Skip to content
Topic Actively litigated

Notified Body Independence

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Notified bodies must maintain strict independence and impartiality standards, which are critical operational obligations that warrant a dedicated topic for detailed coverage.

77 linked items 1 Laws13 Case Law34 Guidance16 Enforcement8 News

Overview

19 sources · Jul 23, 2026

Legal Framework

Notified body independence is grounded in several overlapping EU and national provisions. DSA Recital 112 establishes that competent authorities designated under the regulation must act fully independently from both private and public bodies, without the obligation or possibility to seek or receive instructions — even from government. This independence is balanced against constitutional requirements and the obligation to cooperate with other competent authorities, Digital Services Coordinators, the Digital Services Board, and the Commission. DSA Recital 59 extends independence requirements to out-of-court dispute settlement bodies, requiring that independence be ensured not only at the institutional level but also at the level of the natural persons charged with resolving disputes, through explicit conflict-of-interest rules. At the national level, procurement law provisions such as Article 2.87(1)(e) in conjunction with Article 1.10b of the Dutch Public Procurement Act 2012 mandate exclusion of contractors where a conflict of interest compromises impartial performance. Article 3:40 of the Dutch Civil Code provides the broader nullity framework for acts conflicting with public policy, which encompasses violations of independence principles.

Key Developments

The Gerechtshof Den Haag ruling of 30 June 2026 (cases 200.361.266/01, 200.361.440/01, and 200.361.896/01) clarifies the threshold for establishing that a conflict of interest undermines procurement integrity. The court examined whether a share transaction between municipal entities and a private party constituted prohibited state aid that should have triggered exclusion under Article 2.87(1)(e) jo. 1.10b Aw 2012. The court held that the claimant failed to sufficiently demonstrate that the transaction involved unlawful state aid influencing the procurement procedure's pricing, and consequently could not establish that the contracting authority should have excluded the bidder on conflict-of-interest grounds. The ruling reinforces the Xafax jurisprudence, under which a contract between a contracting authority and a contractor can only be set aside in appeal proceedings where nullity under Article 3:40 BW applies — specifically, conflict with public policy other than procurement law itself. The court's reasoning establishes that mere allegations of financial entanglement or below-market transactions are insufficient; parties must demonstrate a concrete causal link between the alleged conflict and the procurement outcome. Separately, the exhibitie procedure under Article 843a Rv confirms that a mediator's disclosure obligation regarding direct or indirect interests constitutes a statutory legal relationship, giving clients a right to inspect documents relevant to assessing whether a conflict of interest compromises representation.

Practical Guidance

  • Structural separation: Implement organizational firewalls ensuring that personnel involved in conformity assessment or dispute resolution cannot receive instructions from any government body, market participant, or affiliated entity, consistent with the independence standard articulated in DSA Recital 112.

  • Individual-level conflict protocols: Maintain written conflict-of-interest declarations for every natural person involved in assessment or dispute resolution activities, requiring recusal where any direct or indirect financial or personal interest exists — the standard demanded by DSA Recital 59.

  • Transaction vetting: Before engaging contractors or transferring ownership interests involving notified body functions, conduct documented market-conformity pricing analyses to pre-empt state aid and conflict-of-interest challenges under Article 2.87(1)(e) Aw 2012.

  • Evidentiary readiness: Preserve records demonstrating the absence of any causal link between alleged financial entanglements and assessment or procurement outcomes, as the Gerechtshof Den Haag ruling places the burden squarely on the challenging party to prove such a nexus.

  • Disclosure as legal obligation: Treat conflict-of-interest disclosure not merely as best practice but as a statutory obligation creating enforceable legal relationships, giving affected parties potential inspection rights under Article 843a Rv.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 1
Art. 28(3) Notifying authorities shall be established, organised and operated in such a way that no conflict of interest arises with conformity assessment bodies… AI Act Art. 19(8) Member States shall ensure that any risk of conflict of interest concerning the designated cybersecurity experts is revealed to the other Member State… NIS2 rec 59 Recital 59 — certified out-of-court dispute settlement DSA Oct 2022
Case Law 13
¶277 That being so, it may be justified for a judge who has not recused him or herself and who is the subject of an application for recusal made by a party… Judgment of the Court (Grand Chamber) of 5 June 2023.#European Commission v Republic of Poland.#Failure of a Member State to fulfil obligations – Second subparagraph of Article 19(1) TEU – Article 47 of the Charter of Fundamental Rights of the European Union ‐ Rule of law – Effective legal protection in the fields covered by EU law – Independence of judges – Article 267 TFEU – Possibility of making a reference to the Court for a preliminary ruling – Primacy of EU law – Jurisdiction in relation t ¶149 In those circumstances, the applicant is incorrect in calling into question OLAF’s independence in suspecting the Commission of being subject to a con… Judgment of the General Court (Fourth Chamber) of 20 July 2016 (Extracts).#Athanassios Oikonomopoulos v European Commission.#Non-contractual liability — Damage caused by the Commission in the context of an OLAF investigation and by OLAF — Actions for damages — Action for a declaration that certain measures taken by OLAF were void and inadmissible for evidentiary purposes before the national authorities — Admissibility — Misuse of powers — Processing of personal data — Rights of the defence.#Case ¶11 Article 16 of Law 2/2011 stated as follows: ‘The President and the members of the board shall cease to perform their duties: (a) if they resign; (b) o… Judgment of the Court (Second Chamber) of 19 October 2016.#Xabier Ormaetxea Garai and Bernardo Lorenzo Almendros v Administración del Estado.#Request for a preliminary ruling from the Tribunal Supremo.#Reference for a preliminary ruling — Electronic communications networks and services — Directive 2002/21/EC — Article 3 — Impartiality and independence of national regulatory authorities — Institutional reform — Merger of national regulatory authority with other regulatory authorities — Dismissal ¶8 Since the Law of 1992 was silent as regards the duration or the ending of the Supervisor’s term in office, Law LIX of 1993 on the Parliamentary Commis… Judgment of the Court (Grand Chamber), 8 April 2014.#European Commission v Hungary.#Failure of a Member State to fulfil obligations — Directive 95/46/EC — Protection of individuals with regard to the processing of personal data and the free movement of such data — Article 28(1) — National supervisory authorities — Independence — National legislation prematurely bringing to an end the term served by the supervisory authority — Creation of a new supervisory authority and appointment of another per 614/10 Judgment of the Court (Grand Chamber), 16 October 2012.#European Commission v Republic of Austria.#Failure of a Member State to fulfil obligations – Directive 95/46/EC – Processing of personal data and free movement of such data – Protection of natural persons – Article 28(1) – National supervisory authority – Independence – Supervisory authority and the Federal Chancellery – Personal and organisational links.#Case C‑614/10. Court of Justice of the European Union Oct 2012 424/15 Judgment of the Court (Second Chamber) of 19 October 2016.#Xabier Ormaetxea Garai and Bernardo Lorenzo Almendros v Administración del Estado.#Request for a preliminary ruling from the Tribunal Supremo.#Reference for a preliminary ruling — Electronic communications networks and services — Directive 2002/21/EC — Article 3 — Impartiality and independence of national regulatory authorities — Institutional reform — Merger of national regulatory authority with other regulatory authorities — Dismissal Court of Justice of the European Union Oct 2016 288/12 Judgment of the Court (Grand Chamber), 8 April 2014.#European Commission v Hungary.#Failure of a Member State to fulfil obligations — Directive 95/46/EC — Protection of individuals with regard to the processing of personal data and the free movement of such data — Article 28(1) — National supervisory authorities — Independence — National legislation prematurely bringing to an end the term served by the supervisory authority — Creation of a new supervisory authority and appointment of another per Court of Justice of the European Union Apr 2014 453/21 Judgment of the Court (Sixth Chamber) of 9 February 2023.#X-FAB Dresden GmbH & Co. KG v FC.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 38(3) – Data protection officer – Prohibition on dismissing data protection officer for performing his or her tasks – Requirement for functional independence – National legislation prohibiting Court of Justice of the European Union Feb 2023 272/19 Judgment of the Court (Third Chamber) of 9 July 2020.#VQ v Land Hessen.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling — Article 267 TFEU — Concept of ‘court or tribunal’ — Protection of natural persons with regard to the processing of personal data — Regulation (EU) 2016/679 — Scope — Article 2(2)(a) — Meaning of ‘activity which falls outside the scope of Union law’ — Article 4(7) — Concept of ‘controller’ — Petitions Committee of the Court of Justice of the European Union Jul 2020 579/21 Judgment of the Court (First Chamber) of 22 June 2023.#Proceedings brought by J.M.#Request for a preliminary ruling from the Itä-Suomen hallinto-oikeus.#Reference for a preliminary ruling – Processing of personal data – Regulation (EU) 2016/679 – Articles 4 and 15 – Scope of the right of access to information referred to in Article 15 – Information contained in log data – Article 4 – Definition of ‘personal data’ – Definition of ‘recipients’ – Temporal application.#Case C-579/21. Court of Justice of the European Union Jun 2023 GDPRhub CJEU - C-288/12 - European Commission v Hungary GDPRhub Apr 2014 257/19 Judgment of the Court (Fifth Chamber) of 9 July 2020.#European Commission v Ireland.#Failure of a Member State to fulfil obligations — Principles governing the investigation of accidents in the maritime transport sector — Directive 2009/18/EC — Article 8(1) — Parties whose interests could conflict with the task entrusted to the investigative body — Members of the investigative body simultaneously performing other functions — Failure to provide for an independent investigative body.#Case C-257/19 Court of Justice of the European Union Jul 2020 534/20 Judgment of the Court (First Chamber) of 22 June 2022.#Leistritz AG v LH.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Second sentence of Article 38(3) – Data protection officer – Prohibition of the dismissal, by a controller or processor, of a data protection officer or of the imposition, by a controller or processor, of a penalty on h Court of Justice of the European Union Jun 2022 GDPRhub CJEU - C-614/10 - Commission v. Austria GDPRhub Oct 2012 Supreme Administrative Court of Finland Korkein hallinto-oikeus (Finland) - KHO:2021:125 Supreme Administrative Court of Finland Sep 2021 German Federal Administrative Court BVerwG - 6 C 1.24 German Federal Administrative Court Nov 2025 Municipal Civil Court in Zagreb OGS Zagreb - Pn-877/2023-29 Municipal Civil Court in Zagreb Jan 2026
Guidance 34
§19 In addition, a monitoring body in the EEA may subcontract its activities to an external entity outside the EEA, acting on its behalf, provided that su… Guidelines 04/2021 on Codes of Conduct as tools for transfers §28 Under i tem 5.2 of the Requirements, “ the certification body shall demonstrate to the accreditation body that it is independent in accordance with Ar… Opinion 13/2026 on the draft decision of the Office of the Data Protection Ombudsman (FI SA) regarding the approval of the requirement for accreditation of a certification body pursuant to Article 43(3) GDPR §23 With respect to section 4.2.3 of the SE SA’s accreditation requirements, the Board welcomes the explanations provided by the SE SA on how the impartia… Opinion 10/2024 on the draft decision of the competent supervisory authority of Sweden regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) §45 Regarding ‘general requirements for accreditation’, the Board recommends that the SE SA: 1) clarifies in the requirements clarify the terms “risk anal… Opinion 10/2024 on the draft decision of the competent supervisory authority of Sweden regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) 42018 on the accreditation of certification bodies under article 43 Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679) EDPB Dec 2018 12023 on the draft decision of the competent Opinion 1/2023 on the draft decision of the competent supervisory authority of Croatia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR EDPB Feb 2023 92019 on the austrian data protection supervisory Opinion 9/2019 on the Austrian data protection supervisory authority draft accreditation requirements for a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2019 032023 on the draft decision of the competent Opinion 03/2023 on the draft decision of the competent supervisory authority of Romania regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Feb 2023 142022 on the draft decision of the competent Opinion 14/2022 on the draft decision of the competent supervisory authority of Bulgaria regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2022 152022 on the draft decision of the competent Opinion 15/2022 on the draft decision of the competent supervisory authority of Luxembourg regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2022 162022 on the draft decision of the competent Opinion 16/2022 on the draft decision of the competent supervisory authority of Slovenia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2022 372021 on the draft decision of the competent Opinion 37/2021 on the draft decision of the competent supervisory authority of Malta regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Nov 2021 242021 on the draft decision of the competent Opinion 24/2021 on the draft decision of the competent supervisory authority of Slovakia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2021 232021 on the draft decision of the competent Opinion 23/2021 on the draft decision of the competent supervisory authority of Czech Republic regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2021 102021 on the draft decision of the competent Opinion 10/2021 on the draft decision of the competent supervisory authority of Hungary regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Mar 2021 312020 on the draft decision of the competent Opinion 31/2020 on the draft decision of the competent supervisory authority of Poland regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Dec 2020 192020 on the draft decision of the competent Opinion 19/2020 on the draft decision of the competent supervisory authority of Denmark regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Aug 2020 182020 on the draft decision of the competent Opinion 18/2020 on the draft decision of the competent supervisory authority of the Netherlands regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2020 132020 on the the draft decision of the competent Opinion 13/2020 on the the draft decision of the competent supervisory authority of Italy regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB May 2020 112020 on the draft decision of the competent Opinion 11/2020 on the draft decision of the competent supervisory authority of Ireland regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB May 2020 122020 on the draft decision of the competent Opinion 12/2020 on the draft decision of the competent supervisory authority of Finland regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB May 2020 112023 on the draft decision of the competent Opinion 11/2023 on the draft decision of the competent supervisory authority of Sweden regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2023 022023 on the draft decision of the competent Opinion 02/2023 on the draft decision of the competent supervisory authority of Latvia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR EDPB Feb 2023 202020 on the draft decision of the competent Opinion 20/2020 on the draft decision of the competent supervisory authority of Greece regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2020 Show 14 more →
Enforcement 16
DSB (Austria) Austrian DSB rules 360-degree feedback unlawful without specific works agreement DSB (Austria) Mar 2026 HDPA (Greece) HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens HDPA (Greece) May 2026 Austrian Data Protection Authority (dsb) Company: Lack of appointment of data protection officer Austrian Data Protection Authority (dsb) Oct 2024 APD/GBA (Belgium) Belgian DPA finds cookie banner without reject-all button and unequal withdrawal violates APD/GBA (Belgium) Oct 2024 Croatian Data Protection Authority (azop) Bedrijf: Onvoldoende juridische basis voor de verwerking van gegevens. Croatian Data Protection Authority (azop) Mar 2025 NL Estonian Data Protection Authority (AKI) Asper Biogene OÜ: Insufficient technical and organisational measures to ensure information security Estonian Data Protection Authority (AKI) Jan 2025 Croatian Data Protection Authority (azop) Company: Insufficient legal basis for data processing Croatian Data Protection Authority (azop) Mar 2025 Persónuvernd (Iceland) Persónuvernd (Iceland) - 2020061979 Persónuvernd (Iceland) Jun 2022 Croatian Data Protection Authority (azop) Hotel: Insufficient legal basis for data processing Croatian Data Protection Authority (azop) Sep 2023 Garante per la protezione dei dati personali (Italy) Garante per la protezione dei dati personali (Italy) - 9794895 Garante per la protezione dei dati personali (Italy) Jun 2022 Data Protection Authority of Berlin Clinic: Insufficient involvement of data protection officer Data Protection Authority of Berlin Jan 2021 Belgian Data Protection Authority (APD) Proximus SA: Insufficient involvement of data protection officer Belgian Data Protection Authority (APD) Apr 2020 Belgian Data Protection Authority (APD) Bank: Insufficient involvement of data protection officer Belgian Data Protection Authority (APD) Dec 2021 Data Protection Authority of Berlin Company: Insufficient involvement of data protection officer Data Protection Authority of Berlin Sep 2022 Italian Data Protection Authority (Garante) Conservatorio di Musica S. Cecilia di Roma: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Nov 2022 Italian Data Protection Authority (Garante) Policoro municipality: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Aug 2022
News 8
GDPRhub De IJslandse toezichthouder heeft geoordeeld dat er sprake is van een belangenconflict wanneer een Functionaris Gegevensbescherming (FG) tegelijkertijd ook de hoofdjurist van een bedrijf is. GDPRhub Sep 2022 NL IAPP Can the roles of DPO and whistleblowing officer be merged? IAPP Mar 2023 GDPRhub Het Italiaanse bedrijf SA heeft juridische stappen ondernomen tegen een gemeente vanwege het gebruik van haar videosurveillance systeem en omdat het haar Functionaris Gegevensbescherming (FG) heeft aangesteld om de gemeente in een rechtszaak te vertegenwoordigen. GDPRhub Sep 2022 NL IAPP Berlin DPA imposes 525K euro fine over DPO violation IAPP Sep 2022 NL EU Court Expert EU-Hof: gegevens waaruit indirect de seksuele geaardheid van een persoon kan worden afgeleid vormen gevoelige gegevens in de zin van de AVG NL EU Court Expert Aug 2022 IAPP Kunnen organisaties efficiëntieverbeteringen realiseren door de functies van Data Protection Officer (DPO) en klokkenluider te combineren? IAPP Apr 2023 NL IAPP Berlijn, DPA: Boete van 525.000 euro opgelegd vanwege schending van de DPO-regels. IAPP Sep 2022 NL White Label Consultancy Data Protection Officer or Chief Privacy Officer?The rise of the Data Protection Officer White Label Consultancy Jan 2022
Literature 5
PinG Privacy in Germany The independence requirement for national data protection supervisory authorities. PinG Privacy in Germany Apr 2019 Journal of Computer Science and Technology Studies Event-Driven Compliance: Reconciling Privacy Regulation with Real-Time Advertising Infrastructure Journal of Computer Science and Technology Studies Nov 2025 Frontiers in Education The AI Act and the future of STEM education in Europe: rethinking pedagogy, assessment, and teacher agency Frontiers in Education Jul 2026 As-Syar i Jurnal Bimbingan & Konseling Keluarga Perlindungan Hukum Data Pribadi di Era Globalisasi Digital: Studi Perbandingan General Data Protection Regulation Uni Eropa dengan Undang-Undang Perlindungan Data Pribadi Indonesia As-Syar i Jurnal Bimbingan & Konseling Keluarga Jul 2026 Journal of Ethics and Emerging Technologies The Magician’s Eye Journal of Ethics and Emerging Technologies Jul 2026