Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: EN
- General data protection
Basic legislative acts
- GDPR regulation
Article 41 Monitoring of approved codes of conduct
Summary What does Article 41 of the GDPR regulation say?
This article sits directly beneath Article 40, which establishes the framework for codes of conduct, and deals with how compliance with those codes is monitored in practice.
It introduces the possibility of delegating day-to-day compliance monitoring to an accredited third-party body, rather than leaving it solely to the supervisory authority.
The article sets out the conditions such a body must meet to gain accreditation, the enforcement actions it can take against non-compliant controllers or processors, and the circumstances under which its accreditation can be revoked.
Public authorities and bodies are explicitly excluded from the scope of this article.
Important points:
- Accredited monitoring bodies must demonstrate independence, expertise, complaint-handling procedures, and the absence of conflicts of interest to the satisfaction of the competent supervisory authority.
- Accredited monitoring bodies are required to take action against controllers or processors that infringe the code, including suspension or exclusion, and must inform the competent supervisory authority of any such actions taken.
- The competent supervisory authority shall revoke a body's accreditation if the accreditation requirements are no longer met or if the body's actions infringe the Regulation.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58, the monitoring of compliance with a code of conduct pursuant to Article 40 may be carried out by a body which has an appropriate level of expertise in relation to the subject-matter of the code and is accredited for that purpose by the competent supervisory authority.
A body as referred to in paragraph 1 may be accredited to monitor compliance with a code of conduct where that body has:
demonstrated its independence and expertise in relation to the subject-matter of the code to the satisfaction of the competent supervisory authority;
established procedures which allow it to assess the eligibility of controllers and processors concerned to apply the code, to monitor their compliance with its provisions and to periodically review its operation;
established procedures and structures to handle complaints about infringements of the code or the manner in which the code has been, or is being, implemented by a controller or processor, and to make those procedures and structures transparent to data subjects and the public; and
demonstrated to the satisfaction of the competent supervisory authority that its tasks and duties do not result in a conflict of interests.
- ▼C1ModificationCorrectedParagraph 3 corrected by a corrigendum to Regulation (EU) 2016/679. Published in the Official Journal 23 May 2018.
The competent supervisory authority shall submit the draft requirements for accreditation of a body as referred to in paragraph 1 of this Article to the Board pursuant to the consistency mechanism referred to in Article 63.
Without prejudice to the tasks and powers of the competent supervisory authority and the provisions of Chapter VIII, a body as referred to in paragraph 1 of this Article shall, subject to appropriate safeguards, take appropriate action in cases of infringement of the code by a controller or processor, including suspension or exclusion of the controller or processor concerned from the code. It shall inform the competent supervisory authority of such actions and the reasons for taking them.
- ▼C1ModificationCorrectedParagraph 5 corrected by a corrigendum to Regulation (EU) 2016/679. Published in the Official Journal 23 May 2018.
The competent supervisory authority shall revoke the accreditation of a body as referred to in paragraph 1 if the requirements for accreditation are not, or are no longer, met or where actions taken by the body infringe this Regulation.
This Article shall not apply to processing carried out by public authorities and bodies.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
processing
Definition
controller
Definition
processor
Definition
supervisory authority
Definition
personal data