This publication from the European Data Protection Board marks the tenth anniversary of the GDPR by reflecting on its evolution and current enforcement priorities. While no new legal text or binding…
Opinion 13/2026 on the draft decision of the Office of the Data Protection Ombudsman (FI SA) regarding the approval of the requirement for accreditation of a certification body pursuant to Article 43(3) GDPR
General Data Protection Regulation. Sourced from EDPB, summarised by Matproof.
AI Analysis
What changed and what to do.
The European Data Protection Board has published Opinion 13/2026, endorsing a draft decision by the Finnish Data Protection Ombudsman to approve accreditation requirements for certification bodies under Article 43(3) GDPR. This opinion clarifies the standards that certification bodies must meet to be accredited for GDPR certification schemes, such as those for data processing seals or marks. It does not introduce new law but formalizes the criteria that national accreditation bodies will use when assessing these organizations.
This change primarily affects certification bodies seeking to offer GDPR-related certifications, as well as data controllers and processors in any sector that may wish to use accredited certification to demonstrate compliance. Organizations that rely on or plan to develop GDPR certification schemes should pay close attention, as the opinion sets a precedent for how other EU supervisory authorities may handle similar accreditation requests.
Compliance teams should review the opinion to understand the specific accreditation requirements, particularly around independence, expertise, and conflict-of-interest rules. If your organization uses or intends to use a certification body, verify that the body is accredited under these new standards. For those developing internal certification programs, begin aligning your processes with the criteria outlined in the opinion to ensure future accreditation readiness.
This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.
More GDPR updates
Latest in General Data Protection Regulation.
The European Data Protection Board has published its formal Opinion approving the updated Europrivacy certification criteria as a European Data Protection Seal. This approval is significant as it…
The European Data Protection Board has published its formal Opinion 14/2026, approving the updated Europrivacy certification criteria as a European Data Protection Seal under Article 42.5 of the…
The European Data Protection Board (EDPB) has launched its 2026 Coordinated Enforcement Framework (CEF) action, focusing on the practical application of GDPR transparency and information obligations.…
Map this to your controls
Connect regulatory changes to your compliance work.
Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.