TIER 00
No legal effect
Market and procurement signal only. No statute references it.
Changes a negotiating position, not an outcome.
Legal effects at TIER 00
Artificial Intelligence ActRegulation (EU) 2024/1689European UnionCoverage drafting
001ISO/IEC 42001AI Act Art. 40TIER 00Confers no presumption of conformity with the AI Act. Article 40(1) attaches the presumption only to harmonised standards whose references are published in the Official Journal, and no reference has been published for the AI Act. EN 18286:2026, the European standard written for the Article 17 quality management system, was published by CEN-CENELEC in July 2026 but is not cited in the Official Journal either.
Invalidation trigger
A harmonised standard covering the requirement is cited in the Official Journal; EN 18286:2026 is the first candidate.
Sources
- Regulation (EU) 2024/1689 (AI Act), consolidated text of 27 July 2026, Art. 40(1) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng
- European Commission, Standardisation of the AI Act, standards referenced in the Official Journal after Commission assessment; prEN 18286 entered public enquiry on 30 October 2025 · retrieved 2026-09-17 · https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation
- CEN-CENELEC, EN 18286 in the Spotlight (31 July 2026), EN 18286:2026 published · retrieved 2026-09-17 · https://www.cencenelec.eu/news-events/news/2026/en-in-the-spotlight/2026-07-30-ai-quality-management/
VERIFIED 2026-09-17 · REVIEW BY 2026-11-16
Permalink /effect/european-union/ai-act-40/iso-42001
General Data Protection RegulationRegulation (EU) 2016/679European UnionCoverage drafting
002GDPR-CARPAGDPR Art. 46(2)(f)TIER 00An approved national Article 42 scheme, adopted by the Luxembourg supervisory authority, but not approved as a transfer tool under Article 46(2)(f).
Invalidation trigger
The Board approves the GDPR-CARPA criteria for use as a transfer tool.
Sources
- EDPB Opinion 1/2022 on the draft decision of the Luxembourg Supervisory Authority regarding the GDPR-CARPA certification criteria, section 2.1, "not a certification according to article 46(2)(f) of the GDPR" · retrieved 2026-09-17 · https://www.edpb.europa.eu/system/files/documents/2022-02/opinion_01-2022_gdpr-carpa_certification_criteria_en.pdf
- CNPD, The certification scheme GDPR-CARPA, criteria adopted by the CNPD on 13 May 2022 · retrieved 2026-09-17 · https://cnpd.public.lu/en/professionnels/outils-conformite/certification/gdpr-carpa.html
- EDPB register of certification mechanisms, seals and marks (filtered on certification as tool for transfers), GDPR-CARPA (LU) listed; not among certifications usable as a tool for transfers · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-46-2-f/gdpr-carpa003Global CBPRGDPR Art. 46(2)(f)TIER 00Not an approved certification under Article 42 and not a European transfer tool, although other jurisdictions, Singapore among them, recognise CBPR certification as a transfer basis.
Invalidation trigger
CBPR-based criteria are approved under Article 42 and recognised by the Board as a transfer tool.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 42(5) and 46(2)(f) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks, no CBPR-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
- Personal Data Protection Regulations 2021 (Singapore), reg. 12(2)(b), as amended by S 86/2026 with effect from 2 March 2026 · retrieved 2026-09-17 · https://sso.agc.gov.sg/SL/PDPA2012-S63-2021
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-46-2-f/global-cbpr004ISO/IEC 27001GDPR Art. 42TIER 00Not an Article 42 certification, because ISO is neither a supervisory authority nor the Board, and not evidence of compliance with a data protection statute. Good evidence of technical and organisational measures within the certified scope and of diligence in processor selection.
Invalidation trigger
Criteria based on the scheme are approved by a supervisory authority under Article 58(3) or by the Board under Article 63.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 42(5) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks, no ISO/IEC 27001-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
- Regulation (EU) 2016/679 (GDPR), Art. 28(1) and 32(1) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-42/iso-27001005ISO/IEC 27701GDPR Art. 42TIER 00Not a GDPR certification. Criteria published by an ISO technical committee have not been approved under Article 58(3) or Article 63; the defect is one of authority, not of substance.
Invalidation trigger
Criteria based on the scheme are approved by a supervisory authority under Article 58(3) or by the Board under Article 63.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 42(5) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks, no ISO/IEC 27701-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-42/iso-27701006ISO/IEC 27701GDPR Art. 46(2)(f)TIER 00Cannot be used as a transfer tool under Article 46(2)(f). The only criteria approved for that purpose are Europrivacy's.
Invalidation trigger
ISO/IEC 27701-based criteria are approved under Article 42 and recognised by the Board as a transfer tool.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 46(2)(f) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks (filtered on certification as tool for transfers), 1 item, Europrivacy Certification Scheme Extension for Certifying Data Importers under Article 46 · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-46-2-f/iso-27701007ISO/IEC 27701GDPR Art. 83(2)(j)TIER 00Does not attract the Article 83(2)(j) treatment given to adherence to an approved certification mechanism, although a supervisory authority may take it into account under technical and organisational measures.
Invalidation trigger
Criteria based on the scheme are approved by a supervisory authority under Article 58(3) or by the Board under Article 63.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 83(2)(d) and (j) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks, no ISO/IEC 27701-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-83-2-j/iso-27701008SOC 2GDPR Art. 42TIER 00Not an approved certification mechanism under Article 42: its criteria have not been approved by any supervisory authority or by the Board. Evidence relevant to Article 32 measures and processor due diligence, not of compliance with any data protection law.
Invalidation trigger
Criteria based on the scheme are approved by a supervisory authority under Article 58(3) or by the Board under Article 63.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 42(5) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks, no SOC 2-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
- Regulation (EU) 2016/679 (GDPR), Art. 28(1) and 32(1) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-42/soc-2009SOC 2GDPR Art. 46(2)(f)TIER 00Not a valid transfer tool under Article 46(2)(f). The only criteria approved for that purpose are Europrivacy's.
Invalidation trigger
SOC 2-based criteria are approved under Article 42 and recognised by the Board as a transfer tool.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 46(2)(f) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
- EDPB register of certification mechanisms, seals and marks (filtered on certification as tool for transfers), 1 item, Europrivacy Certification Scheme Extension for Certifying Data Importers under Article 46 · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
VERIFIED 2026-09-17 · REVIEW BY 2027-03-16
Permalink /effect/european-union/gdpr-46-2-f/soc-2
9 ROWS · 0 AT TIERS 03 TO 05. TIERS 03 TO 05 CHANGE AN OUTCOME. EVERYTHING BELOW CHANGES A NEGOTIATING POSITION.