Article 41
Monitoring of approved codes of conduct

Official
Texts
Guidelines Caselaw Review of
EU Regulation
Review of
Nat. Regulation

The GDPR

Article 41 authorises, on certain conditions, an independent body to monitor the compliance with a code of conduct approved under article 40 without prejudice to the tasks and powers of the competent supervisory authority pursuant to Articles 57 and 58. Paragraph 1 stipulates that the monitoring of compliance may be carried out only by a body which has an appropriate level of expertise in relation to the subject-matter of the code.

The second paragraph sets out the conditions that such body must meet:

- it must have demonstrated its independence and expertise in relation to the subject-matter of the code to monitor (a);

- the body must have established procedures which allow it to assess the eligibility of controllers and processors concerned to apply the code, to monitor their compliance with its provisions and to periodically review its operation (b);

- the body must have established transparent procedures to handle complaints about infringements of the code by a controller or processor, by guaranteeing the absence of conflicts of interest (c);

- the body must have demonstrated to the satisfaction of the competent supervisory authority that its tasks and duties do not result in a conflict of interests (d). 

The competent supervisory authority shall submit the draft criteria as referred to in paragraph 1 of this Article to the Board pursuant to the consistency mechanism referred to in Article 63 (3)).

Without prejudice to the tasks and powers of the competent supervisory authority, such body shall, subject to appropriate safeguards, take appropriate action in cases of infringement of the code by a controller or processor, including suspension or exclusion of the controller or processor concerned from the code. It shall inform the competent supervisory authority of such actions and the reasons for taking them (paragraph 4).

The competent supervisory authority shall revoke the accreditation of a body if the conditions for accreditation are not met or where actions taken by the body infringe this Regulation (paragraph 5).

This provision shall not apply to processing carried out by public authorities and bodies (paragraph 6).

The Directive

There was no provision of the Directive for monitoring of the approved codes as no procedure for approval of such codes was provided.

Potential issues

We may wonder what will be the status of the control body in national law, separate from the national supervisory authority. A priori, it will not a public institution, but private, which would then have powers of sanctions with respect to an enterprise established as appropriate in a third country.

The regulation says nothing either in terms of the management of the costs of this compulsory control, which may also pose difficulties, in addition to the management of potential conflicts of interest.

Also, it should be noted that the provision does not apply to public authorities and public institutions even though they are not excluded from article 38 and are therefore required to adopt the codes. We may also ask which conditions precisely these qualifications of public authorities meet as not defined by the Regulation.

Summary

European Union

European Union

European data protection baord (EDPB)

Guidelines on Codes of conduct and Monitoring Bodies - 1/2019 (4 June 2019)

The aim of these guidelines is to provide practical guidance and interpretative assistance in relation to the application of Articles 40 and 41 of the GDPR.

They are intended to help clarify the procedures and the rules involved in the submission, approval and publication of codes at both a National and European level. They intend to set out the minimum criteria required by a Competent Supervisory Authority (“CompSA”) before accepting to carry out an in depth review and evaluation of a code. Further, they intend to set out the factors relating to the content to be taken into account when evaluating whether a particular code provides and contributes to the proper and effective application of the GDPR. Finally, they intend to set out the requirements for the effective monitoring of compliance with a code. These guidelines should also act as a clear framework for all CompSAs, the Board and the Commission to evaluate codes in a consistent manner and to streamline the procedures involved in the assessment process.

This framework should also provide greater transparency, ensuring that code owners who intend to seek approval for a code are fully conversant with the process and understand the formal requirements and the appropriate thresholds required for approval. Guidance on codes of conduct as a tool for transfers of data as per Article 40(3) of the GDPR will be considered in separate guidelines to be issued by the EDPB. All codes previously approved will need to be reviewed and re-evaluated in line with the requirements of the GDPR and then resubmitted for approval as per the requirements of Articles 40 and 41 and as per the procedures outlined in this document.

Lien

Retour au sommaire
Retour au sommaire
Regulation
1e 2e

Art. 41

1.   Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58, the monitoring of compliance with a code of conduct pursuant to Article 40 may be carried out by a body which has an appropriate level of expertise in relation to the subject-matter of the code and is accredited for that purpose by the competent supervisory authority.

2.   A body as referred to in paragraph 1 may be accredited to monitor compliance with a code of conduct where that body has:

a) demonstrated its independence and expertise in relation to the subject-matter of the code to the satisfaction of the competent supervisory authority;

b) established procedures which allow it to assess the eligibility of controllers and processors concerned to apply the code, to monitor their compliance with its provisions and to periodically review its operation;

c) established procedures and structures to handle complaints about infringements of the code or the manner in which the code has been, or is being, implemented by a controller or processor, and to make those procedures and structures transparent to data subjects and the public; and

d) demonstrated to the satisfaction of the competent supervisory authority that its tasks and duties do not result in a conflict of interests.

3.   The competent supervisory authority shall submit the draft criteria for accreditation of a body as referred to in paragraph 1 of this Article to the Board pursuant to the consistency mechanism referred to in Article 63.

4.   Without prejudice to the tasks and powers of the competent supervisory authority and the provisions of Chapter VIII, a body as referred to in paragraph 1 of this Article shall, subject to appropriate safeguards, take appropriate action in cases of infringement of the code by a controller or processor, including suspension or exclusion of the controller or processor concerned from the code. It shall inform the competent supervisory authority of such actions and the reasons for taking them.

5.   The competent supervisory authority shall revoke the accreditation of a body as referred to in paragraph 1 if the conditions for accreditation are not, or are no longer, met or where actions taken by the body infringe this Regulation.

6.   This Article shall not apply to processing carried out by public authorities and bodies.

1st proposal close

No specific provision

2nd proposal close

Art. 38a

1. Without prejudice to the tasks and powers of the competent supervisory authority under Articles 52 and 53, the monitoring of compliance with a code of conduct pursuant to Article 38 (1b), may be carried out by a body which has an appropriate level of expertise in relation to the subject-matter of the code and is accredited for this purpose by the competent supervisory authority.

2. A body referred to in paragraph 1 may be accredited for this purpose if:

(a) it has demonstrated its independence and expertise in relation to the subject-matter of the code to the satisfaction of the competent supervisory authority;

(b) it has established procedures which allow it to assess the eligibility of controllers and processors concerned to apply the code, to monitor their compliance with its provisions and to periodically review its operation;

(c) it has established procedures and structures to deal with complaints about infringements of the code or the manner in which the code has been, or is being, implemented by a controller or processor, and to make these procedures and structures transparent to data subjects and the public;

(d) it demonstrates to the satisfaction of the competent supervisory authority that its tasks and duties do not result in a conflict of interests.

3. The competent supervisory authority shall submit the draft criteria for accreditation of a body referred to in paragraph 1 to the European Data Protection Board pursuant to the consistency mechanism referred to in Article 57.

4. Without prejudice to the provisions of Chapter VIII, a body referred to in paragraph 1 may, subject to adequate safeguards, take appropriate action in cases of infringement of the code by a controller or processor, including suspension or exclusion of the controller or processor concerned from the code. It shall inform the competent supervisory authority of such actions and the reasons for taking them.

5. The competent supervisory authority shall revoke the accreditation of a body referred to in paragraph 1 if the conditions for accreditation are not, or no longer, met or actions taken by the body are not in compliance with this Regulation.

6. This article shall not apply to the processing of personal data carried out by public authorities and bodies.

Directive close

No specific provision

Artículo 38. Códigos de conducta.

1. Los códigos de conducta regulados por la sección 5.ª del Capítulo IV del Reglamento (UE) 2016/679 serán vinculantes para quienes se adhieran a los mismos.

Dichos códigos podrán dotarse de mecanismos de resolución extrajudicial de conflictos.

2. Dichos códigos podrán promoverse, además de por las asociaciones y organismos a los que se refiere el artículo 40.2 del Reglamento (UE) 2016/679, por empresas o grupos de empresas así como por los responsables o encargados a los que se refiere el artículo 77.1 de esta ley orgánica.

Asimismo, podrán ser promovidos por los organismos o entidades que asuman las funciones de supervisión y resolución extrajudicial de conflictos a los que se refiere el artículo 41 del Reglamento (UE) 2016/679.

Los responsables o encargados del tratamiento que se adhieran al código de conducta se obligan a someter al organismo o entidad de supervisión las reclamaciones que les fueran formuladas por los afectados en relación con los tratamientos de datos incluidos en su ámbito de aplicación en caso de considerar que no procede atender a lo solicitado en la reclamación, sin perjuicio de lo dispuesto en el artículo 37 de esta ley orgánica. Además, sin menoscabo de las competencias atribuidas por el Reglamento (UE) 2016/679 a las autoridades de protección de datos, podrán voluntariamente y antes de llevar a cabo el tratamiento, someter al citado organismo o entidad de supervisión la verificación de la conformidad del mismo con las materias sujetas al código de conducta.

En caso de que el organismo o entidad de supervisión rechace o desestime la reclamación, o si el responsable o encargado del tratamiento no somete la reclamación a su decisión, el afectado podrá formularla ante la Agencia Española de Protección de Datos o, en su caso, las autoridades autonómicas de protección de datos.

La autoridad de protección de datos competente verificará que los organismos o entidades que promuevan los códigos de conducta han dotado a estos códigos de organismos de supervisión que reúnan los requisitos establecidos en el artículo 41.2 del Reglamento (UE) 2016/679.

3. Los códigos de conducta serán aprobados por la Agencia Española de Protección de Datos o, en su caso, por la autoridad autonómica de protección de datos competente.

4. La Agencia Española de Protección de Datos o, en su caso, las autoridades autonómicas de protección de datos someterán los proyectos de código al mecanismo de coherencia mencionado en el artículo 63 de Reglamento (UE) 2016/679 en los supuestos en que ello proceda según su artículo 40.7. El procedimiento quedará suspendido en tanto el Comité Europeo de Protección de Datos no emita el dictamen al que se refieren los artículos 64.1.b) y 65.1.c) del citado reglamento.

Cuando sea una autoridad autonómica de protección de datos la que someta el proyecto de código al mecanismo de coherencia, se estará a lo dispuesto en el artículo 60 de esta ley orgánica.

5. La Agencia Española de Protección de Datos y las autoridades autonómicas de protección de datos mantendrán registros de los códigos de conducta aprobados por las mismas, que estarán interconectados entre sí y coordinados con el registro gestionado por el Comité Europeo de Protección de Datos conforme al artículo 40.11 del citado reglamento.

El registro será accesible a través de medios electrónicos.

6. Mediante real decreto se establecerán el contenido del registro y las especialidades del procedimiento de aprobación de los códigos de conducta.

Disposición transitoria segunda. Códigos tipo inscritos en las autoridades de protección de datos conforme a la Ley Orgánica 15/1999, de 13 de diciembre, de Protección de Datos de Carácter Personal.

Los promotores de los códigos tipo inscritos en el registro de la Agencia Española de Protección de Datos o en las autoridades autonómicas de protección de datos deberán adaptar su contenido a lo dispuesto en el artículo 40 del Reglamento (UE) 2016/679 en el plazo de un año a contar desde la entrada en vigor de esta ley orgánica.

Si, transcurrido dicho plazo, no se hubiera solicitado la aprobación prevista en el artículo 38.4 de esta ley orgánica, se cancelará la inscripción y se comunicará a sus promotores.

---

Article 38. Codes of Conduct.

1. The codes of conduct regulated by Section 5.a of Chapter IV of Regulation (EU) 2016/679 shall be binding on those who adhere to them.

These codes may include mechanisms for the extrajudicial resolution of conflicts.

2. Such codes may be promoted, in addition to the associations and bodies referred to in Article 40.2 of Regulation (EU) 2016/679, by companies or groups of companies as well as by the managers or persons in charge referred to in Article 77.1 of this Organic Law.

They may also be promoted by the bodies or entities that assume the functions of supervision and out-of-court dispute resolution referred to in Article 41 of Regulation (EU) 2016/679.

Data controllers or processors who adhere to the code of conduct are obliged to submit to the supervisory body or entity any complaints made to them by data subjects in relation to the processing of data included in its scope of application in the event that they consider that it is not appropriate to meet the request in the complaint, without prejudice to the provisions of article 37 of this Organic Law. In addition, without prejudice to the powers conferred by Regulation (EU) 2016/679 on the data protection authorities, may, on a voluntary basis and prior to carrying out the processing, submit to the said supervisory body or entity the verification of the compliance of the processing with the matters subject to the code of conduct.

In the event that the supervisory body or entity rejects or dismisses the complaint, or if the controller or processor does not submit the complaint to its decision, the data subject may file a complaint with the Spanish Data Protection Agency or, where appropriate, the regional data protection authorities.

The competent data protection authority shall verify that the bodies or entities promoting the codes of conduct have provided these codes with supervisory bodies that meet the requirements set out in Article 41(2) of Regulation (EU) 2016/679.

3. The codes of conduct shall be approved by the Spanish Data Protection Agency or, as the case may be, by the competent regional data protection authority.

4. The Spanish Data Protection Agency or, where appropriate, the regional data protection authorities shall submit the draft codes to the consistency mechanism referred to in Article 63 of Regulation (EU) 2016/679 in the cases in which this is appropriate according to its Article 40.7. The procedure shall be suspended as long as the European Data Protection Committee does not issue the opinion referred to in Articles 64.1.b) and 65.1.c) of the aforementioned regulation.

When it is an autonomous data protection authority that submits the draft code to the consistency mechanism, the provisions of article 60 of this Organic Law shall apply.

5. The Spanish Data Protection Agency and the autonomous data protection authorities shall keep registers of the codes of conduct approved by them, which shall be interconnected with each other and coordinated with the register managed by the European Data Protection Committee in accordance with article 40.11 of the aforementioned regulation.

The registry will be accessible through electronic means.

6. A Royal Decree will establish the content of the registry and the special features of the procedure for the approval of the codes of conduct.

Second Transitory Provision. Standard codes registered with the data protection authorities in accordance with Organic Law 15/1999, of December 13, 1999, on the Protection of Personal Data.

The promoters of the standard codes registered in the registry of the Spanish Data Protection Agency or in the regional data protection authorities must adapt their content to the provisions of Article 40 of Regulation (EU) 2016/679 within one year from the entry into force of this Organic Law.

If, after said period has elapsed, the approval provided for in Article 38.4 of this Organic Law has not been requested, the registration shall be cancelled and the promoters shall be notified.

Old law close

Article 75.- Guarantees of compliance with Codes of Coduct.- Royal Decree 1720/2007 Implementing Organic Law 15/1999.- .

1. The codes of conduct shall include independent supervision procedures to guarantee compliance with the obligations assumed by subscribers, and to establish adequate, effective and dissuasive penalties.

2. Such procedure shall guarantee:

a) The independence and impartiality of the supervisory body;

b) The simple, accessible, fast and cost-free presentation of complaints and claims before the body for possible breaches of the code of conduct;

c) The right to contest;

d) Various levels of penalties so they may be adjusted to the severity of the breach. Such penalties shall be dissuasive and may involve suspension of the subscription to the code or expulsion from the member entity. If appropriate, it may establish its publication;

e) Notification of the decision taken to the data subject.

3. Similarly, and without prejudice to the provisions of Article 19 of Organic Law 15/1999, of 13 December, the codes of conduct may include procedures to determine measures to repair harm that may have been caused to data subjects as a result of the breach of the code of conduct.

4. These provisions of this Article shall be applied without prejudice to the powers of the Spanish Data Protection Agency and, if appropriate, of the supervisory authorities of the Autonomous Communities.

 

Article 76.- List of Subscribers.- Royal Decree 1720/2007 Implementing Organic Law 15/1999.-

The code of conduct shall have attached as a schedule a list of subscribers, which shall be kept up-to-date, available to the Spanish Data Protection Agency.

 

Article 77.- Filing and Publication of Codes of Conduct.- Royal Decree 1720/2007 Implementing Organic Law 15/1999.-

1. In order for the codes of conduct to be considered as such for the purposes provided in Article 32 of Organic Law 15/1999, of 13 December, and herein, they shall be filed and registered in the General Data Protection Register of the Spanish Data Protection Agency or, when appropriate, in the register created by the Autonomous Communities, which shall transfer them for their inclusion in the General Data Protection Register.

2. For this purpose, the codes of conduct shall be presented before the relevant supervisory authority, that shall process their registration, in the event they are subject to the decision of the Spanish Data Protection Agency, pursuant to the procedure established in Chapter VI of Title IX hereof.

3. In any case, the Spanish Data Protection Agency shall publish the registered codes of conduct, preferably through computerised or telematic means.

 

Article 78.- Obligatons after Registration of the  Code of Conduct.- Royal Decree 1720/2007 Implementing Organic Law 15/1999.-

The promoting entities or bodies, persons or entities designated for this purpose in the code of conduct shall have, once it has been published, the following obligations:

a) Maintain accessible to the public the updated information on the promoting entities, the content of the code of conduct, the procedures for subscription and guarantee of compliance and the list of subscribers to which the previous Article refers.

Such information shall be presented clearly and concisely and shall be permanently accessible by electronic means.

b) Send to the Spanish Data Protection Agency an annual report on the activities carried out to disseminate the code of conduct and promote subscription to it, the actions for verifying compliance with the code and their results, the complaints and claims handled and the process they have undergone and any other aspect that the promoting entities deem relevant.

Regarding codes of conduct registered in the register of a supervisory authority of an Autonomous Community, the report shall be sent to that authority, which shall transfer it to the General Data Protection Register.

c) Periodically evaluate the effectiveness of the code of conduct, measuring the degree of satisfaction of the data subjects and, if appropriate, updating the contents to adapt it to the general or sectoral legislation on the protection of data that is in force at any time.

This evaluation shall take place, at least, every four years, unless adaptation of the commitments of the code to an amendment of the applicable legislation is required earlier.

d) Promote accessibility of all persons, paying particular attention to those with a disability or of advanced age, to the information available on the code of conduct.

close