L 119/60
EN
Official Journal of the European Union
4.5.2016
(b) undertaken to respect the criteria referred to in Article 42(5) and approved by the supervisory authority which is
competent pursuant to Article 55 or 56 or by the Board pursuant to Article 63;
(c) established procedures for the issuing, periodic review and withdrawal of data protection certification, seals and
marks;
(d) established procedures and structures to handle complaints about infringements of the certification or the manner in
which the certification has been, or is being, implemented by the controller or processor, and to make those
procedures and structures transparent to data subjects and the public; and
(e) demonstrated, to the satisfaction of the competent supervisory authority, that their tasks and duties do not result in
a conflict of interests.
3.
The accreditation of certification bodies as referred to in paragraphs 1 and 2 of this Article shall take place on the
basis of criteria approved by the supervisory authority which is competent pursuant to Article 55 or 56 or by the Board
pursuant to Article 63. In the case of accreditation pursuant to point (b) of paragraph 1 of this Article, those
requirements shall complement those envisaged in Regulation (EC) No 765/2008 and the technical rules that describe
the methods and procedures of the certification bodies.
4.
The certification bodies referred to in paragraph 1 shall be responsible for the proper assessment leading to the
certification or the withdrawal of such certification without prejudice to the responsibility of the controller or processor
for compliance with this Regulation. The accreditation shall be issued for a maximum period of five years and may be
renewed on the same conditions provided that the certification body meets the requirements set out in this Article.
5.
The certification bodies referred to in paragraph 1 shall provide the competent supervisory authorities with the
reasons for granting or withdrawing the requested certification.
6.
The requirements referred to in paragraph 3 of this Article and the criteria referred to in Article 42(5) shall be
made public by the supervisory authority in an easily accessible form. The supervisory authorities shall also transmit
those requirements and criteria to the Board. The Board shall collate all certification mechanisms and data protection
seals in a register and shall make them publicly available by any appropriate means.
7.
Without prejudice to Chapter VIII, the competent supervisory authority or the national accreditation body shall
revoke an accreditation of a certification body pursuant to paragraph 1 of this Article where the conditions for the
accreditation are not, or are no longer, met or where actions taken by a certification body infringe this Regulation.
8.
The Commission shall be empowered to adopt delegated acts in accordance with Article 92 for the purpose of
specifying the requirements to be taken into account for the data protection certification mechanisms referred to in
Article 42(1).
9.
The Commission may adopt implementing acts laying down technical standards for certification mechanisms and
data protection seals and marks, and mechanisms to promote and recognise those certification mechanisms, seals and
marks. Those implementing acts shall be adopted in accordance with the examination procedure referred to in
Article 93(2).
CHAPTER V
Transfers of personal data to third countries or international organisations
Article 44
General principle for transfers
Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third
country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the
conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers
of personal data from the third country or an international organisation to another third country or to another internat
ional organisation. All provisions in this Chapter shall be applied in order to ensure that the level of protection of
natural persons guaranteed by this Regulation is not undermined.