The entire Article 43 in one conceptual framework
Article 43 can ultimately be reduced to this sequence:
A certification body wants to certify GDPR processing.
It cannot simply begin doing so.
It must demonstrate appropriate expertise and independence.
The competence must correspond to the subject matter of certification.
It must satisfy the accreditation requirements.
This may involve the DPA and/or the national accreditation body.
It must commit to using the approved certification criteria.
It cannot invent an alternative standard and call it Article 42 certification.
It must establish proper certification procedures.
These must cover issuing, reviewing, renewing and withdrawing certification.
It must have a functioning complaints mechanism.
The process must be transparent to data subjects and the public.
It must avoid conflicts of interest.
The certification decision must be sufficiently independent.
Once accredited, it can assess controllers and processors.
But its assessment responsibility does not transfer the controller's GDPR responsibility to the certifier.
It must keep the DPA informed.
The DPA must receive information and reasons concerning certification decisions.
Its accreditation itself is temporary.
It can last no more than five years at a time.
Its accreditation can be revoked.
If the accreditation conditions cease to be satisfied or the body infringes the GDPR.
The entire system operates within a wider European framework.
The EDPB supports consistency and transparency, while the Commission can adopt the relevant delegated and implementing measures within its powers.
The core principle of Article 43
The best way to remember Article 43 is:
Article 42 creates the possibility of GDPR certification; Article 43 makes sure that the entity issuing that certification is itself competent, independent, accountable and subject to regulatory oversight.
The most important distinction is therefore:
A certificate is evidence about the controller/processor's processing.
Accreditation is evidence about the certification body's competence to issue that certificate.
And neither changes the fundamental rule that:
The controller or processor remains responsible for complying with the GDPR.
That is the central architecture connecting Articles 42 and 43.