Codes of Conduct
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Industry codes of conduct for data protection
Overview
20 sources · Jul 23, 2026Legal Framework
Codes of conduct under the GDPR are governed primarily by Article 40, which enables representative associations to draft codes contributing to proper application of the Regulation. While Article 40's operative text is not reproduced here, its practical force is felt through cross-references in key compliance provisions.
Article 32(3) explicitly recognizes adherence to an approved code of conduct as a compliance demonstration tool:
"Adherence to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate compliance"
— GDPR Art. 32(3)
Similarly, Article 25(3) provides that an approved certification mechanism under Article 42 may demonstrate compliance with data protection by design and by default obligations. Article 28 requires controllers to select processors providing sufficient guarantees — a standard that industry codes can help operationalize. Article 47 governs binding corporate rules, a distinct but related instrument for international transfers.
Key Developments
The CJEU's Schrems II judgment invalidated the EU-US Privacy Shield, reinforcing the need for robust transfer safeguards including BCRs under Article 47. The Court situated this within the broader context of escalating data collection:
"De mate waarin persoonsgegevens worden verzameld en gedeeld, is significant gestegen."
— HvJ EU: Privacy Shield ongeldig verklaard (Schrems II) ¶8
At the national level, Dutch courts have examined the binding force of industry codes. In the EVR registration case, the court analyzed the Gedragscode Behandeling Letselschadedossiers (GBL):
"De Medische paragraaf van de gedragscode Behandeling Letselschadedossiers (GBL), waar verzekeraars aan gebonden zijn, bepaalt welke informatie aan verzekeraars moet worden verstrekt."
— Handhaving EVR registratie ¶3.3
In a separate whistleblowing dispute, the court found that reliance on a code of conduct does not automatically create enforceable disclosure rights:
"Daarvoor is geen grondslag te vinden in Regeling A van de Gedragscode en de Wbk"
— Afwijzing vorderingen ¶4.7
Status of the Debate
This topic is actively contested. Courts diverge on the legal weight of codes of conduct — whether adherence creates enforceable rights for data subjects or merely serves as a compliance indicator. The Schrems II line applies rigorous scrutiny to transfer-related safeguards under Article 47, while national courts take varying approaches to industry-specific codes under Article 40. The Dutch cases illustrate that codes may bind industry participants contractually but do not necessarily generate standalone claims for third parties. No definitive CJEU ruling on Article 40 codes specifically has yet resolved this boundary. Clarification would likely require a preliminary reference on whether code adherence creates direct enforceable rights for data subjects, or remains a compliance-demonstration tool limited to accountability under Article 32 and Article 25.
Practical Guidance
- Leverage codes for compliance demonstration: Adherence to an approved code under Article 40 can evidence compliance with Article 32 security requirements and, through Article 42 certification, with Article 25 data protection by design obligations.
- Select processors with code adherence in mind: Article 28 requires processors providing sufficient guarantees — participation in a relevant industry code can serve as supporting evidence.
- Do not treat codes as substitutes for legal obligations: Dutch case law confirms that codes define industry practice but do not override GDPR requirements or create independent enforcement rights for third parties.
- Document code adherence systematically: Maintain records of which approved codes your organization follows and map specific provisions to corresponding GDPR articles to demonstrate accountability.
- Monitor transfer-safeguard distinctions: Given Schrems II, ensure that any code-based transfer mechanisms comply with Article 46 safeguards — codes of conduct under Article 40 alone do not constitute an adequate transfer basis.