4.5.2016
EN
Official Journal of the European Union
L 119/59
2.
In addition to adherence by controllers or processors subject to this Regulation, data protection certification
mechanisms, seals or marks approved pursuant to paragraph 5 of this Article may be established for the purpose of
demonstrating the existence of appropriate safeguards provided by controllers or processors that are not subject to this
Regulation pursuant to Article 3 within the framework of personal data transfers to third countries or international
organisations under the terms referred to in point (f) of Article 46(2). Such controllers or processors shall make binding
and enforceable commitments, via contractual or other legally binding instruments, to apply those appropriate
safeguards, including with regard to the rights of data subjects.
3.
The certification shall be voluntary and available via a process that is transparent.
4.
A certification pursuant to this Article does not reduce the responsibility of the controller or the processor for
compliance with this Regulation and is without prejudice to the tasks and powers of the supervisory authorities which
are competent pursuant to Article 55 or 56.
5.
A certification pursuant to this Article shall be issued by the certification bodies referred to in Article 43 or by the
competent supervisory authority, on the basis of criteria approved by that competent supervisory authority pursuant to
Article 58(3) or by the Board pursuant to Article 63. Where the criteria are approved by the Board, this may result in a
common certification, the European Data Protection Seal.
6.
The controller or processor which submits its processing to the certification mechanism shall provide the certifi
cation body referred to in Article 43, or where applicable, the competent supervisory authority, with all information
and access to its processing activities which are necessary to conduct the certification procedure.
7.
Certification shall be issued to a controller or processor for a maximum period of three years and may be
renewed, under the same conditions, provided that the relevant requirements continue to be met. Certification shall be
withdrawn, as applicable, by the certification bodies referred to in Article 43 or by the competent supervisory authority
where the requirements for the certification are not or are no longer met.
8.
The Board shall collate all certification mechanisms and data protection seals and marks in a register and shall
make them publicly available by any appropriate means.
Article 43
Certification bodies
1.
Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58,
certification bodies which have an appropriate level of expertise in relation to data protection shall, after informing the
supervisory authority in order to allow it to exercise its powers pursuant to point (h) of Article 58(2) where necessary,
issue and renew certification. Member States shall ensure that those certification bodies are accredited by one or both of
the following:
(a) the supervisory authority which is competent pursuant to Article 55 or 56;
(b) the national accreditation body named in accordance with Regulation (EC) No 765/2008 of the European Parliament
and of the Council (1) in accordance with EN-ISO/IEC 17065/2012 and with the additional requirements established
by the supervisory authority which is competent pursuant to Article 55 or 56.
2.
Certification bodies referred to in paragraph 1 shall be accredited in accordance with that paragraph only where
they have:
(a) demonstrated their independence and expertise in relation to the subject-matter of the certification to the
satisfaction of the competent supervisory authority;
(1) Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 setting out the requirements for accredi
tation and market surveillance relating to the marketing of products and repealing Regulation (EEC) No 339/93 (OJ L 218, 13.8.2008,
p. 30).