How GDPR Certification Audits Work From Application to Seal

For businesses operating across Europe, protecting personal data is both a legal responsibility and an important part of maintaining customer and business trust. The General Data Protection Regulation, commonly known as GDPR, establishes requirements for how organizations collect, use, store, share, and protect personal data.
While GDPR compliance is a legal obligation where the Regulation applies, organizations can also use certification as a voluntary accountability mechanism. Article 42 of the GDPR provides for data protection certification mechanisms, seals, and marks that can demonstrate compliance of specified processing operations with the Regulation. Certification is granted under an approved certification mechanism by an eligible certification body or, where applicable, a competent supervisory authority.
A GDPR certification audit examines whether processing activities covered by a defined certification scope meet the applicable certification criteria. Understanding how the process works is important for organizations considering certification, particularly because GDPR certification does not automatically mean that every activity performed by an organization complies with every GDPR requirement.
Demonstrate Stronger GDPR Compliance. Show customers and stakeholders that your organization takes personal data protection and privacy requirements seriously.
What Is GDPR Certification?
GDPR certification is a voluntary mechanism designed to demonstrate that specified processing operations meet defined data protection certification criteria. Article 42 establishes the legal basis for certification mechanisms, seals, and marks under the GDPR.
Certification is focused on a particular scope. Depending on the applicable certification mechanism, the scope may cover specific processing operations, products, services, systems, or other defined activities. The certificate therefore needs to be considered together with its stated scope and certification criteria.
The European Data Protection Board maintains information on certification mechanisms and data protection seals and marks that have been approved through the applicable European process. This provides organizations with an important reference when evaluating a potential GDPR certification mechanism.
GDPR Certification vs GDPR Compliance
GDPR certification and GDPR compliance are related but are not the same thing.
GDPR compliance refers to an organization's legal obligations under the Regulation. These obligations can cover areas such as lawful processing, transparency, data subject rights, security, data retention, processor relationships, international transfers, accountability, and other requirements applicable to the organization's processing activities.
GDPR certification, on the other hand, is a voluntary mechanism through which specified processing operations are assessed against defined certification criteria.
A GDPR certificate should therefore not be interpreted as a universal declaration that an organization complies with every provision of the GDPR. The certificate applies to the processing activities and scope covered by the applicable certification mechanism.
What GDPR Certification Demonstrates
A GDPR certificate can demonstrate that specified processing activities have been independently assessed against the requirements of an approved certification mechanism.
This can provide organizations with an additional way to demonstrate their privacy practices to customers, business partners, processors, controllers, and other stakeholders. Certification can also be relevant to certain international data transfer arrangements because the GDPR recognizes approved certification mechanisms as one possible safeguard under Article 46, subject to the conditions established by the Regulation.
The value of certification depends on the certification mechanism, its criteria, the defined scope, and the competence and status of the certification body.
The Role of Third-Party Certification Under GDPR
Third-party certification introduces an independent assessment into the certification process. Instead of relying only on an organization's own declaration, an eligible certification body evaluates the defined processing activities against the applicable criteria.
This independent assessment can provide greater transparency when an organization needs to demonstrate how it manages personal data. The European Data Protection Board has recognized certification as an accountability mechanism that can provide information about an organization's compliance with GDPR requirements within the relevant scope.
However, third-party certification does not transfer responsibility for GDPR compliance from the organization to the certification body. Controllers and processors remain responsible for meeting the GDPR obligations that apply to their activities.
Who Can Obtain GDPR Certification?
Both controllers and processors can potentially obtain GDPR certification where their processing activities fall within an applicable certification mechanism.
The GDPR specifically refers to certification of processing operations carried out by controllers and processors. The availability of certification depends on the applicable certification scheme, its criteria, scope, and eligibility requirements.
Organizations located outside the European Union may also be able to use certain approved certification mechanisms in specific circumstances, including as a safeguard for international transfers where the requirements of Article 46 are satisfied.
What Is a GDPR Certification Audit?
A GDPR certification audit is an assessment of processing activities against the criteria established by the relevant GDPR certification mechanism.
The auditor reviews information and evidence associated with the defined scope to determine whether the applicable certification criteria have been met. The assessment may involve reviewing policies and records, examining processes, interviewing relevant personnel, and evaluating technical and organizational measures.
The exact assessment methodology depends on the certification mechanism. For this reason, organizations should review the applicable scheme before assuming that every GDPR certification audit follows an identical process.
Purpose of a GDPR Certification Audit
The purpose of a GDPR certification audit is to determine whether the processing activities within the certification scope conform to the applicable certification criteria.
The assessment can examine how an organization manages privacy responsibilities, personal data processing, data subject rights, security measures, processor relationships, international transfers, retention, and other areas included within the certification scheme.
The audit is therefore focused on demonstrating conformity with defined criteria rather than simply reviewing whether an organization has a general privacy policy.
What a GDPR Certification Auditor Evaluates
A GDPR certification auditor evaluates objective evidence against the requirements of the applicable certification mechanism.
Depending on the scheme, the assessment may cover the organization's privacy governance, lawful processing arrangements, handling of data subject requests, privacy by design practices, data protection impact assessments, processor relationships, security measures, incident management, retention practices, and international data transfers.
The auditor does not simply evaluate whether a document exists. The assessment can also consider whether the relevant processes are established and operating as required by the applicable certification criteria.
Scope of a GDPR Certification Audit
The certification scope determines what the audit actually covers.
For example, an organization may seek certification for particular processing activities associated with a SaaS platform rather than every processing activity performed throughout the organization. The scope could also involve particular services, products, systems, locations, or processing operations, depending on what the certification mechanism permits.
A clearly defined scope is important because activities outside the certified scope are not automatically covered by the certificate.
Evidence and Records Reviewed During the Audit
The auditor reviews evidence that demonstrates how the organization meets the applicable certification criteria.
Depending on the scope, this may include privacy policies, records of processing activities, data protection impact assessments, legal basis records, processor agreements, data subject request records, incident records, employee training records, retention arrangements, and technical security evidence.
The precise evidence requirements depend on the certification scheme and the processing activities being assessed.
Who Conducts a GDPR Certification Audit?
A GDPR certification audit is performed within the framework of an approved certification mechanism. Article 43 of the GDPR establishes requirements for certification bodies, including appropriate data protection expertise and applicable accreditation requirements.
This makes the choice of certification body an important part of the certification process.
Role of a GDPR Certification Body
A GDPR certification body assesses an applicant against the applicable certification criteria and follows the certification mechanism's procedures for making a certification decision.
The body is responsible for maintaining appropriate procedures for assessment, decision-making, certification validity, surveillance where applicable, and handling matters such as suspension or withdrawal.
Article 43 also addresses requirements concerning independence, conflicts of interest, expertise, and accreditation.
Role and Competence of a GDPR Certification Auditor
A GDPR certification auditor assesses the organization's processing activities against the relevant criteria.
The auditor needs knowledge of data protection principles, audit methods, privacy processes, information security where relevant, and the requirements of the specific certification mechanism.
Auditor competence is particularly important because GDPR processing environments can vary significantly between sectors. A technology company processing customer account data can have very different privacy risks from a healthcare organization processing sensitive personal data.
What to Look for in a GDPR Certification Body
Organizations considering GDPR certification should examine whether the certification body is authorized or accredited within the applicable framework and whether its scope covers the type of certification being sought.
The organization should also review the certification methodology, assessment process, auditor competence, decision-making arrangements, certification validity, surveillance requirements, and rules governing the use of certification marks.
Simply choosing a provider that advertises "GDPR certification" does not establish that the resulting certificate belongs to an approved certification mechanism.
Accredited Certification Bodies and GDPR Certification
Article 43 establishes the framework for accreditation of certification bodies. Depending on the applicable national framework, certification bodies can be accredited by the competent supervisory authority, the national accreditation body, or both.
The European Data Protection Board has published guidelines addressing the accreditation of certification bodies under Article 43. Organizations should therefore verify the accreditation or authorization status and applicable scope of a certification body before entering into a certification process.
GDPR Certification Audit Process: From Application to Certification
The GDPR certification audit process can vary according to the certification mechanism. However, organizations generally move through several stages, beginning with an application and ending with a certification decision.
Step 1: Submit the Certification Application
The process generally begins when an organization submits an application to an eligible certification body.
The application provides information about the organization and the processing activities it wants to include within the certification scope. The certification body uses this information to determine whether the requested certification can be assessed under the applicable mechanism.
Step 2: Define the Certification Scope
Once the application is reviewed, the certification scope needs to be clearly established.
This can include the relevant processing activities, products, services, systems, organizational units, locations, or other elements defined by the certification scheme.
A precise scope prevents confusion about what the eventual certificate actually covers.
Step 3: Review Applicable GDPR Requirements
The organization and certification body identify the certification criteria that apply to the selected scheme.
These criteria may address specific GDPR principles, accountability requirements, data subject rights, privacy controls, security measures, processor relationships, or other data protection requirements.
The applicable certification criteria are more specific than simply referring to "GDPR compliance." They establish the requirements against which the assessment is performed.
Step 4: Plan the Certification Audit
The certification body plans the audit based on the defined scope and characteristics of the processing activities.
The audit plan can take into account the size of the organization, number of locations, complexity of processing operations, systems involved, relevant personnel, and evidence that needs to be reviewed.
For organizations operating across multiple European locations, additional planning may be required to ensure that the defined certification scope is appropriately assessed.
Step 5: Conduct the Certification Audit
The auditor then evaluates the processing activities against the applicable certification criteria.
Depending on the certification mechanism, the assessment can involve interviews, document and record review, sampling, observation, technical evidence review, and other assessment techniques.
The auditor's focus is on determining whether objective evidence demonstrates conformity with the applicable criteria.
Step 6: Identify and Evaluate Nonconformities
If the auditor identifies an area that does not meet an applicable certification criterion, the issue may be recorded as a nonconformity or other type of finding according to the certification body's procedures.
The classification of findings can vary between certification schemes. Organizations should therefore refer to the rules of the specific certification mechanism.
Step 7: Review Corrective Actions and Evidence
Where findings require further action, the organization may need to address the identified issue and submit evidence for review.
The certification body evaluates the evidence according to the applicable certification procedures. The purpose is to determine whether the relevant certification criteria have ultimately been satisfied.
Step 8: Certification Decision
The certification decision is made according to the certification body's established decision-making process.
The decision is based on the assessment results and available evidence. Where the applicable requirements have been satisfied, certification can be granted.
Step 9: Issue the GDPR Certificate and Certification Mark
After a positive certification decision, the certification body issues the certificate in accordance with the applicable certification mechanism.
Some approved mechanisms may also provide a certification mark or data protection seal. The organization must follow the rules governing how and where that mark can be used.
A certification mark should not be treated as a general statement covering processing activities outside the certified scope.
Step 10: Ongoing Surveillance and Recertification
GDPR certification is not necessarily a one-time activity. The applicable certification mechanism can establish surveillance activities or other monitoring requirements during the certification period.
Article 42 states that certification may be issued for a maximum period of three years and can be renewed where the relevant conditions continue to be met. Certification can also be withdrawn where the applicable requirements are no longer satisfied.
This means organizations need to continue maintaining conformity within the certified scope rather than treating certification as a permanent status.
What Does a GDPR Certification Auditor Check?
The specific criteria depend on the certification mechanism, but auditors may assess several important areas of privacy governance and data protection.
Data Protection Policies and Governance
The auditor may examine how data protection responsibilities are established within the certified scope.
This can include privacy policies, assigned responsibilities, governance arrangements, accountability measures, and processes for monitoring data protection obligations.
The assessment considers whether the arrangements satisfy the criteria of the applicable certification mechanism.
Lawfulness of Personal Data Processing
Lawfulness is a fundamental GDPR requirement.
Depending on the certification criteria, the auditor may examine whether processing activities have an appropriate legal basis and whether the organization can demonstrate the basis relied upon for relevant processing.
The evidence required will depend on the processing activity and the certification scheme.
Data Subject Rights
Data subjects have rights under the GDPR, including rights relating to access, rectification, erasure, restriction, objection, and data portability in applicable circumstances.
A GDPR certification auditor may examine how the organization receives, evaluates, and responds to requests within the certified scope.
Records of requests can provide evidence of how these processes operate in practice.
Privacy by Design and Default
Privacy by design and by default are important concepts under the GDPR.
The assessment may therefore consider whether privacy considerations are incorporated into relevant systems, products, services, and processing activities covered by the certification scope.
This can involve examining how privacy requirements are considered during the design and modification of relevant processing activities.
Data Protection Impact Assessments
A Data Protection Impact Assessment, or DPIA, may be required where processing is likely to result in a high risk to individuals.
Where DPIAs are relevant to the certified scope, auditors may review whether the organization has identified applicable processing risks, assessed those risks, and established appropriate measures.
Data Breach Management
Personal data breach management can also form part of a GDPR certification audit where it falls within the certification criteria.
The auditor may review how incidents are identified, assessed, recorded, escalated, and handled, including the organization's processes for determining whether notification requirements apply.
Processor and Third-Party Management
Organizations frequently rely on external processors to handle personal data.
The auditor may therefore review how processor relationships are established and managed. This can include contracts, processing instructions, third-party oversight, and evidence demonstrating that relevant processor requirements are addressed.
International Data Transfers
International data transfers can create additional GDPR requirements when personal data is transferred outside the European Economic Area or to an international organization.
A certification audit may examine the transfer mechanisms and safeguards relevant to the certified processing activities.
The GDPR recognizes approved certification as one possible safeguard for certain transfers under Article 46, subject to the conditions of the Regulation.
Data Retention and Deletion
Organizations need to establish appropriate approaches to retaining and deleting personal data.
Within the certification scope, auditors may review retention periods, deletion processes, relevant system configurations, and evidence demonstrating how retention requirements are applied.
Technical and Organizational Measures
The GDPR requires appropriate technical and organizational measures to protect personal data.
Depending on the certification criteria, auditors may therefore examine areas such as access controls, authentication, encryption, security monitoring, incident management, resilience, and other measures relevant to the processing activities.
What Evidence Is Reviewed During a GDPR Certification Audit?
A GDPR certification audit relies on objective evidence rather than statements alone. The auditor needs sufficient evidence to determine whether the organization meets the applicable certification criteria.
Policies and Procedures
Privacy and security policies can demonstrate how the organization establishes its approach to personal data protection.
The auditor may review whether the policies are relevant to the certified scope and whether they are consistent with the organization's actual processing activities.
Records of Processing Activities
Records of Processing Activities, commonly referred to as ROPAs, provide information about processing activities carried out by an organization.
Where relevant to the certification scope, these records can help demonstrate the purposes of processing, categories of personal data, data subjects, recipients, retention periods, and other information required under the GDPR.
Data Protection Impact Assessments
DPIAs provide evidence of how an organization assesses privacy risks associated with relevant processing activities.
The auditor may review the assessment methodology, identified risks, proposed measures, and review or approval process.
Consent and Legal Basis Records
Where consent is the legal basis for processing, relevant records can demonstrate how consent was obtained and managed.
For processing based on another legal basis, different evidence may be required to demonstrate the basis relied upon.
Data Subject Request Records
Records of data subject requests can demonstrate how rights requests are handled.
The auditor may examine how requests are received, verified, assessed, responded to, and recorded within the certification scope.
Vendor and Processor Agreements
Contracts with processors can demonstrate how third-party processing arrangements are established.
The auditor may review whether the relevant agreements contain provisions required by the GDPR and applicable certification criteria.
Incident and Breach Records
Incident and breach records can provide evidence of how privacy and security events are managed.
Depending on the certification scope, the auditor may review incident identification, investigation, escalation, notification decisions, and corrective measures.
Training and Awareness Records
Personnel involved in processing personal data may require appropriate data protection awareness and training.
Training records can provide evidence that relevant personnel have received information appropriate to their responsibilities.
Security and Privacy Control Evidence
Technical evidence can be particularly important where certification criteria include security controls.
Depending on the scope, this may include access control configurations, authentication settings, encryption information, monitoring records, security testing results, and other evidence demonstrating the operation of relevant safeguards.
What Happens When a GDPR Certification Audit Finds Nonconformities?
Finding a nonconformity during an audit does not automatically mean that certification can never be achieved. The outcome depends on the nature of the finding, applicable certification criteria, and the rules of the certification mechanism.
Understanding Audit Findings
An audit finding identifies an area where the evidence reviewed does not demonstrate conformity with an applicable criterion.
The finding should be understood in relation to the defined certification scope and the specific requirement involved.
This distinction is important because a certification audit does not necessarily provide a complete assessment of every GDPR obligation across an entire organization.
Major and Minor Nonconformities
Some certification schemes distinguish between major and minor nonconformities based on their significance.
However, terminology and classification rules can differ between certification mechanisms. Organizations should therefore review the applicable scheme instead of assuming that every GDPR certification body uses identical classifications.
Corrective Action and Evidence Review
Where a finding requires corrective action, the organization may need to address the underlying issue and provide objective evidence demonstrating conformity.
The certification body reviews the evidence according to the certification scheme's procedures before reaching or confirming a certification decision.
Impact of Unresolved Findings on Certification
Unresolved findings can affect whether certification is granted or maintained.
Depending on the certification mechanism and the nature of the finding, certification may be delayed, restricted, suspended, or not granted until the applicable requirements are satisfied.
How Long Does a GDPR Certification Audit Take?
There is no universal duration for a GDPR certification audit.
The timeframe depends on the certification mechanism, certification scope, organization size, processing activities, number of locations, complexity of systems, and amount of evidence requiring review.
Factors That Influence Audit Duration
The more complex the certified processing environment, the more assessment planning may be required.
For example, a narrowly defined processing activity involving a single service may require a different assessment approach from a certification covering several products, locations, processors, and international data flows.
Organization Size and Scope
The size of an organization can affect the amount of evidence and number of personnel involved in the audit.
However, organization size alone does not determine audit duration. The certification scope and complexity of the processing activities are also significant factors.
Number and Type of Processing Activities
Organizations with multiple processing activities may require broader assessment coverage.
Different processing activities can involve different legal bases, categories of personal data, data subjects, processors, systems, and retention requirements.
Complexity of Data Processing Operations
Complex processing environments can require additional assessment time.
For example, automated processing, large-scale personal data processing, extensive third-party relationships, cloud environments, and cross-border data transfers can create additional areas for review where relevant to the certification criteria.
Multi-Site and International Operations
Organizations operating across multiple European countries or international locations may have additional scope considerations.
The certification body may need to determine how the different locations and processing activities fit within the certification mechanism and assessment plan.
Because of these variables, organizations should obtain a proposed audit duration from the certification body after the scope and applicable certification criteria have been established.
What Happens After GDPR Certification?
Obtaining a certificate does not end an organization's responsibilities under the GDPR.
Certification applies to a defined scope and remains subject to the requirements of the applicable certification mechanism.
Issuing the GDPR Certificate
Following a positive certification decision, the certification body issues the certificate according to its certification procedures.
The certificate normally identifies important information about the certified organization, certification mechanism, scope, validity period, and other scheme-specific details.
Use of the Certification Mark or Seal
An approved certification mechanism may allow the certified organization to use a certification mark or data protection seal.
The organization must follow the rules governing its use. The mark cannot be presented in a way that suggests certification covers activities outside the defined scope.
Maintaining Compliance Within the Certified Scope
Organizations must continue to meet the applicable certification criteria throughout the certification period.
Changes to systems, processing activities, products, suppliers, locations, or organizational structures can potentially affect the certification scope or conformity.
Surveillance Audits
Some certification mechanisms require surveillance activities during the certification period.
Surveillance can provide a way for the certification body to verify continuing conformity with the relevant certification criteria.
The frequency and nature of surveillance depend on the applicable certification mechanism.
Recertification and Certificate Renewal
GDPR certification can be issued for a maximum period of three years under Article 42 and may be renewed when the relevant requirements continue to be satisfied.
The renewal process can involve another assessment of the certified scope and applicable criteria. Organizations should therefore plan for renewal before the existing certificate reaches its expiry date.
How to Choose a GDPR Certification Body
Choosing a GDPR certification body requires careful consideration because not every organization using GDPR-related terminology provides certification under an approved mechanism.
Certification Scope and Competence
The first consideration is whether the certification body has the appropriate scope and competence for the processing activities being considered for certification.
The organization should establish exactly what the proposed certificate will cover before beginning the assessment.
Auditor Qualifications and Experience
Auditor competence is another important consideration.
Organizations should consider whether auditors have appropriate knowledge of data protection, auditing, privacy controls, and the specific certification mechanism being used.
Experience with the organization's sector and processing environment can also be relevant.
Accreditation and Recognition
The organization's accreditation or authorization status should be verified against the applicable GDPR certification framework.
Article 43 establishes requirements for certification bodies, while EDPB guidance provides further information concerning accreditation.
Certification Methodology and Transparency
The certification body should clearly explain its certification criteria, assessment process, decision-making arrangements, certificate validity, surveillance requirements, and conditions for suspension or withdrawal.
Transparency helps organizations understand what their certificate actually demonstrates.
Experience With Your Industry and Processing Activities
The processing environment of a SaaS provider can differ significantly from that of a healthcare provider, financial institution, manufacturer, or digital platform.
An organization should therefore consider whether the certification body and its auditors have relevant experience with the types of processing activities included within the proposed certification scope.
GDPR Certification Audit vs GDPR Compliance Audit
Although the terms are sometimes used interchangeably, a GDPR certification audit and a GDPR compliance audit can have different purposes.
Differences in Purpose
A GDPR certification audit assesses specified processing activities against the criteria of an applicable certification mechanism.
A GDPR compliance audit can have a broader objective and may assess an organization's compliance position against applicable GDPR requirements without being linked to a certification mechanism.
Differences in Audit Process
A certification audit follows the rules and assessment criteria of the selected certification scheme.
A compliance audit can be designed around an organization's specific audit objectives, regulatory requirements, contractual commitments, or governance processes.
The methodology can therefore differ considerably between the two activities.
Differences in Certification Outcomes
A successful certification audit can result in a GDPR certificate where the applicable requirements have been satisfied.
A compliance audit does not necessarily result in a certification. It may instead produce findings, observations, recommendations, or an assessment report depending on its purpose and methodology.
When Organizations May Consider Third-Party Certification
Organizations may consider third-party certification when they want an independent mechanism for demonstrating conformity of specified processing operations against approved criteria.
Certification can be particularly relevant where customers, business partners, or other stakeholders want additional evidence of privacy practices.
However, certification remains one accountability mechanism and does not replace the organization's broader responsibilities under the GDPR.
Assess Your Organization’s GDPR Compliance. Gain an independent view of how your privacy practices align with applicable GDPR requirements. Connect With INTERCERT for GDPR Assessment Services.
GDPR Certification for Businesses and Organizations
GDPR certification can be relevant to organizations across many industries, provided their processing activities fall within an applicable certification mechanism.
SaaS and Technology Companies
SaaS and technology companies often process customer account information, employee data, usage information, contact details, and other personal data.
For these organizations, certification may provide a structured way to demonstrate conformity of defined processing operations associated with a product or service.
The certification scope needs to clearly identify which processing activities are covered.
Healthcare and Life Sciences Organizations
Healthcare and life sciences organizations can process sensitive personal data and may operate complex data-sharing environments.
Where an applicable certification mechanism covers the relevant processing activities, certification can provide evidence that those activities have been assessed against defined criteria.
Financial Services Companies
Financial institutions, fintech companies, insurers, and related businesses process substantial amounts of personal information.
A defined certification scope can cover relevant processing operations where the applicable certification mechanism permits it.
E-Commerce and Digital Platforms
E-commerce businesses and digital platforms can process customer identities, contact information, account details, transaction information, and online activity.
Certification can provide an additional mechanism for demonstrating conformity of specified processing activities, subject to the criteria and scope of the applicable scheme.
Organizations Processing Data Across Multiple Countries
Organizations operating across Europe may have complex data flows involving multiple countries, systems, suppliers, and processing activities.
When considering certification, these organizations need to establish how the certification scope will address their different processing operations and locations.
International transfers should also be assessed separately against the GDPR requirements and applicable transfer safeguards.
Read More:
What Is a European Data Protection Seal in GDPR?
GDPR Certification Explained Under Article 42 of the GDPR