Filers who named this exact article number in their own text. It is their sentence, not our reading — and not a causal claim.
| Who | Country | What they wrote |
|---|---|---|
| Bitkom e.V. | DE | bodies optional, aligning with the objective of encouraging code development outlined in Article 40(1) of the GDPR. 21 13. Certification, including as a tool for international transfers a. Do you consider that adequate use is made of certifications? The GDPR a ↗ |
| Selbstregulierung Informationswirtschaft e.V. (SRIW) | DE | E.g. Codes of Conduct require a general validity involving the European Commission (see Art. 40.3 GDPR, Art. 40.5 to 40.9 GDPR), whereas Certifications do not require such additional step (see Art. 42.3 and 42.5 GDPR). Differences in the approach could be argu ↗ |
| SCOPE Europe | BE | relevant entities in the direction of encouraging the drawing up of codes of conduct – as defined in Article 40 GDPR. On a final note, once the work on the report is concluded and the Commission is able to assess the state of play of codes of conduct across th ↗ |
| BDI e.V. (Federation of German Industries) | DE | g ROM II Regulation (EC) 864/2007. This means that only the national laws for international private law apply, e.g.: - in Germany Art 40, Art 41 EGBGB - in Austria national codification of international private law in the IPRG: compare § 5, § 48 IPRG. b) Admin ↗ |
| ESOMAR | NL | alization of such tools is still facing procedural obstacles. Further streamlining of approval and accreditation procedures under Article 40 and 41 GDPR is highly welcomed in that area and recommended to be taken into consideration in the in view of the 2024 G ↗ |
| MyData-TRUST | BE | fications, marks and seals a. Do you consider that adequate use is made of codes of conduct? The use of the tool foreseen by GDPR article 40 is sub-optimal because of the length and complexity of the development pathway. ↗ |
| Insurance Europe | BE | include industry-related specifications, create legal certainty for users and facilitate the work of the supervisory authorities. Article 40(1) GDPR therefore rightly specifies the legislators’ objective to encourage the drawing up of codes of conduct. There a ↗ |
| European Tech Alliance | BE | like encouraging the creation and adoption of codes of conduct as outlined in Article 40 of the GDPR. These codes could clarify how the GDPR applies within specific industries. Although these codes hold the potential to significantly enhance compliance, their ↗ |
| AUSTRIAN FEDERAL ECONOMIC CHAMBER | AT | for international transfers a. Do you consider that adequate use is made of codes of conduct? Codes of conduct in accordance with Article 40 of the GDPR would be a bright success if they were approved more quickly and if there were no need to set up a monitori ↗ |
| Anonos Inc. | US | 9(1).” b. Pseudonymization helps to satisfy Article 35(8) creation of and adherence to “approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing ope ↗ |
| SCOPE Europe | BE | when it comes to the approval process of transnational Codes of Conduct in accordance with Article 40.5 GDPR. As organizations involved in the approval process of several Codes of Conduct, we have encountered varying interpretations by data protection supervis ↗ |
| Selbstregulierung Informationswirtschaft e.V. | DE | ection supervisory authorities, particularly in the context of transnational Codes of Conduct. 5 Streamlining of procedures under Article 40 and 41 GDPR Given that those tools provide a significant added value when it comes to supporting GDPR enforce- ment, we ↗ |
| Bitkom e.V. | DE | etermine the competent DPA is required when it comes to the approval process of transnational Codes of Conduct in accordance with Article 40.5 GDPR. Experience has shown varying interpretations by DPAs when it comes to factors that determine their competence. ↗ |
| David BARNARD-WILLS | GB | heltenham, 2013. 113 Galetta, Kloza & De Hert, op. cit., April 2016, p. 52. 114 Ibid, p. 61. General recommendations 34 Resources Article 40(k) GDPR on codes of conduct provides the potential for “[o]ut of court proceedings and other dispute resolution procedu ↗ |
| SRIW & SCOPE Europe | DE | to Art. 46.2 (e) in conjunction with Art. 40 GDPR can be a crucial, robust but innovation-friendly transfer mechanism. Codes of conduct can be developed by industries themselves, making it possible to in- troduce modern business practices and giving the flexib ↗ |
| IAB Europe | BE | ta subjects, since they clarify how the GDPR can be applied with regard to the particular features of a given industry or sector. Art. 40 GDPR encourages Member States, DPAs, the EDPB and the Commission to promote the drawing up of codes of conduct, contributi ↗ |
| COCIR | BE | guidelines and other suitable means to meet this need. For instance, drafting sector-specific codes of conduct in accordance with Article 40 of the GDPR could be a suitable way to contribute to the proper application of the GDPR. Such codes of conduct could pa ↗ |
| — | lculation of the 72- hour period.“ 5. The drawing up and the application of codes of conduct should be further encouraged un- der Art. 40 and 41 GDPR. The EDPB should support with a practical interpretation of the GDPR. a) Request: We strongly support the idea ↗ | |
| Gesamtverband der Deutschen Versicherungswirtschaft e.V. | DE | 9 (para. 60), the EDPB states that a monitoring body must be identified for codes of conduct to be approved within the meaning of Article 40 GDPR, whereas Arti- cle 41(1) GDPR explicitly includes an optional provision (“may” clause) in this context. In its G ↗ |
| ESOMAR | NL | nstrumental to safeguard such trust. As a sector, we are also actively exploring the opportunity offered by GDPR and specifically Article 40 to develop a robust GDPR Research Code that provides specific guidance on GDPR compliance requirements for market, opin ↗ |
| Centre for Information Policy Leadership (CIPL) | GB | substantive overlap such as the APEC CBPR. The EDPB and DPAs should continue the work initiated by the Article 29 WP and APEC.19 Article 40 GDPR Codes of Conducts should similarly be available as soon as feasible and, importantly, the conditions for their app ↗ |
| EFAMRO | BE | rd (EDPB)? • What is the binding mechanism of a Code of Conduct to processor who is not party to it? • Can the Commission clarify Art 40.9 and how “implementing acts” will be adopted and with which effect? • How will the interaction between national and transn ↗ |
Source: public consultation submissions and position papers. n = 22 mentions; counted as a literal reference to the article number.