Skip to main content
Data Protection / GDPR

Data protection certification

A voluntary procedure in which an accredited certification body or a supervisory authority attests that a defined processing operation meets the requirements of an approved GDPR certification criteria set.

Article 42 GDPR establishes data protection certification mechanisms, seals and marks as an instrument of regulated self-regulation. What gets certified is never a company as a whole, but a clearly delimited processing operation or set of operations carried out by a controller or processor. Participation is voluntary (Art. 42(3) GDPR) and must be based on a transparent set of criteria: the criteria are approved by the competent supervisory authority or, where they are to apply across the Union, endorsed by the European Data Protection Board under the consistency mechanism, in which case the scheme may result in a European Data Protection Seal (Art. 42(5) GDPR). Europrivacy, endorsed by the EDPB in 2022, was the first scheme to obtain that status.

Certificates are issued either by the supervisory authority itself or by a certification body accredited under Article 43 GDPR. In Germany this accreditation combines the national accreditation body (DAkkS) working to EN ISO/IEC 17065 with the additional data protection requirements laid down by the supervisory authority; Section 39 of the Federal Data Protection Act (BDSG) governs how the two interact. A certificate is valid for a maximum of three years and may be renewed on the same conditions; it must be withdrawn once the criteria are no longer met (Art. 42(7) GDPR). The organisation being certified has to provide the certification body with all information and access to the processing activities that the assessment requires (Art. 42(6) GDPR).

The practical value lies in the evidentiary effect. An approved certification is an element by which compliance with the obligations under Art. 24(3), Art. 25(3) and Art. 32(3) GDPR can be demonstrated, and it therefore supports the accountability principle in Art. 5(2) GDPR. When selecting processors it counts towards the sufficient guarantees required by Art. 28(5) GDPR, and adherence to approved certification mechanisms must be taken into account as a mitigating factor when a fine is calculated (Art. 83(2)(j) GDPR). A certification combined with binding and enforceable commitments by the data importer can additionally serve as a safeguard for transfers to third countries (Art. 46(2)(f) GDPR). The limit matters just as much: certification does not reduce the responsibility of the controller or processor and leaves the powers of the supervisory authorities untouched (Art. 42(4) GDPR). It is evidence, not a shield, and no substitute for a data protection management system that is actually lived.

Legal Basis

Art. 42 GDPR, Art. 43 GDPR, Art. 24(3), Art. 25(3), Art. 32(3), Art. 46(2)(f), Art. 83(2)(j) GDPR; Sections 39 and 40 BDSG (German Federal Data Protection Act); EN ISO/IEC 17065; EDPB Guidelines 1/2018 (certification) and 4/2018 (accreditation)

Practical Example

A cloud provider wants to show public-sector buyers that its customer portal is operated in line with data protection law. The data protection officer first defines the scope of certification (hosting and operation of the portal in two EU data centres, excluding the consulting services), selects a criteria set approved by the supervisory authority and engages a certification body accredited under Article 43 GDPR. For the assessment she assembles the evidence: the record of processing activities, the documentation of technical and organisational measures, the deletion concept, the sub-processor chain with the relevant data processing agreements, the results of the last data protection impact assessment and the training records. The assessors raise two non-conformities: administrative access is not logged, and there is no documented procedure for handling data subject requests arriving through the portal. Once the corrective actions are in place the certificate is granted for three years. The data protection officer schedules annual surveillance audits and adds a reminder in the data protection management system, because any material change to the portal has to be reported to the certification body.

FAQ

No. Certification is expressly voluntary (Art. 42(3) GDPR) and replaces no statutory obligation. It is an instrument of proof: controllers can use it to demonstrate compliance with Articles 24, 25 and 32 GDPR and to support their accountability. It only becomes binding where a contract or a public tender requires it.
A certificate is issued for a maximum of three years and can be renewed under the same conditions (Art. 42(7) GDPR). If the criteria are no longer met, the certification body or the supervisory authority must withdraw it. Material changes to the certified processing operation have to be notified to the certification body and may trigger a fresh assessment.
Not automatically. Article 42(4) GDPR makes clear that certification neither reduces the responsibility of the controller nor limits the powers of the supervisory authorities. That said, adherence to approved certification mechanisms must be weighed in favour of the organisation when a fine is set, under Art. 83(2)(j) GDPR. Only certifications under Article 42 GDPR have that effect - generic marketing seals do not.

How preeco supports you

Learn how our software supports you with this topic.

Learn more