Codes of Practice Compliance and Monitoring
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Codes of practice require specific mechanisms for monitoring compliance and enforcement, which is distinct from general AI Act compliance and deserves dedicated topic coverage.
Overview
12 sources · Jul 23, 2026Legal Framework
Articles 40 and 41 GDPR establish the regime for codes of conduct and their monitoring. Article 40 permits associations or bodies representing categories of controllers or processors to prepare codes of conduct, which must be submitted to a competent supervisory authority for approval. Article 41 imposes the critical monitoring obligation: once a code is approved, compliance must be monitored by an accredited body with appropriate expertise. That body must be accredited by the competent supervisory authority under Article 41(1), and its accreditation can be withdrawn where conditions are no longer met or where the body's monitoring is inadequate.
Articles 42 and 43 GDPR create a parallel certification mechanism. Article 42(1) explicitly links certification to demonstration of compliance with codes of conduct, making the two instruments mutually reinforcing. Article 43(2) requires certification bodies to be accredited by a supervisory authority or national accreditation body, and they must comply with EN-ISO/IEC 17065/2012 standards. The EDPB's Guidelines 1/2018 elaborate how certification criteria must map to GDPR obligations and how certification serves as an accountability tool under Article 5(2).
Key Developments
The Spanish DPA's enforcement against ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓN demonstrates that failure to maintain or demonstrate certified compliance with applicable codes carries direct financial consequences, even where the underlying fine is modest (€750). The decision underscores that supervisory authorities treat code compliance not as a voluntary nicety but as a binding accountability mechanism where certification has been pursued.
The EDPB's Guidelines 04/2022 on administrative fine calculation further reinforces this approach: adherence to approved codes of conduct is identified as a mitigating factor under the five-step fine methodology, while failure to comply with commitments under such codes can constitute an aggravating circumstance. This creates a bilateral enforcement incentive — organizations that obtain certification benefit from reduced exposure, but those that fail to maintain compliance face heightened penalties.
Practical Guidance
Identify applicable sectoral codes: Determine whether your industry has an approved code of conduct under Article 40. If so, map your processing activities against its specific requirements rather than relying solely on general GDPR compliance.
Engage an accredited monitoring body: Where you claim compliance with an approved code, engage a body accredited under Article 41(1) to conduct ongoing monitoring. Self-assessment without accredited oversight does not satisfy the accountability obligation.
Maintain documentation of certification status: If you hold certification under Article 42, keep current records demonstrating continued compliance. Lapsed or unverified certification provides no protection and may attract enforcement.
Treat code compliance as a living obligation: Codes may be amended and re-approved. Track revisions to any code you follow and update internal policies accordingly, as continued certification depends on alignment with the current version.
Leverage code compliance in enforcement scenarios: Where facing a DPA investigation, proactively present evidence of code adherence and certification as a mitigating factor under the EDPB's fine calculation methodology.
No content yet
Content for this topic will be added soon.