Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Codes of Conduct & Certifications (Art. 40-43)
Courses Guides Blog Resources News
Français English Nederlands
Fiche 48/54 Part 5 — Operational Obligations & Sanctions Advanced Reviewed 2026-08-23

Codes of Conduct & Certifications (Art. 40-43)

Codes of conduct (Art. 40) and certification mechanisms (Art. 42) are voluntary instruments serving to demonstrate compliance (accountability). They do not create a general presumption of compliance n

Open in interactive reader
⚖️ Binding Provisions (Art. 40 to 43) 📘 EDPB Guidelines 1/2019 Codes of Conduct

Codes of Conduct & Certifications (Art. 40-43)

⚡ In 30 seconds

Codes of conduct and certifications facilitate demonstrating compliance, enhance transparency with partners, and can frame international transfers, without exempting actors from their legal responsibilities.

Codes of Conduct (Art. 40)

Drafted by trade associations or bodies representing sectors to tailor the GDPR to specific industry realities. Following approval by the competent supervisory authority (or EDPB), adherence serves as a tangible element to prove compliance.

Certifications (Art. 42)

Issued by accredited certification bodies for a maximum duration of 3 years. Certification provides verifiable evidence of compliance without establishing a general presumption of legality nor diminishing controller or processor liability.

⚡ Key Takeaways
  • Voluntary mechanisms providing structured evidence of compliance without conferring any general immunity.
  • Obtaining certification (Art. 42) does not reduce the legal liability of the controller or processor.
  • Approved codes and certification schemes can serve as appropriate safeguards for international data transfers (Art. 46.2.f).
⚠️ Common Pitfall

Assuming that obtaining a certification grants blanket legal immunity or relieves the organisation from continuously auditing the effectiveness of its safeguards.

🛠️ Practical Action

Assess whether approved sector-specific codes of conduct or official certification schemes (such as Europrivacy) exist in your sector to reinforce accountability.

⚖️ Official sources: Art. 40–43 GDPR · Recitals 98–100 · EDPB Guidelines 1/2019 ✓ Last legal review: 23 August 2026

✓ Key takeaways

  • Voluntary mechanisms providing structured evidence of compliance without conferring any general immunity.
  • Obtaining certification (Art. 42) does not reduce the legal liability of the controller or processor.
  • Approved codes and certification schemes can serve as appropriate safeguards for international data transfers (Art. 46.2.f).

⚠ Common pitfall: Assuming that obtaining a certification grants blanket legal immunity or relieves the organisation from continuously auditing the effectiveness of its safeguards.

→ Actionable practice: Assess whether approved sector-specific codes of conduct or official certification schemes (such as Europrivacy) exist in your sector to reinforce accountability.

← Personal Data Breaches: Notification Procedure (Art. 33 & 34) Compliance Audit & Continuous Action Plan →