European Data Protection Certification

06 dicembre 2017

On November 29, 2017, Enisa issued the a report destined to familiarise data protection experts with the terminology of certification and to clarify concepts which are relevant to the General Data Protection Regulation (GDPR) certification. The report identifies and analyses challenges and opportunities faced by data protection certification mechanisms, including seals and marks

As of 25 May 2018, GDPR will be the main data protection legal framework in the EU and will be directly applicable to all EU Member States. GDPR will introduce provisions on certification to enhance the transparency of data controllers’ processing operations and the processors. The legislature also envisages a role of certification in assisting controllers and processors to demonstrate compliance with the regulation.

Prof. Dr. Udo Helmbrecht, Executive Director of ENISA, stated: “The GDPR is a landmark piece of legislation which is designed to protect personal information. Given the digitalisation of our world protecting our personal data is critical to the operation of the Digital Single Market, I expect that this report will contribute to the effective implementation of this important piece of legislation.”

Goal-oriented certifications

GDPR data protection mechanisms should not focus only on whether measures are in place or not, but also on to what extent such measures are sufficient in ensuring compliance with the provisions of the regulation.

Certifying a processing operation

 The GDPR regulates the processing of personal data, which may be conducted for a product, system or service. The regulation requires that a certification mechanism under GDPR must concern an activity of data processing. However, the certification must be granted in relation to the processing activity or activities and not to the product, system or service as such.

 Certification as an accountability-based mechanism

 A controller that has had its processing operations successfully evaluated by a certification body may use the certification and its supporting documentation as an element to demonstrate compliance to the supervisory authority. The fact that data protection certification in the GDPR is an accountability-based mechanism is supported by its voluntary nature.

 The recommendations of the report are meant to be of use to all actors involved, from the European Commission and the European Data Protection Board to national certification bodies and supervisory authorities – who are in a position to develop a harmonised understanding of GDPR data protection certification mechanisms and to provide further guidelines should queries and/or challenges arise.

Archivio news

 

News dello studio

mag12

12/05/2026

Approvazione delle condizioni tecnico economiche del servizio “Open Stream FWA 5G” per il completamento della copertura nelle c.d. aree bianche (Listino "C&D”) da parte di Open Fiber S.p.A. beneficiario di aiuto di Stato

Con la delibera n. 96/26/CONS Agcom approva, ai sensi delle delibere n. 120/16/CONS e n. 171/25/CONS e sulla base dei criteri indicati negli Orientamenti della Commissione europea, nel rispetto di quanto

mag12

12/05/2026

Avvio del procedimento e della consultazione pubblica concernenti l’approvazione delle offerte di riferimento di TIM per gli anni 2025 e 2026 relative ai servizi di terminazione delle chiamate nella rete telefonica pubblica fissa

In applicazione della delibera n. 13/22/CONS di analisi dei mercati dei servizi d’interconnessione nella rete telefonica pubblica fissa, TIM ha pubblicato le offerte di riferimento relative ai

mag12

12/05/2026

Concorsi pubblici ed intelligenza artificiale

(T.A.R. Lazio Roma, Sez. III bis, 02/02/2026, n. 1895CONCORSI A PUBBLICI IMPIEGHI › Bando del concorso, requisiti, ammissione ed esclusioneParti: P.C. c. Ministero dell'Istruzione e

News Giuridiche

mag13

13/05/2026

FaceBoarding: il provvedimento del Garante sull’Aeroporto di Milano Linate

<p>Con il Provvedimento n. 164/2026,

mag13

13/05/2026

Appalti regionali: illegittimo il criterio premiale del trattamento economico minimo in favore dei lavoratori

<p>La <a href="https://onelegale.wolterskluwer.it/document/10SE0003156686"