GDPR Codes of Conduct: How They Work and Why They Matter

Learn how GDPR Codes of Conduct turn data protection requirements into practical, sector-specific standards. Explore how codes are developed, approved and monitored, why organizations may choose to join them, and how they can support accountability, compliance and international data transfers.

GDPR Codes of Conduct: How They Work and Why They Matter
Key Points (1) The GDPR encourages the development and use of approved codes of conduct as a practical way to support compliance with data protection requirements; (2) Codes are designed to translate GDPR requirements into sector-specific standards, taking into account the characteristics of different processing activities and the particular needs of micro, small, and medium-sized enterprises (SMEs); (3) Trade associations and other bodies representing controllers or processors can develop codes of conduct, allowing sectors to establish practical and potentially cost-effective approaches to common data protection challenges; (4) Adherence to a code of conduct is voluntary, but organizations may benefit from joining an approved code relevant to their sector or processing activities; (5) Adherence can help organizations demonstrate accountability and compliance to Supervisory Authorities, customers, business partners, and the public; (6) Approved codes are subject to formal approval and ongoing monitoring, helping ensure that participation remains a meaningful and trustworthy indicator of compliance with the code's standards; (7) Approved codes may also support specific GDPR requirements, including international data transfers, where the applicable additional requirements are satisfied.

What Are Codes of Conduct?

Codes of conduct provide a practical, sector-specific framework for complying with European data protection law. Rather than applying general legal requirements in the abstract, they translate those obligations into standards and practices tailored to the particular processing activities, risks, and compliance needs of a specific industry or sector.

Articles 40 and 41 of the GDPR establish a framework for developing, approving, and monitoring codes of conduct that help organizations apply GDPR requirements in a practical and sector-specific manner. The GDPR expressly encourages the development of these codes, taking into account the characteristics of different processing sectors and the particular needs of micro, small, and medium-sized enterprises (SMEs).

Under Article 40 of GDPR, associations and other bodies representing controllers or processors may develop, amend, or extend codes that explain how GDPR requirements should apply to particular industries or processing activities. Codes may address matters ranging from transparency, legitimate interests, and individual rights to security, data breaches, children's data, and international data transfers. Codes must be submitted to the competent supervisory authority for approval, with additional procedures applying to codes covering processing activities in multiple EU Member States. Certain approved codes may ultimately be given general validity throughout the EU by the European Commission.

Article 41 of GDPR provides the accountability mechanism behind approved codes. Compliance may be monitored by an independent body with appropriate expertise that has been accredited by the competent supervisory authority. Monitoring bodies must have procedures for assessing eligibility, monitoring compliance, periodically reviewing the code, and handling complaints. Where a participating controller or processor violates the code, the monitoring body may take appropriate action, including suspending or excluding the organization from the code, while supervisory authorities retain their regulatory powers.

Together, Articles 40 and 41 make codes of conduct more than voluntary industry guidance: approved codes provide a structured and supervised mechanism for translating GDPR requirements into practical standards tailored to particular sectors and processing activities.

What Can a Code of Conduct Cover?

GDPR codes of conduct can address a wide range of data protection requirements, translating general legal obligations into practical standards for a particular sector or type of processing. They may cover:

  • fair and transparent processing;
  • the application of legitimate interests in specific contexts;
  • the collection of personal data;
  • pseudonymization of personal data;
  • privacy notices and individual rights;
  • the protection of children, including mechanisms for obtaining parental consent;
  • technical and organizational measures (TOMs), including data protection by design and by default and appropriate security measures;
  • personal data breach notification;
  • international data transfers; and
  • dispute-resolution procedures.

Codes of conduct can also be relevant when selecting and conducting due diligence on service providers and other third parties. An organization may wish to consider whether a prospective provider has committed to an approved code of conduct as one factor in evaluating its data protection practices and ability to meet applicable GDPR requirements.

Why Are Codes of Conduct Useful?

Codes of Conduct can be particularly valuable for micro, small, and medium-sized enterprises (SMEs) by allowing organizations within a sector to collaborate on common compliance challenges. By developing shared approaches to recurring data protection issues, codes can provide added value and a more cost-effective path to compliance, particularly for organizations with limited compliance resources.Codes of conduct provide a practical, sector-specific framework for complying with European data protection law. Rather than applying general legal requirements in the abstract, they translate those obligations into standards and practices tailored to the particular processing activities, risks, and compliance needs of a specific industry or sector.Why Are Codes of Conduct Useful?

Who Can Develop a Code of Conduct?

Trade associations and other bodies representing specific sectors may develop codes of conduct to help organizations apply European data protection requirements in a practical, sector-specific way.

When developing a code, these organizations should consult relevant stakeholders, including members of the public where feasible. They may also amend or extend existing codes so that they align with the requirements of European data protection law.

This approach allows industries to build on existing standards and practices while translating broader data protection obligations into practical rules tailored to the particular needs and risks of their sector.

How Are GDPR Codes of Conduct Approved?

The approval process begins when an association or other representative body submits a draft code—or an amendment or extension to an existing code—to the competent Supervisory Authority. The Supervisory Authority assesses whether the code complies with the GDPR and provides sufficient appropriate safeguards. If these requirements are satisfied, it may approve the code.

Approved codes must also include mechanisms for monitoring compliance. Except for processing carried out by public authorities and bodies, this monitoring may be performed by an independent monitoring body accredited by the competent Supervisory Authority. To qualify, the monitoring body must demonstrate appropriate expertise and independence and establish procedures for monitoring compliance, periodically reviewing the code, and handling complaints.

As part of this framework, Supervisory Authorities are responsible for:

  • assessing whether proposed codes provide sufficient appropriate safeguards;
  • establishing the requirements for accrediting monitoring bodies, subject to the GDPR's consistency mechanism;
  • accrediting qualifying monitoring bodies;
  • approving and publishing qualifying codes that do not concern processing activities in several Member States; and
  • overseeing the operation of the code and its monitoring arrangements.

What if the Code Applies in Multiple EU Countries?

Where a proposed code relates to processing activities in several EU Member States, an additional approval process applies. Before approving the code, the competent Supervisory Authority must submit it to the European Data Protection Board (EDPB) through the GDPR's consistency mechanism.

The EDPB then issues an opinion on whether the code complies with the GDPR and, where applicable, whether it provides appropriate safeguards for international data transfers. If the EDPB's opinion is favorable, it submits its opinion to the European Commission.

The Commission may then adopt an implementing act providing that the approved code has general validity throughout the European Union.

Codes of Conduct and International Data Transfers

Approved codes of conduct can also play a role in transfers of personal data outside the EU. Under Articles 40 and 46 of the GDPR, an approved code may serve as an appropriate safeguard for international transfers when the recipient controller or processor makes binding and enforceable commitments to comply with the code and protect individuals' rights.

This means that, when the applicable GDPR requirements are satisfied, a code of conduct can function not only as a sector-specific compliance framework but also as a transfer mechanism for personal data sent to third countries or international organizations.

Adhering to a Code of Conduct

Organizations may voluntarily sign up to an approved code of conduct that is relevant to their sector or processing activities. The code may be newly developed or may result from an amendment or extension of an existing code.

To participate, an organization must generally demonstrate to the code's monitoring body that it satisfies the applicable requirements for membership. Those requirements should reflect the particular characteristics of the sector and processing activities covered by the code.

Although adherence is voluntary, participating in an approved code of conduct can provide significant compliance and business benefits. In particular, it can help organizations:

  • demonstrate accountability and transparency by providing customers, business partners, and individuals with greater assurance that particular processing activities, products, or services follow recognized data protection standards;
  • demonstrate compliance with certain GDPR obligations, as adherence to an approved code may be used as an element to demonstrate compliance;
  • reduce regulatory risk, since adherence to an approved code is one of the factors Supervisory Authorities must consider when deciding whether to impose an administrative fine and determining its amount;
  • strengthen safeguards designed to protect individuals' rights and freedoms and mitigate risks associated with data processing;
  • establish and promote sector-specific best practices;
  • provide a potential competitive advantage by demonstrating a commitment to recognized data protection standards; and
  • in appropriate circumstances, provide appropriate safeguards for international data transfers when the additional requirements of the GDPR are satisfied.

Adherence does not, however, provide immunity from enforcement or automatically establish GDPR compliance. Organizations remain responsible for complying with the GDPR, and monitoring bodies may take action where a participating organization breaches the code, including suspending or excluding it from the code.

How Is Compliance with a Code of Conduct Monitored?

Once an organization has been accepted as a member of an approved code of conduct, its compliance with the code is monitored on an ongoing basis. The accredited monitoring body is responsible for assessing participating organizations, monitoring their compliance, and periodically reviewing the operation of the code. This oversight helps ensure that participation in the code remains a meaningful and trustworthy indicator of adherence to its standards.

Participation is also intended to be transparent. Information about approved codes and participating organizations may be made publicly available through the code's own website or membership information, as well as through public registers maintained by the relevant Supervisory Authorities and the EDPB.

If an organization fails to comply with the code, the monitoring body may take appropriate action. Depending on the circumstances, this can include suspending or excluding the organization from the code. The monitoring body must inform the competent Supervisory Authority of such action and the reasons for taking it.

Importantly, monitoring under a code of conduct does not replace regulatory oversight. Supervisory Authorities retain their powers under the GDPR and may take enforcement action where appropriate.

Additional Resources

For organizations seeking additional guidance on GDPR certification mechanisms, the following provisions and regulatory materials provide useful starting points.

GDPR Provisions

The principal GDPR provisions governing certification are:

EDPB Guidelines on Certification

The European Data Protection Board (EDPB) has issued detailed guidance explaining GDPR certification and the development and approval of codes of conduct under Articles 40 and 41.

Key resources include:

Cloud computing

Cloud Security Alliance Code of Conduct of GDPR Compliance

Belgian DPA Approves First EU Data Protection Code of Conduct for Cloud Service Providers — Posted on Hunton’s blog May 24, 2021

Subscribe to The de la Torre Review

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe