignored data-subject complaints;

  • failed to implement required safeguards;

  • breached a Code requirement.

The Monitoring Body must take appropriate action.

The precise response should depend on the circumstances.

A minor issue may justify corrective instructions.

A serious or repeated violation may justify suspension or exclusion.

The Monitoring Body cannot simply ignore non-compliance

This is an important consequence of accreditation.

A Monitoring Body is not established merely to publish reports.

It must have the capacity and willingness to act.

The EDPB specifically emphasises the need for sufficient resources and powers and the willingness to impose corrective measures.

If a Monitoring Body routinely discovers violations but never takes action, the credibility of the Code could be seriously undermined.

Does exclusion from the Code equal a GDPR fine?

No.

This is another critical distinction.

Suppose Company X is excluded from a Code.

That does not itself mean:

"Company X has been fined under the GDPR."

Exclusion is a consequence under the Code-monitoring framework.

A DPA may separately determine whether the company's conduct violated the GDPR and whether enforcement action is appropriate.

The two consequences should therefore not be conflated.

Can the Monitoring Body impose GDPR administrative fines?

The Monitoring Body should not be confused with the supervisory authority's statutory enforcement powers.

Article 41 preserves the DPA's competence.

The Monitoring Body's powers arise from its role under the Code and its monitoring framework.

The DPA, by contrast, exercises the statutory powers granted by the GDPR, including the enforcement powers in Chapter VIII.

Thus:

Code sanction ≠ GDPR administrative fine

unless some separate legal mechanism provides otherwise.

What if the same conduct triggers both mechanisms?

That is entirely possible.

Imagine an organisation violates a Code requirement concerning security.

The Monitoring Body could:

  • require remediation;

  • suspend participation;

  • ultimately exclude the organisation.

At the same time, the DPA could investigate whether the same conduct amounts to a breach of the GDPR's security obligations.

The existence of the Code process does not prevent the DPA from acting.

This is precisely why Article 41 preserves the DPA's powers.

What if a data subject complains directly to the DPA?

The existence of a Code does not remove the individual's ability to approach the competent supervisory authority.

A Code's complaint mechanism is an additional accountability structure.

It should not be understood as replacing statutory rights and remedies under the GDPR.

This is consistent with the broader principle that Code monitoring operates without prejudice to the DPA's statutory responsibilities.

What if the Monitoring Body discovers a systemic problem?

This is where the communication and review functions become especially important.

Suppose the Monitoring Body monitors 200 organisations and discovers that 150 of them misunderstand one particular Code requirement.

That may indicate that the problem is not simply individual non-compliance.

The Code itself may be:

  • ambiguous;

  • outdated;

  • technically difficult to implement;

  • inconsistent with new technology;

  • insufficiently clear.

The Monitoring Body's review function can therefore identify whether the Code itself requires amendment.

This makes Article 41 more than an enforcement provision.

It also creates a feedback loop:

Code → implementation → monitoring → problems identified → Code review → improved Code

The Monitoring Body as an accountability layer

The architecture can therefore be understood as having three distinct levels.

First level, Organisation

The controller or processor implements the Code.

Second level, Monitoring Body

The Monitoring Body independently checks adherence to the Code.

Third level, Supervisory Authority

The DPA retains regulatory oversight and enforcement powers under the GDPR.

This layered model is important because it combines:

  • industry-specific expertise;

  • independent monitoring; and

  • public regulatory authority.

Why Article 41 matters to the credibility of Article 40

Without Article 41, a Code could become little more than an industry pledge.

Consider two scenarios.

Scenario A

An industry says: "We promise to follow these privacy principles." Nobody monitors adherence.

Scenario B

An industry says: "We have an approved Code, participation is monitored by an accredited body, complaints can be investigated, violations can lead to corrective action or exclusion, and serious matters are communicated to the DPA." The second framework provides considerably stronger accountability. That is the practical purpose of Article 41.

An important distinction: monitoring the Code is not monitoring the GDPR as a whole

This is one of the most useful nuances to retain.

Suppose a Code covers:

  • transparency;

  • profiling;

  • data-subject complaints.

The Monitoring Body is concerned with those Code obligations.

It does not automatically become responsible for every aspect of the organisation's GDPR compliance.

For example, the organisation may have another processing operation involving employee data that is outside the Code's scope.

The Monitoring Body does not automatically acquire general supervisory jurisdiction over that processing.

The DPA remains the appropriate authority for broader GDPR supervision.

Accreditation can be lost

Article 41(5) is particularly important.

The DPA must revoke the Monitoring Body's accreditation where:

  1. the accreditation conditions are no longer met; or

  2. the Monitoring Body's actions infringe the GDPR.

The consequence is significant because accreditation is not necessarily permanent.

A Monitoring Body must continue to satisfy the conditions that justified its accreditation.

Why revocation matters

Imagine a Monitoring Body was initially independent.

Five years later:

  • its funding becomes controlled by the Code Owner;

  • its leadership changes;

  • conflicts of interest emerge;

  • its complaints procedure stops functioning;

  • it begins systematically ignoring serious Code violations.

The fact that it was once accredited does not save it.

The DPA can revoke its accreditation if the relevant conditions are no longer satisfied.

This creates an ongoing accountability mechanism.

Revocation is different from suspension of a Code member

These two concepts should not be confused.

Suspension of Code member

The Monitoring Body takes action against an organisation that violates the Code.

Revocation of Monitoring Body accreditation

The DPA takes action against the Monitoring Body itself because it no longer satisfies the accreditation conditions or is infringing the GDPR.

The institutional direction is therefore different:

Monitoring Body → Code member

versus

DPA → Monitoring Body

Article 41 does not apply to public authorities

Article 41(6) excludes processing carried out by public authorities or bodies from the application of this provision.

This limitation is important because Article 41 is designed around a particular model of sectoral Code monitoring.

The public-sector context involves different institutional accountability structures, including direct regulatory and administrative oversight.

Therefore, the Article 41 Monitoring Body mechanism should not simply be transplanted into the public-authority context.

The deeper relationship between Articles 40 and 41

The easiest way to understand the relationship is:

Article 40 answers:

How can a sector develop an approved GDPR Code?

Article 41 answers:

Who checks whether participants actually follow that Code?

Article 40 without Article 41 risks creating a largely voluntary industry standard.

Article 41 gives the standard an independent monitoring architecture.

But Article 41 without Article 40 would have no Code to monitor.

The two provisions are therefore structurally interdependent.

A practical end-to-end example

Consider a hypothetical European Online Retailers Code of Conduct.

An association representing online retailers develops a Code addressing:

  • transparency;

  • profiling;

  • direct marketing;

  • data-subject rights;

  • security;

  • breach management.

The competent DPA approves the Code.

An independent Monitoring Body is accredited.

Now imagine Retailer A joins the Code.

A customer complains that Retailer A's profiling practices do not comply with the Code.

The Monitoring Body receives the complaint.

It investigates.

It discovers that Retailer A has failed to implement a required transparency mechanism.

The Monitoring Body could require Retailer A to:

  • correct the transparency mechanism;

  • retrain relevant employees;

  • change its customer-facing disclosures;

  • provide evidence of remediation.

If Retailer A refuses to comply, the Monitoring Body could potentially suspend or exclude it from the Code.

The Monitoring Body then informs the competent DPA of the action taken.

If the underlying conduct also appears to violate the GDPR, the DPA remains free to investigate and exercise its statutory powers.

This example captures almost the entire logic of Article 41.

Another example: healthcare

Imagine a healthcare Code requiring participating organisations to implement specific access-control practices for patient information.

Hospital A joins the Code.

The Monitoring Body conducts an assessment and discovers that employees in Hospital A can access patient records without sufficient authorisation controls.

The Monitoring Body could require remediation.

If Hospital A refuses, stronger measures may follow.

But if the weakness also constitutes a violation of GDPR security requirements, the competent DPA can separately investigate.

The Monitoring Body therefore provides sector-specific oversight, while the DPA retainsgeneral legal authority.

Another example: cloud computing

Imagine a Code for cloud processors requiring:

  • defined security controls;

  • incident-response procedures;

  • deletion/return procedures;

  • subcontractor governance;

  • complaint handling.

A cloud provider joins the Code.

The Monitoring Body discovers that the provider repeatedly fails to delete customer data after the contractual retention period.

The Monitoring Body may require corrective action.

If the provider continues to disregard the Code, suspension or exclusion may become appropriate.

If the conduct also violates GDPR processor obligations, the DPA remains competent to address that issue.

Why the eight accreditation areas matter together

The eight areas identified in the EDPB framework are not independent boxes that can be satisfied mechanically.

They reinforce one another.

For example:

A Monitoring Body might have excellent expertise.

But if it lacks independence, its expertise is not enough.

It might be independent.

But if it has no complaint-handling procedure, individuals cannot effectively trigger monitoring.

It might have excellent procedures.

But if it lacks resources, those procedures may not work in practice.

It might have resources and independence.

But if it does not communicate with the DPA, broader regulatory oversight could be impaired.

Thus, accreditation is fundamentally about whether the Monitoring Body is institutionally capable of performing its function credibly.

The central principle of Article 41

The best way to understand Article 41 is not:

"It creates an organisation that checks Code compliance."

That is technically true but incomplete.

Its deeper purpose is to ensure that voluntary sectoral accountability does not become purely self-policing.

The GDPR allows industry to participate in developing practical compliance standards.

But it places safeguards around that system:

  • the Monitoring Body must demonstrate independence;

  • it must have appropriate expertise;

  • it must have procedures for complaints;

  • it must avoid conflicts of interest;

  • it must have adequate resources;

  • it must monitor actual adherence;

  • it must take appropriate action when violations occur;

  • it must communicate relevant action to the DPA;

  • and its accreditation can be revoked.

This produces a balance between industry-specific expertise and regulatory oversight.

That balance is the real significance of Article 41.

Final understanding

Article 41 should therefore be read as the enforcement and credibility mechanism attached to Article 40's Code of Conduct framework.

The Code itself is sector-specific and voluntary to join. But once an organisation undertakes to adhere to it, the system requires meaningful monitoring. The Monitoring Body must be sufficiently independent from the organisations and interests it monitors, must possess expertise appropriate to the sector and subject matter, must have credible complaint and investigation procedures, and must be capable of imposing proportionate corrective measures, including suspension or exclusion where appropriate.

At the same time, Article 41 carefully prevents the Monitoring Body from becoming a substitute for the supervisory authority. The DPA retains its statutory powers under the GDPR, and the Monitoring Body's activities operate alongside, not instead of, the DPA's regulatory functions.

The most important conceptual distinction is consequently this:

The Monitoring Body monitors adherence to the Code; the supervisory authority enforces the GDPR.

And the second distinction is equally important:

Joining the Code may be voluntary, but adherence to the Code is subject to mandatory monitoring once an organisation has undertaken to follow it.

That is what turns a Code of Conduct from a mere industry commitment into a structured accountability mechanism.