Ledger
GDPR Art. 42 · Certification
ISO/IEC 27001 under GDPR Art. 42
TIER 00No legal effect
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Not an Article 42 certification, because ISO is neither a supervisory authority nor the Board, and not evidence of compliance with a data protection statute. Good evidence of technical and organisational measures within the certified scope and of diligence in processor selection.
- Invalidation trigger
- Criteria based on the scheme are approved by a supervisory authority under Article 58(3) or by the Board under Article 63.
- Sources
- Regulation (EU) 2016/679 (GDPR), Art. 42(5) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks, no ISO/IEC 27001-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
- Regulation (EU) 2016/679 (GDPR), Art. 28(1) and 32(1) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- Confidence
- medium
- Jurisdiction
- European Union · coverage drafting
- Permanent URL
- /effect/european-union/gdpr-42/iso-27001