These guidelines are focused on defining the general requirements and criteria for certification mechanisms under Articles 42 and 43 of the GDPR. They explore the role of certification as an accountability tool, explaining key concepts of certification within Articles 42 and 43, and detailing the scope and purpose of what can be certified under these articles.
Author: European Data Protection Board
Status: Adopted / Published
Adoption date: 2019-06-04
Last updated: 08 Aug 2025
Category: Guidance
Subcategory: Official guidance