Article 43 GDPR
Legal Text
1. Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58, certification bodies which have an appropriate level of expertise in relation to data protection shall, after informing the supervisory authority in order to allow it to exercise its powers pursuant to point (h) of Article 58(2) where necessary, issue and renew certification. Member States shall ensure that those certification bodies are accredited by one or both of the following:
- (a) the supervisory authority which is competent pursuant to Article 55 or 56;
- (b) the national accreditation body named in accordance with Regulation (EC) No 765/2008 of the European Parliament and of the Council (20) in accordance with EN-ISO/IEC 17065/2012 and with the additional requirements established by the supervisory authority which is competent pursuant to Article 55 or 56.
2. Certification bodies referred to in paragraph 1 shall be accredited in accordance with that paragraph only where they have:
- (a) demonstrated their independence and expertise in relation to the subject-matter of the certification to the satisfaction of the competent supervisory authority;
- (b) undertaken to respect the criteria referred to in Article 42(5) and approved by the supervisory authority which is competent pursuant to Article 55 or 56 or by the Board pursuant to Article 63;
- (c) established procedures for the issuing, periodic review and withdrawal of data protection certification, seals and marks;
- (d) established procedures and structures to handle complaints about infringements of the certification or the manner in which the certification has been, or is being, implemented by the controller or processor, and to make those procedures and structures transparent to data subjects and the public; and
- (e) demonstrated, to the satisfaction of the competent supervisory authority, that their tasks and duties do not result in a conflict of interests.
3. The accreditation of certification bodies as referred to in paragraphs 1 and 2 of this Article shall take place on the basis of criteria approved by the supervisory authority which is competent pursuant to Article 55 or 56 or by the Board pursuant to Article 63. In the case of accreditation pursuant to point (b) of paragraph 1 of this Article, those requirements shall complement those envisaged in Regulation (EC) No 765/2008 and the technical rules that describe the methods and procedures of the certification bodies.
4. The certification bodies referred to in paragraph 1 shall be responsible for the proper assessment leading to the certification or the withdrawal of such certification without prejudice to the responsibility of the controller or processor for compliance with this Regulation. The accreditation shall be issued for a maximum period of five years and may be renewed on the same conditions provided that the certification body meets the requirements set out in this Article.
5. The certification bodies referred to in paragraph 1 shall provide the competent supervisory authorities with the reasons for granting or withdrawing the requested certification.
6. The requirements referred to in paragraph 3 of this Article and the criteria referred to in Article 42(5) shall be made public by the supervisory authority in an easily accessible form. The supervisory authorities shall also transmit those requirements and criteria to the Board. The Board shall collate all certification mechanisms and data protection seals in a register and shall make them publicly available by any appropriate means.
7. Without prejudice to CHAPTER VIII, the competent supervisory authority or the national accreditation body shall revoke an accreditation of a certification body pursuant to paragraph 1 of this Article where the conditions for the accreditation are not, or are no longer, met or where actions taken by a certification body infringe this Regulation.
8. The Commission shall be empowered to adopt delegated acts in accordance with Article 92 for the purpose of specifying the requirements to be taken into account for the data protection certification mechanisms referred to in Article 42(1).
9. The Commission may adopt implementing acts laying down technical standards for certification mechanisms and data protection seals and marks, and mechanisms to promote and recognise those certification mechanisms, seals and marks. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2).
Relevant Recitals
You can help us fill this section!
Commentary
Article 43 GDPR explains the procedure involved in establishing certification bodies in order to assist with the certification mechanisms laid out in Article 42 GDPR. As established in the aforementioned article, certification is a means through which controllers and processors can demonstrate compliance with their legal obligations under the GDPR. However, certification itself does not prove compliance, but rather only constitutes an element of it. To this end, certification bodies can assist controllers and processors with demonstrating their compliance by certifying their processing operations.
Certification bodies require an appropriate level of expertise and need to be accredited by either the supervisory authority (DPA) or a national accreditation body.
Article 43(1) GDPR allows accredited certification bodies to issue and renew certifications. This provision further requires that certification bodies inform the DPA when issuing or renewing a certification and highlights that the tasks and powers of the DPA remain unaffected by the certification bodies' competences.
Article 43(2) GDPR lists requirements a certification body has to fulfil in order to be accredited.
Article 43(3) GDPR states that the accreditation of a certification body hast to take place on the bases of approved certification criteria.
Article 43(4) GDPR tasks certification bodies with the proper assessment of the controller or processor, but highlights that the controller or processor remains responsible for data protection compliance. Further, this provision provides for a maximum duration for the certification bodies accreditation (i.e. five years) and allows for the option to renew the accreditation if the certification body continues to meet the necessary requirements.
Article 43(5) GDPR requires certification bodies to provide the competent DPA with the reasons for granting or withdrawing a requested certification.
Article 43(6) GDPR obliges the DPA to publish the accreditation requirements for certification bodies as well as the certification criteria (see Article 42(5) GDPR). The DPA also has to transmit this information to the European Data Protection Board (EDPB) which has to collate and publish all certification mechanisms and data protection seals.
Article 43(7) GDPR stipulates that the competent DPA or, where applicable, the national accreditation body has to revoke an accreditation of a certification body in case the conditions for accreditation are not, or are no longer, met or where the certification body's action infringe the GDPR.
Article 43(8) GDPR empowers the Commission to adopt delegated acts in accordance with Article 92 GDPR for the purpose of specifying the requirements to be taken into account for data protection certification mechanisms.
Article 43(9) GDPR allows the Commission to adopt implementing acts laying down technical standards for certification mechanisms and data protection seals and marks, and mechanisms to promote and recognise those certification mechanisms, seals and marks.
EDPB Guideline:
- EDPB, ‘Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation’, 4 June 2019 (Version 3.0) (available here);
- EDPB, ‘Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679)’, 4 June 2019 (Version 3.0) (available here); and
- EDPB, ‘Guidelines 07/2022 on certification as a tool for transfers’, 14 February 2023 (Version 2.0) (available here).
(1) Certification Bodies issue and renew certifications
Certification bodies issue and renew certification
Article 43(1) GDPR stipulates that certification bodies shall issue and renew certification. This provision should be read in conjunction with Article 42(5) and (7) GDPR which stipulates that the a certification has to be issued by a certification body or by the competent supervisory authority on the basis of approved criteria (Article 42(5) GDPR) and that provide further rules on such certification (e.g. a maximum period of three years in Article 42(7) GDPR.[1]
"A certification body’s role is to issue, review, renew, and withdraw certifications (Article 42(5), (7)) on the basis of a certification mechanism and approved criteria (Article 43(1))."
Without prejudice to the DPA's tasks and powers
This provisions also emphasises that the fact that certification bodies issue (or renew) a certification is without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58 GDPR. For more information see commentary on Article 42(4) GDPR which provides for a similar provision.
Appropriate level of expertise
In order for a certification body to issue or renew a certification, Article 43(1) GDPR requires such body to have an "appropriate level of expertise in relation to data protection". Regarding the requirements of a certification body, see Commentary on Article 43(2) GDPR.
After informing the DPA
This provision requires the certification body to inform the DPA when issuing and renew a certification. This is necessary in order to allow the DPA to effectively use its powers under Article 58(2)(h) GDPR; i.e. to withdraw a certification or to order the certification body to withdraw a certification, or to order the certification body not to issue certification.
It should be pointed out that the certification body similarly has to inform the DPA in case it withdraws a certification (see Article 43(5) GDPR). In this context, the EDPB highlights that the certification body should provide all the information necessary for the DPA to fulfil its tasks.[2]
"The certification body is required by the GDPR to provide supervisory authorities with information, especially on individual certifications, which is necessary to monitor the application of the certification mechanism (Article 42(7), 43(5), 58(2)(h))."
Accreditation by DPA or accreditation body
The second sentence in Article 43(1) GDPR requires Member States to ensure that certification bodies are accredited by either (a) the DPA and/or (b) the national accreditation body named in accordance with Regulation (EC) No 765/2008[3] in accordance with EN-ISO/IEC 17065/2012 and with the additional requirements established by the DPA which is competent pursuant to Article 55 or 56 GDPR.
"Art. 43(1)(b) refers to ISO 17065 which provides for the accreditation of certification bodies assessing the conformity of products, services and processes. A processing operation or a set of operations may result in a product or service in the terminology of ISO 17065 and such can be subject of certification. For instance, the processing of employee data for the purpose of salary payment or leave management is a set of operations within the meaning of the GDPR and can result in a product, process or a service in the terminology of ISO."
While the GDPR does not define the term "accreditation", it should be understood as an attestation by a national accreditation body and/or by a DPA, that a certification body is qualified to carry out certification pursuant to Article 42 and 43 GDPR, taking into account ISO/IEC 17065/2012 and the additional requirements established by the DPA and or by the EDPB.[4]
The purpose of the accreditation of a certification body is to make sure that such body is capable of assessing whether or not a controller or processor qualifies for a certification. Accordingly, this should ensure a high quality of the certification mechanism.[5]
The DPA (or the national accreditation body) competent for the main establishment of a controller or processor in accordance with Article 56 GDPR should be considered the competent authority for the purposes of the accreditation.[6]
"Accreditation for the scope of a European Data Protection Seal will require accreditation in the Member State of the headquarters of the certification body intending to operate the scheme, i.e. responsible for issuing certifications and managing the certification activities of its entities and subsidiaries in other Member States. Where other establishments or offices manage and perform certifications autonomously, each of these establishments or offices will require separate accreditation in the Member State where they are based. In other words, accreditation is necessary only in the Member State of the headquarters of the certification body when only the headquarters issue the certificates. By contrast, when other establishments of the certification body also issue certificates, these establishments need to be accredited as well.
Consequently, if a certification body has not been accredited to certify under the European Data Protection Seal, then the EDPB approved criteria cannot be used and the Seal cannot be offered."
(2) Requirements for a Certification Body
In order for a certification body to become accredited, it must demonstrate that it has the necessary elements required for accreditation, listed in Articles 43(2)(a) to (e) GDPR. Namely, a certification body must have:
- demonstrated their independence and expertise in relation to the subject-matter of the certification to the satisfaction of the competent supervisory authority (Article 43(2)(a) GDPR);[7]
- undertaken to respect the criteria referred to in Article 42(5) GDPR and approved by the DPA which is competent pursuant to Article 55 or 56 or by the EDPB pursuant to Article 63 GDPR (Article 43(2)(b) GDPR);
- established procedures for the issuing, periodic review and withdrawal of data protection certifications, seals and marks (Article 43(2)(c) GDPR);
- established procedures and structures to handle complaints about infringements of the certification or the manner in which the certification has been, or is being, implemented by the controller or processor, and to make those procedures and structures transparent to data subjects and the public (Article 43(2)(d) GDPR); and
- demonstrated, to the satisfaction of the competent supervisory authority, that their tasks and duties do not result in a conflict of interests (Article 43(2)(e) GDPR).
Only once a certification body has demonstrated these elements, it may apply to become accredited. However, Article 43(2) GDPR does not conclusively regulate the requirements (see Article 43(3) GDPR); in particular, in case the accreditation is issued by a national accreditation body, there are further requirements.[8]
(3) Approved Accreditation Criteria
Article 43(3) GDPR provides that the accreditation of certification bodies shall take place on the basis of the criteria approved by the competent DPA (in accordance with Articles 55 or 56 GDPR) or by the EDPB (in accordance with Article 63 GDPR).
In the case of accreditation pursuant to Article 43(1)(b) GDPR, those requirements shall complement those envisaged in Regulation 765/2008[3] and the technical rules that describe the methods and procedures of the certification bodies.
For more extensive information on accreditation criteria, see EDPB Guidelines on the accreditation of certification bodies.
(4) Accountability of controller and processor and maximum period for accreditation
Accountability of controller and processor
Article 43(4) GDPR stipulates that the certification bodies are responsible for the proper assessment leading to the certification or the withdrawal of a certification. However, the certification body's responsibility for this assessment is without prejudice to the responsibility of the controller or processor. In other words, even when certified, the controller or processor continue to be responsible and accountable for compliance with the GDPR.
Maximum period for accreditation
Article 43(4) GDPR states that, if an accreditation is issued, it is limited to (a maximum of) five years in duration, and may be renewed on the same conditions provided that the certification body continues to meet the requirements for accreditation. An accreditation could also be granted for a shorter period; however, in accordance with Article 34(7) GDPR the accreditation can also be revoked at any time in case the conditions for the accreditation are not, or are no longer, met or where actions taken by a certification body infringe the GDPR.[9]
(5) Information to the DPA about granting or withdrawing requested certification
Once accredited, the certification body can begin to carry out its functions of issuing and renewing certifications for controllers and processors. However, as per Article 43(5), for every acceptance or withdrawal of certification that the certification body oversees, it must inform the competent DPA of its reasons for doing so. It should be recalled that Article 43(1) GDPR already provides for the certification body's obligation to inform the DPA when granting or renewing a certification in order to enable the DPA to exercise its powers.[10]
(6) Criteria for certification to be made public
In order to promote transparency, the criteria for accreditation (Article 43(3) GDPR) as well as the criteria for certification (Article 42(5) GDPR) should be made public by the DPA in an easily accessible form.
Here, the EDPB has also stated that certification bodies using certification mechanisms, seals or marks directed towards data subjects as consumers or customers, should also provide easily accessible and intelligible information about the processing operations it has certified. The information to be made transparent should include: a description of the target of evaluation (the processing operation), reference to the approved criteria which have been applied in the particular instance, which methodology has been used for evaluating the criteria, the duration of the validity of the certificate issued.[11]
"[T]o ensure transparency, all criteria and requirements approved by a supervisory authority shall be published. In terms of quality and trust in the certification bodies, it would be desirable, if all the requirements for accreditation were readily available to the public."
Further, Article 43(6) GDPR requires the DPAs to transmit those requirements and criteria to the EDPB. The Board shall collate all certification mechanisms and data protection seals in a register and shall make them publicly available by any appropriate means. The respective register by the EDPB can be found here.
(7) Revocation of an Accreditation
In accordance with Article 43(7) GDPR, the DPA or the national accreditation body has to revoke an accreditation of a certification body pursuant where the conditions for the accreditation are not, or are no longer, met or where actions taken by a certification body infringe the GDPR. Arguably, this provision provides not just for the option to revoke an accreditation if the requirements for revocation are met, but rather an obligation of the DPA.[12]
This provision highlights that this obligation of the DPA to revoke an accreditation is without prejudice to Chapter VIII of GDPR (remedies, liability and penalties). In other words, the DPA's option to revoke an accreditation does not limit the option of other remedies. Reasons for such a revocation could be that the certification body issued certifications without the necessary requirements being fulfilled or it failed to inform the DPA in accordance with its information duties.[13]
(8-9) The role of the European Commission
Articles 43(8) GDPR and Article 43(9) GDPR equip the European Commission with the power to adopt acts in relation to certification mechanisms. While Article 43(8) GDPR deals with delegated acts in accordance with Article 92 GDPR for the purpose of specifying requirements to be taken into account for certification mechanisms, Article 43(9) GDPR deals with implementing acts which lay down technical standards for certification mechanisms.
Delegated acts
The delegated acts of Article 43(8) GDPR aim to specify the requirements taken into account for certification mechanisms. The Commission has interpreted this provision as presenting the opportunity to further flesh out the GDPR with regard to data protection certification mechanisms. However, the Commission reminds that Article 290 of the Treaty on the Functioning of the European Union (TFEU) states that the content of these delegated acts should (1) complement the GDPR and be in compliance with it, and (2) only refer to non-essential elements of the legislation, which the law has not specified.[14]
Implementing acts
Alongside the power to adopt delegated acts, the Commission also has the power to adopt implementing acts. As mentioned in Recital 167 GDPR and Article 291 TFEU, the aim of implementing acts is to “ensure uniform conditions for implementing” the GDPR. In its GDPR Certification Study, the Commission has stated that the purpose of referring to technical standards in Article 43(9) for certification mechanisms is precisely to ensure uniformity of implementation.[15] Furthermore, Article 43(9) GDPR also allows the Commission to adopt mechanisms to promote and recognise data protection certification mechanisms, seals, and marks. This is to be read in light of Article 42(1) GDPR, which obliges the Commission to encourage the establishment of such mechanisms, seals, and marks. Those implementing acts must be adopted in accordance with the examination procedure referred to in Article 93(2) GDPR.[16]
Decisions
→ You can find all related decisions in Category:Article 43 GDPR
References
- ↑ EDPB, ‘Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation’, 4 June 2019 (Version 3.0), margin number 27 (available here); see also Commentary on Article 42 GDPR.
- ↑ EDPB, ‘Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation’, 4 June 2019 (Version 3.0), margin number 29 (available here).
- ↑ 3.0 3.1 Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 setting out the requirements for accreditation and market surveillance relating to the marketing of products and repealing Regulation (EEC) No 339/93, available here: https://eur-lex.europa.eu/eli/reg/2008/765/oj/eng
- ↑ EDPB, ‘Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679)’, 4 June 2019 (Version 3.0) margin number 28 (available here).
- ↑ Compare Scholz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 43 GDPR, margin numbers 3 (NOMOS 2025, 2nd Edition).
- ↑ Bergt, Pesch, in Kühling, Buchner, DS-GVO BDSG, Article 43 GDPR, margin number 4 (C.H. Beck 2024, 4th Edition).
- ↑ Including an appropriate level of expertise in relation to data protection as required by Article 43(1) GDPR; compare Bergt, Pesch, in Kühling, Buchner, DS-GVO BDSG, Article 43 GDPR, margin number 7 (C.H. Beck 2024, 4th Edition).
- ↑ See Scholz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 43 GDPR, margin numbers 18 (NOMOS 2025, 2nd Edition); Bergt, Pesch, in Kühling, Buchner, DS-GVO BDSG, Article 43 GDPR, margin number 5 (C.H. Beck 2024, 4th Edition); EDPB, ‘Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679)’, 4 June 2019 (Version 3.0) margin number 39 et seq. (available here).
- ↑ Bergt, Pesch, in Kühling, Buchner, DS-GVO BDSG, Article 43 GDPR, margin number 14 (C.H. Beck 2024, 4th Edition); see also Commentary on Article 43(7) GDPR.
- ↑ See Commentary on Article 43(1) GDPR.
- ↑ EDPB, ‘Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation’, 4 June 2019 (Version 3.0), pp. 19-20 (available here).
- ↑ Bergt, Pesch, in Kühling, Buchner, DS-GVO BDSG, Article 43 GDPR, margin number 15 (C.H. Beck 2024, 4th Edition).
- ↑ Bergt, Pesch, in Kühling, Buchner, DS-GVO BDSG, Article 43 GDPR, margin number 15 (C.H. Beck 2024, 4th Edition).
- ↑ European Commission, ‘Data Protection Certification Mechanisms Study on Articles 42 and 43 of the Regulation (EU) 2016/679’, February 2019, pp. 26-27 (available here).
- ↑ European Commission, ‘Data Protection Certification Mechanisms Study on Articles 42 and 43 of the Regulation (EU) 2016/679’, February 2019, p. 28 (available here).
- ↑ See Commentary on Article 93 GDPR.




