Skip to content
Topic Actively litigated

Notified Body Responsibilities and Operational Obligations

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This new topic is needed to capture the specific operational obligations, responsibilities, and procedural requirements that notified bodies must fulfill when conducting conformity assessments and maintaining their designation.

30 linked items 1 Laws5 Guidance14 Enforcement9 News1 Literature

Overview

13 sources · Jul 23, 2026

Legal Framework

Recital 173 of the AI Act establishes the Commission's delegated authority to amend conformity assessment procedures, technical documentation requirements, and the EU declaration of conformity content. This delegation power under Article 290 TFEU ensures the regulatory framework can adapt as AI technologies evolve. Notified bodies operating under this framework must conduct conformity assessments for high-risk AI systems, verifying that providers have met the substantive requirements set out in the Act's core provisions. Their designation depends on maintaining technical competence, impartiality, and operational independence. Notified bodies must assess quality management systems, review technical documentation, and issue EU-type examination certificates where applicable. They are also obligated to suspend or withdraw certificates where compliance is no longer assured. The Commission's power to modify the conditions under which an AI system is classified as high-risk directly affects the scope of notified body involvement, meaning these entities must monitor regulatory amendments continuously.

Key Developments

The Croatian DPA's enforcement action against a company publishing personal data of sole traders (fine of €40,000) underscores the broader regulatory environment in which notified bodies operate — where data protection failures carry concrete financial consequences. While this decision arose under GDPR rather than the AI Act, it signals the enforcement appetite that supervisory authorities will bring to AI-adjacent compliance failures. The EDPB's guidance on accreditation of certification bodies provides a structural parallel: accreditation standards demand rigorous independence and competence assessments, and notified bodies under the AI Act face analogous scrutiny. The Polish DPA's ongoing activity (UODO, DKN.5131.4.2025, February 2026) indicates continued national-level enforcement pressure on data governance practices that overlap with AI system compliance.

Practical Guidance

  • Maintain documented evidence of technical competence for each AI domain in which conformity assessments are performed, updating qualifications as the Commission exercises its delegated powers to modify high-risk classifications under Recital 173.
  • Establish internal procedures to monitor delegated acts and implementing acts issued under Article 290 TFEU, ensuring assessment protocols are revised within defined timelines after any amendment to conformity assessment procedures or technical documentation requirements.
  • Implement conflict-of-interest controls that prevent any commercial relationship with AI providers from compromising impartiality, with documented reviews at regular intervals.
  • Develop a certificate lifecycle management system covering issuance, suspension, withdrawal, and notification to the notifying authority and market surveillance authorities when non-compliance is identified.
  • Conduct periodic internal audits of quality management system assessments to verify that providers' post-certification modifications to high-risk AI systems trigger reassessment where required.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 1
Art. 3(21) ‘conformity assessment body’ means a body that performs third-party conformity assessment activities, including testing, certification and inspection;… AI Act Art. 17(1)(a) a strategy for regulatory compliance, including compliance with conformity assessment procedures and procedures for the management of modifications to… AI Act Art. 29(2) The application for notification shall be accompanied by a description of the conformity assessment activities, the conformity assessment module or mo… AI Act Art. 30(3) The notification referred to in paragraph 2 of this Article shall include full details of the conformity assessment activities, the conformity assessm… AI Act rec 173 Recital 173 — Commission delegated powers to adapt AI rules AI Act Jun 2024
Guidance 5
guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 guidelines on the territorial scope of the gdpr Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) EDPB Nov 2019 guidelines on codes of conduct and monitoring bodies Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679 EDPB Jun 2019 42018 on the accreditation of certification bodies under article 43 Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679) EDPB Dec 2018
Enforcement 14
Croatian Data Protection Authority (azop) Bedrijf: Onvoldoende juridische basis voor de verwerking van gegevens. Croatian Data Protection Authority (azop) Mar 2025 NL Croatian Data Protection Authority (azop) Company: Insufficient legal basis for data processing Croatian Data Protection Authority (azop) Mar 2025 Estonian Data Protection Authority (AKI) Asper Biogene OÜ: Insufficient technical and organisational measures to ensure information security Estonian Data Protection Authority (AKI) Jan 2025 Austrian Data Protection Authority (dsb) Company: Lack of appointment of data protection officer Austrian Data Protection Authority (dsb) Oct 2024 Croatian Data Protection Authority (azop) Hotel: Insufficient legal basis for data processing Croatian Data Protection Authority (azop) Sep 2023 Italian Data Protection Authority (Garante) Conservatorio di Musica S. Cecilia di Roma: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Nov 2022 Data Protection Authority of Berlin Company: Insufficient involvement of data protection officer Data Protection Authority of Berlin Sep 2022 Italian Data Protection Authority (Garante) Policoro municipality: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Aug 2022 Persónuvernd (Iceland) Persónuvernd (Iceland) - 2020061979 Persónuvernd (Iceland) Jun 2022 Garante per la protezione dei dati personali (Italy) Garante per la protezione dei dati personali (Italy) - 9794895 Garante per la protezione dei dati personali (Italy) Jun 2022 Belgian Data Protection Authority (APD) Bank: Insufficient involvement of data protection officer Belgian Data Protection Authority (APD) Dec 2021 Data Protection Authority of Berlin Clinic: Insufficient involvement of data protection officer Data Protection Authority of Berlin Jan 2021 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) SC Cntar Tarom SA: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Jul 2020 Belgian Data Protection Authority (APD) Proximus SA: Insufficient involvement of data protection officer Belgian Data Protection Authority (APD) Apr 2020
News 9
Legislation Decision to amend the "Decision on Notification Procedures and Data Processing in the Shipping Sector" in connection with the implementation of the Maritime National Single Window. Legislation Sep 2025 IAPP Can the roles of DPO and whistleblowing officer be merged? IAPP Mar 2023 GDPRhub De IJslandse toezichthouder heeft geoordeeld dat er sprake is van een belangenconflict wanneer een Functionaris Gegevensbescherming (FG) tegelijkertijd ook de hoofdjurist van een bedrijf is. GDPRhub Sep 2022 NL GDPRhub Het Italiaanse bedrijf SA heeft juridische stappen ondernomen tegen een gemeente vanwege het gebruik van haar videosurveillance systeem en omdat het haar Functionaris Gegevensbescherming (FG) heeft aangesteld om de gemeente in een rechtszaak te vertegenwoordigen. GDPRhub Sep 2022 NL IAPP Berlijn, DPA: Boete van 525.000 euro opgelegd vanwege schending van de DPO-regels. IAPP Sep 2022 NL IAPP Berlin DPA imposes 525K euro fine over DPO violation IAPP Sep 2022 NL EU Court Expert EU-Hof: gegevens waaruit indirect de seksuele geaardheid van een persoon kan worden afgeleid vormen gevoelige gegevens in de zin van de AVG NL EU Court Expert Aug 2022 White Label Consultancy Data Protection Officer or Chief Privacy Officer?The rise of the Data Protection Officer White Label Consultancy Jan 2022 IAPP Kunnen organisaties efficiëntieverbeteringen realiseren door de functies van Data Protection Officer (DPO) en klokkenluider te combineren? IAPP Apr 2023 NL
Literature 1
Law and Economy Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects Law and Economy Feb 2026