Laws · GDPR ·art-42-par-7 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Certification shall be issued to a controller or processor for a maximum period of three years and may be renewed, under the same conditions, provided that the relevant requirements continue to be met. Certification shall be withdrawn, as applicable, by the certification bodies referred to in Article 43 or by the competent supervisory authority where the requirements for the certification are not or are no longer met.
How it connects
Cited by
- Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation
- Opinion 10/2024 on the draft decision of the competent supervisory authority of Sweden regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)
- Opinion 12/2023 on the draft decision of the competent supervisory authority of Cyprus regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)
- Opinion 11/2022 on the draft decision of the competent supervisory authority of Poland regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)
- Opinion 25/2021 on the draft decision of the competent supervisory authority of Lithuania regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)
All 9
- Contribution of the EDPB to the evaluation of the GDPR under Article 97
- Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679)
- High Court examines DPA inquiry into Meta's refusal of raw data access and portability
- Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR
Related across sources
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
Opinion 15/2023 Brand Compliance certification criteria ·Opinion ·EDPB Sep 19, 2023 Certification Supervision Supervisory Authorities
Opinion 18/2024 DSGVO-zt GmbH certification criteria ·Opinion ·EDPB Jul 18, 2024 Certification Supervision Supervisory Authorities
Opinion 26/2024 “Catalogue of Criteria for the Certification of IT-supported processing of Personal Data pursuant to art 42 GDPR (‘GDPR – information privacy standard’)” presented ·Opinion ·EDPB Dec 2, 2024 Certification Supervision Supervisory Authorities
Opinion 15/2025 certification criteria of BDO Consulting GmbH ·Opinion ·EDPB Jul 14, 2025 Certification Supervision Supervisory Authorities
Opinion 7/2024 EU Cloud Service Data Protection (Auditor) certification criteria ·Opinion ·EDPB Apr 19, 2024 Certification Supervision Supervisory Authorities