What GDPR tells about certification. Issue 38 (September 2020)
- Record Type:
- Journal Article
- Title:
- What GDPR tells about certification. Issue 38 (September 2020)
- Main Title:
- What GDPR tells about certification
- Authors:
- Lachaud, Eric
- Abstract:
- Abstract: The EU lawmaker has introduced several certification models in the GDPR. A first model entitles accredited private certification bodies to design and manage certification schemes under the close monitoring of the supervisory authorities. Another model gives to the supervisory authorities the opportunity to design and manage their own schemes. The EU lawmaker has also left the door open to the establishment of schemes at the margin of the data protection framework. Nothing in the GDPR prohibits to create certification schemes outside Articles 42/43 regime. The diversity of arrangements shows that certification is a flexible system capable of adapting to many different situations and environments. This is also a free market that proves to be difficult, if not impossible, to entirely monitor. These basic features challenge the attempt of the EU lawmaker to monitor the design and management of certification schemes in the GDPR. The GDPR also tells that the definition of certification suggested by the European Data Protection Board does not fully map this notion as designed in the GDPR. The data protection regulation offers a much more detailed picture of certification than the one proposed by the European Data Protection Board. The GDPR shows that the nature of certification is driven by the context in which this instrument is used. The analysis of the monitoring process of the codes of conduct set in Article 41 GDPR contributes, by contrast, to clarify the very natureAbstract: The EU lawmaker has introduced several certification models in the GDPR. A first model entitles accredited private certification bodies to design and manage certification schemes under the close monitoring of the supervisory authorities. Another model gives to the supervisory authorities the opportunity to design and manage their own schemes. The EU lawmaker has also left the door open to the establishment of schemes at the margin of the data protection framework. Nothing in the GDPR prohibits to create certification schemes outside Articles 42/43 regime. The diversity of arrangements shows that certification is a flexible system capable of adapting to many different situations and environments. This is also a free market that proves to be difficult, if not impossible, to entirely monitor. These basic features challenge the attempt of the EU lawmaker to monitor the design and management of certification schemes in the GDPR. The GDPR also tells that the definition of certification suggested by the European Data Protection Board does not fully map this notion as designed in the GDPR. The data protection regulation offers a much more detailed picture of certification than the one proposed by the European Data Protection Board. The GDPR shows that the nature of certification is driven by the context in which this instrument is used. The analysis of the monitoring process of the codes of conduct set in Article 41 GDPR contributes, by contrast, to clarify the very nature certification. It shows that this is neither the attestation of conformity nor the conformity assessment that best defines certification. … (more)
- Is Part Of:
- Computer law & security review. Issue 38(2020)
- Journal:
- Computer law & security review
- Issue:
- Issue 38(2020)
- Issue Display:
- Volume 38, Issue 38 (2020)
- Year:
- 2020
- Volume:
- 38
- Issue:
- 38
- Issue Sort Value:
- 2020-0038-0038-0000
- Page Start:
- Page End:
- Publication Date:
- 2020-09
- Subjects:
- Certification -- Code of conduct -- GDPR -- Article 42 -- Self-regulation -- Co-regulation
Computers -- Law and legislation -- Periodicals
Computer security -- Law and legislation -- Periodicals
Electronic commerce -- Law and legislation -- Periodicals
Data protection -- Law and legislation -- Periodicals
Computer security -- Law and legislation
Computers -- Law and legislation
Data protection -- Law and legislation
Electronic commerce -- Law and legislation
Periodicals
343.0999 - Journal URLs:
- http://www.elsevier.com/journals ↗
- DOI:
- 10.1016/j.clsr.2020.105457 ↗
- Languages:
- English
- ISSNs:
- 2212-473X
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 14020.xml