Skip to content
Topic Contested in court

Notified Body Independence

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Notified bodies must maintain strict independence and impartiality standards, which are critical operational obligations that warrant a dedicated topic for detailed coverage.

79 linked items 1 Laws12 Case Law34 Guidance19 Enforcement8 News

Overview

20 sources · Aug 27, 2026

Legal Framework

Independence and impartiality of notified bodies and analogous accreditation entities are governed by a multi-instrument framework spanning the AI Act, GDPR, and sectoral cybersecurity law. Under Article 28(3) of the AI Act, notifying authorities themselves must be structured so that no conflict of interest arises with the conformity assessment bodies they oversee:

"Notifying authorities shall be established, organised and operated in such a way that no conflict of interest arises with conformity assessment bodies, and that the objectivity and impartiality of their activities are safeguarded."
— AI Act Art. 28(3)

This is reinforced by Article 28(4), which mandates functional separation between assessors and decision-makers, and Article 28(5), which prohibits notifying authorities from offering consultancy services on a commercial basis.

The GDPR mirrors these structural safeguards for bodies accredited to monitor codes of conduct and issue data protection certifications. Under Article 41(2)(d) GDPR, a monitoring body must demonstrate that its tasks and powers do not give rise to a conflict of interest. Similarly, Article 43(2)(a) GDPR requires certification bodies to demonstrate their independence and expertise to the supervisory authority's satisfaction. These provisions are operationalized through EN-ISO/IEC 17065:2012, which provides the technical accreditation baseline.

Key Developments

The EDPB has actively scrutinized national supervisory authorities' accreditation requirements to ensure they impose substantive—not merely formal—independence obligations. In its review of the Finnish supervisory authority's draft requirements, the EDPB noted that a provision requiring certification bodies to demonstrate independence:

The EDPB similarly advised the Swedish supervisory authority to explicitly tie its impartiality requirements to Article 43(2)(e) GDPR, ensuring consistency between accreditation criteria and the statutory conflict-of-interest prohibition. This signals that supervisory authorities must go beyond referencing ISO standards and articulate concrete, enforceable independence criteria.

On the judicial side, the CJEU's ruling in XH v European Commission illustrates how conflict-of-interest declarations are operationalized institutionally: once a conflict was identified, the official was immediately released from the affected case. The procedural steps—declaration, review, and remediation—demonstrate the expected workflow when a conflict surfaces.

Status of the Debate

This topic is actively litigated and regulator-defined. The EDPB continues to issue opinions on national accreditation requirements, indicating that the doctrinal line on what constitutes sufficient independence has not settled. The core open question is whether ISO 17065 compliance alone satisfies the GDPR's independence mandate or whether supervisory authorities must impose additional, substantive conflict-of-interest tests. The EDPB's consistent push for "substantive obligations" beyond ISO standards suggests the latter, but no court has yet ruled on whether ISO compliance is legally sufficient. A CJEU preliminary reference on the relationship between EN-ISO/IEC 17065 and Article 43(2) GDPR would resolve this.

Practical Guidance

  • Structural separation: Ensure that personnel who assess conformity or accreditation are not the same individuals who make the notification or accreditation decision, per Article 28(4) AI Act. Document this separation in organizational charts and decision logs.
  • Conflict-of-interest declarations: Implement a formal declaration system covering all personnel involved in assessment and certification activities. The XH v European Commission proceedings confirm that declarations must be actively reviewed, with prompt case reassignment upon identification of a conflict.
  • No commercial consultancy: Notifying authorities and accredited bodies must not provide consultancy services on a competitive basis. Certification bodies should review any ancillary service offerings for potential conflicts with their certification function.
  • Substantive independence criteria: When seeking accreditation under Article 41 or 43 GDPR, do not rely solely on ISO 17065 compliance. Prepare demonstrable evidence of independence—governance structures, financial autonomy, and personnel policies—that goes beyond the ISO baseline, as the EDPB has consistently required.
  • Transparency to supervisory authorities: Ensure that accreditation applications allow full transparency regarding the certification procedure, including contractually confidential matters, as recommended by the EDPB in its review of Swedish accreditation requirements.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section

This is the top of each pile — all 34 Guidance