Standards Publication
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal โ legal information, not advice.The content discusses how harmonised standards are published and enter into force, which is a distinct procedural topic that deserves dedicated coverage separate from general standards adoption.
Overview
6 sources ยท Jul 23, 2026Legal Framework
The publication and entry into force of harmonised standards in the EU data protection context is governed primarily by Regulation (EU) No 1025/2012 on European standardisation, read in conjunction with Article 42 and Article 43 GDPR. Under Regulation 1025/2012, the European Commission may issue standardisation requests to European Standardisation Organisations (ESOs) โ namely CEN, CENELEC, and ETSI โ to develop harmonised standards supporting specific EU legislation. Once a standard is adopted by an ESO, it must be published in the Official Journal of the European Union to acquire presumptive legal effect. Article 42(1) GDPR explicitly contemplates data protection certification mechanisms and seals, while Article 42(2) references the possibility of certification issued under Article 43 by accredited certification bodies. The rationale is to provide organisations with a tangible, auditable benchmark demonstrating GDPR compliance, while preserving the GDPR's direct applicability and the primacy of the supervisory authorities' interpretive role.
Key Developments
The European Commission's 2021 standardisation request (M/571) tasked CEN and CENELEC with developing harmonised standards for data protection management, culminating in the EN 12795 series. These standards were published in the Official Journal, triggering their presumptive compliance value under the New Legislative Framework. However, the EDPB has consistently emphasised โ including in its Guidelines 07/2020 on controller and processor concepts โ that adherence to standards does not relieve controllers of their accountability obligations under Article 5(2) GDPR. The Court of Justice of the European Union in Schrems II (C-311/18) reinforced that certification schemes and adequacy mechanisms cannot substitute for substantive adequacy assessments of third-country data protection levels. This establishes a clear boundary: harmonised standards provide operational guidance but do not alter the legal obligations set by the GDPR itself.
Practical Guidance
- Track Official Journal publications: Monitor the European Commission's publication of harmonised standard references in the OJ, as only standards listed there carry presumptive compliance value โ internal adoption of draft or unpublished standards provides no legal benefit.
- Distinguish certification from standardisation: Article 42 GDPR certification and adherence to harmonised standards are separate mechanisms; pursuing EN-standard alignment does not constitute formal certification and offers no binding safe harbour.
- Maintain accountability documentation: Even when implementing harmonised standards, document under Article 5(2) GDPR how the standard's technical measures map to each applicable GDPR obligation, particularly lawful basis, data minimisation, and security under Article 32.
- Verify scope alignment: Confirm that a published standard's scope actually covers your processing activities โ partial applicability does not extend presumptive compliance to uncovered operations.
- Monitor withdrawal and revision notices: Standards referenced in the OJ can be withdrawn or superseded; reliance on a withdrawn standard eliminates any compliance presumption and must trigger immediate reassessment.