ICO updates its GDPR certification guidance

Share This Post

The Information Commissioner’s Office has updated its guidance regarding certification schemes under GDPR.

Section 5 of the GDPR sets out approaches towards codes of conduct and certification, with Article 42 specifically addressing certification. Simply put the regulation suggests the implementation of data protection certification schemes to provide a way for data controllers and processors to demonstrate their compliance. It also allows “data subjects” to recognise organisations that apply appropriate levels of data protection compliance (by looking for a certification badge).

There currently are no approved certification schemes available, but once the EDPB (European Data Protection Board) have finished their current consultation on accreditation and certification guidelines, the ICO plan on submitting the UK’s own requirements to the EDPB for comment. The EDPB’s guidelines are due in the Summer with the likelihood of a UK scheme in place around autumn, although everything is dependent on how the EDPB get on with finalising their guidelines and approving the ICO’s approach.

The ICO though are calling for contact from any organisations currently developing or have developed a GDPR related certification scheme.

More detailed guidance is available for Hub subscribers, here.

More To Explore


The key message from the ICO regarding the use of AI is not to forget if AI is processing personal data, then you need to

Read More »

Eat. Sleep. GDPR. Repeat.

We live and breathe GDPR and ePrivacy compliance, so you don’t have too. Our GDPR UNLIMITED helpline is all about offering you help and support, whenever you need it most. As well as the unlimited helpline, you get up to 4 hours “hands-on” help each month, which we can configure to help you in anyway you need such as a GDPR review, or acting as your DPO.

As well as the unlimited helpline and hands-on help you get GDPR and privacy updates, access to our GDPR knowledge centre and webinars.

Unlimited email & phone support

Unlimited email and phone support. Email or organise a voice call as often as you need each month.​

Up to 4 hours "hands-on" help per month

We use these "hands-on" hours to do the GDPR work for you, such as reviews, acting as your DPO, checking DPIA, dealing with breaches, training your staff, etc. (Additional hours: £100+VAT per hour)

Online resources

Our Knowledge Centre gives you access to information, guidance, topic related guides and other tools to support your GDPR and PECR compliance

Updates, alerts & briefings

We provide updates and alerts and a monthly compliance briefing. You can either sign into the Knowledge Centre or sign up via email to receive an email every time we add a new update or alert

DPO services

Whether mandated or not we can act as your Data Protection Officer (DPO) and manage your day to day compliance

Webinars, workshops & training

Whether updates on the latest issue, workshops or team training, it's all included in your monthly retainer.

LIKE WHAT YOU'RE READING? join our email list

Sign up for monthly briefings and the occasional emails about our webinars and services

Want to know more about how we use your data? Check out our privacy policy