← back to the act's dossier

GDPR — Article 41

The article's text

Article 41 Monitoring of approved codes of conduct 1. Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58, the monitoring of compliance with a code of conduct pursuant to Article 40 may be carried out by a body which has an appropriate level of expertise in relation to the subject-matter of the code and is accredited for that purpose by the competent supervisory authority. relation to the subject-matter of the code and is accredited for that purpose by the competent supervisory authority. 2. A body as referred to in paragraph 1 may be accredited to monitor compliance with a code of conduct where that body has: (a) demonstrated its independence and expertise in relation to the subject-matter of the code to the satisfaction of the competent supervisory authority; (b) established procedures which allow it to assess the eligibility of controllers and processors concerned to apply the code, to monitor their compliance with its provisions and to periodically review its operation; (c) established procedures and structures to handle complaints about infringements of the code or the manner in which the code has been, or is being, impl
full text
emented by a controller or processor, and to make those procedures and structures transparent to data subjects and the public; and (d) demonstrated to the satisfaction of the competent supervisory authority that its tasks and duties do not result in a conflict of interests. satisfaction of the competent supervisory authority that its tasks and duties do not result in a conflict of interests. 3. The competent supervisory authority shall submit the draft requirements for accreditation of a body as referred to in paragraph 1 of this Article to the Board pursuant to the consistency mechanism referred to in Article 63. 4. Without prejudice to the tasks and powers of the competent supervisory authority and the provisions of Chapter VIII, a body as referred to in paragraph 1 of this Article shall, subject to appropriate safeguards, take appropriate action in cases of infringement of the code by a controller or processor, including suspension or exclusion of the controller or processor concerned from the code. It shall inform the competent supervisory authority of such actions and the reasons for taking them. from the code. It shall inform the competent supervisory authority of such actions and the reasons for taking them. 5. The competent supervisory authority shall revoke the accreditation of a body as referred to in paragraph 1 if the requirements for accreditation are not, or are no longer, met or where actions taken by the body infringe this Regulation. 6. This Article shall not apply to processing carried out by public authorities and bodies.

Who wrote about this article in the consultations

Filers who named this exact article number in their own text. It is their sentence, not our reading — and not a causal claim.

15
business association
5
NGO
3
company
2
other
1
ACADEMIC_RESEARCH_INSTITTUTION
WhoCountryWhat they wrote
Selbstregulierung Informationswirtschaft e.V. (SRIW)DEclarification to this regard. 12.4. The Monitoring In addition to drafting the Code of Conduct, the monitoring of the Code under Art. 41 GDPR plays a significant role.
ESOMARNLproved Code of Conduct, pre-requisite is the monitoring of the adherence to its principles by an accredited Monitoring Body under Article 41 GDPR. For accreditation, monitoring bodies must meet the requirements defined by Art. 41 GDPR, as well as those of the
ANITEC-ASSINFORMITe EDPB. The right to be heard before an administration takes a measure that would adversely affect a person is enshrined in Article 41 CFEU and has long been recognised as a general principle of EU law. The Guidelines describe the process for a con
SCOPE EuropeBEin Europe and is an accredited monitoring body under the European General Data Protection Regulation since May 2021, pursuant to Article 41 GDPR. SCOPE Europe gathered expertise in levelling industry and data subject needs and interests to credible but also r
Bitkom e.V.DEct. The EDPB and DPAs are noted for interpreting the GDPR in a manner that some perceive as conflicting with the clear wording of Article 41. This misalignment, especially regarding the monitoring of codes of conduct, needs clarification and practical support
BDI e.V. (Federation of German Industries)DERegulation (EC) 864/2007. This means that only the national laws for international private law apply, e.g.: - in Germany Art 40, Art 41 EGBGB - in Austria national codification of international private law in the IPRG: compare § 5, § 48 IPRG. b) Administrativ
Insurance EuropeBEto Article 41 GDPR, which is designed as a “may” clause, the establishment of a private monitoring body is optional. Due to the fact that the GDPR must apply to all industries, codes of conduct, which include industry-related specifications, create legal certa
AUSTRIAN FEDERAL ECONOMIC CHAMBERATd be a bright success if they were approved more quickly and if there were no need to set up a monitoring body in accordance with Article 41 of the GDPR. Finding monitoring bodies that would like to take on these tasks is becoming increasingly difficult, as co
Bitkom e.V.DEEuropean administrative procedure which leads to an effective exercise of fundamental rights to good administration enshrined in Article 41 of the Charter of Fundamental Rights of the EU [and Article 6 of the European Convention of Human Rights] by the invest
ITI - Information Technology Industry CouncilUSated party, must provide direct recourse for appeal. Not recognising this infringes the fundamental right of good administration (Article 41 of the Charter of Fundamental Rights of the EU) and the rights of defence (Article 48 of the Charter) of the investigat
Hans-Hermann SchildDEn unter den Begriff „gute Verwaltung“ fallen, was speziell in Bezug auf die Tätigkeiten der Organe und Einrichtungen der Union in Art. 41 GRCh Ausdruck gefunden hat. Das Beschwer- deverfahren sollte gestärkt werden, um daraus einen echten ver- waltungsrechtlic
noybATA). Concept 2 should take care of this matter, as the national law of the relevant CSA/LSA applies, but the minimum guarantees of Article 41 CFR has to Procedural rights - Access to the file: modalities of access SAs do not always provide electronic access to
EuroCommerceBEents. o The right to be heard should cover both the factual and legal elements raised in the investigation, as it is enshrined in Article 41 of the Charter of Fundamental Rights of the EU. The right to be heard should also be granted by the EDPB in the situati
ITI - Information Technology Industry CouncilUSith due regard to fair procedure rights conferred by national and EU law, including the right to good administration conferred by Article 41 of the Charter of Fundamental Rights of the EU.
Ecommerce EuropeBEuring judicial proceedings. More specifically, we firmly argue that to give full effect to the right to be heard, as laid down in Article 41 of the Charter of Fundamental Rights of the European Union, it is vital that this right entails both factual and legal
Bitkom e.V.DEvestigation can only make submissions on factual points. We submit that to give full effect to the right to be heard enshrined in Article 41 of the Charter of Fundamental Rights of the EU, it is necessary that this right covers both the factual page 3 / 7 and
Polish Confederation LewiatanPLtigation can only make submissions on factual points. • We insist that, to give full effect to the right to be heard enshrined in Article 41 of the Charter of Fundamental Rights of the EU (CFREU), it is necessary that this right covers both the factual and leg
AmCham SlovenijaSItigation can only make submissions on factual points.  We insist that, to give full effect to the right to be heard enshrined in Article 41 of the Charter of Fundamental Rights of the EU (CFREU), it is necessary that this right covers both the factual and leg
Asociación Española de Economía Digital (Adigital)EStigation can only make submissions on factual points. ● We insist that, to give full effect to the right to be heard enshrined in Article 41 of the Charter of Fundamental Rights of the EU (CFREU), it is necessary that this right covers both the factual and leg
American Chamber of Commerce to the EU (AmCham EU)BEates, the parties under investigation can only make submissions on factual points. However, the right to be heard is enshrined in Article 41 of the Charter of Fundamental Rights of the EU; this includes both the factual and legal elements raised in an investig
American Chamber of Commerce in PolandPLtigation can only make submissions on factual points. • We insist that, to give full effect to the right to be heard enshrined in Article 41 of the Charter of Fundamental Rights of the EU (CFREU), it is necessary that this right covers both the factual and leg
European Digital Rights (EDRi)BE1040 Bruxelles, Belgium | Tel. +32 2 274 25 70 | www.edri.org The complainant should always be heard at the EDPB level under Article 41 CFR. Complaintants should also have a right to be heard before all SAs. Additionally, the fact that the complainant was
CCIA - Computer & Communications Industry AssociationBEwhich the party has never had an opportunity to comment on. In order to ensure a fair and impartial hearing, and consistent with Article 41(2) CFR, the EDPB should be required to proactively disclose all relevant materials to the party under investigation. Th
Centre for Information Policy Leadership (CIPL)BEsidering any procedural deadlines. The worst outcome would be cases rushed to the decision under artificial deadlines contrary to Article 41 of the Charter of Fundamental rights, which would then more likely than not be challenged in court, ultimately extendin
Access Now EuropeFRindividual measure which would affect him or her adversely is taken; 19 EU Charter of Fundamental Rights, Article 41. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:12012P/TXT consistent with the structure of the cooperation and consistency arrangem
SRIW & SCOPE EuropeDEriations based on the same principles. ■ Member states e.g. could define additional requirements for monitoring bodies pur- suant Art. 41 GDPR if and to the extent they will be also monitoring public authorities or bodes (in general or related to specific auth
tions in Art. 40 and 41 GDPR should not be in- terpreted more strictly or even contrary to the wording by the EDPB. b) Reasoning: Article 41 subsection 1 GDPR rules that the monitoring of compliance with a code of conduct MAY be carried out by a body with an a
BraveUSided for in Article 8(3) of the Charter, and by Article 16(2) of the TFEU. Article 52(4) of the GDPR (Regulation 2016/679/EU) and Article 41(1) of the LED (Directive 2016/680/EU) require that national governments give DPAs the human and financial resources nec

Source: public consultation submissions and position papers. n = 28 mentions; counted as a literal reference to the article number.

Ask about this article →