Adherence to Approved Codes of Conduct with Monitoring, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 40(4).
Assessment Step
1
Adherence to Approved Codes of Conduct with Monitoring (AdherencetoApprovedCodesofConductwithMonitoring)
If the entity adheres to a code of conduct that has been approved by the supervisory authority and published in the Official Journal of the European Union, does it submit to monitoring of compliance by an accredited monitoring body? Note that adherence to a code of conduct is not mandatory.
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Adherence to Approved Codes of Conduct with Monitoring
If the data controller or the data processor adheres to a code of conduct that has been approved by the supervisory authority and published in the Official Journal of the European Union, it must submit to the monitoring of compliance carried out by an accredited monitoring body.
Citation
GDPR
Art. 40(4), Recital 98
|