Codes of conduct
Codes of conduct under Art. 40 GDPR are sector-specific rulebooks drawn up by associations to translate the GDPR into concrete practice for an industry; once approved by a supervisory authority, adherence can be used to demonstrate compliance.
Codes of conduct are a self-regulation instrument that the GDPR explicitly encourages in Art. 40. They are not drafted by individual companies but by associations and other bodies representing a category of controllers or processors, such as trade associations in the insurance, advertising, healthcare or cloud sectors. Their purpose is to turn the deliberately abstract requirements of the Regulation into workable rules for the processing situations that are typical of a given industry. Art. 40(2) GDPR sets out an open list of possible subjects: fair and transparent processing, legitimate interests, pseudonymisation, information given to data subjects, the exercise of data subject rights, the protection of children, technical and organisational measures, breach notification, international transfers and out-of-court dispute resolution. Joining a code is voluntary, but once a member has signed up, the commitments become binding.
A code only acquires legal effect through the approval procedure. The association submits the draft to the competent supervisory authority under Art. 40(5) GDPR, which checks whether it complies with the Regulation and provides sufficient appropriate safeguards; in Germany this is either a state data protection authority or the federal commissioner, depending on the scope and seat of the applicant. Where the code relates to processing activities in several member states, the authority forwards the draft to the European Data Protection Board for an opinion before approving it (Art. 40(7) GDPR), and the European Commission may then grant it general validity within the Union by implementing act (Art. 40(9) GDPR). Approved codes are registered and published, and the Board maintains a central register for this purpose (Art. 40(11) GDPR). For private-sector codes an accredited monitoring body under Art. 41 GDPR is also mandatory: an independent, suitably expert organisation that monitors adherence, handles complaints and sanctions infringements up to and including exclusion from the code. The procedural detail is set out in the European Data Protection Board guidelines 1/2019 on codes of conduct and monitoring bodies.
As evidence of compliance, codes of conduct appear at several points in the Regulation. Adherence to an approved code may be used under Art. 24(3) GDPR to demonstrate that a controller meets its obligations, under Art. 28(5) GDPR to show that a processor offers sufficient guarantees, and under Art. 32(3) GDPR to support the adequacy of security measures. For transfers to third countries, an approved code combined with binding and enforceable commitments by the recipient can serve as a safeguard under Art. 46(2)(e) GDPR, and Art. 40(3) GDPR allows organisations outside the scope of the Regulation to sign up as well. In enforcement proceedings, the supervisory authority takes adherence into account as a factor when setting a fine under Art. 83(2)(j) GDPR. The limits are equally clear: a code replaces neither a legal basis nor the accountability principle, it does not shift responsibility between parties, and it does not bind the courts. In practice, codes have gained the most traction in cloud services – the EU Cloud Code of Conduct was approved by the Belgian data protection authority in 2021 and the CISPE code by the French CNIL in the same year, each following an opinion of the European Data Protection Board.
Legal Basis
Art. 40 and Art. 41 GDPR; supplemented by Art. 24(3), Art. 28(5), Art. 32(3), Art. 46(2)(e) and Art. 83(2)(j) GDPR; EDPB Guidelines 1/2019 on codes of conduct and monitoring bodies
Practical Example
A mid-sized company plans to move its personnel files to a European cloud service. During vendor selection, the data protection coordinator checks whether the provider has signed up to an approved code and finds it on the public adherence list of the EU Cloud Code of Conduct. She records in the selection file that the declaration of adherence, the scope of the covered services and the responsible monitoring body have all been verified, so that membership supports the evidence of sufficient guarantees required by Art. 28(1) and (5) GDPR. Because a code does not replace a contract, she still concludes a full data processing agreement under Art. 28(3) GDPR, reconciles the list of sub-processors and storage locations, and files the adherence certificate, her assessment note and a diary entry for the annual review with the vendor records.