HomeInsightsInformation Commissioner’s Office publishes guidance for organisations wanting to develop GDPR Codes of Conduct or Certification schemes

Contact

From 28 February 2020 organisations can submit their proposals for GDPR Codes of Conduct or Certification scheme criteria to the ICO for approval.

The ICO says that these two services will be an asset to businesses, helping both data controllers and processors demonstrate compliance with the GDPR.

The ICO explains that accountability is an important data protection principle and means organisations must be able to demonstrate their compliance with the GDPR. Codes of Conduct and Certification schemes are both important voluntary accountability tools.

Codes of Conduct, provisions for which are set out in the GDPR, help organisations such as trade, membership or professional bodies to support compliance with data protection issues identified or specific to their sector. Organisations will be able to sign up to an ICO approved Code of conduct to demonstrate their compliance with data protection legislation.

Certification is a separate provision under the GDPR. It will give businesses a tool that they can use to enhance trust in their business and demonstrate their commitment to compliance to their customers.

Scheme criteria can now be submitted for ICO approval. Controllers and processors will then be able to apply to have their personal data processing certified under the relevant scheme. To read the ICO’s press release in full and for a link to the guidance, click here.

Expertise