Article 40 GDPR

From GDPRhub
Article 40 - Codes of conduct
Chapter 10: Delegated and implementing acts

Legal Text


Article 40 - Codes of conduct

1. The Member States, the supervisory authorities, the Board and the Commission shall encourage the drawing up of codes of conduct intended to contribute to the proper application of this Regulation, taking account of the specific features of the various processing sectors and the specific needs of micro, small and medium-sized enterprises.

2. Associations and other bodies representing categories of controllers or processors may prepare codes of conduct, or amend or extend such codes, for the purpose of specifying the application of this Regulation, such as with regard to:

(a) fair and transparent processing;
(b) the legitimate interests pursued by controllers in specific contexts;
(c) the collection of personal data;
(d) the pseudonymisation of personal data;
(e) the information provided to the public and to data subjects;
(f) the exercise of the rights of data subjects;
(g) the information provided to, and the protection of, children, and the manner in which the consent of the holders of parental responsibility over children is to be obtained;
(h) the measures and procedures referred to in Articles 24 and 25 and the measures to ensure security of processing referred to in Article 32;
(i) the notification of personal data breaches to supervisory authorities and the communication of such personal data breaches to data subjects;
(j) the transfer of personal data to third countries or international organisations; or
(k) out-of-court proceedings and other dispute resolution procedures for resolving disputes between controllers and data subjects with regard to processing, without prejudice to the rights of data subjects pursuant to Articles 77 and 79.

3. In addition to adherence by controllers or processors subject to this Regulation, codes of conduct approved pursuant to paragraph 5 of this Article and having general validity pursuant to paragraph 9 of this Article may also be adhered to by controllers or processors that are not subject to this Regulation pursuant to Article 3 in order to provide appropriate safeguards within the framework of personal data transfers to third countries or international organisations under the terms referred to in point (e) of Article 46(2). Such controllers or processors shall make binding and enforceable commitments, via contractual or other legally binding instruments, to apply those appropriate safeguards including with regard to the rights of data subjects.

4. A code of conduct referred to in paragraph 2 of this Article shall contain mechanisms which enable the body referred to in Article 41(1) to carry out the mandatory monitoring of compliance with its provisions by the controllers or processors which undertake to apply it, without prejudice to the tasks and powers of supervisory authorities competent pursuant to Article 55 or 56.

5. Associations and other bodies referred to in paragraph 2 of this Article which intend to prepare a code of conduct or to amend or extend an existing code shall submit the draft code, amendment or extension to the supervisory authority which is competent pursuant to Article 55. The supervisory authority shall provide an opinion on whether the draft code, amendment or extension complies with this Regulation and shall approve that draft code, amendment or extension if it finds that it provides sufficient appropriate safeguards.

6. Where the draft code, or amendment or extension is approved in accordance with paragraph 5, and where the code of conduct concerned does not relate to processing activities in several Member States, the supervisory authority shall register and publish the code.

7. Where a draft code of conduct relates to processing activities in several Member States, the supervisory authority which is competent pursuant to Article 55 shall, before approving the draft code, amendment or extension, submit it in the procedure referred to in Article 63 to the Board which shall provide an opinion on whether the draft code, amendment or extension complies with this Regulation or, in the situation referred to in paragraph 3 of this Article, provides appropriate safeguards.

8. Where the opinion referred to in paragraph 7 confirms that the draft code, amendment or extension complies with this Regulation, or, in the situation referred to in paragraph 3, provides appropriate safeguards, the Board shall submit its opinion to the Commission.

9. The Commission may, by way of implementing acts, decide that the approved code of conduct, amendment or extension submitted to it pursuant to paragraph 8 of this Article have general validity within the Union. Those implementing acts shall be adopted in accordance with the examination procedure set out in Article 93(2).

10. The Commission shall ensure appropriate publicity for the approved codes which have been decided as having general validity in accordance with paragraph 9.

11. The Board shall collate all approved codes of conduct, amendments and extensions in a register and shall make them publicly available by way of appropriate means.

Relevant Recitals

Recital 98: Codes of Conduct
Associations or other bodies representing categories of controllers or processors should be encouraged to draw up codes of conduct, within the limits of this Regulation, so as to facilitate the effective application of this Regulation, taking account of the specific characteristics of the processing carried out in certain sectors and the specific needs of micro, small and medium enterprises. In particular, such codes of conduct could calibrate the obligations of controllers and processors, taking into account the risk likely to result from the processing for the rights and freedoms of natural persons.

Recital 99: Consultation of Stakeholders for Codes of Conduct
When drawing up a code of conduct, or when amending or extending such a code, associations and other bodies representing categories of controllers or processors should consult relevant stakeholders, including data subjects where feasible, and have regard to submissions received and views expressed in response to such consultations.

Commentary

Article 40 GDPR opens Section 5 (Codes of Conduct and Certification) of Chapter IV (Controller and Processor) and outlines the possibility to prepare codes of conducts (CoC) for the effective application of the GDPR, taking into account the specific features of various sectors and the specific needs of micro, small and medium-sized enterprises. Article 40 GDPR is closely connected to Article 41 GDPR which stipulates the monitoring of approved codes of conduct.

CoC are a voluntary accountability tool providing for specific data protection rules for categories of controllers and processors. In other words, CoC can provide a rule book for a group of controllers and processors describing how a GDPR compliant processing operation looks like in the specific processing situation.[1]

Various actors are involved in setting up, monitoring and adhering to CoC:

  • First, an association or other body representing categories of controllers or processors (i.e. "Code Owners"[2]) creates the CoC.
  • Second, the competent supervisory authority (i.e. Data Protection Authority; "DPA") approves the CoC (potentially involving the European Data Protection Board ("EDPB"), and the European Commission (EC)).
  • Third, the controllers and processors which voluntarily undertake to apply the CoC.
  • And finally, the body under Article 41(1) GDPR ("Monitoring Body") which monitors the compliance with the CoC.

For the controllers and processors undertaking to apply the CoC of a given sector, adherence to the CoC is a measure to demonstrate compliance with the GDPR.[3]

Article 40(1) GDPR is directed to Member States, the DPAs, the EDPB, and the EC and requires the encouragement of the drawing up of CoC.

Article 40(2) GDPR provides for the option of Code Owners to draw up CoC. Further, this provisions lists examples of the scope of such CoC such as how the collection of personal data and the information provided to the public and to data subjects should take place.

Article 40(3) GDPR is directed at controllers and processors that are not subject to the territorial scope of the GDPR and provides them with the option to enter into binding agreements to apply certain CoC in order to provide for appropriate safeguards within the framework of personal data transfers to third countries or international organisations under Article 46(2)(e) GDPR.

Article 40(4) GDPR requires CoC to contain mechanisms which enable the monitoring body under Article 41(1) GDPR to carry out the mandatory monitoring of compliance with the CoC.

Article 40(5) GDPR describes the approval mechanism for CoC and obliges Code Owners to submit the a draft of CoC to the competent DPA. The DPA then has to provide an opinion on whether the draft CoC complies with the GDPR and approves the CoC if it finds that it provides sufficient appropriate safeguards.

Article 40(6) GDPR requires the competent DPAs to register and publish approved CoC which do not relate to processing activities in several Member States.

Article 40(7) to (10) GDPR deal with the case that CoC relate to processing activities in several Member States and requires the competent DPA under Article 55 GDPR to submit the draft CoC to the EDPB in accordance with the consistency mechanism in Article 63 GDPR; then, the EDPB has to provide an opinion regarding the draft CoCs compliance with the GDPR (Article 40(7) GDPR). In case the EDPB's opinion is positive, it submits the draft CoC to the EC (Article 40(8) GDPR) which may decide that the approved CoC have general validity within the Union (Article 40(9) GDPR. The EC must ensure appropriate publicity of such CoC (Article 40(10) GDPR).

Lastly, in accordance with Article 40(11) GDPR, the EDPB must collate all approved CoC and make them publicly available.

EDPB Guidelines:

  • EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0) (available here), and
  • EDPB, ‘Guidelines 04/2021 on Codes of Conduct as tools for transfers’ 22 February 2022 (Version 2.0), (available here).

(1) Encouragement of CoC

Article 40(1) GDPR requires (i) the Member States, (ii) the DPAs, (iii) the EDPB and (iv) the EC to encourage the drawing up of CoC intended to contribute to the proper application of the GDPR, taking account of the specific features of the various processing sectors and the specific needs of micro, small and medium-sized enterprises.

This provision requires its addressees to take some measures in order to encourage the drawing up of CoC.[4]

Addressees

This provision is addressed to the Member States, DPAs, the EDPB and the EC. It is therefore not relevant for the Code Owners, the controllers and processors undertaking to apply the CoC or the Monitoring Bodies.

Shall encourage drawing up of CoCs

It should be recalled that CoC are a voluntary accountability tool and it is neither obligatory so draw them up not to undertake to apply them. In order to increase their presence and functionality in practice, Article 40(1) GDPR provides that some important actors (i.e. Member States, DPAs, the EDPB and the EC) shall encourage the development of CoC.

Therefore, while the development of CoC is voluntary, the addressees of this provision are obliged to encourage the usage of this instrument in order to contribute to the proper application of the GDPR.[5] For example, the EDPB's Guidelines on CoC can be considered a measure to facilitate their usage by, inter alia, clarifying the rules on procedures and rules involved in the submission, approval and publication of CoC.[6]

For more information on CoC themselves, see the Commentary or Article 40(2) GDPR.

Specific features of a processing sector and specific needs

Article 40(1) GDPR clarifies that CoC must be tailored to “specific features” of a sector, as well as the “specific needs of micro, small and medium-sized enterprises”. Recitals 98 and 99 GDPR provide additional information as to how the content of these CoC may be developed. The former highlights that the CoC should take into account “risk likely to result from the [relevant] processing for the rights and freedoms of natural persons”. According to the latter recital, the drafter “should consult relevant stakeholders, including data subjects” in order to develop these CoC. They should also duly consider the “submissions received and views expressed in response to such consultations”.

See Commentary on Article 40(2) and (5) GDPR for more information on the scope of CoC.

(2) Drawing up CoCs

Associations and other bodies representing categories of controllers or processors

According to Article 40(2) GDPR, CoC are to be drafted by trade associations and other bodies “representing categories of controllers or processors” (i.e. Code Owners).[7] Generally, the Code Owners act as representatives of specific sectors. The EDPB lists trade and representative associations, sectoral organisations, academic organisations and interest groups as potential Code Owners.[8]

"Trade associations or bodies representing a sector can create codes to help their sector comply with the GDPR in an efficient and potentially cost effective way. "

EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 8.

Regarding the question whether other actors (e.g. a sole controller) can submit CoC, the EDPB notes that only an association/consortium of associations or other bodies representing categories of controllers or processors in accordance with Article 40(2) GDPR can submit CoC to the competent DPA. Such body has to demonstrate that the are an effective representative body and that they are capable of understanding the needs of their members and defining the respective processing activities of the sector.[9]

Further, the EDPB notes that the representativeness of a Code Owner can be derived amongst others from the number (or percentage) of potential organisations applying the CoC in a given sector and the experience of the Code Owner with regard to the sector.

Prepare, amend or extend

Article 40(2) GDPR does not only apply to the initial preparation of CoC, rather it is also applicable to any amendments or extensions to existing CoC.

Recital 99 of the GDPR emphasises that a Code Owner should consult relevant stakeholders when preparing a CoC (or a amendment or extension to it), including data subjects, and have regard to submissions received and views expressed in response to such consultations.

CoC specifying the application of the GDPR

It is important to clarify what is meant by CoC. According to Article 40 GDPR, the purpose of a code of conduct is to “[contribute] to the proper application”, as well as to “[specify] the application” of the GDPR. Additionally, they may be developed to “calibrate the obligations of controllers and processors” according to Recital 98 GDPR. As such, codes are intended to be an additional (and voluntary) accountability tool which describes how a compliant processing operation in a particular sector should look like, acting as guard rails or a rule books for controllers and processors that fall within the scope of the GDPR (and in certain cases, see below, those who fall outside of it). The codes provide measures which data controllers and processors in a specific sector can implement in addition to, or to comply with, their existing legal obligations under the GDPR.[10]

"[CoCs] are voluntary accountability tools which set out specific data protection rules for categories of controllers and processors. They can be a useful and effective accountability tool, providing a detailed description of what is the most appropriate, legal and ethical set of behaviours of a sector. From a data protection viewpoint, codes can therefore operate as a rulebook for controllers and processors who design and implement GDPR compliant data processing activities which give operational meaning to the principles of data protection set out in European and National law."

EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 7.

The focus on a particular sector is supposed to allow for a cost effective way to achieve data protection compliance by taking into account all the specific characteristics of processing carried out in that sector - with particular emphasis on the needs of micro, small and medium enterprises.[11] It should be recalled that under Article 24(3) GDPR, adherence to approved CoC can be used as an element to demonstrate compliance with the GDPR.[12]

"Adherence to an approved code of conduct will also be a factor taken into consideration by supervisory authorities when evaluating specific features of data processing such as the security aspects, assessing the impact of processing under a DPIA or when imposing an administrative fine. In case of a breach of one of the provisions of the Regulation, adherence to an approved code of conduct might be indicative of how comprehensive the need is to intervene with an effective, proportionate, dissuasive administrative fine or other corrective measure from the supervisory authority."

EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 18.

While adherence to approved CoC can increase data protection compliance and provide for some increased legal certainty for controllers and processors, it is important to point out that even approved CoC are in no way binding to DPA or courts and even a practice described in the CoC can later be considered unlawful.[13]

Regarding the scope of CoC, the GDPR leaves a wide margin of discretion to Code Owners when drafting CoC; they can provide only for narrow rules on certain aspects or provide for wide-ranging rules for a particular sector.[14] In any case, a Code Owner must clearly specify the scope of the CoC when submitting them to the DPA for approval.[15] See Commentary on Article 40(4) GDPR for further requirements of CoC for their approval by the competent DPA.

Article 40(2) GDPR provides for a non-exhaustive list of topics CoC could cover:

(a) fair and transparent processing;

(b) the legitimate interests pursued by controllers in specific contexts;

(c) the collection of personal data;

(d) the pseudonymisation of personal data;

(e) the information provided to the public and to data subjects;

(f) the exercise of the rights of data subjects;

(g) the information provided to, and the protection of, children, and the manner in which the consent of the holders of parental responsibility over children is to be obtained;

(h) the measures and procedures referred to in Articles 24 and 25 GDPR and the measures to ensure security of processing referred to in Article 32 GDPR;

(i) the notification of personal data breaches to supervisory authorities and the communication of such personal data breaches to data subjects;

(j) the transfer of personal data to third countries or international organisations; or

(k) out-of-court proceedings and other dispute resolution procedures for resolving disputes between controllers and data subjects with regard to processing, without prejudice to the rights of data subjects pursuant to Articles 77 GDPR and 79 GDPR.

(3) Controllers and Processors not Subject to the Territorial Scope of the GDPR

Generally speaking, CoC developed in accordance with Article 40 GDPR are aimed at categories of controllers and processors within the scope of application of the GDPR. These categories are determined by their varying processing sectors. For example, a CoC for processing of personal data by banks would differ from one for the education sector. This is clear from the wording of Article 40(1) GDPR, which specifies that the codes should take into account “the specific features of the various processing sectors”.

However, Article 40(3) GDPR provides that certain CoC can be followed by controllers and processors of personal data that are not subject to the GDPR pursuant to Article 3 GDPR (i.e. its territorial scope). This could enable an appropriate safeguard for the transfer of personal data to a third country or an international organisation in accordance with Article 46(2)(e) GDPR. Such CoC must not only be approved by the competent DPA per Article 40(5) GDPR, but must also have gained general validity from the EC pursuant to Article 40(9) GDPR. The third country controllers and processors should also make “binding and enforceable commitments” (i.e. contractual or other legally binding instruments).[16]

"[CoC] may also provide to be a significant and useful mechanism in the area of international transfers. New provisions in the GDPR allow third parties to agree to adhere to approved codes in order to satisfy legal requirements to provide appropriate safeguards in relation to international transfers of personal data to third countries. Additionally, approved codes of this nature may result in the promotion and cultivation of the level of protection which the GDPR provides to the wider international community while also permitting sustainable legally compliant international transfers of personal data. They may also serve as a mechanism which further develops and fosters data subject trust and confidence in the processing of data outside of the European Economic Area."

EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 17 footnotes omitted.


For this paragraph and its interaction with Article 40(2)(j) and 46(2)(e) GDPR, please see in particular Guidelines 04/2021 on Codes of Conduct as tools for transfers.[17]

(4) Mandatory Monitoring of Compliance

Article 40(4) GDPR outlines that a CoC must contain information on how a Monitoring Body (provided for in Article 41 GDPR) can monitor the compliance of the CoC (i.e. the respective mechanism) by the controllers and processors which undertake to apply it. The Monitoring Body must be accredited by the competent DPA in accordance with Article 41(1) GDPR.

It is important to note that such monitoring by these bodies should be carried out “without prejudice to the tasks and powers of supervisory authorities”, which means that the powers of such a monitoring body do not prevent the DPAs from using their own.

See Commentary on Article 41 GDPR for more information on the Monitoring Body, its required procedures and structures.

(5) Approval of CoC

Article 40(5) GDPR outlines that Code Owners which “intend to prepare a code of conduct or to amend or extend an existing [one]” must submit their draft CoC to the competent DPA. Once the code owner has submitted the draft, amendment or extension, in either an electronic or written format, the competent DPA should review the CoC against the admissibility criteria and the conditions for approval which will be discussed in the following subsections. The DPA will then approve the CoCs, amendment or extension when it “provides sufficient appropriate safeguards”. Not much detail is provided by the provisions in the GDPR with regards to the admissibility criteria and conditions for approval. Therefore, much of the following discussion is derived from the EDPB Guidelines, which elaborate on these requirements.[18]

Competent Authority

Although Article 40(5) GDPR mentions that the competent DPA will be determined through the application of Article 55 GDPR, the GDPR does not provide specific rules on this. However, the EDPB Guidelines explain how Code Owners may identify the competent DPA in its Appendix 2. This document provides factors that can be considered such as:

  • where most of the processing activity takes place, or where the processing sector is predominant;
  • where data subjects are most affected;
  • where the drafting association or other body has its headquarters;
  • where the monitoring body will have its headquarters;
  • where a DPA has developed initiatives in the CoC’s specific field.[19]

"The [competent DPA's] role includes, inter alia, acting as a single point of contact with the code owners during the approval process, managing the application procedure in its cooperation phase, accrediting the monitoring body (if relevant) and acting as the supervisory lead in ensuring that an approved code is being monitored effectively."

EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), p. 28.


CoC comply with the Regulation

Admissibility criteria

The EDPB Guidelines provide a series of conditions that Code Owners should fulfil before considering submitting their CoC, amendment or extension to the competent DPA for approval. The content of the draft CoC, amendment or extension will not be reviewed further if it fails to fulfil the criteria for admissibility outlined below.[20]

The first step for admissibility of draft CoC is to have a “clear and concise explanatory statement”. This will include an explanation of: the purpose of the CoC; the scope of the CoC; and the way in which it will foster compliance with the GDPR. Supporting documentation will also provide additional clarity.[21]

The draft CoC must be drafted by an association or other bodies representing categories of controllers and processors (Article 40(2) GDPR). The EDPB highlights that Code Owners must demonstrate to the competent DPA that they fall within the meaning of “associations and other bodies” before submitting the CoC for approval. The Guidelines add that this entails providing proof of their capability to address the needs of controllers and processors and understanding of their processing activities.[22]

The scope of application of the CoC must be sufficiently precise. This includes information on the type of processing performed, and the controllers and processors targeted by it. The drafters must clarify whether the code applies to processing within one or several Member States. This will then facilitate the determination of whether further steps must be taken (e.g. general validity from the EC, as elaborated upon in Article 40(9) GDPR).[23]

The Code Owner must similarly ensure that steps for monitoring compliance are clearly laid out in the CoC. They must also provide for a monitoring body and the mechanisms that this body will apply to ensure compliance with it. The Code Owner must consult relevant stakeholders such as data subjects, as well as controllers and processors, before the draft is considered admissible.[24]

If national legislation applies, Code Owners must confirm that the CoC does not infringe such provisions. According to the EDPB, this is particularly the case if the code involves a sector which is specifically regulated by national law, or the processing at stake is subject to specific assessment requirements under national law.[25]

The CoC must be written in the language in which the competent DPA works in. Transnational CoC,[26] however, should also have an English version of the CoC, in addition to one in the competent DPA’s language.[27]

The Code Owner must ensure that they fulfil all the above conditions before submitting the CoC for approval. Appendix 3 of the EDPB Guidelines provides a possible checklist for a Code Owner to verify this. They can then present it to the competent DPA.[28]

Conditions for approval

The EDPB Guidelines also provide a series of criteria that must be fulfilled by Code Owners in order to gain formal approval for their CoC, amendment or extension from the competent DPA. The following sections reflect the minimum cumulative requirements for approval.

First, the CoC must address a specific need or a data protection issue that is common in a sector, or in relation to a processing activity by a category of controllers or processors. The Code Owner must also demonstrate that it understands relevant processing issues, and clearly show how the CoC proposes to resolve them in an “effective and beneficial” way for their members and for data subjects. Without this, the CoC cannot get approval from the competent DPA.[29]

Second, the Code Owner must ensure that the code “facilitate[s] the effective application of this Regulation” in the sector or processing activity it seeks to address.[30]

"In this regard, a code will need to clearly stipulate its sector-specific application of the GDPR and identify and address such specific needs of a sector."

EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 35.


Third, according to the EDPB Guidelines, in order to gain approval, the Code Owner must ensure that the CoC specifies how the GDPR should apply in relation to the targeted processing activities or sector. This includes providing (non-exhaustively): clear improvements to ensure the targeted sector complies with the GDPR; realistic and attainable standards for the controllers and processors targeted; detailed information on data protection areas, such as those outlined in Article 40(2) GDPR; sufficiently clear and effective solutions to concerns over processing in this sector; an “operational meaning” of the Article 5 GDPR principles; and clarifications on any EDPB opinions or guidance for the specific sector.[31] The EDPB also clarifies that a Code Owner cannot simply restate provisions within the GDPR. The CoC must supplement the GDPR by providing information on how it “shall apply in a specific, practical and precise manner” which relates to the processing activity or sector at the heart of the CoC. This can be achieved by using, for example, sector-specific terminology without being too “legalistic”, and by giving examples of good practices.[32]

Fourth, as outlined in Article 40(5) GDPR, the CoC must provide sufficient appropriate safeguards, “taking into account the risk likely to result from the processing for the rights and freedoms of natural persons” (Recital 98 GDPR).[33]

Finally, an oversight and compliance monitoring mechanism is a requirement stipulated under Article 40(4) GDPR. According to the EDPB, structures and procedures for enforcing the CoC must be stipulated by the Code Owner before gaining approval. This includes identifying a Monitoring Body within the meaning of Article 41 GDPR. Such monitoring mechanisms must be “clear, suitable, attainable, efficient and enforceable (testable)”, according to the Guidelines.[34]

Approval from the DPA

Subject to the Code Owners fulfilling the admissibility and approval requirements outlined above, the competent DPA can approve the draft CoC, amendment or extension pursuant to Article 40(5) GDPR. The EDPB Guidelines suggest that the DPA should do so within a “reasonable period of time” (unless a specific time for approving a CoC is provided for in national law) and update the Code Owners throughout the approval process. The DPA should motivate its approval in line with the prerequisite criteria for admissibility and approval, and in cases when it does not approve a CoC, it should provide a reasoning for its opinion. This can then enable the Code Owners to redraft and re-submit the draft CoC if they wish to do so.[35]

(6) Publication of Approved Codes

Article 40(6) GDPR requires the competent DPA to register and publish any approved CoC, amendment or extension of CoC unless they relate to processing activities in several Member States. Regarding CoC that relate to processing activities in several Member States, see Article 40(11) GDPR.

The publication of CoC is in particular important for the data subjects involved in the respective processing activities.[36] Contrary to the approval by the DPA, the publication of the CoC is not a requirement for the validity of the CoC.[37]

(7) CoC relating to processing in several Member States

Article 40(7) to (10) GDPR deal with CoC relating to processing activities in several Member States. In particular, Article 40(7) GDPR stipulates that in case a draft CoC relates to processing activities in several Member States, the competent DPA[38] must, before approving the draft CoC, amendment or extension, submit it in the procedure referred to in Article 63 GDPR to the EPDB (i.e. the consistency mechanism) which must provide an opinion on whether the draft CoC, amendment or extension complies with the GDPR or, in the situation referred to in Article 40(3), provides appropriate safeguards.

Similar to the case of national CoC, the competent DPA with which the Code Owner has submitted the draft CoC, must determine whether this CoC fulfils the admissibility criteria[39] before proceeding. After this initial step, according to the EDPB, the DPA should then notify other DPAs about the transnational CoC, pursuant to Article 40(7) GDPR; in order to let those other DPAs confirm whether they are “supervisory authorities concerned” (see Article 4(22)(a)(b) GDPR):

"The [competent DPA] will immediately notify all other supervisory authorities of the submission of a code and provide the salient details which will allow for ease of identification and reference. All supervisory authorities should confirm by return whether they are concerned SAs as per Article 4(22) (a) and (b) of the GDPR."

EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 48 (footnotes omitted).

Then, the DPAs will cooperate in a mechanism closely described in the EDPB Guidelines.[40]

As per Article 40(7) GDPR, the competent DPA must then submit the draft CoC, amendment or extension to the EDPB which shall provide an opinion[41] on whether the draft CoC, amendment or extension complies with the GDPR or, in the situation referred to in 40(3) GDPR, provides appropriate safeguards.[42]

(8) Submission to the Commission by the EDPB

In case the EDPB's opinion[43] regarding transnational CoC confirms that the CoC (or its amendment or extension) complies with the GDPR (or in in the situation referred to in 40(3) GDPR, provides appropriate safeguards), the EDPB has to submit its opinion to the EC in accordance with Article 40(8) GDPR.

(9) CoC with General Validity

After receiving the EDPB’s opinion,[44] the EC will be the one to determine, “by way of implementing acts”, whether to grant the transnational CoC “general validity within the Union” as per Article 40(9) GDPR. This provision specifies that the aforementioned “implementing acts” must be adopted in line with the examination procedure under Article 93(2) GDPR.[45]

Should the EC grant the CoC general validity, there is no territorial limit to the CoC,[46] and the adherence by controllers or processors not subject to the GDPR due to its territorial scope can be considered an appropriate safeguard within the framework of personal data transfers to third countries or international organisations.[47]

(10) Commission Ensures Publicity for Approved COC with General Validity

According to Article 40(10) GDPR, the EC is responsible for the “appropriate publicity” that should be given to a transnational CoC which has been granted general validity. This publication obligation exists in parallel to the EDPB's obligation to keep a register of all approved codes of conduct, amendments and extensions.[48]

(11) Register of Codes of Conduct

Article 40(11) GDPR stipulates that the EDPB shall keep a register on “all approved codes of conduct, amendments and extensions” which is freely accessible and available to all “by way of appropriate means”.

The wording in Article 40(11) GDPR only specifically refers to “approved codes” without mentioning those with “general validity”, leading to some ambiguity as to the scope of this provision. Nonetheless, it is presumed that this requirement to register CoC applies to approved CoC within the meaning of Articles 40(5) and (6) GDPR, as well as CoC granted “general validity” by the EC as per Articles 40(7), (8), (9) and (10) GDPR. In other words, the EDPB has to publish national as well as transnational CoC.[49] The register can be found on the EDPB website.[50]

Decisions

→ You can find all related decisions in Category:Article 40 GDPR

References

  1. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 7 (available here).
  2. See definition used by the EDPB: EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), p. 7 (available here).
  3. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 9 (available here); see also Commentary on Article 24(3) GDPR.
  4. Compare Schweinoch, in Ehmann, Selmayr, DS-GVO, Article 40 GDPR, margin number 29 (C.H. Beck 2024, 3rd Edition); as well as Bergt, Pesch, in Kühling, Buchner, DS-GVO BDSG, Article 40 GDPR, margin number 10 (C.H. Beck 2024, 4th Edition).
  5. Compare Schweinoch, in Ehmann, Selmayr, DS-GVO, Article 40 GDPR, margin number 29 (C.H. Beck 2024, 3rd Edition).
  6. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 2 et seq. (available here).
  7. See definition in the Commentary section above.
  8. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 21 (available here).
  9. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 21 et seq. (available here).
  10. Compare EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 7 (available here).
  11. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 11 (available here).
  12. See Commentary on Article 24 GDPR.
  13. Compare EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 15 (available here) and CJEU, Joined Cases C‑26/22 and C‑64/22, SCHUFA, 7 December 2023, martin number 104 (available here); other opinion Schweinoch, in Ehmann, Selmayr, DS-GVO, Article 40 GDPR, margin number 10 (C.H. Beck 2024, 3rd Edition).
  14. Compare EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 12 (available here).
  15. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 23 (available here).
  16. See EDPB, ‘Guidelines 04/2021 on Codes of Conduct as tools for transfers’ 22 February 2022 (Version 2.0), margin number 26 et seqq. (available here).
  17. EDPB, ‘Guidelines 04/2021 on Codes of Conduct as tools for transfers’ 22 February 2022 (Version 2.0) (available here).
  18. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 19 et seqq. (available here).
  19. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), p. 28 (available here).
  20. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin numbers 43 et seq. (available here).
  21. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 20 (available here).
  22. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 21 et seq. (available here); see also Commentary on Article 40(2) GDPR.
  23. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 23 et seq. (available here);
  24. See Recital 99 and EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 26 et seqq. (available here).
  25. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 29 (available here).
  26. See Article 40(7) et seqq. GDPR.
  27. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 30 (available here).
  28. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), pp. 11-14 (available here).
  29. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 33 et seq. (available here).
  30. See also Recital 98 GDPR.
  31. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 36 et seqq. (available here).
  32. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 37 (available here).
  33. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 39 (available here).
  34. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 40 et seq. (available here).
  35. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 45 et seqq. (available here).
  36. Roßnagel, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 40 GDPR, margin numbers 74 (NOMOS 2025, 2nd Edition).
  37. Schweinoch, in Ehmann, Selmayr, DS-GVO, Article 40 GDPR, margin number 58 (C.H. Beck 2024, 3rd Edition).
  38. See Commentary on Article 40(5) GDPR regarding the assessment of the competent DPA.
  39. See Commentary on Article 40(5) GDPR.
  40. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 51 et seqq. (available here).
  41. See Article 64(1)(b) GDPR.
  42. See EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 55 et seq. (available here).
  43. See Article 40(7) GDPR.
  44. See Article 40(8) GDPR.
  45. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), p. 20 (available here).
  46. Schweinoch, in Ehmann, Selmayr, DS-GVO, Article 40 GDPR, margin number 64 et seq. (C.H. Beck 2024, 3rd Edition).
  47. See Commentary on Article 40(3) GDPR.
  48. Schweinoch, in Ehmann, Selmayr, DS-GVO, Article 40 GDPR, margin number 67 (C.H. Beck 2024, 3rd Edition); see Article 40(11) GDPR for the EDPB's respective obligation.
  49. EDPB, ‘Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679’, 4 June 2019 (Version 2.0), margin number 47 and 57 (available here).
  50. See https://www.edpb.europa.eu/our-work-tools/accountability-tools/register-codes-conduct-amendments-and-extensions-art-4011_en