Article 41
Monitoring of approved codes of conduct
There is no recital in the Regulation related to article 41.
There is no recital in the Directive related to article 41.
|
Regulation
Art. 41 1. Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58, the monitoring of compliance with a code of conduct pursuant to Article 40 may be carried out by a body which has an appropriate level of expertise in relation to the subject-matter of the code and is accredited for that purpose by the competent supervisory authority. 2. A body as referred to in paragraph 1 may be accredited to monitor compliance with a code of conduct where that body has: a) demonstrated its independence and expertise in relation to the subject-matter of the code to the satisfaction of the competent supervisory authority; b) established procedures which allow it to assess the eligibility of controllers and processors concerned to apply the code, to monitor their compliance with its provisions and to periodically review its operation; c) established procedures and structures to handle complaints about infringements of the code or the manner in which the code has been, or is being, implemented by a controller or processor, and to make those procedures and structures transparent to data subjects and the public; and d) demonstrated to the satisfaction of the competent supervisory authority that its tasks and duties do not result in a conflict of interests. 3. The competent supervisory authority shall submit the draft criteria for accreditation of a body as referred to in paragraph 1 of this Article to the Board pursuant to the consistency mechanism referred to in Article 63. 4. Without prejudice to the tasks and powers of the competent supervisory authority and the provisions of Chapter VIII, a body as referred to in paragraph 1 of this Article shall, subject to appropriate safeguards, take appropriate action in cases of infringement of the code by a controller or processor, including suspension or exclusion of the controller or processor concerned from the code. It shall inform the competent supervisory authority of such actions and the reasons for taking them. 5. The competent supervisory authority shall revoke the accreditation of a body as referred to in paragraph 1 if the conditions for accreditation are not, or are no longer, met or where actions taken by the body infringe this Regulation. 6. This Article shall not apply to processing carried out by public authorities and bodies. |
Directive
No specific provision |
Poland
Starting from May 25, 2018 GDPR came into force and is fully applicable in Poland. The Act on Protection of Personal Data of 29th August 1997 [unified text: Journal of Laws 2015, item 2135, 2281] is not in force since May 25, 2018. It was replaced by new regulation - The Act on Personal Data Protection of 10th May 2018, which implements GDPR in Poland. The Act on Personal Data Protection of 10th May 2018: Article 28 [Body monitoring compliance with an approved code of conduct] Article 29 [Accreditation of the monitoring body] 1. Accreditation of the body referred to in Article 28 shall be granted upon application, which shall contain at least:
2. Documents confirming compliance with the criteria referred to in Article 41(1) and (2) of Regulation (EU) 2016/679, or copies thereof, shall be attached to the application. 3. The application shall be submitted in writing either in paper form bearing a handwritten signature or in electronic form bearing a qualified electronic signature or a signature confirmed by a trusted profile (ePUAP). Article 30 [Time limit for examining the application by the President of the Office] 1. The President of the Office shall examine the application referred to in Article 29(1) and, no later than within 3 months from the date of submission of an application compliant with Article 29, after verifying compliance with the criteria referred to in Article 41(1) and (2) of Regulation (EU) 2016/679, shall notify the entity applying for accreditation of the granting or refusal of accreditation. 2. An application submitted to the President of the Office that does not contain the information referred to in Article 29(1)(1) shall be left unexamined. Where the application does not contain the information referred to in Article 29(1)(2), or does not meet the requirements referred to in paragraph 2 or 3, the President of the Office shall request the applicant to supplement it, together with an instruction that failure to do so within 7 days from service of the request will result in the application being left unexamined. 3. Where it is established that the entity applying for accreditation does not meet the criteria referred to in Article 41(1) and (2) of Regulation (EU) 2016/679, the President of the Office shall refuse to grant accreditation. A refusal to grant accreditation shall be made by way of a decision. |
