European Data Protection Seal

{{notability|date=June 2025}}

{{Short description|Data protection certification}}

The European Data Protection Seal is the official European data protection certification under the General Data Protection Regulation (GDPR).{{Cite web |title=EDPB Document on the procedure for the adoption of the EDPB opinions regarding national criteria for certification and European Data Protection Seals {{!}} European Data Protection Board |url=https://www.edpb.europa.eu/our-work-tools/our-documents/procedure/edpb-document-procedure-adoption-edpb-opinions-regarding_en |access-date=2024-11-04 |website=www.edpb.europa.eu}} According to Art. 42 GDPR, the aim of this certification is to demonstrate "compliance with the GDPR of processing operations by controllers and processors".{{Cite web |title=Art. 42 GDPR – Certification |url=https://gdpr-info.eu/art-42-gdpr/ |access-date=2024-11-03 |website=General Data Protection Regulation (GDPR) |language=en-US}} Over 70 references to certification can be found in the GDPR, encompassing various obligations, such as:

  • Adequacy of the technical and organizational measures;
  • Data sharing with data processors;
  • Data protection by design and by default;
  • International data transfers.

The adoption of the European Data Protection Seals falls under the responsibility of the European Data Protection Board (EDPB) and is recognized across all EU and EEA Member States.{{Cite web |title=EDPB document on the procedure for the approval of certification criteria by the EDPB resulting in a common certification, the European Data Protection Seal {{!}} European Data Protection Board |url=https://www.edpb.europa.eu/our-work-tools/our-documents/procedure/edpb-document-procedure-approval-certification-criteria-edpb_en |access-date=2024-11-03 |website=www.edpb.europa.eu}}

Implementation

In parallel to the adoption of the GDPR, several European research projects have been working on GDPR certification. This has led to the specification of the Europrivacy criteria that have been transferred to the European Centre for Certification and Privacy (ECCP). Europrivacy is managed by the International Board of Experts of ECCP.

In October 2022, the EDPB approved the Europrivacy criteria to serve as European Data Protection Seal under Art. 42 GDPR.{{Cite web |title=Europrivacy {{!}} European Data Protection Board |url=https://www.edpb.europa.eu/our-work-tools/accountability-tools/certification-mechanisms-seals-and-marks/europrivacy_en |access-date=2024-11-03 |website=www.edpb.europa.eu}} In 2024, Europrivacy was validated by the European Accreditation for accreditation under Art. 43 GDPR. Since then, several Certification Bodies have been accredited and the first European Data Protection Seals have been delivered.{{Cite web |title=Register of certification mechanisms, seals and marks {{!}} European Data Protection Board |url=https://www.edpb.europa.eu/our-work-tools/accountability-tools/certification-mechanisms-seals-and-marks_en |access-date=2024-11-03 |website=www.edpb.europa.eu}}

References