HomeSearch

Lenses
Business lenslens
Certifying body lenslens
End user / data subject lenslens
Front-line staff lenslens
Government lenslens
Human rights / privacy advocate lenslens
Policymaker (Government lens)lens
Regulator / enforcer (Government lens)lens
Africa
Egyptplanned
Ghanaplanned
Kenyaplanned
Moroccoplanned
Nigeriaplanned
Rwandaplanned
South Africaplanned
Asia-Pacific
Australiaplanned
Chinadrafting
Hong Kongplanned
Indiaplanned
Indonesiaplanned
Japanplanned
Malaysiaplanned
New Zealandplanned
Philippinesplanned
Singaporeplanned
South Koreaplanned
Thailandplanned
Vietnamplanned
Europe
European Uniondrafting
Switzerlandplanned
Türkiyeplanned
United Kingdomplanned
Latin America
Argentinaplanned
Brazilplanned
Chileplanned
Colombiaplanned
Peruplanned
Uruguayplanned
Middle East
Bahrainplanned
Israelplanned
Qatarplanned
Saudi Arabiaplanned
United Arab Emiratesplanned
North America
Canadaplanned
Mexicoplanned
United States (federal)drafting
United States
Californiadrafting
Coloradoplanned
Connecticutplanned
Delawareplanned
Floridaplanned
Indianaplanned
Iowaplanned
Kentuckyplanned
Marylandplanned
Minnesotaplanned
Montanaplanned
Nebraskaplanned
New Hampshireplanned
New Jerseyplanned
Ohioplanned
Oregonplanned
Rhode Islandplanned
Tennesseeplanned
Texasplanned
Utahplanned
Virginiaplanned
Menu

TIER 00

No legal effect

Market and procurement signal only. No statute references it.

Changes a negotiating position, not an outcome.

Legal effects at TIER 00

Artificial Intelligence ActRegulation (EU) 2024/1689European UnionCoverage drafting

  1. 001ISO/IEC 42001AI Act Art. 40TIER 00Confers no presumption of conformity with the AI Act. Article 40(1) attaches the presumption only to harmonised standards whose references are published in the Official Journal, and no reference has been published for the AI Act. EN 18286:2026, the European standard written for the Article 17 quality management system, was published by CEN-CENELEC in July 2026 but is not cited in the Official Journal either.

    Invalidation trigger

    A harmonised standard covering the requirement is cited in the Official Journal; EN 18286:2026 is the first candidate.

    Sources

    1. Regulation (EU) 2024/1689 (AI Act), consolidated text of 27 July 2026, Art. 40(1) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng
    2. European Commission, Standardisation of the AI Act, standards referenced in the Official Journal after Commission assessment; prEN 18286 entered public enquiry on 30 October 2025 · retrieved 2026-09-17 · https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation
    3. CEN-CENELEC, EN 18286 in the Spotlight (31 July 2026), EN 18286:2026 published · retrieved 2026-09-17 · https://www.cencenelec.eu/news-events/news/2026/en-in-the-spotlight/2026-07-30-ai-quality-management/

    VERIFIED 2026-09-17 · REVIEW BY 2026-11-16

    Permalink /effect/european-union/ai-act-40/iso-42001

General Data Protection RegulationRegulation (EU) 2016/679European UnionCoverage drafting

  1. 002GDPR-CARPAGDPR Art. 46(2)(f)TIER 00An approved national Article 42 scheme, adopted by the Luxembourg supervisory authority, but not approved as a transfer tool under Article 46(2)(f).

    Invalidation trigger

    The Board approves the GDPR-CARPA criteria for use as a transfer tool.

    Sources

    1. EDPB Opinion 1/2022 on the draft decision of the Luxembourg Supervisory Authority regarding the GDPR-CARPA certification criteria, section 2.1, "not a certification according to article 46(2)(f) of the GDPR" · retrieved 2026-09-17 · https://www.edpb.europa.eu/system/files/documents/2022-02/opinion_01-2022_gdpr-carpa_certification_criteria_en.pdf
    2. CNPD, The certification scheme GDPR-CARPA, criteria adopted by the CNPD on 13 May 2022 · retrieved 2026-09-17 · https://cnpd.public.lu/en/professionnels/outils-conformite/certification/gdpr-carpa.html
    3. EDPB register of certification mechanisms, seals and marks (filtered on certification as tool for transfers), GDPR-CARPA (LU) listed; not among certifications usable as a tool for transfers · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en

    VERIFIED 2026-09-17 · REVIEW BY 2027-03-16

    Permalink /effect/european-union/gdpr-46-2-f/gdpr-carpa
  2. 003Global CBPRGDPR Art. 46(2)(f)TIER 00Not an approved certification under Article 42 and not a European transfer tool, although other jurisdictions, Singapore among them, recognise CBPR certification as a transfer basis.

    Invalidation trigger

    CBPR-based criteria are approved under Article 42 and recognised by the Board as a transfer tool.

    Sources

    1. Regulation (EU) 2016/679 (GDPR), Art. 42(5) and 46(2)(f) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
    2. EDPB register of certification mechanisms, seals and marks, no CBPR-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
    3. Personal Data Protection Regulations 2021 (Singapore), reg. 12(2)(b), as amended by S 86/2026 with effect from 2 March 2026 · retrieved 2026-09-17 · https://sso.agc.gov.sg/SL/PDPA2012-S63-2021

    VERIFIED 2026-09-17 · REVIEW BY 2027-03-16

    Permalink /effect/european-union/gdpr-46-2-f/global-cbpr
  3. 004ISO/IEC 27001GDPR Art. 42TIER 00Not an Article 42 certification, because ISO is neither a supervisory authority nor the Board, and not evidence of compliance with a data protection statute. Good evidence of technical and organisational measures within the certified scope and of diligence in processor selection.

    Invalidation trigger

    Criteria based on the scheme are approved by a supervisory authority under Article 58(3) or by the Board under Article 63.

    Sources

    1. Regulation (EU) 2016/679 (GDPR), Art. 42(5) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
    2. EDPB register of certification mechanisms, seals and marks, no ISO/IEC 27001-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
    3. Regulation (EU) 2016/679 (GDPR), Art. 28(1) and 32(1) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj

    VERIFIED 2026-09-17 · REVIEW BY 2027-03-16

    Permalink /effect/european-union/gdpr-42/iso-27001
  4. 005ISO/IEC 27701GDPR Art. 42TIER 00Not a GDPR certification. Criteria published by an ISO technical committee have not been approved under Article 58(3) or Article 63; the defect is one of authority, not of substance.

    Invalidation trigger

    Criteria based on the scheme are approved by a supervisory authority under Article 58(3) or by the Board under Article 63.

    Sources

    1. Regulation (EU) 2016/679 (GDPR), Art. 42(5) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
    2. EDPB register of certification mechanisms, seals and marks, no ISO/IEC 27701-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en

    VERIFIED 2026-09-17 · REVIEW BY 2027-03-16

    Permalink /effect/european-union/gdpr-42/iso-27701
  5. 006ISO/IEC 27701GDPR Art. 46(2)(f)TIER 00Cannot be used as a transfer tool under Article 46(2)(f). The only criteria approved for that purpose are Europrivacy's.

    Invalidation trigger

    ISO/IEC 27701-based criteria are approved under Article 42 and recognised by the Board as a transfer tool.

    Sources

    1. Regulation (EU) 2016/679 (GDPR), Art. 46(2)(f) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
    2. EDPB register of certification mechanisms, seals and marks (filtered on certification as tool for transfers), 1 item, Europrivacy Certification Scheme Extension for Certifying Data Importers under Article 46 · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en

    VERIFIED 2026-09-17 · REVIEW BY 2027-03-16

    Permalink /effect/european-union/gdpr-46-2-f/iso-27701
  6. 007ISO/IEC 27701GDPR Art. 83(2)(j)TIER 00Does not attract the Article 83(2)(j) treatment given to adherence to an approved certification mechanism, although a supervisory authority may take it into account under technical and organisational measures.

    Invalidation trigger

    Criteria based on the scheme are approved by a supervisory authority under Article 58(3) or by the Board under Article 63.

    Sources

    1. Regulation (EU) 2016/679 (GDPR), Art. 83(2)(d) and (j) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
    2. EDPB register of certification mechanisms, seals and marks, no ISO/IEC 27701-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en

    VERIFIED 2026-09-17 · REVIEW BY 2027-03-16

    Permalink /effect/european-union/gdpr-83-2-j/iso-27701
  7. 008SOC 2GDPR Art. 42TIER 00Not an approved certification mechanism under Article 42: its criteria have not been approved by any supervisory authority or by the Board. Evidence relevant to Article 32 measures and processor due diligence, not of compliance with any data protection law.

    Invalidation trigger

    Criteria based on the scheme are approved by a supervisory authority under Article 58(3) or by the Board under Article 63.

    Sources

    1. Regulation (EU) 2016/679 (GDPR), Art. 42(5) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
    2. EDPB register of certification mechanisms, seals and marks, no SOC 2-based criteria among the 17 entries · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
    3. Regulation (EU) 2016/679 (GDPR), Art. 28(1) and 32(1) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj

    VERIFIED 2026-09-17 · REVIEW BY 2027-03-16

    Permalink /effect/european-union/gdpr-42/soc-2
  8. 009SOC 2GDPR Art. 46(2)(f)TIER 00Not a valid transfer tool under Article 46(2)(f). The only criteria approved for that purpose are Europrivacy's.

    Invalidation trigger

    SOC 2-based criteria are approved under Article 42 and recognised by the Board as a transfer tool.

    Sources

    1. Regulation (EU) 2016/679 (GDPR), Art. 46(2)(f) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
    2. EDPB register of certification mechanisms, seals and marks (filtered on certification as tool for transfers), 1 item, Europrivacy Certification Scheme Extension for Certifying Data Importers under Article 46 · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en

    VERIFIED 2026-09-17 · REVIEW BY 2027-03-16

    Permalink /effect/european-union/gdpr-46-2-f/soc-2

9 ROWS · 0 AT TIERS 03 TO 05. TIERS 03 TO 05 CHANGE AN OUTCOME. EVERYTHING BELOW CHANGES A NEGOTIATING POSITION.