← back to the act's dossier

GDPR — Article 42

The article's text

Article 42 Certification 1. The Member States, the supervisory authorities, the Board and the Commission shall encourage, in particular at Union level, the establishment of data protection certification mechanisms and of data protection seals and marks, for the purpose of demonstrating compliance with this Regulation of processing operations by controllers and processors. The specific needs of micro, small and medium-sized enterprises shall be taken into account. and processors. The specific needs of micro, small and medium-sized enterprises shall be taken into account. 2. In addition to adherence by controllers or processors subject to this Regulation, data protection certification mechanisms, seals or marks approved pursuant to paragraph 5 of this Article may be established for the purpose of demonstrating the existence of appropriate safeguards provided by controllers or processors that are not subject to this Regulation pursuant to Article 3 within the framework of personal data transfers to third countries or international organisations under the terms referred to in point (f) of Article 46(2). Such controllers or processors shall make binding and enforceable commitments, via
full text
contractual or other legally binding instruments, to apply those appropriate safeguards, including with regard to the rights of data subjects. binding instruments, to apply those appropriate safeguards, including with regard to the rights of data subjects. 3. The certification shall be voluntary and available via a process that is transparent. 4. A certification pursuant to this Article does not reduce the responsibility of the controller or the processor for compliance with this Regulation and is without prejudice to the tasks and powers of the supervisory authorities which are competent pursuant to Article 55 or 56. prejudice to the tasks and powers of the supervisory authorities which are competent pursuant to Article 55 or 56. 5. A certification pursuant to this Article shall be issued by the certification bodies referred to in Article 43 or by the competent supervisory authority, on the basis of criteria approved by that competent supervisory authority pursuant to Article 58(3) or by the Board pursuant to Article 63. Where the criteria are approved by the Board, this may result in a common certification, the European Data Protection Seal. 6. The controller or processor which submits its processing to the certification mechanism shall provide the certification body referred to in Article 43, or where applicable, the competent supervisory authority, with all information and access to its processing activities which are necessary to conduct the certification procedure. all information and access to its processing activities which are necessary to conduct the certification procedure. 7. Certification shall be issued to a controller or processor for a maximum period of three years and may be renewed, under the same conditions, provided that the relevant criteria continue to be met. Certification shall be withdrawn, as applicable, by the certification bodies referred to in Article 43 or by the competent supervisory authority where the criteria for the certification are not or are no longer met. 8. The Board shall collate all certification mechanisms and data protection seals and marks in a register and shall make them publicly available by any appropriate means.

Who wrote about this article in the consultations

Filers who named this exact article number in their own text. It is their sentence, not our reading — and not a causal claim.

4
business association
3
company
1
ACADEMIC_RESEARCH_INSTITTUTION
1
other
1
non-EU citizen
WhoCountryWhat they wrote
European Centre for Certification and Privacy (ECCP)LUation outside of Europe, the current approach under Art. 43 GDPR makes it difficult to implement and enters into tension with the Art. 42 GDPR obligations to take into account small and micro-enterprise needs as required by GDPR Art. 42: “The specific needs of
Selbstregulierung Informationswirtschaft e.V. (SRIW)DEEuropean Commission (see Art. 40.3 GDPR, Art. 40.5 to 40.9 GDPR), whereas Certifications do not require such additional step (see Art. 42.3 and 42.5 GDPR). Differences in the approach could be argued in the different approaches of Codes of Conduct and Certific
ISPA-Internet Service Provdiers AustriaATfers a. Do you consider that adequate use is made of certifications? No: So far there are 2 certifications in the EU according to Art 42 GDPR that are not being used appropriately. There is no experience in connection with certifications regarding data transfe
VNO-NCW / MKB NederlandNLcreate level playing field 7. Promote Codes of Conduct include clarification facultative character of appointing monitoring body article 42 8. Fragmentation in EU - 9. International transfers trusted free flow of data 10. GDPR and innovation / new technologie
Federation of Austrian IndustriesATional transfers a. Do you consider that adequate use is made of certifications? Until now there are 2 certifications according to Art 42 GDPR in the EU. These certifications are not used in an adequate way. For third country data transfer there is no experienc
Hangzhou Hikvision Digital Technology Co.,Ltd. (Hikvision)CHunder the Europrivacy certification. As a manufacturer, we would appreciate the availability of certification schemes pursuant to Article 42 GDPR that would demonstrate product compliance with specific GDPR requirements, such as data protection by design and b
David BARNARD-WILLSGB, David Barnard-Wills & Vagelis Papakonstantinou, “The future of privacy certification in Europe: an exploration of options under article 42 of the GDPR”, International Review of Law, Computers & Technology, Vol.30, No. 3, 2016, pp. 246-270. 102 Barnard-Wills
Deutsche Vereinigung für Datenschutz e.V.DEweniger großen Teil ihrer Daten- verarbeitung zur Erbringung der Dienstleistung an andere Unternehmen auslagern. Zertifizierung (Art. 42) Leider gibt es auch fast vier Jahre nach dem Inkrafttreten und fast zwei Jahre nach dem Wirksamwer- den der DSGVO noch ke
DIGITALEUROPEBEg it ’a global standard: it is not GDPR specific, nor does it constitute as such, a GDPR certification instrument as described in Article 42 of the GDPR.’ See https://www.cnil.fr/en/iso-27701-international-standard-addressing- personal-data-protection 8 https:
Centre for Information Policy Leadership (CIPL)GBs a global standard: it is 22 not GDPR specific, nor does it constitute, as such, a GDPR certification instrument as described in Article 42 of the regulation”. https://www.cnil.fr/en/iso-27701-international-standard-addressing-personal-data-protection. 17 Art
McAfeeBEl customers coming on-site. © 2019 Law Business Research Ltd Infosec and EU Privacy Requirements 10 ii EU Code of Conduct for CSP Article 42 of the GDPR provides that: Member States, the supervisory authorities, the Board and the Commission shall encourage, in

Source: public consultation submissions and position papers. n = 11 mentions; counted as a literal reference to the article number.

Ask about this article →