These guidelines define the role of accreditation in the context of the GDPR and outline the available routes for accrediting certification bodies as per Article 43(1), highlighting key considerations. They provide frameworks for establishing additional accreditation requirements, both when accreditation is managed by the national accreditation body and when handled by the supervisory authority.
Author: European Data Protection Board
Status: Adopted / Published
Adoption date: 2018-12-14
Last updated: 08 Aug 2025
Category: Guidance
Subcategory: Official guidance