CHAPTER IVCONTROLLER AND PROCESSOR

Article 43Certification bodies

Official text

(1)Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58, certification bodies which have an appropriate level of expertise in relation to data protection shall, after informing the supervisory authority in order to allow it to exercise its powers pursuant to point (h) of Article 58 (2) where necessary, issue and renew certification. Member States shall ensure that those certification bodies are accredited by one or both of the following:

(a)the supervisory authority which is competent pursuant to Article 55 or 56;

(b)the national accreditation body named in accordance with Regulation (EC) No 765/2008 of the European Parliament and of the Council ¹ in accordance with EN-ISO/IEC 17065/2012 and with the additional requirements established by the supervisory authority which is competent pursuant to Article 55 or 56.

(2)Certification bodies referred to in paragraph 1 shall be accredited in accordance with that paragraph only where they have:

(a)demonstrated their independence and expertise in relation to the subject-matter of the certification to the satisfaction of the competent supervisory authority;

(b)undertaken to respect the criteria referred to in Article 42 (5) and approved by the supervisory authority which is competent pursuant to Article 55 or 56 or by the Board pursuant to Article 63;

(c)established procedures for the issuing, periodic review and withdrawal of data protection certification, seals and marks;

(d)established procedures and structures to handle complaints about infringements of the certification or the manner in which the certification has been, or is being, implemented by the controller or processor, and to make those procedures and structures transparent to data subjects and the public; and

(e)demonstrated, to the satisfaction of the competent supervisory authority, that their tasks and duties do not result in a conflict of interests.

(3)The accreditation of certification bodies as referred to in paragraphs 1 and 2 of this Article shall take place on the basis of requirements approved by the supervisory authority which is competent pursuant to Article 55 or 56 or by the Board pursuant to Article 63. In the case of accreditation pursuant to point (b) of paragraph 1 of this Article, those requirements shall complement those envisaged in Regulation (EC) No 765/2008 and the technical rules that describe the methods and procedures of the certification bodies.

(4)The certification bodies referred to in paragraph 1 shall be responsible for the proper assessment leading to the certification or the withdrawal of such certification without prejudice to the responsibility of the controller or processor for compliance with this Regulation. The accreditation shall be issued for a maximum period of five years and may be renewed on the same conditions provided that the certification body meets the requirements set out in this Article.

(5)The certification bodies referred to in paragraph 1 shall provide the competent supervisory authorities with the reasons for granting or withdrawing the requested certification.

(6)The requirements referred to in paragraph 3 of this Article and the criteria referred to in Article 42 (5) shall be made public by the supervisory authority in an easily accessible form. The supervisory authorities shall also transmit those requirements and criteria to the Board.

(7)Without prejudice to Chapter VIII, the competent supervisory authority or the national accreditation body shall revoke an accreditation of a certification body pursuant to paragraph 1 of this Article where the conditions for the accreditation are not, or are no longer, met or where actions taken by a certification body infringe this Regulation.

(8)The Commission shall be empowered to adopt delegated acts in accordance with Article 92 for the purpose of specifying the requirements to be taken into account for the data protection certification mechanisms referred to in Article 42 (1).

(9)The Commission may adopt implementing acts laying down technical standards for certification mechanisms and data protection seals and marks, and mechanisms to promote and recognise those certification mechanisms, seals and marks. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93 (2).

¹ Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 setting out the requirements for accreditation and market surveillance relating to the marketing of products and repealing Regulation (EEC) No 339/93 (OJ L 218, 13.8.2008, p. 30).

Commentary

At a glance

SubjectCertification bodies and their accreditation
Accreditation bySupervisory authority and/or national accreditation body (ISO/IEC 17065)
DutiesIndependence, expertise, complaint handling, transparency of criteria
OversightAccreditation valid up to five years; may be revoked

Article 42 establishes what GDPR certification is and what it is intended to achieve. Article 43 answers the next and equally important question:

Who is legally and technically qualified to issue that certification, and how is that body itself controlled?

This is important because certification would have very little regulatory value if any private consultant could simply declare:

"This organisation is GDPR certified."

Article 43 therefore creates a second layer of assurance.

There are essentially two separate assessments:

First layer: Is the controller or processor compliant with the applicable certification criteria?

Second layer: Is the organisation conducting that assessment itself sufficiently independent, competent and trustworthy to be allowed to issue the certification?

Article 43 is primarily concerned with this second layer.

The basic architecture of Article 43

The easiest way to understand Article 43 is to think of three different actors.

The controller or processor

This is the organisation whose processing is being certified.

For example:

A cloud service provider wants certification for the processing it performs for its customers.

The certification body

This is the organisation that assesses the processing against the approved certification criteria and, if the requirements are satisfied, issues the certification.

The supervisory authority / national accreditation body

This is the body that assesses whether the certification body itself is sufficiently competent, independent and properly structured to perform certification.

So the chain is:

Controller/processor → assessed by → certification body → accredited by → DPA or national accreditation body

This distinction is absolutely fundamental.

A certification body is not itself the supervisory authority. It is an accredited entity performing a certification function within a regulatory framework overseen by the competent authorities.

Why does Article 43 regulate the certification body so heavily?

Because otherwise certification could become meaningless.

Imagine a company called PrivacyCert Ltd.

It has no meaningful data-protection expertise, no independent assessment procedures and no complaints mechanism.

It nevertheless issues certificates saying:

"Company X is fully GDPR compliant."

If those certificates had regulatory significance, the entire certification framework would be undermined.

Article 43 therefore asks:

Who checks the checker?

The answer is essentially:

The certification body must itself satisfy an accreditation framework before it can perform Article 42 certification.

This is why accreditation is so important.

Certification and accreditation are not the same thing

This is probably the most important distinction to understand in Article 43.

Certification

Certification concerns the controller or processor.

It answers:

Does this defined processing operation satisfy the applicable certification criteria?

Accreditation

Accreditation concerns the certification body.

It answers:

Is this organisation competent and appropriately structured to conduct certification assessments?

So:

==Certification = assessment of the processing.==

==Accreditation = assessment of the certifier.==

Example

Suppose ABC Privacy Ltd wants to certify a cloud provider. ABC Privacy Ltd cannot simply begin issuing Article 42 certificates. First, ABC Privacy Ltd itself must obtain accreditation under Article 43. Only then can it perform certification within the scope for which it has been accredited.

This creates a hierarchy of trust:

Accredited certification body → certifies controller/processor → certificate supports demonstration of compliance.

Article 43(1): certification bodies issue and renew certifications

Article 43(1) gives properly accredited certification bodies the authority to issue and renew certifications.

But this authority is subject to several important limitations.

First, the body must have an appropriate level of expertise in relation to data protection.

Second, it must be appropriately accredited.

Third, its activities remain subject to supervisory-authority oversight.

Fourth, certification does not displace the supervisory authority's powers.

So the certification body is not an alternative regulator.

"Without prejudice" to the DPA's powers

The phrase "without prejudice" is extremely important.

It essentially means that the fact that a certification body is allowed to issue certification does not reduce or take away the powers of the competent supervisory authority.

The DPA retains its regulatory powers under Articles 57 and 58.

For example, suppose a certification body certifies a company's processing.

The DPA subsequently discovers that the processing is unlawful.

The company cannot argue:

"The DPA cannot interfere because an accredited certification body already certified us."

The DPA can still exercise its statutory powers.

This reflects the principle discussed under Article 42:

Certification is an accountability mechanism, not a transfer of regulatory authority from the DPA to a private certification body.

The DPA can intervene even though certification was issued by someone else

This is particularly important under Article 58(2)(h).

The supervisory authority can, where appropriate, withdraw a certification or order the certification body not to issue or to withdraw a certification.

Therefore, the certification body operates under a form of regulatory supervision.

Example

A certification body decides to certify a company despite evidence that the company does not satisfy the approved criteria. The DPA becomes aware of this. The DPA is not required simply to accept the certification body's conclusion. It can exercise its powers under Article 58.

This ensures that private certification does not become a parallel regulatory system outside the DPA's control.

What does "appropriate level of expertise" actually mean?

The phrase is deliberately broader than simply saying:

"The certification body must employ lawyers."

GDPR certification can involve legal, organisational, technical and operational issues.

A certification body assessing a sophisticated cloud infrastructure may require expertise in:

  • GDPR;

  • information security;

  • system architecture;

  • access controls;

  • encryption;

  • logging;

  • incident management;

  • data governance;

  • risk management.

A body assessing a complex AI processing operation may require additional technical and legal expertise concerning the particular processing.

Therefore, expertise must be assessed in relation to the subject matter of the certification.

Expertise is therefore scope-dependent

This is a subtle but important point.

Suppose a certification body is competent to assess:

employee payroll processing.

That does not necessarily mean that it has sufficient expertise to assess:

large-scale biometric identification systems.

The certification body's competence must correspond to the certification scope.

This is one reason Article 43(2)(a) refers specifically to expertise in relation to the subject matter of the certification.

Who can accredit the certification body?

Article 43 provides two possible accreditation routes.

The certification body may be accredited by:

  1. the competent supervisory authority; or

  2. the relevant national accreditation body.

The GDPR therefore does not create a single European institution that must accredit every certification body.

Instead, it allows national accreditation structures to participate.

Why does the national accreditation body matter?

The national accreditation route connects GDPR certification with the existing European accreditation infrastructure.

The provision refers to the national accreditation body designated under Regulation (EC) No 765/2008 and to EN-ISO/IEC 17065:2012, supplemented by additional GDPR-specific requirements.

The basic idea is:

The national accreditation system provides a recognised framework for evaluating whether an organisation is competent to perform conformity assessment, while GDPR-specific requirements ensure that data-protection concerns are properly addressed.

This prevents GDPR certification from becoming completely disconnected from established accreditation practices.

What is ISO/IEC 17065 doing here?

ISO/IEC 17065 is fundamentally concerned with requirements for bodies that certify products, processes and services.

The GDPR incorporates this established conformity-assessment framework into its certification architecture, but does not stop there.

There are additional GDPR-specific requirements.

This is important because ISO accreditation alone does not automatically transform an organisation into an Article 43 GDPR certification body.

The body must satisfy the GDPR-specific requirements as well.

Certification of processing operations may fit within ISO terminology

At first glance, there can be a conceptual problem.

The GDPR talks about processing operations.

ISO/IEC 17065 deals with certification of products, processes and services.

How do these fit together?

The EDPB explains that a processing operation or collection of processing operations can be framed within the relevant conformity-assessment terminology.

For example:

An organisation's processing of employee data for payroll and leave management can constitute a defined set of processing operations that is capable of being assessed.

This is important because it demonstrates that the certification target need not literally be a physical product.

The certification target must nevertheless be clearly defined

This links Article 43 back to Article 42.

A certification body cannot meaningfully assess something described simply as:

"The company's GDPR compliance."

That is too broad.

Instead, the certification body needs to know what is actually being evaluated.

For example:

"Processing of employee personal data for payroll and leave management using systems X and Y."

Now the assessor can identify:

  • what data is involved;

  • what purposes exist;

  • which systems are involved;

  • which people have access;

  • which processes are relevant;

  • what criteria must be assessed.

This makes certification objectively assessable.

Article 43(2): the certification body's own requirements

Article 43(2) contains the core requirements that a certification body must satisfy before accreditation.

There are five particularly important areas:

Independence and expertise

Commitment to approved criteria

Certification lifecycle procedures

Complaints handling

Absence of conflicts of interest

These requirements are not merely formalities.

Together, they are designed to establish that the certification body can be trusted to perform an impartial and technically competent assessment.

Independence

The certification body must demonstrate its independence.

Why?

Because certification becomes meaningless if the assessor has a financial or organisational interest in giving the applicant a favourable result.

Example

Suppose a consultancy:

  1. designs a company's privacy programme;
  2. implements all its privacy controls;
  3. receives payment for implementation; and
  1. then certifies the same controls.

There is an obvious independence concern.

The organisation may have an incentive to certify the system it itself designed.

This is why independence is a central Article 43 requirement.

Independence is more than simply being a separate company

This is an important grey area.

Suppose Consultancy A and Certification Company B are legally separate companies.

But:

  • they share directors;

  • they share personnel;

  • Consultancy A refers clients to Certification Company B;

  • Certification Company B derives most of its revenue from Consultancy A's clients.

Simply creating two corporate entities does not automatically eliminate the independence concern.

The substance of the relationship matters.

The competent authority must be satisfied that the certification body's independence is genuine.

Expertise and independence must coexist

An assessor must be:

competent enough to understand the processing

and

independent enough to assess it objectively.

This creates an important practical tension.

For highly technical processing, the organisation may need specialists.

But those specialists must not have relationships with the applicant that compromise impartiality.

Example

A certification body is assessing a company's AI platform. It hires an external AI consultant who previously designed that company's architecture. The consultant may have exceptional technical expertise. But their previous involvement may create an independence concern.

The certification body therefore has to manage competence and impartiality together.

Commitment to approved certification criteria

Under Article 43(2)(b), the certification body must undertake to respect the relevant certification criteria approved under Article 42(5).

This prevents the certification body from inventing its own informal standard.

Suppose the approved certification criteria require evidence of:

  • appropriate access controls;

  • data-subject rights procedures;

  • retention controls;

  • documented privacy governance.

The certification body cannot simply decide:

"We think encryption is sufficient, so we will ignore the other criteria."

It must assess according to the approved framework.

Why this matters for consistency

Imagine two certification bodies assessing identical processing.

If Body A applies the approved criteria while Body B uses its own informal interpretation, certificates issued by the two bodies would have radically different meanings.

The approval of certification criteria therefore creates a common baseline.

This is essential for:

  • comparability;

  • trust;

  • procurement;

  • cross-border recognition;

  • regulatory oversight.

But criteria do not mean mechanical box-ticking

There is another nuance.

Approved criteria create the assessment framework.

They do not necessarily eliminate professional judgment.

Consider a requirement that technical and organisational measures must be appropriate to risk.

Whether a particular control is appropriate may depend on:

  • the nature of the processing;

  • volume of data;

  • sensitivity;

  • threat environment;

  • consequences of compromise;

  • technological architecture.

Therefore, the certification body still needs qualified experts capable of interpreting the criteria in the context of the processing.

Procedures for issuing, reviewing and withdrawing certification

Article 43(2)(c) requires certification bodies to establish procedures covering the entire certification lifecycle.

This is significant.

A certification body cannot have a procedure only for:

"How do we issue a certificate?"

It must also have procedures for:

  • initial assessment;

  • periodic review;

  • renewal;

  • withdrawal.

This reflects the principle that GDPR compliance is not static.

Why periodic review is necessary

Imagine an organisation obtains certification in January.

Six months later it:

  • introduces a new processing purpose;

  • changes its cloud provider;

  • expands processing to new categories of personal data;

  • materially changes its security architecture.

The certification body must have a mechanism for determining whether those changes affect continued conformity.

Otherwise, the certificate could continue to be displayed even though the certified processing has materially changed.

Withdrawal is therefore a substantive function

Withdrawal is not merely an administrative possibility.

It is an important enforcement mechanism within the certification framework.

If the organisation no longer meets the certification requirements, the certification body needs the ability to withdraw the certification.

Example

A processor was certified because it maintained:

  • strict access controls;
  • documented deletion procedures;
  • appropriate technical safeguards.

Later, it removes those controls to reduce costs.

If those controls were essential to satisfying the certification criteria, continuing to display the certificate would be misleading.

The certification body needs a mechanism to withdraw it.

Complaint handling is a major safeguard

Article 43(2)(d) requires certification bodies to establish procedures and structures for handling complaints.

This is extremely important because certification affects not only the certified organisation but potentially:

  • customers;

  • business partners;

  • data subjects;

  • other stakeholders.

A certification body therefore cannot operate on a model where:

"We issue certificates and nobody can challenge us."

There must be a mechanism through which concerns can be raised.

What kinds of complaints can arise?

The provision covers complaints concerning:

  1. infringements of the certification; and

  2. the manner in which the certification has been or is being implemented by the controller or processor.

Consider two different complaints.

Complaint A, against the certification body

A data subject believes that the certification body failed to apply the approved criteria properly.

Complaint B, against the certified organisation

A company has a certificate, but the data subject believes that the organisation is not actually implementing the certified requirements.

Both situations can trigger the complaint-handling architecture.

Complaints must be transparent

The certification body must make its complaint procedures and structures transparent to data subjects and the public.

This means the public should not have to guess:

"Where do I complain?"

or:

"What happens after I complain?"

A credible certification mechanism should make the process accessible and understandable.

This is particularly important because certification marks may influence consumer or customer decisions.

Conflict of interest

Article 43(2)(e) requires the certification body to demonstrate that its tasks and duties do not result in a conflict of interests.

This goes beyond general independence.

Independence concerns the broader ability to operate objectively.

Conflict of interest concerns situations where competing interests could compromise, or appear capable of compromising, the assessment.

Example

of a conflict Suppose a certification body receives 80% of its revenue from one large technology company. It is assessing whether that company's processing complies with certification criteria. Even if the assessors technically act honestly, there may be a serious concern: Would the certification body be willing to withdraw the certificate if doing so threatened its financial relationship? This is precisely the type of structural risk Article 43 seeks to address.

Another conflict: consultancy and certification

Consider a company that sells two services:

Privacy consulting

and

GDPR certification.

It advises clients on how to implement controls and then certifies those same controls.

This arrangement is not necessarily automatically unlawful in every conceivable structure, but it creates obvious independence and conflict-of-interest questions.

The certification body must be able to demonstrate that its arrangements do not compromise the impartiality of certification.

This is why the accreditation framework becomes important.

Article 43(3): accreditation itself must be based on criteria

Article 43 does not merely say:

"The DPA decides whether it likes the certification body."

Accreditation itself must be based on defined criteria.

Those criteria are approved by:

  • the competent supervisory authority; or

  • the EDPB in the circumstances provided for by the Regulation.

This introduces another layer of standardisation.

There are therefore two different sets of criteria

This is an exam-important distinction.

Certification criteria

These determine whether the controller or processor's processing qualifies for certification.

They arise under Article 42(5).

Accreditation criteria

These determine whether the certification body qualifies to perform certification.

They arise under Article 43(3).

So:

Article 42 criteria → "Is the processing compliant with the certification standard?"

Article 43 criteria → "Is the certification body competent to assess that compliance?"

Confusing these two is a common conceptual mistake.

Accreditation criteria supplement the general accreditation framework

Where accreditation is performed by the national accreditation body, Article 43(3) requires the GDPR-specific requirements to complement the requirements under Regulation (EC) No 765/2008 and the relevant technical rules.

This means there is a layered framework:

General European accreditation requirements

ISO/technical conformity-assessment requirements

GDPR-specific requirements

The certification body therefore has to satisfy the complete applicable framework rather than merely one component.

Why this layered framework matters

Imagine a certification body is technically excellent at conformity assessment but has no meaningful GDPR expertise.

It might satisfy general accreditation principles but still be unsuitable to certify GDPR processing.

Conversely, a privacy consultancy might have excellent GDPR lawyers but lack the formal organisational and technical infrastructure needed for reliable conformity assessment.

Article 43 attempts to address both problems.

The certification body must be both competent in certification and competent in data protection.

Article 43(4): responsibility for proper assessment

Article 43(4) creates an important division of responsibility.

The certification body is responsible for the proper assessment leading to certification or withdrawal.

That means the body cannot evade responsibility by saying:

"The company provided the information; we simply issued the certificate."

The assessment itself is the certification body's responsibility.

If the body conducts an inadequate assessment, that can raise serious accreditation and regulatory issues.

But the controller or processor remains responsible

At the same time, Article 43(4) expressly preserves the controller's or processor's responsibility for GDPR compliance.

This creates a dual-responsibility model.

Certification body

Responsible for:

conducting a proper certification assessment.

Controller/processor

Responsible for:

actually complying with the GDPR.

This distinction is fundamental.

A certificate cannot transfer the controller's responsibility

Imagine a controller tells a certification body:

"Our system complies with GDPR."

The certification body assesses it and grants certification.

Later it turns out that the controller was unlawfully processing personal data.

The controller cannot simply say:

"The certification body made the mistake, so we have no responsibility."

The GDPR does not work that way.

The controller remains responsible for its processing.

Certification is evidence; it is not a delegation of the controller's statutory responsibility.

What if the certification body itself made a serious mistake?

That is a separate issue.

The certification body may potentially face consequences concerning:

  • its accreditation;

  • its compliance with Article 43;

  • regulatory oversight;

  • withdrawal of accreditation.

But this does not automatically erase the controller's own responsibility.

There can therefore be parallel accountability:

Controller/processor → responsible for GDPR compliance

Certification body → responsible for proper certification assessment

Accreditation authority/DPA → responsible for oversight of the certification body

This is the governance architecture Article 43 creates.

Five-year maximum accreditation period

Article 43(4) provides that accreditation may be issued for a maximum of five years.

This should be carefully distinguished from the validity of an individual GDPR certification.

Certification

Maximum validity under Article 42:

3 years.

Accreditation of certification body

Maximum period under Article 43:

5 years.

These are two entirely different periods.

Why is the accreditation period longer?

Conceptually, the certification body is being assessed for its ability to operate as a certification institution.

The organisation may receive accreditation for up to five years, subject to continued compliance.

Individual certificates issued by that body have their own validity period, subject to Article 42.

Therefore:

Five years does not mean that the controller's certification lasts five years.

It refers to the accreditation of the certification body.

Accreditation can be renewed

The five-year period is a maximum, not necessarily an automatic five-year entitlement.

Accreditation may be renewed where the certification body continues to satisfy the applicable requirements.

The renewal therefore operates as another opportunity to examine whether the certification body remains competent and compliant.

Accreditation can also be revoked before expiry

This becomes especially important when read with Article 43(7).

Suppose a certification body receives accreditation for five years.

Two years later, it:

  • loses independence;

  • repeatedly violates the certification criteria;

  • issues certificates without proper assessment;

  • fails to maintain complaint procedures.

The authority does not have to wait until the five-year period expires.

Accreditation can be revoked where the statutory conditions are satisfied.

Article 43(5): reasons must be given to the DPA

A certification body must provide the competent supervisory authority with the reasons for granting or withdrawing certification.

This is more significant than merely sending a notification.

The DPA needs to know:

Why was certification granted?

and:

Why was certification withdrawn?

This enables the DPA to perform meaningful oversight.

Why does the DPA need the reasons?

Imagine a certification body grants certification to a company processing highly sensitive data.

If the DPA receives only:

"Certificate granted."

it has little information to assess whether the certification mechanism is functioning properly.

If it receives:

"Certificate granted because criteria X, Y and Z were satisfied following the specified assessment methodology, with deficiencies A and B remediated before issuance."

the DPA has a much better basis for oversight.

Withdrawal information is equally important

Suppose a certification body withdraws certification.

The DPA should understand:

  • what deficiency was discovered;

  • how serious it was;

  • whether the deficiency was within the certification scope;

  • whether corrective action was attempted;

  • why withdrawal became necessary.

This information can help the DPA identify broader regulatory issues.

The information duty is connected with Article 43(1)

Article 43(1) already requires the certification body to inform the DPA when issuing or renewing certification.

Article 43(5) goes further by requiring the body to provide the reasons for granting or withdrawing the certification.

Together, these provisions create an oversight channel:

Certification decision → DPA notification → reasons/evidence → regulatory oversight

Article 43(6): transparency

Article 43(6) requires the accreditation requirements and certification criteria to be made publicly accessible.

This is crucial because certification must be understandable and verifiable from outside.

Imagine a certification body saying:

"We have assessed your company according to our proprietary GDPR standard."

A data subject asks:

"What does your standard actually require?"

If the criteria are secret, the public cannot meaningfully evaluate what the certificate represents.

The GDPR therefore pushes toward transparency.

What should transparency allow people to understand?

The relevant information should enable people to understand things such as:

  • what processing was certified;

  • which criteria were used;

  • how the assessment was conducted;

  • who performed it;

  • how long certification is valid.

This becomes particularly important when certification is directed toward consumers or customers.

A person should not see a privacy seal and have to guess what it actually means.

The certification mark must not become misleading

Consider a website displaying:

🛡 GDPR Certified

A consumer may interpret this as:

"Everything this company does with my personal data has been assessed and approved."

But suppose the certificate only covers:

customer-support processing.

The visual representation could create a much broader impression than the legal scope.

This is why defining and communicating the target of evaluation is so important.

EDPB's register

The supervisory authorities must transmit the relevant certification requirements and criteria to the EDPB.

The EDPB then collates certification mechanisms and data-protection seals and makes the information publicly available.

This provides a European-level transparency mechanism.

It helps distinguish recognised certification mechanisms from arbitrary private claims.

Why a European register is useful

Without a central register, a company operating across Europe might encounter dozens of claims:

  • GDPR seal;

  • GDPR trusted;

  • EU privacy certified;

  • data protection approved;

  • privacy compliant.

The existence of a recognised register makes it easier to establish whether a particular mechanism forms part of the GDPR certification architecture.

This is particularly relevant for procurement and cross-border business.

Article 43(7): revocation of accreditation

This provision concerns the certification body, not merely an individual certificate.

That distinction is essential.

Suppose Certification Body X has 100 organisations that it has certified.

If X itself ceases to satisfy the accreditation requirements, the issue is much broader than one individual certificate.

The authority can revoke X's accreditation.

This is effectively a regulatory intervention against the certifier itself.

When can accreditation be revoked?

Two broad situations are identified.

First

The conditions for accreditation are no longer met.

For example:

  • independence is compromised;

  • expertise is inadequate;

  • complaint structures disappear;

  • required procedures are no longer maintained.

Second

The certification body's actions infringe the GDPR.

For example, the certification body might systematically issue certifications in circumstances where the applicable requirements are not satisfied.

Why revocation is such a powerful safeguard

Imagine a certification body repeatedly issues weak certificates.

If the only remedy were to challenge individual certificates one by one, the system would be inefficient.

Article 43(7) allows the regulator to address the root of the problem:

the accreditation of the certification body itself.

This protects the credibility of the entire certification mechanism.

Article 43(7) expressly preserves Chapter VIII.

This means revoking accreditation does not necessarily exhaust the legal consequences available under the GDPR.

Other remedies, enforcement mechanisms and liability consequences may remain relevant.

The principle is:

Loss of accreditation is one regulatory consequence, not necessarily the only consequence.

What happens to certificates already issued?

This is an important operational issue.

Suppose Certification Body X loses its accreditation after having issued 500 certificates.

It does not follow automatically that every historical certification can simply be treated as though it never existed.

The precise consequences depend on the applicable certification mechanism, the circumstances of the revocation and the relevant decisions.

However, the situation clearly creates a need to examine the status and continuing validity of certificates issued by the body.

This illustrates why certification mechanisms need robust lifecycle and withdrawal procedures.

Article 43(8): delegated acts

Article 43(8) gives the European Commission power to adopt delegated acts concerning requirements to be taken into account for the certification mechanisms under Article 42(1).

This is an important distinction from Article 43(9).

The Commission has two different kinds of powers here:

Delegated acts

and

Implementing acts.

They should not be treated as interchangeable.

What is the purpose of the delegated-act power?

The GDPR itself establishes the basic architecture.

But certification is technically complex.

There may be matters that need further specification to make certification mechanisms function effectively.

The delegated-act power allows the Commission to supplement the framework within the limits imposed by EU law.

It is not a power to rewrite the fundamental architecture of the GDPR.

Delegated acts versus implementing acts

This distinction is particularly important for an exam or professional understanding.

Delegated acts

Broadly:

supplement or amend certain non-essential elements of the legislative framework within the limits of the delegation.

Implementing acts

Broadly:

establish uniform conditions for implementing existing legal requirements.

Therefore, Article 43(8) and Article 43(9) serve different functions.

Article 43(9): implementing acts

Article 43(9) allows the Commission to adopt implementing acts concerning:

  • technical standards for certification mechanisms;

  • data-protection seals and marks;

  • mechanisms for promoting and recognising those certification mechanisms, seals and marks.

The focus is therefore more operational and technical.

Why implementing acts may be necessary

Imagine different Member States develop certification mechanisms using technically incompatible approaches.

One mechanism might define assessment documentation in one way.

Another might use a completely different methodology.

A third might represent certificates in an incompatible format.

This could undermine cross-border recognition and comparability.

EU-level technical implementation can therefore help create greater uniformity.

Promotion and recognition

Article 43(9) also refers to mechanisms to promote and recognise certification mechanisms, seals and marks.

This connects back to Article 42(1), which encourages the establishment of certification mechanisms.

The idea is not merely to create certificates that nobody uses.

For certification to be useful, there must be sufficient recognition and understanding of what the certification means.

A practical example: multinational cloud provider

Consider a multinational cloud provider processing customer information for European businesses.

It wants to obtain Article 42 certification.

Step 1, define the target

It identifies:

customer account-management and hosting-related processing.

Step 2, identify applicable criteria

The relevant approved certification criteria are determined.

Step 3, certification body

The provider approaches an appropriately accredited certification body.

Step 4, assessment

The body examines:

  • processing activities;

  • systems;

  • policies;

  • technical measures;

  • data-subject rights processes;

  • retention;

  • processor/subprocessor arrangements where relevant;

  • other criteria within scope.

Step 5, decision

If the requirements are satisfied, certification is issued.

Step 6, DPA information

The certification body informs the competent DPA and provides the reasons required under Article 43.

Step 7, continuing review

The provider must continue satisfying the certification requirements.

Step 8, material change

Suppose it introduces a completely new processing architecture.

The certification body must determine whether the change affects conformity.

This demonstrates how Article 43 operates as a continuing governance mechanism, rather than a one-time inspection.

Another example: employee-data processing

Take a much simpler organisation.

A company wants certification for:

processing employee data for payroll and leave management.

The processing may involve:

  • names;

  • employee identification numbers;

  • bank details;

  • salary information;

  • leave records.

The certification body does not need to assess every aspect of the company's business.

It assesses the defined processing against the approved certification criteria.

This illustrates why the EDPB's concept of a clearly defined target of evaluation is so important.

Another example: AI processing

Consider an AI company processing customer conversations to train and improve a model.

The certification body might need expertise across several disciplines.

It may need to understand:

  • the data flows;

  • purposes of processing;

  • retention;

  • access controls;

  • data-subject rights;

  • training pipelines;

  • model-development processes;

  • technical safeguards.

A certification body with only generic legal expertise may not have sufficient competence for such a technically complex certification scope.

This demonstrates why Article 43(1) speaks of an appropriate level of expertise in relation to the subject matter.

GDPR certification is neither purely a legal opinion nor purely a cybersecurity audit.

A certification body may need to determine whether the processing satisfies requirements that combine:

  • legal obligations;

  • organisational controls;

  • technical safeguards;

  • operational procedures.

Therefore, a competent certification body may require a multidisciplinary assessment team.

For example:

Privacy lawyer

→ evaluates legal and governance requirements.

Security specialist

→ evaluates technical and organisational security measures.

Process auditor

→ evaluates whether operational procedures actually function as documented.

This is one reason the accreditation process is important.

Certification body versus law firm

A law firm may advise:

"In our opinion, your processing complies with GDPR."

That is not automatically equivalent to Article 42 certification.

A legal opinion and a GDPR certification are different forms of assurance.

A legal opinion is generally an advisory legal assessment.

An Article 42 certification involves an approved certification mechanism, defined criteria and an appropriately accredited certification body.

This distinction is important in professional practice.

Certification body versus consultant

Similarly, a privacy consultant may conduct a GDPR readiness assessment.

For example:

"We identified 14 gaps and recommend corrective measures."

That is not necessarily certification.

The certification mechanism has its own requirements concerning:

  • independence;

  • accreditation;

  • approved criteria;

  • assessment;

  • complaints;

  • review;

  • withdrawal.

Therefore:

Consulting ≠ certification

unless the relevant organisation separately satisfies the requirements to act as an accredited certification body and performs certification within that scope.

Certification body versus DPA

Another important distinction:

The DPA remains the regulator.

The certification body performs an assessment/certification function.

The DPA can supervise and intervene.

Therefore, obtaining certification does not amount to obtaining prior regulatory approval from the DPA unless the DPA itself is performing the relevant certification function.

The three levels of responsibility

Article 43 is best understood through three levels.

Level 1, Controller/processor

Responsible for actual GDPR compliance.

Level 2, Certification body

Responsible for conducting a proper certification assessment.

Level 3, DPA/accreditation body

Responsible for ensuring that the certification body satisfies the applicable accreditation requirements and, where relevant, taking regulatory action.

This layered system prevents responsibility from disappearing into the certification process.

A critical distinction: certification body accreditation vs certification validity

Consider this scenario:

Certification Body A is accredited for five years.

It issues a certificate to Company B that is valid for three years.

If Company A's accreditation is later renewed, that does not mean Company B's certificate automatically becomes valid beyond its own expiry.

Conversely, Company B's three-year certificate does not mean Certification Body A's accreditation lasts for three years.

These are independent legal time periods.

Certification body accreditation → maximum 5 years.

Individual certification → maximum 3 years.

This distinction is worth remembering.

What happens if the certification body is no longer competent?

Suppose a certification body loses several key experts and can no longer demonstrate the expertise required for the certification scopes for which it is accredited.

The issue is not simply whether future certificates should be issued.

Its accreditation itself may need to be reviewed or revoked.

This demonstrates why Article 43(7) focuses on whether the conditions for accreditation are still met.

Certification is therefore a controlled ecosystem

Article 43 does not merely regulate a company that issues certificates.

It creates an ecosystem consisting of:

  1. approved certification criteria
  2. accreditation requirements
  3. accredited certification bodies
  4. assessment of controllers/processors
  5. certification
  6. DPA oversight
  7. periodic review / renewal / withdrawal
  8. public transparency

That is the deeper structure of Article 43.

The most important grey area: "certified" does not mean "compliant with everything"

Suppose a company has a valid Article 42 certificate.

The certificate covers:

processing of customer data for a specific online service.

The company also:

  • processes employee data;

  • conducts marketing;

  • operates CCTV;

  • uses biometric authentication;

  • transfers data internationally.

The certificate does not automatically cover all these activities.

Therefore, one of the most important questions when evaluating a certification claim is:

What exactly is within the certification scope?

This is arguably more important than merely asking:

"Does the company have a GDPR certificate?"

The certification body must therefore avoid over-certification

A certification body should not allow its certificate to create an impression broader than the actual assessment.

For example:

"Certified for GDPR compliance"

is potentially misleading if the actual certificate concerns only a narrowly defined processing activity.

The certification mechanism should make the target and scope sufficiently clear.

This is where Article 43(6)'s transparency requirement becomes practically significant.

Complaints can act as a quality-control mechanism

The complaints procedure under Article 43(2)(d) is not merely a consumer-service requirement.

It can function as a quality-control mechanism for the certification system itself.

Imagine a certified company is publicly claiming:

"Our processing is certified."

A data subject discovers that the company is doing something materially inconsistent with the certified criteria.

A complaint can bring that issue to the certification body's attention.

The body may then investigate whether:

  • the certification was improperly granted;

  • the certified organisation is no longer complying;

  • the scope was misunderstood;

  • withdrawal or corrective action is necessary.

Thus, complaints contribute to continuing assurance.

Why public transparency and complaints work together

The system can be visualised as:

Public certification criteria

→ people know what certification means.

Public certification information

→ people know what was certified.

Complaint mechanism

→ people can challenge apparent non-conformity.

Certification body investigation

→ the certificate can be reviewed.

Withdrawal

→ misleading or non-compliant certification can be removed.

This is a much stronger system than simply issuing a certificate and leaving it untouched.

Article 43 and accountability

Article 43 ultimately supports the GDPR's broader accountability principle.

A controller can demonstrate:

"An independent accredited certification body assessed this defined processing operation against approved criteria."

That is stronger evidence than merely stating:

"Our internal privacy team believes we comply."

But the evidence has value precisely because Article 43 regulates the body providing it.

Without Article 43, the credibility of Article 42 certification would be substantially weaker.

The relationship between Articles 42 and 43

The simplest way to distinguish them is:

Article 42 asks:

What is certification, why does it exist, what can it demonstrate, and what are the rules governing certification?

Article 43 asks:

Who is allowed to perform certification, what qualifications must they have, how are they accredited, and how are they supervised?

So Article 42 regulates the certification mechanism.

Article 43 regulates the certification body.

The relationship with Article 58

Article 58 is important because it ensures that certification does not become a regulatory substitute.

The DPA retains powers to intervene where necessary.

This means the relationship is:

Certification body performs assessment

but

DPA retains regulatory authority.

If the certification body makes an improper certification decision, the DPA can potentially intervene.

The relationship with Article 46

Article 43 also becomes relevant when certification is used as an appropriate safeguard for international transfers under Article 46.

But the certification mechanism used for transfers must satisfy the applicable conditions.

In particular, certification cannot simply be treated as a universal transfer authorisation.

Where Article 46(2)(f) is relied upon, the relevant certification framework and binding and enforceable commitments must also be considered.

So:

Article 43 establishes the credibility of the certification body; Article 46 determines the legal role certification may play in transfers.

The role of the European Commission

The Commission's powers under paragraphs 8 and 9 are essentially designed to support EU-level consistency.

The architecture is therefore divided:

DPA / accreditation body

→ assesses certification bodies.

EDPB

→ supports consistency and maintains the European-level register.

European Commission

→ may adopt delegated and implementing measures within the powers provided by the GDPR.

This creates a multi-level governance structure.

The deeper purpose of Article 43

The ultimate objective is not simply to create another compliance industry.

It is to ensure that when an organisation says:

"Our processing is certified"

there is a credible institutional structure behind that statement.

That requires:

  • competent assessors;

  • independence;

  • approved criteria;

  • objective procedures;

  • complaint mechanisms;

  • regulatory oversight;

  • public transparency;

  • continuing review;

  • withdrawal mechanisms.

Article 43 builds that infrastructure.

The most important practical lesson

If you are evaluating a GDPR certificate in practice, the question should never stop at:

"Does the organisation have a GDPR certificate?"

The more meaningful questions are:

Who issued it?

Was that body properly accredited?

Under which certification mechanism?

What were the approved criteria?

What exactly was assessed?

What processing operations are within scope?

What is the validity period?

Has the certification been renewed, suspended or withdrawn?

What assessment methodology was used?

Can the certification body's accreditation be verified?

These questions flow directly from the architecture of Articles 42 and 43.

The entire Article 43 in one conceptual framework

Article 43 can ultimately be reduced to this sequence:

A certification body wants to certify GDPR processing.

It cannot simply begin doing so.

It must demonstrate appropriate expertise and independence.

The competence must correspond to the subject matter of certification.

It must satisfy the accreditation requirements.

This may involve the DPA and/or the national accreditation body.

It must commit to using the approved certification criteria.

It cannot invent an alternative standard and call it Article 42 certification.

It must establish proper certification procedures.

These must cover issuing, reviewing, renewing and withdrawing certification.

It must have a functioning complaints mechanism.

The process must be transparent to data subjects and the public.

It must avoid conflicts of interest.

The certification decision must be sufficiently independent.

Once accredited, it can assess controllers and processors.

But its assessment responsibility does not transfer the controller's GDPR responsibility to the certifier.

It must keep the DPA informed.

The DPA must receive information and reasons concerning certification decisions.

Its accreditation itself is temporary.

It can last no more than five years at a time.

Its accreditation can be revoked.

If the accreditation conditions cease to be satisfied or the body infringes the GDPR.

The entire system operates within a wider European framework.

The EDPB supports consistency and transparency, while the Commission can adopt the relevant delegated and implementing measures within its powers.

The core principle of Article 43

The best way to remember Article 43 is:

Article 42 creates the possibility of GDPR certification; Article 43 makes sure that the entity issuing that certification is itself competent, independent, accountable and subject to regulatory oversight.

The most important distinction is therefore:

A certificate is evidence about the controller/processor's processing.

Accreditation is evidence about the certification body's competence to issue that certificate.

And neither changes the fundamental rule that:

The controller or processor remains responsible for complying with the GDPR.

That is the central architecture connecting Articles 42 and 43.