GDPR certification

Data protection digest 17 Aug – 1 Sep 2026: GDPR certification – why “full compliance” is a risky claim

GDPR certification: why “fully compliant” should not be claimed

Certification mechanisms can contribute to greater transparency and compliance with the GDPR and enable data subjects, business partners and other interested parties to more easily assess the level of personal data protection associated with a particular product, service or process, explains the Croatian data protection agency AZOP.  A product, service, process or system may be listed as the subject of GDPR certification only to the extent that the personal data processing operations associated with it are clearly identified.

Stay up to date! Sign up to receive our fortnightly digest via email. 

For example, an organisation may request certification of the processing operations carried out within a specific digital service or the authentication process, or transfers of personal data to third countries. The certificate must clearly state what was assessed, what the boundaries of the certified process are, and which version of the product or service the certificate applies to. The certification therefore does not automatically apply to the entire organisation, all its processing, or the entire product or software

Information or management system certificates, such as ISO/IEC 27001 or ISO/IEC 27701, and certificates of professional competence of data protection officers should not be confused with the certification referred to in Art. 42 and 43 of the GDPR.  Certification does not reduce the responsibility of the controller or processor, does not replace their legal obligations and does not limit the tasks and powers of the regulators. A certified organisation may at any time still be subject to supervision and sanctions. 

The decision to pursue certification is voluntary. However, once the certificate is issued, the organisation is required to meet the approved criteria, report relevant changes, and undergo surveillance audits by the certification body throughout its validity period.

Meta trial in the US over minors’ safety

Meta has settled a lawsuit brought by 29 US states for designing and deploying addictive harmful features on Instagram and Facebook that drive compulsive use by children and teens to their mental and physical detriment. The proposed settlement includes a monetary payment of up to 17 billion dollars to the states over ten years.  Meta has also agreed to implement:

  • default daily time limits on social media,
  • enhanced parental supervision tools, 
  • robust age assurance measures to detect users under 18 and children under 13, 
  • a ban on displaying numbers of likes or reactions to users under 18,
  • a ban on cosmetic procedure image filters for users under 18,
  • an option for users under 18 to have a non-personalised feed, and 
  • an independent auditor to oversee compliance, etc.

The limits Meta will put on its US platform are, in large part, similar to limits the UK and Australia have already achieved through regulation. A similar law was recently approved in France, but was struck down by the constitutional council over freedom of expression and communication concerns. The French government is now working on a more legally robust draft document. 

More legal updates

Platform regulations in the EU: On 31 August, the European Commission said ChatGPT, Reddit and Roblox will need ​to adhere to the Digital Services Act (DSA) for very large online platforms and search engines. These services declared that they reach at least 45 million average monthly users in the EU and thus meet the threshold for designation. They now have four months to comply with additional obligations following their designation, including mitigating risks of illegal content and negative effects on minors.

The Commission has so far designated 28 very large platforms and search engines under the DSA. 

FRIA for AI is coming: As of December 2027, private and public entities working with high-risk AI must assess in advance what impact their AI system may have on people’s fundamental rights. Such an assessment is called a fundamental rights impact assessment, as prescribed by the EU AI Act.  The Dutch data protection regulator AP recommends starting assessments now and offers participation in a pilot project. It is intended for learning purposes and is explicitly NOT an audit, inspection, or enforcement process. 

Cyber Resilience Act reporting obligation: The first major EU Cyber Resilience Act (CRA) compliance deadline is fast approaching. From 11 September, manufacturers of products with digital elements must comply with new reporting obligations for actively exploited vulnerabilities and severe incidents (routine bugs and ordinary patches are not in its scope). ENISA has scheduled the Single Reporting Platform to be operational by the same date. In particular, the manufacturers must submit an early warning within 24 hours of becoming aware, and a fuller notification within 72 hours

The reporting obligations are the earliest major part of the CRA to take effect, while most provisions will apply from 11 December 2027. 

More official guidance

GDPR certification

CCTV by municipalities:  The Cypriot data protection authority reminds us of the legal foundations for mass street surveillance. The installation of CCTV cameras in public spaces generally falls within the scope of security and civil protection responsibilities, for the purposes of preventing vandalism, fire and environmental risks, in compliance with the GDPR. The installation and operation of cameras may constitute a legitimate measure, provided that it is necessary and proportionate to the specific intended purpose

Pursuant to Art. 35 and 36 of the GDPR, municipalities are required to carry out and submit a Data Protection Impact Assessment (DPIA). In this context, it should be considered whether the intended purpose can be achieved effectively by less intrusive means. At the same time, appropriate information for citizens on the processing of their data, including retention periods, should be ensured. 

Football club facial recognition: The Danish data protection agency Datatilsynet has, following an application from Lyngby Boldklub and AC Horsens, granted permission for the clubs to process biometric data and thus use automatic facial recognition during football matches. The permit only applies if the club in question is part of the Superliga, and that processing of biometric data for uniquely identifying a person can be done when hosting football matches, including training matches, as well as matches under UEFA auspices. 

Safety app for teens: The Swedish Data Protection Authority (IMY) is launching FantomApp, an app that helps young people protect their personal data on social media. The app can help with social media security settings, testing passwords and blurring photos, among other things. FantomApp is aimed at children between the ages of 10 and 15. It is free to download and is available on the App Store and Google Play as well as a web version. 

Receive our digest by email 

Sign up to receive our digest by email every 2 weeks

TIA working tools

When personal data is transferred to countries outside the EU/EEA based on, for example, the Commission’s Standard Clauses (SCC), the data exporter must ensure that the level of protection under the GDPR is not undermined. A prerequisite for this is that the data exporter has carried out a so-called Transfer Impact Assessment (TIA).

If you consider that the basis for the transfer is not sufficient, for example due to problematic legislation in the third country, you must establish additional measures to ensure an essentially equivalent level of protection for the data. If it is not possible to establish effective additional measures, you must not transfer the data, explains the Danish Datalitsynet. Some of the existing tools that might help with the task include: 

  • TIA guide from the French data protection regulator CNIL (with templates and explainers also available in English) 
  • The European Data Protection Supervisor’s TIA checklist targeted at EU institutions.  

Personalised pricing

In the US, the Federal Trade Commission is seeking public comment on a proposed enforcement policy statement regarding “personalised pricing,” which it describes as the use of personal data to set prices of goods and services based on the amount a company believes an individual consumer is willing to pay. Although personalised pricing is a long-established norm in some markets, it is not in many others, where consumers reasonably expect that the price they see for a product or service is the same price that any other consumer at the same place and time would see. 

In other news

Satirical deepfakes are illegal: The Italian data protection authority Garante has banned satirical deepfakes about Enrico Mentana (TV presenter). His image and voice had been manipulated using AI systems. The videos attributed statements to the well-known journalist that he never made, while his image was virtually placed in the television studio of the broadcaster for which he works.  The regulator, therefore, found a violation of Art. 5 of the GDPR, concerning the principles of lawfulness, fairness, and transparency, and Art. 25, concerning data protection by design and default. 

Uber multimillion fine over account deletion: In cooperation with the CNIL, the Dutch data protection agency AP fined Uber 824,990,000 euros for taking automated individual decisions concerning the drivers of its platform. The regulator considered that deactivations of drivers’ accounts in case of suspected fraud (temporary deactivation) as well as in case of low customer ratings (temporary deactivation and definitional) constitute automated individual decisions due to the complete absence of human intervention in the decision-making process. These decisions significantly affect drivers who, if their account is blocked, can no longer make rides and generate revenue. 

French tax data stolen: On 14 August, the French Ministry of Economy and Finance reported that the information system of the Directorate General of Public Finances (DGFiP) had been affected by a data breach (hacking), allowing a third party to access and extract information relating to individuals and professionals. The data concerned are tax information (reference income, family quotient, withholding tax rate, SIREN and company names) and cadastral data (addresses and areas of real estate). The usernames and passwords of individuals and professionals would not be affected by these breaches. The Ministry has notified these violations to the CNIL and will inform the persons concerned individually. 

And Finally

AI bots systemic risks: Many online posts or comments don’t come from people, but from computer programs, so-called bots. While simple bots on many websites react with predefined text snippets, modern, AI-powered bots can communicate at a human-like level, spreading misinformation or impersonating real people. They can be used for phishing attacks and fraud attempts. With new AI models, bots can even carry out attacks online independently.  

The European AI Act now mandates transparency towards natural persons. However, this obligation only applies to intended use. Anyone wishing to deceive will try to deliberately circumvent the AI bots’ labelling, explains the German Federal Office for Information Security. The EU’s Digital Services Act (DSA) has established further transparency and due diligence obligations for digital platforms. Yet, some are not applying the DSA standards and their own rules consistently enough, according to the European Commission’s observations. 

Open source AI models and data traceability: AI models published in open source can be downloaded, modified, specialised with new data, or combined with other models, before being made available again. The same model (eg, Kimi K3, Mistral Medium, LLaMA, etc.) can thus be at the origin of many derived models. The Genmod demonstrator developed by the CNIL (interface available in English) makes it possible to explore these links and to find the ancestors of a model as well as its descendants. This traceability is particularly useful for studying the consequences of the memorisation of training data by AI models. 

This makes it possible to study the conditions for exercising the rights provided for by the GDPR.

Do you need support on data protection, privacy or GDPR? TechGDPR can help.

Request your free consultation

Tags

Show more +