These guidelines are designed to assist in applying Articles 40 and 41 of the GDPR, focusing on the submission, approval, and publication of codes at national and European levels. They detail the criteria for Competent Supervisory Authorities to review and evaluate codes, and how to ensure these codes effectively apply and monitor GDPR compliance. The guidelines also provide a framework for consistent evaluation of codes and address the need for re-evaluating previously approved codes under the new GDPR requirements.
Author: European Data Protection Board
Status: Adopted / Published
Adoption date: 2019-06-04
Last updated: 08 Aug 2025
Category: Guidance
Subcategory: Official guidance