Chapter 12 of 16
Codes, Certification, and Structured Transfer Safeguards
The GDPR supplements direct regulatory duties with sector-specific codes and voluntary certification, but neither mechanism displaces legal responsibility. Articles 40–47 then show how approved instruments and binding corporate rules can also support lawful international transfers.
Module Map: Two Compliance Tools, One Transfer Framework
The architecture
Articles 40-43 establish codes of conduct and certification. Articles 44-47 set the framework for transfers to third countries or international organisations.
A key distinction
A code or certification can support compliance evidence. It does not displace the controller's or processor's responsibility under the GDPR.
Currency note
A May 21, 2025 proposal would add consideration of small mid-cap enterprises to Articles 40(1) and 42(1). It is proposed, not current GDPR law.
Article 40: What Codes of Conduct Are For
Article 40(1)
Member States, supervisory authorities, the Board and the Commission shall encourage codes of conduct intended to contribute to the proper application of this Regulation.
Designed for context
That encouragement must account for sector-specific processing features and the specific needs of micro, small and medium-sized enterprises.
Article 40(2)
Representative associations and bodies may prepare, amend or extend a code to specify GDPR application, including transparency, rights, security, breaches, transfers and dispute resolution.
Article 40(2) in Practice: Building a Sector Code
A sector-specific code
A learning-platform association may specify GDPR application for student data: collection, pseudonymisation, transparent information, rights requests, security and breach-related processes.
Not a replacement rulebook
A code specifies GDPR application; it does not cancel it. Out-of-court dispute procedures are without prejudice to data-subject rights under Articles 77 and 79.
Cross-border use
An approved code with general validity may support Article 46(2)(e) transfers, but a non-GDPR participant shall make binding and enforceable commitments.
Article 40: Monitoring, Approval, Publication, and Union Validity
Monitoring is compulsory
A code shall contain mechanisms enabling the Article 41(1) body to conduct the mandatory monitoring of adherence to the code.
National or multi-state route
A draft goes to the Article 55 competent authority. Multi-Member-State processing adds the Article 63 consistency procedure and a Board opinion before approval.
Visibility and general validity
The Commission may decide by implementing act that a code has Union-wide general validity. The Commission and Board have publication and register duties.
Article 41: Who Can Monitor an Approved Code?
Accredited subject expertise
A monitoring body may oversee compliance only if it has appropriate code-related expertise and accreditation from the competent supervisory authority.
Five accreditation features
It needs independence, expertise, eligibility and monitoring procedures, transparent complaint structures, periodic review, and no conflict of interests.
Consequences
For infringement, the body shall take appropriate action, including suspension or exclusion from the code, and tell the authority why. Article 41 excludes public-authority processing.
Article 42: Certification Is Voluntary, Not a Liability Shield
Certification objective
Article 42(1) encourages the establishment of data protection certification mechanisms and of data protection seals and marks to demonstrate compliance of processing operations.
Voluntary does not mean consequence-free
The certification shall be voluntary and transparent. But certification does not reduce the controller's or processor's GDPR responsibility or supervisory-authority powers.
Three-year maximum
The applicant must provide necessary information and processing access. Certification lasts a maximum of three years, may be renewed, and is withdrawn if requirements fail.
Article 43: Certification Bodies and Their Accreditation
Two accreditation routes
Member States shall ensure certification bodies are accredited by the competent supervisory authority, the national accreditation body under Regulation (EC) No 765/2008, or both.
Accreditation safeguards
The body needs independence, expertise, commitment to approved criteria, issuance-review-withdrawal procedures, transparent complaints handling, and no conflict of interests.
Five-year maximum
A certification body assesses certification, but the controller or processor remains responsible for GDPR compliance. Accreditation has a maximum period of five years.
Quiz: Code Monitoring and Certification
Select the statement that accurately reflects Articles 40 to 43.
Which statement is correct?
- Certification transfers all GDPR compliance responsibility from the controller to the certification body.
- A code must contain mechanisms enabling the Article 41(1) body to conduct mandatory monitoring, while certification remains voluntary.
- Every controller and processor must join an approved code before processing personal data.
- Certification accreditation and certification always have the same maximum duration of three years.
Show Answer
Answer: B) A code must contain mechanisms enabling the Article 41(1) body to conduct mandatory monitoring, while certification remains voluntary.
Article 40(4) requires code mechanisms enabling mandatory monitoring. Article 42(3) states that certification is voluntary. Article 42(4) preserves controller and processor responsibility. Certification lasts up to three years, while certification-body accreditation lasts up to five years.
Article 44: The General Principle for Every Transfer
Scope
Article 44 covers transfers to third countries or international organisations, including onward transfers from the recipient to another third country or organisation.
The controlling principle
All Chapter V provisions shall be applied so the level of protection of natural persons guaranteed by the GDPR is not undermined.
A framework, not a shortcut
Article 44 does not choose a transfer mechanism. It requires compliance with Chapter V conditions, subject to the GDPR's other provisions.
Article 45: Adequacy Decisions
Adequacy route
A Commission adequacy decision may cover a country, territory, sector or international organisation. Such a transfer shall not require any specific authorisation.
Assessment factors
The Commission considers law, rights, public-authority access, safeguards, onward transfers, redress, independent supervision, enforcement and international commitments.
Review and response
An adequacy act must provide for a periodic review at least every four years. The Commission also monitors developments on an ongoing basis.
Article 46: Appropriate Safeguards When There Is No Adequacy Decision
The Article 46 condition
Without an Article 45(3) decision, transfer is allowed only with appropriate safeguards and where enforceable data-subject rights and effective legal remedies are available.
No specific authorisation
Article 46(2) includes public-authority instruments, binding corporate rules, standard clauses, approved codes plus commitments, and approved certification plus commitments.
Authorisation-required routes
Article 46(3) also permits certain contractual clauses and public-authority administrative arrangements, but only subject to competent supervisory-authority authorisation.
Article 47: Binding Corporate Rules Must Be Enforceable Across the Group
Three approval conditions
Binding corporate rules require legal binding force across every concerned group member and employee, enforceable data-subject rights, and fulfilment of Article 47(2).
What the rules must specify
They must identify the group and transfers, apply GDPR principles, address onward transfers, explain rights and remedies, and allocate specified liability.
Operational governance
They must include monitoring, complaints, audits, corrective action, authority cooperation, change reporting, third-country-law reporting and personnel training.
Flashcards: Exact Requirements and Time Limits
Flip each card and recall the Article, condition, or maximum period before checking the answer.
- Article 40(1): What is the stated purpose of codes?
- They are "codes of conduct intended to contribute to the proper application of this Regulation".
- Article 40(4): What must a code contain?
- Mechanisms enabling the Article 41(1) body to carry out the mandatory monitoring of compliance.
- Article 42(3): Is certification compulsory?
- No. "The certification shall be voluntary and available via a process that is transparent."
- How long can Article 42 certification last?
- A maximum period of three years, renewable under the same conditions if requirements continue to be met.
- How long can Article 43 accreditation last?
- A maximum period of five years, renewable on the same conditions if Article 43 requirements are met.
- Article 45: How often must adequacy review occur?
- The implementing act must provide for a periodic review at least every four years.
- Article 46(1): What two elements accompany appropriate safeguards?
- Enforceable data-subject rights and effective legal remedies for data subjects must be available.
- Article 47(1): What makes corporate rules binding?
- They are legally binding and apply to and are enforced by every concerned group member, including employees.
Final Quiz: Choose the Correct Transfer Route
Apply Articles 44 to 47 to the scenario. Read every condition carefully.
A controller has no Article 45(3) adequacy decision for the destination. It wants to rely on an approved Article 40 code to transfer data to a third-country processor. What must be true under Article 46(2)(e)?
- The controller needs no safeguards because the code was approved.
- The third-country processor must make binding and enforceable commitments to apply the appropriate safeguards, including regarding data-subject rights.
- The code automatically removes the need for enforceable data-subject rights and effective legal remedies.
- The transfer is permitted only if the certification body has issued a certificate valid for five years.
Show Answer
Answer: B) The third-country processor must make binding and enforceable commitments to apply the appropriate safeguards, including regarding data-subject rights.
Article 46(2)(e) permits an approved Article 40 code together with binding and enforceable commitments by the third-country controller or processor to apply appropriate safeguards, including concerning data-subject rights. Article 46(1) also conditions safeguarded transfers on enforceable rights and effective legal remedies.
Key Terms
- onward transfer
- A later transfer from a third country or international organisation to another third country or international organisation; Article 44 expressly includes it.
- adequacy decision
- A Commission decision under Article 45 that a country, territory, specified sector or international organisation ensures an adequate level of protection.
- certification body
- An appropriately expert body that issues and renews certification after informing the supervisory authority and that is accredited under Article 43.
- consistency mechanism
- The Article 63 procedure referenced in Articles 40, 41, 42, 43, 46 and 47 for specified cross-border or Union-consistency functions.
- appropriate safeguards
- The Article 46 transfer basis used in the absence of an Article 45(3) decision, conditioned on enforceable data-subject rights and effective legal remedies.
- binding corporate rules
- Group-wide rules approved under Article 47 that are legally binding, enforced by every concerned member including employees, and expressly confer enforceable rights on data subjects.
- certification mechanism
- A voluntary, transparent Article 42 mechanism, seal or mark intended to demonstrate GDPR compliance of processing operations.
- approved code of conduct
- A code prepared by an association or other representative body and approved through the Article 40 process; a code may also be given general validity within the Union by a Commission implementing act.