European Union
Coverage draftingAlso: EEA, Europe, GDPR, AI Act, Brussels
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Europrivacy is the only Art. 42 certification approved as a transfer tool; other approved schemes, such as GDPR-CARPA and EuroPriSe, are not. SOC 2 and ISO/IEC 27001 carry no legal effect under the GDPR provisions assessed.
Instruments
- Artificial Intelligence ActAI Act · Regulation (EU) 2024/1689
- General Data Protection RegulationGDPR · Regulation (EU) 2016/679
Regulator
No regulator with a sourced address is recorded for European Union yet.
Exercisable rights
Directly exercisable against the controller, free of charge, with a right to complain to the supervisory authority where you live, work or where the infringement took place
Through each lens
End user / data subject
What can I actually do about this today, and what does it cost me.
No end user / data subject analysis for European Union yet.
Business
What does this obligate us to build, and by when.
No business analysis for European Union yet.
Government
Government is one lens carrying two sub-lenses, each with judicial reviewability analysis.
No government analysis for European Union yet.
Policymaker
What did the drafters intend, and what did the text achieve.
No policymaker analysis for European Union yet.
Regulator / enforcer
What can this authority make stick on appeal.
No regulator / enforcer analysis for European Union yet.
Certifying body
What is the scope of what we are attesting to.
No certifying body analysis for European Union yet.
Front-line staff
What do I do when this lands on my desk.
No front-line staff analysis for European Union yet.
Human rights / privacy advocate
Who does this regime fail, and can that be shown.
No human rights / privacy advocate analysis for European Union yet.
Legal effects
Artificial Intelligence ActRegulation (EU) 2024/1689European UnionCoverage drafting
001ISO/IEC 42001AI Act Art. 40TIER 00Confers no presumption of conformity with the AI Act. Article 40(1) attaches the presumption only to harmonised standards whose references are published in the Official Journal, and no reference has been published for the AI Act. EN 18286:2026, the European standard written for the Article 17 quality management system, was published by CEN-CENELEC in July 2026 but is not cited in the Official Journal either.
Invalidation trigger
A harmonised standard covering the requirement is cited in the Official Journal; EN 18286:2026 is the first candidate.
Sources
- Regulation (EU) 2024/1689 (AI Act), consolidated text of 27 July 2026, Art. 40(1) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng
- European Commission, Standardisation of the AI Act, standards referenced in the Official Journal after Commission assessment; prEN 18286 entered public enquiry on 30 October 2025 · retrieved 2026-09-17 · https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation
- CEN-CENELEC, EN 18286 in the Spotlight (31 July 2026), EN 18286:2026 published · retrieved 2026-09-17 · https://www.cencenelec.eu/news-events/news/2026/en-in-the-spotlight/2026-07-30-ai-quality-management/
VERIFIED 2026-09-17 · REVIEW BY 2026-11-16
Permalink /effect/european-union/ai-act-40/iso-42001
General Data Protection RegulationRegulation (EU) 2016/679European UnionCoverage drafting
002GDPR-CARPAGDPR Art. 46(2)(f)TIER 00An approved national Article 42 scheme, adopted by the Luxembourg supervisory authority, but not approved as a transfer tool under Article 46(2)(f).
Invalidation trigger
The Board approves the GDPR-CARPA criteria for use as a transfer tool.
Sources
- EDPB Opinion 1/2022 on the draft decision of the Luxembourg Supervisory Authority regarding the GDPR-CARPA certification criteria, section 2.1, "not a certification according to article 46(2)(f) of the GDPR" · retrieved 2026-09-17 · https://www.edpb.europa.eu/system/files/documents/2022-02/opinion_01-2022_gdpr-carpa_certification_criteria_en.pdf
- CNPD, The certification scheme GDPR-CARPA, criteria adopted by the CNPD on 13 May 2022 · retrieved 2026-09-17 · https://cnpd.public.lu/en/professionnels/outils-conformite/certification/gdpr-carpa.html
- EDPB register of certification mechanisms, seals and marks (filtered on certification as tool for transfers), GDPR-CARPA (LU) listed; not among certifications usable as a tool for transfers · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-46-2-f/gdpr-carpa003Global CBPRGDPR Art. 46(2)(f)TIER 00Not an approved certification under Article 42 and not a European transfer tool, although other jurisdictions, Singapore among them, recognise CBPR certification as a transfer basis.
Invalidation trigger
CBPR-based criteria are approved under Article 42 and recognised by the Board as a transfer tool.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 42(5) and 46(2)(f) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks, no CBPR-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
- Personal Data Protection Regulations 2021 (Singapore), reg. 12(2)(b), as amended by S 86/2026 with effect from 2 March 2026 · retrieved 2026-09-17 · https://sso.agc.gov.sg/SL/PDPA2012-S63-2021
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-46-2-f/global-cbpr004ISO/IEC 27001GDPR Art. 42TIER 00Not an Article 42 certification, because ISO is neither a supervisory authority nor the Board, and not evidence of compliance with a data protection statute. Good evidence of technical and organisational measures within the certified scope and of diligence in processor selection.
Invalidation trigger
Criteria based on the scheme are approved by a supervisory authority under Article 58(3) or by the Board under Article 63.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 42(5) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks, no ISO/IEC 27001-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
- Regulation (EU) 2016/679 (GDPR), Art. 28(1) and 32(1) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-42/iso-27001005ISO/IEC 27701GDPR Art. 42TIER 00Not a GDPR certification. Criteria published by an ISO technical committee have not been approved under Article 58(3) or Article 63; the defect is one of authority, not of substance.
Invalidation trigger
Criteria based on the scheme are approved by a supervisory authority under Article 58(3) or by the Board under Article 63.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 42(5) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks, no ISO/IEC 27701-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-42/iso-27701006ISO/IEC 27701GDPR Art. 46(2)(f)TIER 00Cannot be used as a transfer tool under Article 46(2)(f). The only criteria approved for that purpose are Europrivacy's.
Invalidation trigger
ISO/IEC 27701-based criteria are approved under Article 42 and recognised by the Board as a transfer tool.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 46(2)(f) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks (filtered on certification as tool for transfers), 1 item, Europrivacy Certification Scheme Extension for Certifying Data Importers under Article 46 · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-46-2-f/iso-27701007ISO/IEC 27701GDPR Art. 83(2)(j)TIER 00Does not attract the Article 83(2)(j) treatment given to adherence to an approved certification mechanism, although a supervisory authority may take it into account under technical and organisational measures.
Invalidation trigger
Criteria based on the scheme are approved by a supervisory authority under Article 58(3) or by the Board under Article 63.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 83(2)(d) and (j) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks, no ISO/IEC 27701-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-83-2-j/iso-27701008SOC 2GDPR Art. 42TIER 00Not an approved certification mechanism under Article 42: its criteria have not been approved by any supervisory authority or by the Board. Evidence relevant to Article 32 measures and processor due diligence, not of compliance with any data protection law.
Invalidation trigger
Criteria based on the scheme are approved by a supervisory authority under Article 58(3) or by the Board under Article 63.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 42(5) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks, no SOC 2-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
- Regulation (EU) 2016/679 (GDPR), Art. 28(1) and 32(1) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-42/soc-2009SOC 2GDPR Art. 46(2)(f)TIER 00Not a valid transfer tool under Article 46(2)(f). The only criteria approved for that purpose are Europrivacy's.
Invalidation trigger
SOC 2-based criteria are approved under Article 42 and recognised by the Board as a transfer tool.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 46(2)(f) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks (filtered on certification as tool for transfers), 1 item, Europrivacy Certification Scheme Extension for Certifying Data Importers under Article 46 · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-46-2-f/soc-2010EuroprivacyGDPR Art. 83(2)(j)TIER 02Adherence to an approved certification mechanism is a factor in whether a fine is imposed and in its amount. A modest benefit, contingent on already being in enforcement; under Article 42(4) certification does not reduce the controller's or processor's responsibility.
Invalidation trigger
The certificate is withdrawn or lapses, or the processing at issue falls outside the certified processing operations.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 83(2)(j) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- Regulation (EU) 2016/679 (GDPR), Art. 42(4) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-83-2-j/europrivacy011EuroprivacyGDPR Art. 42TIER 05Approved by the EDPB as the first certification mechanism usable as a transfer tool under Articles 42 and 46 (Opinion 15/2026). Opinion 14/2026 also extended the criteria to controllers and processors outside the EEA that are subject to Article 3(2).
Invalidation trigger
The EDPB withdraws or amends Opinion 15/2026, or the certificate is withdrawn or lapses (maximum validity three years).
Sources
- EDPB Opinion 15/2026 on the Europrivacy certification criteria as European Data Protection Seal to be used as tool for transfers, paras 20, 25 and 53 · retrieved 2026-09-17 · https://www.edpb.europa.eu/system/files/2026-04/edpb_opinion_202615_europrivacy_en.pdf
- EDPB Opinion 14/2026 on the Europrivacy certification criteria as European Data Protection Seal, paras 27 and 54 · retrieved 2026-09-17 · https://www.edpb.europa.eu/system/files/2026-05/edpb_opinion_202614_europrivacy_en.pdf
- EDPB register of certification mechanisms, seals and marks (filtered on certification as tool for transfers), 1 item, Europrivacy Certification Scheme Extension for Certifying Data Importers under Article 46 · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
- Regulation (EU) 2016/679 (GDPR), Art. 42(2), (5) and (7) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-42/europrivacy012EuroprivacyGDPR Art. 46(2)(f)TIER 05An approved Article 42 certification, together with binding and enforceable commitments of the importer, is an appropriate safeguard for transfers. Europrivacy's criteria are the only ones approved for that purpose (Opinion 15/2026).
Invalidation trigger
The EDPB withdraws or amends Opinion 15/2026, the certificate is withdrawn or lapses, or the importer's binding and enforceable commitments are absent.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 46(2)(f) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB Opinion 15/2026 on the Europrivacy certification criteria as European Data Protection Seal to be used as tool for transfers, paras 25, 52 and 53 · retrieved 2026-09-17 · https://www.edpb.europa.eu/system/files/2026-04/edpb_opinion_202615_europrivacy_en.pdf
- EDPB register of certification mechanisms, seals and marks (filtered on certification as tool for transfers), 1 item, Europrivacy Certification Scheme Extension for Certifying Data Importers under Article 46 · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-46-2-f/europrivacy
12 ROWS · 2 AT TIERS 03 TO 05. TIERS 03 TO 05 CHANGE AN OUTCOME. EVERYTHING BELOW CHANGES A NEGOTIATING POSITION.
Sources
- Regulation (EU) 2016/679 (GDPR), Arts. 12(5), 15-22 and 77(1) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks, 17 entries; one usable as a tool for transfers (Europrivacy extension); GDPR-CARPA and EuroPriSe listed · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en