At a glance
| Instrument | Certification, seals and data protection marks (voluntary) |
| Who certifies | Accredited certification bodies or the competent supervisory authority |
| Duration | Maximum three years, renewable; withdrawal where criteria are no longer met |
| Effect | Evidence of compliance; may support transfers under Art. 46(2)(f), never a presumption of lawfulness |
Article 42 is the GDPR’s framework for certification as a means of demonstrating data-protection compliance. It is closely connected with the GDPR’s broader accountability principle: instead of merely asserting that an organisation complies with the Regulation, certification creates a structured process through which particular processing activities can be assessed against defined criteria.
The first point to understand, however, is that certification is evidence of compliance, not a substitute for compliance. A controller or processor does not become GDPR-compliant merely because it possesses a certificate. It remains responsible for complying with the GDPR in its entirety.
This distinction is fundamental to understanding almost every other aspect of Article 42.