Ledger
GDPR Art. 83(2)(j) · Adherence to approved certification as a factor in administrative fines
ISO/IEC 27701 under GDPR Art. 83(2)(j)
TIER 00No legal effect
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Does not attract the Article 83(2)(j) treatment given to adherence to an approved certification mechanism, although a supervisory authority may take it into account under technical and organisational measures.
- Invalidation trigger
- Criteria based on the scheme are approved by a supervisory authority under Article 58(3) or by the Board under Article 63.
- Sources
- Regulation (EU) 2016/679 (GDPR), Art. 83(2)(d) and (j) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks, no ISO/IEC 27701-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
- Confidence
- medium
- Jurisdiction
- European Union · coverage drafting
- Permanent URL
- /effect/european-union/gdpr-83-2-j/iso-27701