Skip to main content
Data Protection / GDPR

Codes of conduct

Codes of conduct under Art. 40 GDPR are sector-specific rulebooks drawn up by associations to translate the GDPR into concrete practice for an industry; once approved by a supervisory authority, adherence can be used to demonstrate compliance.

Codes of conduct are a self-regulation instrument that the GDPR explicitly encourages in Art. 40. They are not drafted by individual companies but by associations and other bodies representing a category of controllers or processors, such as trade associations in the insurance, advertising, healthcare or cloud sectors. Their purpose is to turn the deliberately abstract requirements of the Regulation into workable rules for the processing situations that are typical of a given industry. Art. 40(2) GDPR sets out an open list of possible subjects: fair and transparent processing, legitimate interests, pseudonymisation, information given to data subjects, the exercise of data subject rights, the protection of children, technical and organisational measures, breach notification, international transfers and out-of-court dispute resolution. Joining a code is voluntary, but once a member has signed up, the commitments become binding.

A code only acquires legal effect through the approval procedure. The association submits the draft to the competent supervisory authority under Art. 40(5) GDPR, which checks whether it complies with the Regulation and provides sufficient appropriate safeguards; in Germany this is either a state data protection authority or the federal commissioner, depending on the scope and seat of the applicant. Where the code relates to processing activities in several member states, the authority forwards the draft to the European Data Protection Board for an opinion before approving it (Art. 40(7) GDPR), and the European Commission may then grant it general validity within the Union by implementing act (Art. 40(9) GDPR). Approved codes are registered and published, and the Board maintains a central register for this purpose (Art. 40(11) GDPR). For private-sector codes an accredited monitoring body under Art. 41 GDPR is also mandatory: an independent, suitably expert organisation that monitors adherence, handles complaints and sanctions infringements up to and including exclusion from the code. The procedural detail is set out in the European Data Protection Board guidelines 1/2019 on codes of conduct and monitoring bodies.

As evidence of compliance, codes of conduct appear at several points in the Regulation. Adherence to an approved code may be used under Art. 24(3) GDPR to demonstrate that a controller meets its obligations, under Art. 28(5) GDPR to show that a processor offers sufficient guarantees, and under Art. 32(3) GDPR to support the adequacy of security measures. For transfers to third countries, an approved code combined with binding and enforceable commitments by the recipient can serve as a safeguard under Art. 46(2)(e) GDPR, and Art. 40(3) GDPR allows organisations outside the scope of the Regulation to sign up as well. In enforcement proceedings, the supervisory authority takes adherence into account as a factor when setting a fine under Art. 83(2)(j) GDPR. The limits are equally clear: a code replaces neither a legal basis nor the accountability principle, it does not shift responsibility between parties, and it does not bind the courts. In practice, codes have gained the most traction in cloud services – the EU Cloud Code of Conduct was approved by the Belgian data protection authority in 2021 and the CISPE code by the French CNIL in the same year, each following an opinion of the European Data Protection Board.

Legal Basis

Art. 40 and Art. 41 GDPR; supplemented by Art. 24(3), Art. 28(5), Art. 32(3), Art. 46(2)(e) and Art. 83(2)(j) GDPR; EDPB Guidelines 1/2019 on codes of conduct and monitoring bodies

Practical Example

A mid-sized company plans to move its personnel files to a European cloud service. During vendor selection, the data protection coordinator checks whether the provider has signed up to an approved code and finds it on the public adherence list of the EU Cloud Code of Conduct. She records in the selection file that the declaration of adherence, the scope of the covered services and the responsible monitoring body have all been verified, so that membership supports the evidence of sufficient guarantees required by Art. 28(1) and (5) GDPR. Because a code does not replace a contract, she still concludes a full data processing agreement under Art. 28(3) GDPR, reconciles the list of sub-processors and storage locations, and files the adherence certificate, her assessment note and a diary entry for the annual review with the vendor records.

FAQ

No. Art. 40 GDPR reserves the drafting role for associations and other bodies representing a category of controllers or processors. An individual company can join an existing approved code or take part in drafting one through its trade association. To showcase a specific processing operation of its own, certification under Art. 42 GDPR is the appropriate instrument instead.
A code is a collective rulebook for an entire sector that individual organisations sign up to, whereas certification assesses a specific processing operation of one controller or processor and is granted for a limited period. Both are supervised by accredited bodies and both can be relied on under Art. 24(3), Art. 28(5) and Art. 32(3) GDPR to demonstrate compliance. The two instruments are complementary rather than mutually exclusive.
There is no blanket immunity. Adherence to an approved code is one of the factors a supervisory authority weighs when setting a fine under Art. 83(2)(j) GDPR and can have a mitigating effect. Conversely, breaching the code can trigger measures by the monitoring body up to exclusion, which is reported to the supervisory authority. The accountability obligation under Art. 5(2) GDPR continues to apply regardless.

How preeco supports you

Learn how our software supports you with this topic.

Learn more