# Notified Body Responsibilities and Operational Obligations — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/notified-body-responsibilities-obligations
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed to capture the specific operational obligations, responsibilities, and procedural requirements that notified bodies must fulfill when conducting conformity assessments and maintaining their designation.

## Overview

## Legal Framework

Recital 173 of the AI Act establishes the Commission's delegated authority to amend conformity assessment procedures, technical documentation requirements, and the EU declaration of conformity content. This delegation power under Article 290 TFEU ensures the regulatory framework can adapt as AI technologies evolve. Notified bodies operating under this framework must conduct conformity assessments for high-risk AI systems, verifying that providers have met the substantive requirements set out in the Act's core provisions. Their designation depends on maintaining technical competence, impartiality, and operational independence. Notified bodies must assess quality management systems, review technical documentation, and issue EU-type examination certificates where applicable. They are also obligated to suspend or withdraw certificates where compliance is no longer assured. The Commission's power to modify the conditions under which an AI system is classified as high-risk directly affects the scope of notified body involvement, meaning these entities must monitor regulatory amendments continuously.

## Key Developments

The Croatian DPA's enforcement action against a company publishing personal data of sole traders (fine of €40,000) underscores the broader regulatory environment in which notified bodies operate — where data protection failures carry concrete financial consequences. While this decision arose under GDPR rather than the AI Act, it signals the enforcement appetite that supervisory authorities will bring to AI-adjacent compliance failures. The EDPB's guidance on accreditation of certification bodies provides a structural parallel: accreditation standards demand rigorous independence and competence assessments, and notified bodies under the AI Act face analogous scrutiny. The Polish DPA's ongoing activity (UODO, DKN.5131.4.2025, February 2026) indicates continued national-level enforcement pressure on data governance practices that overlap with AI system compliance.

## Practical Guidance

- Maintain documented evidence of technical competence for each AI domain in which conformity assessments are performed, updating qualifications as the Commission exercises its delegated powers to modify high-risk classifications under Recital 173.
- Establish internal procedures to monitor delegated acts and implementing acts issued under Article 290 TFEU, ensuring assessment protocols are revised within defined timelines after any amendment to conformity assessment procedures or technical documentation requirements.
- Implement conflict-of-interest controls that prevent any commercial relationship with AI providers from compromising impartiality, with documented reviews at regular intervals.
- Develop a certificate lifecycle management system covering issuance, suspension, withdrawal, and notification to the notifying authority and market surveillance authorities when non-compliance is identified.
- Conduct periodic internal audits of quality management system assessments to verify that providers' post-certification modifications to high-risk AI systems trigger reassessment where required.

## Legislation (full text of key provisions)

### Recital 173 — Commission delegated powers to adapt AI rules

*Source: AI Act, aiact-rec-173-en, 2024-06-12 — https://overview.legal/posts/94028*

In order to ensure that the regulatory framework can be adapted where necessary, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission to amend the conditions under which an AI system is not to be considered to be high-risk, the list of high-risk AI systems, the provisions regarding technical documentation, the content of the EU declaration of conformity the provisions regarding the conformity assessment procedures, the provisions establishing the high-risk AI systems to which the conformity assessment procedure based on assessment of the quality management system and assessment of the technical documentation should apply, the threshold, benchmarks and indicators, including by supplementing those benchmarks and indicators, in the rules for the classification of general-purpose AI models with systemic risk, the criteria for the designation of general-purpose AI models with systemic risk, the technical documentation for providers of general-purpose AI models and the transparency information for providers of general-purpose AI models. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making (55). In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.

## Guidance

### Guidelines 04/2021 on Codes of Conduct as tools for transfers

*Source: EDPB, edpb-guidelines-on-codes-of-conduct-as-tools-for-transfers, 2022-02-22 — https://overview.legal/posts/38133 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042021-on-codes-of-conduct-as-tools-for-transfers_en*

The  GDPR  requires  in  its  Article  46  that  controllers/processors shall  put  in  place  appropriate safeguards for transfers of personal data to third countries or international organisations. To that end, the GDPR diversifies the appropriate safeguards that may be used by organisations under Article 46 for  framing transfers  to third countries  by  introducing  amongst  others, codes  of  conduct  as a new transfer  mechanism  (articles  40-3  and  46-2-e).  In  this  respect, as  provi...

### Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020

*Source: EDPB, edpb-guidelines-on-data-protection-by-design-and-by-default, 2020-10-20 — https://overview.legal/posts/38054 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en*

The European Data Protection Board (EDPB) adopted these guidelines (Version 2.0) to provide interpretive guidance on Article 25 of the GDPR, which mandates data protection by design and by default. The guidelines address controllers' obligations to implement appropriate technical and organizational measures and necessary safeguards into processing operations, including the dimensions of data minimization required by default. No fines or enforcement actions are at issue, as this is a guidance document intended to assist controllers in complying with their Article 25 obligations.

### Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)

*Source: EDPB, edpb-guidelines-on-the-territorial-scope-of-the-gdpr, 2019-11-12 — https://overview.legal/posts/38074 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-32018-on-the-territorial-scope-of-the-gdpr-article-3-version-adopted_en*

The European Data Protection Board (EDPB) issued Guidelines 3/2018 to clarify the territorial scope of the GDPR under Article 3, addressing the "establishment" criterion in Article 3(1), the "targeting" criterion in Article 3(2), and the representative requirements under Article 27. The guidelines emphasize that Article 3 applies to specific processing activities rather than to legal entities as a whole, meaning a single controller or processor may have some processing activities subject to the GDPR and others not. The EDPB adopted Version 2.0 on 12 November 2019 following public consultation, providing detailed interpretation to ensure consistent application by data protection authorities across the EU.

### Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-codes-of-conduct-and-monitoring-bodies, 2019-06-04 — https://overview.legal/posts/38051 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-12019-on-codes-of-conduct-and-monitoring-bodies-under-regulation_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the framework for codes of conduct and monitoring bodies under Articles 40 and 41 of the GDPR. The guidelines address the admissibility, content, and approval requirements for draft codes of conduct, as well as the criteria and accreditation process for monitoring bodies responsible for verifying compliance with such codes. This version (2.0) was adopted on 4 June 2019 following public consultation.

### Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679)

*Source: EDPB, guidelines-42018-on-the-accreditation-of-certification-bodies-under-article-43-en, 2018-12-14 — https://overview.legal/posts/126260 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42018-on-the-accreditation-of-certification-bodies-under-article-43_en*

Adopted Guidelines 4 / 2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679) Version 3.0 4 June 2019 A dopted 2 Version history Version 3.0 4 June 2019 Inclusion of Annex 1 (version 2.0 of Annex 1 adopted on 4 June 2019 after public consultation) Version 2.0 4 December 2018 Adoption of the Guidelines after public consultation - On the same date Annex 1 (version 1.0) was adopted for public consultation Version 1.0 6 February 2018…

## Enforcement decisions

### Company: Insufficient legal basis for data processing

*Source: Croatian Data Protection Authority (azop), 2025-03-24 — https://overview.legal/posts/48719 — original: https://www.enforcementtracker.com/ETid-2604*

The Croatian DPA (AZOP) has imposed a fine of EUR 40,000 on a company that published personal data of sole traders on its website. The data originated from public sources and from the financial agency FINA. Although publicly accessible, the authority found that there was no valid legal basis for the publication. Furthermore, the company did not inform the data subjects about the processing of their data and did not properly document its processing activities. Another point of concern was that th

### Bedrijf: Onvoldoende juridische basis voor de verwerking van gegevens.

*Source: Croatian Data Protection Authority (azop), 2025-03-24 — https://overview.legal/posts/52346*

De Kroatische gegevensbeschermingsautoriteit (AZOP) heeft een bedrijf een boete van 40.000 euro opgelegd omdat het persoonlijke gegevens van zelfstandigen op zijn website heeft gepubliceerd. De gegevens waren afkomstig van openbare bronnen en van het financiële agentschap FINA. Hoewel de gegevens openbaar toegankelijk waren, oordeelde de autoriteit dat er geen geldige juridische basis was voor de publicatie. Bovendien heeft het bedrijf de betrokkenen niet geïnformeerd over de verwerking van hun gegevens en heeft het zijn verwerkingsactiviteiten niet correct gedocumenteerd. Een ander punt van zorg was dat...

### Asper Biogene OÜ: Insufficient technical and organisational measures to ensure information security

*Source: Estonian Data Protection Authority (AKI), 2025-01-10 — https://overview.legal/posts/48709 — original: https://www.enforcementtracker.com/ETid-2594*

The Estonian DPA imposed a fine of EUR 85,000 on Asper Biogene OÜ. Asper Biogene OÜ suffered a data leak due to a lack of adequate security measures. The leak affected approximately 100,000 files containing personal, health and genetic data. Asper Biogene OÜ also appointed a member of the board of directors as DPO, resulting in a conflict of interest. A fine of EUR 80,000 was imposed for the inadequate security measures. The unlawful appointment of the DPO was fined EUR 5,000. ---UPDATE--- The T

### Company: Lack of appointment of data protection officer

*Source: Austrian Data Protection Authority (dsb), 2024-10-16 — https://overview.legal/posts/48888 — original: https://www.enforcementtracker.com/ETid-2773*

The Austrian DPA has imposed a fine on a company. The controller appointed a DPO who had a conflict of interest, meaning the person was not suitable for the role.

### Hotel: Insufficient legal basis for data processing

*Source: Croatian Data Protection Authority (azop), 2023-09-26 — https://overview.legal/posts/48175 — original: https://www.enforcementtracker.com/ETid-2060*

The Croatian DPA (AZOP) has imposed of fine of EUR 15,000 to a hotel. The hotel was collecting personal data from guests in excess of what would have been necessary for the purpose of booking a hotel room and without a valid legal basis. Specifically, the hotel collected the CVC number of guests' credit cards and copies of their identification documents. The hotel also failed to provide clear and transparent information to guests on the collection and use of their data. The hotel claimed it coll

### Company: Insufficient involvement of data protection officer

*Source: Data Protection Authority of Berlin, 2022-09-20 — https://overview.legal/posts/47513 — original: https://www.enforcementtracker.com/ETid-1398*

The DPA of Berlin has imposed a fine of EUR 525,000 on the subsidiary of a Berlin-based e-commerce group. The company had appointed a data protection officer, who however was also the managing director of two service companies that processed personal data on behalf of the very same company for which they acted as data protection officer. These service companies are also part of the group to which the e-commerce company belongs. The DPA considered this to be a conflict of interest and found a vio

### Policoro municipality: Non-compliance with general data processing principles

*Source: Italian Data Protection Authority (Garante), 2022-08-01 — https://overview.legal/posts/47441 — original: https://www.enforcementtracker.com/ETid-1326*

The Italian DPA has imposed a fine of EUR 26,000 on Policoro municipality. The municipality had installed a video surveillance system without, however, providing sufficient information about the surveillance. In addition, the DPA found that the municipality had not established a retention period for the video surveillance recordings and kept them for an excessive period of time. In addition, the DPA found that the municipality had not fulfilled its obligations in appointing a data protection off

### Persónuvernd (Iceland) - 2020061979

*Source: Persónuvernd (Iceland), 2022-06-29 — https://overview.legal/posts/6316 — original: https://gdprhub.eu/index.php?title=Persónuvernd_(Iceland)_-_2020061979*

Facts — The Icelandic DPA started an investigation into a genetic research company. More specifically, to assess the company's Data Protection Officer (DPO), as well as the performance of the DPO's tasks. The DPA requested information from the company to determine if and how the company's DPO was compatible with Article 38 GDPR. The DPA stated that the decision to investigate the DPO was made with the intention of ensuring compliance, not because it assumed the requirements of the GDPR were not being followed. The DPA wrote two letters, but the company did not respond to any of them within the prescribed deadlines. After a phone call, the DPA received a response almost two months after the first letter had been sent. Holding — After reviewing the responses from the controller, the Icelandic DPA concluded that there were no violations in relation to the obligations to appoint a DPO (Article 37), to involve the DPO in relevant matters (Article 38(1)), and to provide the DPO with the necessary resources (Article 38(2)). However, the DPA held that the controller violated the obligation to ensure the DPO's independence pursuant to Article 38(3). The acting DPO at the time of the investigation also held the position of deputy CEO, senior lawyer and board member. The DPA held that that could lead to a conflict of interest. The current DPO also held the position of senior lawyer. The DPA held that this also constituted a conflict of interest. The DPA instructed the controller to ensure that the acting DPO would not be responsible for other tasks and duties that may lead to a conflict of interest. The DPA further noted that the despite the delayed answers, it would not impose a fine, taking into account the fact that the information was eventually received as well as the COVID-19 outbreak.

## Recent developments

### Can the roles of DPO and whistleblowing officer be merged?

*Source: IAPP, 2023-03-28 — https://overview.legal/posts/6228 — original: https://iapp.org/news/a/can-be-the-role-of-data-protection-officer-and-whistleblowing-officer-merged-in-one-person#entry-4228*

> 
																						Personal data protection and whistleblowing are two different topics — different regulations with different purposes, scope and requirements. But, in fact, they are closer than they seem, especially for practical reasons.
Both data protection governance and whistleblowing systems are often exercised by the same unit —  the compliance department — or even by the same person. This solution offers several advantages, but also some problematic points that need to be highligh

### De IJslandse toezichthouder heeft geoordeeld dat er sprake is van een belangenconflict wanneer een Functionaris Gegevensbescherming (FG) tegelijkertijd ook de hoofdjurist van een bedrijf is.

*Source: GDPRhub, 2022-09-28 — https://overview.legal/posts/51805*

De IJslandse Autoriteit Persoonsgegevens (SA) heeft vastgesteld dat er sprake is van een belangenconflict wanneer een Functionaris Gegevensbescherming (FG) tegelijkertijd ook de senior jurist, plaatsvervangend CEO of bestuurslid van een bedrijf is. Een FG kan echter wel de functie van compliance officer bekleden.

### Het Italiaanse bedrijf SA heeft juridische stappen ondernomen tegen een gemeente vanwege het gebruik van haar videosurveillance systeem en omdat het haar Functionaris Gegevensbescherming (FG) heeft aangesteld om de gemeente in een rechtszaak te vertegenwoordigen.

*Source: GDPRhub, 2022-09-28 — https://overview.legal/posts/51807*

Tenslotte oordeelde de gegevensbeschermingsautoriteit dat de verantwoordelijke, door de functionaris gegevensbescherming (FG) te betrekken bij de verdediging in rechtszaken, de FG in een positie van belangenconflict bracht, in strijd met artikel 38(6) van de AVG. Dit was met name omdat dit ertoe leidde dat de betrokkene het gevoel had niet in staat te zijn om contact op te nemen met de FG met betrekking tot kwesties die verband houden met de verwerking van hun persoonlijke gegevens en de uitoefening van hun rechten zoals uiteengezet in artikel 38(4) van de AVG.

### Berlijn, DPA: Boete van 525.000 euro opgelegd vanwege schending van de DPO-regels.

*Source: IAPP, 2022-09-22 — https://overview.legal/posts/51816*

De Berlijnse Commissaris voor Gegevensbescherming en Vrijheid van Informatie heeft een boete van 525.000 euro opgelegd aan een detailhandelaar gevestigd in Berlijn wegens schending van de eisen met betrekking tot de functionaris gegevensbescherming (FG) zoals vastgelegd in de [AVG]. Een onderzoek wees op een vermeend belangenconflict met betrekking tot de arbeidsstatus en de beslissingsbevoegdheden van de FG, wat in strijd is met artikel 38(6) van de AVG. Het bedrijf ontving in 2021 een waarschuwing van de toezichthouder.

### Berlin DPA imposes 525K euro fine over DPO violation

*Source: IAPP, 2022-09-22 — https://overview.legal/posts/6275 — original: https://iapp.org/news/a/berlin-dpa-imposes-525k-fine-over-dpo-violation#entry-482*

> The Berlin Commissioner for Data Protection and Freedom of Information issued a 525,000 euro fine to a Berlin-based retailer for violation of data protection officer requirements under the \[GDPR]. An investigation found an alleged conflict of interest concerning the DPO's employment status and decision-making responsibilities that violated Article 38(6) of the GDPR. The company received a warning from the regulator in 2021.

## Literature

### Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects

*Source: Law and Economy, 2026-02-25 — https://overview.legal/posts/132619 — original: https://doi.org/10.63593/le.2788-7049.2026.03.004*

The Italian Artificial Intelligence Act, enacted on September 17, 2025, represents the first comprehensive national implementation of the European Union’s AI Act. This study examines the Italian legislation through the theoretical lens of multi-level governance, analyzing its dual function as both a “bridging legislation” that translates EU framework into domestic practice and a site of significant regulatory innovation. Through detailed textual analysis and case studies, particularly in healthc

## Related topics

- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Scientific Panel Independence** — https://overview.legal/topics/scientific-panel-independence-impartiality
  A specific topic is needed to address the independence and impartiality requirements that are critical for scientific panels to maintain credibility and objecti
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Notified Body Independence** — https://overview.legal/topics/notified-body-independence-impartiality
  Notified bodies must maintain strict independence and impartiality standards, which are critical operational obligations that warrant a dedicated topic for deta

---
Generated by overview.legal · https://overview.legal/topics/notified-body-responsibilities-obligations · 2026-08-22
