2.9 Codes of Conduct, Certifications & Self-Certification Mechanisms
Key Takeaways
- Indicator I.C.1 names codes of practice and self-certification mechanisms alongside laws and regulations, so voluntary instruments are examinable content, not background reading.
- GDPR Articles 40-41 govern codes of conduct with an accredited monitoring body; Articles 42-43 govern certification with an accredited certification body and a maximum three-year validity.
- An approved code or certification is an element used to demonstrate compliance under Articles 24 and 32 — it never replaces a lawful basis or the accountability obligation.
- The EU-US Data Privacy Framework is a self-certification to the US Department of Commerce requiring annual re-certification; the General Court upheld its adequacy decision in September 2025 and an appeal to the CJEU remains pending.
- ISO/IEC 27701 was reissued in October 2025 as a standalone privacy information management system standard rather than an extension of ISO/IEC 27001.
The Voluntary Layer Is Examinable
Performance indicator I.C.1 reads: understand territorial, sectoral and industry regulations, laws, codes of practice and/or self-certification mechanisms. Candidates prepare the statutes and skip the second half, then meet a scenario about a code of conduct or a self-certification and guess.
The voluntary layer matters operationally too. It is how an organization demonstrates compliance to customers who will never read its internal policies, and how mid-sized organizations obtain a transfer mechanism or an assurance credential without negotiating bespoke terms with every counterparty.
GDPR codes of conduct — Articles 40-41
A code of conduct is drawn up by an association representing a category of controllers or processors, approved by a supervisory authority (and, where processing spans member states, subject to the consistency mechanism with the European Data Protection Board and a Commission decision for general validity). Its distinguishing feature is Article 41 monitoring: adherence must be supervised by a body accredited by the supervisory authority, with real power to suspend or exclude non-compliant members. A code without an accredited monitoring body is an industry guideline, not an Article 40 code.
GDPR certification — Articles 42-43
A certification mechanism, seal or mark is issued by an accredited certification body or the supervisory authority itself. Two properties are heavily tested:
- Certification is valid for a maximum of three years and is renewable; it can be withdrawn when criteria are no longer met.
- Certification does not reduce the controller's or processor's responsibility for compliance and is without prejudice to the supervisory authority's powers.
The blunt rule for both instruments: an approved code or certification is an element used to demonstrate compliance under Articles 24 and 32. It never manufactures a lawful basis, never discharges accountability, and never immunizes the organization from enforcement.
Transfer tools built on the voluntary layer
| Mechanism | Legal home | What it is | Who approves |
|---|---|---|---|
| Standard Contractual Clauses | Art. 46(2)(c)-(d) | Pre-approved contract modules, 2021 set | European Commission |
| Binding Corporate Rules | Art. 47 | Intra-group rules for a corporate family; binding, enforceable, with member commitments | Competent supervisory authority via the consistency mechanism |
| Approved code of conduct | Art. 46(2)(e) | Code plus binding and enforceable commitments from the importer | Supervisory authority |
| Approved certification | Art. 46(2)(f) | Certification plus binding and enforceable commitments from the importer | Accredited certification body |
| Adequacy decision | Art. 45 | Commission finding that a country ensures an essentially equivalent level of protection | European Commission |
Note the recurring phrase for the code and certification routes: the importer must give binding and enforceable commitments. Holding a certification alone is not a transfer mechanism.
Self-certification: the EU-US Data Privacy Framework
The EU-US Data Privacy Framework (DPF) is the leading self-certification mechanism. US organizations subject to FTC or Department of Transportation jurisdiction self-certify to the US Department of Commerce that they adhere to the DPF Principles, publicly commit to them, and re-certify annually. The European Commission's adequacy decision of 10 July 2023 means transfers to a DPF-certified importer need no additional Article 46 tool. Parallel extensions cover the UK and Switzerland.
Two current facts worth carrying into an exam scenario. The EU General Court dismissed the Latombe challenge on 3 September 2025, upholding the adequacy decision; an appeal to the Court of Justice (Case C-703/25 P) is pending, and the CJEU is the court that struck down both Safe Harbour and Privacy Shield. So the DPF is valid today and carries real residual risk — the credited privacy-manager posture is to use the DPF where it applies while keeping SCCs and a transfer impact assessment ready as a fallback, exactly the lesson organizations learned when Privacy Shield fell.
Global CBPR. The Global Cross-Border Privacy Rules Forum, established in 2022, operates the Global CBPR and Global Privacy Recognition for Processors systems, extending the APEC model beyond APEC economies. Certification is granted by an accountability agent following assessment.
Standards as the target state
ISO/IEC 27701 is the privacy information management system standard. Its second edition, published on 14 October 2025, is the change to know: 27701 became a standalone management system standard rather than an extension of ISO/IEC 27001 and 27002, so an organization can now build a PIMS without first certifying an ISMS. ISO/IEC 27018 addresses PII in public clouds, ISO/IEC 29100 provides the privacy framework and terminology, and the NIST Privacy Framework offers a US-oriented, outcome-based model that pairs with the Cybersecurity Framework.
How the privacy manager actually uses this layer
Pick instruments for a reason: a customer-assurance reason (a certification answers questionnaires and shortens sales cycles), a transfer reason (BCRs for an intra-group flow at scale, DPF where the importer qualifies), a sector reason (an approved code where one exists for your industry), or a maturity reason (27701 as the target state for a gap analysis under indicator III.A). Then govern them: certifications expire, DPF certification lapses without annual re-certification, and code membership can be suspended by the monitoring body — so ownership, renewal dates and evidence retention belong in the program calendar, not in someone's inbox.
A European trade association publishes an industry privacy code and invites members to display its badge. There is no accredited body monitoring member compliance. How should a CIPM candidate classify it?
A US SaaS provider is certified under the EU-US Data Privacy Framework and receives personal data from EU customers. What is the most defensible position for its privacy manager in 2026?