# Certification bodies 43(6) — GDPR — provision context

> Focused context for a single provision (43(6)), curated from overview.legal on 2026-08-22. Canonical: https://overview.legal/laws/gdpr/art-43#par-6
> Verify against the official text (EUR-Lex / wetten.overheid.nl) before relying on it.

Part of **Certification bodies** (GDPR, full article: https://overview.legal/laws/gdpr/art-43).

## Provision text

### 43(6)

The requirements referred to in paragraph 3 of this Article and the criteria referred to in Article 42(5) shall be made public by the supervisory authority in an easily accessible form. The supervisory authorities shall also transmit those requirements and criteria to the Board. The Board shall collate all certification mechanisms and data protection seals in a register and shall make them publicly available by any appropriate means.


## Topics on this provision

- **Certification** — https://overview.legal/topics/certification
  Data protection certification mechanisms
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

## Cited by (exact-provision citations)

- **Opinion 1/2022 on the draft decision of the Luxembourg Supervisory Authority regarding the GDPR – CARPA certification criteria** (guidance) — https://overview.legal/posts/125965
- **Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679)** (guidance) — https://overview.legal/posts/126260
- **Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation** (guidance) — https://overview.legal/posts/38048
- **Opinion 34/2025 on the draft decision of the Greek Supervisory Authority regarding C.E.C.L certification criteria** (guidance) — https://overview.legal/posts/51416
- **Opinion 16/2025 regarding the draft decision of the German North Rhine Westphalia Supervisory Authority regarding Trusted Site Data Privacy (TÜV IT) certification criteria** (guidance) — https://overview.legal/posts/51080
- **Opinion 26/2024 on the draft decision of the DE Bremen Supervisory Authority regarding the “Catalogue of Criteria for the Certification of IT-supported processing of Personal Data pursuant to art 42 GDPR (‘GDPR – information privacy standard’)” presented** (guidance) — https://overview.legal/posts/125701
- **Opinion 7/2024 on the draft decision of the German North Rhine Westphalia Supervisory Authority regarding the EU Cloud Service Data Protection (Auditor) certification criteria** (guidance) — https://overview.legal/posts/125759
- **Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria** (guidance) — https://overview.legal/posts/125831
- **Opinion 25/2022 regarding the European Privacy Seal (EuroPriSe ) certification criteria for the certification of processing operations by processors** (guidance) — https://overview.legal/posts/125895
- **Opinion 34/2025 on the draft decision of the Greek Supervisory Authority regarding C.E.C.L certification criteria** §45 (guidance, EDPB) — https://overview.legal/posts/51416
- **Opinion 1/2022 on the draft decision of the Luxembourg Supervisory Authority regarding the GDPR – CARPA certification criteria** §57 (guidance, EDPB) — https://overview.legal/posts/125965

---
Generated by overview.legal · https://overview.legal/laws/gdpr/art-43#par-6 · 2026-08-22
