# Processor 28(5) — GDPR — provision context

> Focused context for a single provision (28(5)), curated from overview.legal on 2026-08-22. Canonical: https://overview.legal/laws/gdpr/art-28#par-5
> Verify against the official text (EUR-Lex / wetten.overheid.nl) before relying on it.

Part of **Processor** (GDPR, full article: https://overview.legal/laws/gdpr/art-28).

## Provision text

### 28(5)

Adherence of a processor to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate sufficient guarantees as referred to in paragraphs 1 and 4 of this Article.


## Topics on this provision

- **Codes of Conduct** — https://overview.legal/topics/codes-of-conduct
  Industry codes of conduct for data protection
- **Processors** — https://overview.legal/topics/processors
  Entities that process data on behalf of controllers
- **Certification** — https://overview.legal/topics/certification
  Data protection certification mechanisms
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing

## Cited by (exact-provision citations)

- **COMMISSION V. GERMANY, 9.Mar.2010 (“GERMANY”)** (case-law) — https://overview.legal/posts/5978
- **COMMISSION V. GERMANY, 9.Mar.2010 (“GERMANY”)** ¶45 (case-law, CJEU) — https://overview.legal/posts/5978
- **Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)** (guidance) — https://overview.legal/posts/125715
- **Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation** (guidance) — https://overview.legal/posts/38048
- **Guidelines 07/2020 on the concepts of controller and processor in the GDPR** (guidance) — https://overview.legal/posts/38069
- **Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679** (guidance) — https://overview.legal/posts/38051
- **Opinion 15/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal to be used as tool for transfers pursuant to Articles 42 and 46 GDPR** (guidance) — https://overview.legal/posts/125681
- **Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH** (guidance) — https://overview.legal/posts/51079
- **Opinion 15/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal to be used as tool for transfers pursuant to Articles 42 and 46 GDPR** §11 (guidance, EDPB) — https://overview.legal/posts/125681

---
Generated by overview.legal · https://overview.legal/laws/gdpr/art-28#par-5 · 2026-08-22
