Ledger
GDPR Art. 42 · Certification
SOC 2 under GDPR Art. 42
TIER 00No legal effect
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Not an approved certification mechanism under Article 42: its criteria have not been approved by any supervisory authority or by the Board. Evidence relevant to Article 32 measures and processor due diligence, not of compliance with any data protection law.
- Invalidation trigger
- Criteria based on the scheme are approved by a supervisory authority under Article 58(3) or by the Board under Article 63.
- Sources
- Regulation (EU) 2016/679 (GDPR), Art. 42(5) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks, no SOC 2-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
- Regulation (EU) 2016/679 (GDPR), Art. 28(1) and 32(1) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- Confidence
- medium
- Jurisdiction
- European Union · coverage drafting
- Permanent URL
- /effect/european-union/gdpr-42/soc-2