Europrivacy Community
  • Home
  • Login
  • Register
  • Obtain Welcome Packs
  • News & Public Resources
  • About
    • Terms & Conditions
    • Cookie & Privacy Policy
  • Contact
Select Page
betterdocs-category-icon

About Europrivacy

39
  • Is the certification reducing the risk of fines?
  • How are we informed in case of requirement changes?
  • What is Europrivacy?
  • How can I learn how to use Europrivacy?
  • What are Europrivacy Official Partners, Implementers, and Auditors?
  • What resources are available for Europrivacy?
  • What are the advantages of the Welcome Pack?
  • Can applicants from outside the EU and EEA receive a Europrivacy certificate? 
  • Meaning of verbal forms: shall, should, may, can
  • What is the scope and purpose of Europrivacy certification?
  • Europrivacy Overview
    • What value does Europrivacy bring for data controllers and processors?
    • How does Europrivacy compare to other certification schemes?
    • How does Europrivacy guarantee uniformity, consistency, and homogeneity in its certifications?
    • How does Europrivacy address data processing with higher risks for the data subjects (i.e., special categories of data)?
    • How does Europrivacy address domain and technology specific risks for data subjects?
    • How can Europrivacy assess a large diversity of data processing in an adequate and reliable manner?
    • How does Europrivacy address the national obligations?
    • How does Europrivacy address and comply with the evolution of law and technology?
    • Why and how does Europrivacy encompass all GDPR obligations that may impact data subjects and impose legal risks for Data Controllers and Processors?
    • Why does Europrivacy focus on compliance with the GDPR obligations instead of creating additional requirements?
    • How does Europrivacy guarantee impartiality?
    • What can be certified?
    • Why should a company certify its data processing activities? Is it a legal obligation?
    • What is the scope of data processing?
    • How can I get support for conducting the Europrivacy assessments?
    • How is the maintenance and development of the certification scheme funded?
    • Does an official Partner have to pay for using the Europrivacy Certification Scheme? Does the Partner have to purchase the Welcome Pack?
    • How is the certification scheme funded?
    • When performing a NOCAR, is it sufficient to use the complementary national obligations identified on the Europrivacy Community and Resources website?
    • What does high-risk data processing mean?
    • What is the scope and purpose of Europrivacy certification?
    • How does Europrivacy solve the dilemma between universal versus specialised certification scheme models?
    • What value does Europrivacy bring for data subjects?
  • Rules and obligations
    • What are the fundamental rules to follow when applying Europrivacy?
  • Partnership and partners' duties
    • Where should a partner start delivering Europrivacy services?
    • What is required from a Certification Body to be authorised to deliver formal Europrivacy certification?
    • Can a certification body deliver certificates in other countries?
    • What are the required competencies of the personnel of the Certification Body?
    • What is the role of Implementers?
betterdocs-category-icon

Prepare an offer

8
  • How to pitch Europrivacy Value Proposition?
  • Why should an applicant choose Europrivacy?
  • How much does a Europrivacy certification cost?
  • What is the Europrivacy Welcome Pack?
  • What is usually included in a Europrivacy Welcome Offer by a consulting or law firm?
  • Is the Europrivacy Welcome Pack mandatory?
  • How to calculate the budget for an offer?
  • How to make a certification plan for the Applicant?
betterdocs-category-icon

Prepare and document compliance

5
  • Who can apply for certification?
  • Application and Target of Evaluation
    • Who can apply for certification?
    • How to specify the Target of Evaluation?
    • How to pass the token from an Implementer to a Certification Body once the Target of Evaluation is ready for certification?
  • Document compliance
    • How much time would the documentation and assessment require?
betterdocs-category-icon

Assess and certify compliance

7
  • How long does it take to get certified?
  • Is it possible to certify a data processing activity under joint controllership?
  • Assessment process
    • How long does it take to get certified?
    • What is the difference between Major and Minor Non-Conformities?
    • Can a certificate be delivered in the presence of non-conformities? When is it prohibited to deliver a certificate?
  • Using the criteria
    • Is an ISO certification required to obtain the Europrivacy certification?
    • Can an ISO/IEC 27701 or 27001 certification provide all or part of the evidence of compliance to comply with the Europrivacy criteria?   
betterdocs-category-icon

Europrivacy criteria, checks and controls

10
  • How does Europrivacy organise its criteria, checks and controls?
  • How are Europrivacy criteria specified?
  • Applying the criteria
    • How does Europrivacy organise its criteria, checks and controls?
    • How are criteria differentiated?
    • How are Europrivacy criteria specified?
    • Why does Europrivacy combine several criteria to assess some GDPR requirements?
    • How does Europrivacy ensure the auditability of its criteria?
    • How does Europrivacy address the needs of SMEs?
    • How to determine the number of criteria and to estimate the Audit time?
    • What are the differences between Criteria; Checks and Controls; and Checklists?
betterdocs-category-icon

Communicate and maintain compliance

3
  • How are we informed in case of requirement changes?
  • Is there a surveillance audit required during the validity period of the certificate?
  • Surveillance audits and recertification
    • Is there a surveillance audit required during the validity period of the certificate?
betterdocs-category-icon

Criteria Guidance

207
  • G - Europrivacy GDPR Core Criteria
    • G.1 - Lawfulness of Data Processing
      • G.1.1 - Lawfulness of processing
        • G.1.1.1 – Lawfulness assessment of the processing
        • G.1.1.2 – Lawfulness justification
        • G.1.1.3 – National Regulation Compliance
        • G.1.1.4 – Adequate qualification of the expert
      • G.1.2 - Complementary requirements for consent to be valid (if applicable)
        • G.1.2.1 – Formal requirements for consent
        • G.1.2.2 – Absence of unnecessary constraints for consent
        • G.1.2.3 – Right to withdraw consent
      • G.1.3 - Complementary requirements for consent to be valid (if applicable)
        • G.1.3.1 – Lawfulness of data processing of minors of age and Verification of parental consent
    • G.2 - Special Data Processing
      • G.2.1 - Adequacy of processing special categories of data
        • G.2.1.2 – Legal basis for processing special categories of data
        • G.2.1.1 – Special categories of data – DPO validation
      • G.2.2 - Processing of data relating to criminal convictions and offences (if applicable)
        • G.2.2.1 – Data on criminal convictions and offences
    • G.3 - Rights of the Data Subjects
      • G.3.1 - Transparent information, communication and modalities for exercising the rights of the data subjects
        • G.3.1.1 – Duty to inform in clear language
        • G.3.1.2 – Duty to facilitate data subject rights exercise
        • G.3.1.3 – Ensuring proper data subject rights management and recording
        • G.3.1.4 – Information without undue delay
        • G.3.1.6 – Duty to inform and justify non-action
        • G.3.1.5 – Electronic response
        • G.3.1.7 – Free of charge
        • G.3.1.8 – Machine-readability of icons
      • G.3.2 - Information to be provided where personal data are collected from the data subject
        • G.3.2.1 – Duty to inform
        • G.3.2.2 – Further processing
        • G.3.2.3 – Tolerated Exemption
      • G.3.3 - Information to be provided where personal data have not been obtained from the data subject
        • G.3.3.1 – Duty to inform
        • G.3.3.2 – Duty to inform in due time
        • G.3.3.3 – Duty to inform on purpose extension
        • G.3.3.4 – Tolerated Exemption
      • G.3.4 - Right of access by the data subject
        • G.3.4.1 – Right of access by the data subject
        • G.3.4.2 – Duty to provide a copy
        • G.3.4.3 – Duty to protect the rights of others
      • G.3.5 - Right to rectification
        • G.3.5.1 – Right to rectification
      • G.3.6 - Right to erasure ('right to be forgotten')
        • G.3.6.1 – Right to erasure
        • G.3.6.2 – Duty to relay the request to other data Controllers
        • G.3.6.3 – Tolerated Exemption
      • G.3.7 - Right to restriction of processing
        • G.3.7.1 – Right to restriction of processing
      • G.3.8 - Notification obligation regarding rectification or erasure of personal data or restriction of processing
        • G.3.8.1 – Duty to inform recipients
        • G.3.8.2 – Duty to inform data subjects on recipients if requested
      • G.3.9 - Right to data portability
        • G.3.9.1 – Right to data portability
      • G.3.10 - Right to object
        • G.3.10.1 – Effectiveness of the right to object
        • G.3.10.2 – Clear information on the right to object
      • G.3.11 - Right not to be subject to automated individual decision-making, including profiling
        • G.3.11.1 – Automated individual decision-making, including profiling
        • G.3.11.2 – Rights to obtain human intervention and to contest
    • G.4 - Data Controller Responsibility
      • G.4.1 - Responsibility of the Controller
        • G.4.1.1 – Documentation on technical and organisational measures
        • G.4.1.2 – Duty to review and update
        • G.4.1.3 – Data Protection Policies
    • G.5 - Data Processors (or sub Processors)
      • G.5.1 - Processor
        • G.5.1.1 – Restriction on use of Processors
        • G.5.1.2 – Contractual necessity for Controllers
        • G.5.1.3 – Contractual necessity for Processors
        • G.5.1.4 – Contractual obligations of Processors
        • G.5.1.5 – Complementary demonstration of Processors’ compliance
      • G.5.2 - Processing under the authority of the Controller of Processor
        • G.5.2.1 – Process on instruction only
      • G.5.3 - Records of processing activities
        • G.5.3.1 – Record of data processing by Controller
        • G.5.3.2 – Record of data processing by Processor
        • G.5.3.3 – Data Processing instructions records
        • G.5.3.4 – Completeness of the Registry
    • G.6 - Security of Processing and Data Protection by Design
      • G.6.1 - Data protection by design and by default
        • G.6.1.1 – Data protection by design and by default
        • G.6.1.2 – Data minimisation by default
      • G.6.2 - Security of processing
        • G.6.2.1 – Security policy
        • G.6.2.2 – Process on instruction only
        • G.6.2.3 – Contractual obligation to confidentiality
        • G.6.2.4 – Risk assessment for the data processing
        • G.6.2.5 – Access rights policy and registry
        • G.6.2.7 – Continuity, integrity, and availability
        • G.6.2.6 – Access and transfer logs
        • G.6.2.8 – Communication encryption
        • G.6.2.9 – Duty to backup
        • G.6.2.10 – Complementary Contextual Requirements
        • G.6.2.11 – Complementary Technical and Organisational Measures
    • G.7 - Management of Data Breaches
      • G.7.1 - Notification of a personal data breach to the Supervisory Authority
        • G.7.1.1 – Duty to document data breaches
        • G.7.1.2 – Duty of the Controller to notify and communicate data breaches
        • G.7.1.3 – Duty of the Processor to communicate data breaches without undue delay
        • G.7.1.4 – Notification requirements
      • G.7.2 - Communication of a personal data breach to the data subject
        • G.7.2.1 – Breach communication requirements
        • G.7.2.2 – Tolerated Exemptions
    • G.8 - Data Protection Impact Assessment (DPIA)
      • G.8.1 - Duty to assess if Data Protection Impact Assessment (DPIA) is required
        • G.8.1.1 – Data Protection Impact Assessment (DPIA)
        • G.8.1.2 – Tolerated Exemption
      • G.8.2 - Data Protection Impact Assessment Check (DPIA) requirements
        • G.8.2.1 – DPIA Process requirements
        • G.8.2.2 – DPIA content requirements
        • G.8.2.3 – Data subjects involvement requirement
        • G.8.2.4 – DPIA review in case of change of risks
        • G.8.2.5 – Duty to consult the Supervisory Authority in case of identified high risk
    • G.9 - Data Protection Officer (DPO)
      • G.9.1 - Designation of the data protection officer
        • G.9.1.1 – Designation of the data protection officer
        • G.9.1.2 – DPO requirements
        • G.9.1.3 – DPO contact details communication
      • G.9.2 - Position of the data protection officers
        • G.9.2.1 – DPO mandate communication
        • G.9.2.2 – DPO support
        • G.9.2.4 – Data subjects access to the DPO
        • G.9.2.3 – DPO independence
        • G.9.2.5 – DPO contractual clauses
        • G.9.2.6 – Adequacy of DPO work time
      • G.9.3 - Tasks of the data protection officer
        • G.9.3.1 – DPO tasks and duties
        • G.9.3.2 – Duty to train personnel on data protection
    • G.10 - Transfers of personal data to third countries or international organisations (if applicable)
      • G.10.1 - General principles for transfers
        • G.10.1.1 – Cross border transfer to third countries validation
        • G.10.1.2 – Cross-border transfer legal basis
        • G.10.1.3 – Cross-border transfer based on appropriate safeguards
        • G.10.1.4 – Cross-border transfer based on derogations for specific situations
        • G.10.1.5 – Complementary risk assessment of data transfer to third-countries without adequacy decision
        • G.10.1.6 – Commitment of the data receiver
      • G.10.2 - Transfers subject to appropriate safeguards
        • G.10.2.1 – Complementary requirements for appropriate safeguards
  • T - Technical and Organisational Measures (TOM)
    • T.1 - Core Security Requirements
      • T.1.1 - Data Access Restriction
        • T.1.1.1 – Access rights minimisation (least privilege)
        • T.1.1.2 – Access rights registry updates
        • T.1.1.3 – Password policy
        • T.1.1.4 – Physical access restriction
        • T.1.1.5 – Bring Your Own Device restriction policy
        • T.1.1.6 – Automated session logout
        • T.1.1.7 – Multi-factor authentication
      • T.1.2 - Data Encryption
        • T.1.2.1 – Encrypted communication over public networks
        • T.1.2.2 – Backups encryption
        • T.1.2.3 – User Log data encryption
        • T.1.2.4 – Data at rest encryption
      • T.1.3 - Other Security Measures
        • T.1.3.1 – Backup recovery test
        • T.1.3.2 – Regular server updates
        • T.1.3.3 – Denial of service mitigation
        • T.1.3.4 – Fire and flood protection
        • T.1.3.5 – Firewalling with least privilege port policy
        • T.1.3.6 – Updated antivirus
    • T.2 - Extended Security Requirements
      • T.2.1 - Connectivity Checks for Internet access
        • T.2.1.1 – HTTPS enabled
        • T.2.1.2 – SDNS enabled
        • T.2.1.3 – SSL
        • T.2.1.4 – TLS
        • T.2.1.5 – SSH
        • T.2.1.6 – Backward incompatibility
        • T.2.1.7 – WiFi
      • T.2.2 - Crypto Management
        • T.2.2.1 – Protection Tools Management Policy
        • T.2.2.2 – Cryptographic Policy
        • T.2.2.3 – Key Length
        • T.2.2.4 – Key Update
        • T.2.2.5 – Key revocation
      • T.2.3 - Penetration Tests and Monitoring
        • T.2.3.1 – PEN Test
        • T.2.3.2 – Intrusion Detection
  • C - Complementary Contextual Checks and Controls
    • C.1 - Public Websites Complementary Checks (where applicable)
      • C.1.1.1 – HTTPS enabled
    • C.4 - Video Cameras and Audio Monitoring Complementary Checks (where applicable)
      • C.4.1.1 – Camera deployment validation by the DPO
      • C.4.1.2 – Information on video surveillance
      • C.4.1.3 – Surveillance of customer space
      • C.4.1.4 – Video network protection
      • C.4.1.5 – Access authentication to the camera
      • C.4.1.6 – Access restriction to the video server
    • C.5 - Internet of Things Deployments Complementary Checks (where applicable)
      • C.5.1 - Complementary Checks and Controls for Internet of Things deployments
        • C.5.1.1 – Impact assessment complementary requirements
        • C.5.1.2 – IoT network vulnerability risk assessment
        • C.5.1.3 – IoT deployment documentation
        • C.5.1.4 – IoT firmware updates
        • C.5.1.5 – IoT encryption
        • C.5.1.7 – Modification of “by default” passwords
        • C.5.1.6 – IoT access authentication
        • C.5.1.8 – Least privileged principle
      • C.5.2 - Complementary Checks and Controls for Internet of Things deployed in areas accessible to the public
        • C.5.2.1 – IoT area signage
        • C.5.2.2 – IoT transparent information
        • C.5.2.4 – Resilience to outage
        • C.5.2.3 – Physical protection
      • C.5.3 - Complementary Checks and Controls for IoT with Special Categories of Data
        • C.5.3.1 – Authentication reliability
    • C.6 - Smart Cities Complementary Checks (where applicable)
      • C.6.1.1 – Involvement of data subjects in the DPIA
      • C.6.1.2 – Information of data subjects
      • C.6.1.3 – Online information on IoT data processing
      • C.6.1.4 – IoT devices information
      • C.6.1.5 – Website information ease of access
    • C.7 - Biometric, Medical and Health Data Complementary Checks (where applicable)
      • C.7.1.1 – Data Protection Impact Assessment
      • C.7.1.2 – Pseudonymisation
      • C.7.1.3 – Multi-factor authentication
      • C.7.1.4 – Contact tracing applications restrictions
    • C.8 - Automated Decision-making Complementary Checks (where applicable)
      • C.8.1.1 – Test and analysis
      • C.8.1.2 – Written documentation from third party
      • C.8.1.4 – Procedure for human intervention
      • C.8.1.3 – Rights to explanations on the decisions
    • C.9 - Blockchain and Distributed Ledger Technology Complementary Checks (where applicable)
      • C.9.1.1 – Data Protection Impact Assessment
      • C.9.1.2 – Compliance with effective exercise of data subject rights
      • C.9.1.3 – Encryption
      • C.9.1.4 – Complementary check and clarification of responsibilities
    • C.10 - Data Anonymisation and Pseudonymisation Solutions Complementary Checks (where applicable)
      • C.10.1 - Anonymisation and risk of reidentification
        • C.10.1.1 – Algorithm assessment
        • C.10.1.2 – Deanonymisation check
      • C.10.2 - Pseudonymisation
        • C.10.2.1 – Dissociation
        • C.10.2.2 – Access limitation
        • C.10.2.3 – Rectification compliance
    • C.11 - Artificial Intelligence and Data Analytics Complementary Checks (where applicable)
      • C.11.1 - Artificial Intelligence
        • C.11.1.1 – Complementary risk assessment
        • C.11.1.2 – Complementary informed consent
        • C.11.1.3 – Record keeping
        • C.11.1.4 – Continuous Risk Assessment
      • C.11.2 - Big Data Analytics
        • C.11.2.1 – Complementary conformity check by the DPO
    • C.12 - Work Environment and Relationship Complementary Checks (where applicable)
      • C.12.1 - Work Environment
        • C.12.1.1 – Bring Your Own Device
        • C.12.1.2 – Professional devices
      • C.12.2 - Work Relationship
        • C.12.2.1 – DPO access and validation
    • C.13 - Financial and insurance services Complementary Checks (where applicable)
      • C.13.1 - Financial and insurance services
        • C.13.1.1 – Supervisory Authority information
        • C.13.1.2 – Restriction of data processing
    • C.14 - Connected Vehicles Complementary Checks (where applicable)
      • C.14.1.1 – Data processing information or documentation
      • C.14.1.2 – Vehicle usage data communication
      • C.14.1.3 – Regular processing of geolocation data
      • C.14.1.4 – Special processing of geolocation data in case of theft
      • C.14.1.5 – Tracking via in-vehicle WiFi technology
      • C.14.1.6 – In-car applications and processing
      • C.14.1.7 – Behavioural monitoring
      • C.14.1.8 – Utilisation requirements of eCall system
      • C.14.1.9 – Securing vehicle’s communications
      • C.14.1.10 – Other security measures
      • C.14.1.11 – Biometric data restrictions
      • C.14.1.12 – Data processing revealing criminal offences or other infractions
      • C.14.1.13 – Protection of V2X traffic and communications data
    • C.15 - Smart Grid and Metering Complementary Checks (where applicable)
      • C.15.1.1 – DPIA Extension
      • C.15.1.2 – Data minimisation by design
      • C.15.1.3 – Privacy Enhancing Technologies (PET)
      • C.15.1.4 – Edge processing by default
      • C.15.1.5 – Smart grid complementary security requirements
      • C.15.1.6 – Smart meters decommissioning
    • C.50 - Public Sector Complementary Checks (where applicable)
      • C.50.1 - Public Sector General Requirements
        • C.50.1.1 – Legitimate interest restriction
        • C.50.1.2 – Cross-border data transfer restrictions
  • S - Surveillance Checks and Controls
    • S.1 - Surveillance and Recertification Audits
      • S.1.1.1 – Non-conformities management
      • S.1.2 - Use of Mark of Conformity
        • S.1.2.1 – Use of Mark of Conformity
      • S.1.3 - Information on certification in languages of Member States
        • S.1.3.1 – Information on certification in languages of Member States
      • S.1.4 - Continuous compliance
        • S.1.4.1 – Processing changes
        • S.1.4.2 – Normative changes
betterdocs-category-icon

Public FAQs

15
  • What value does Europrivacy bring for data controllers and processors?
  • How does Europrivacy compare to other certification schemes?
  • How does Europrivacy guarantee uniformity, consistency, and homogeneity in its certifications?
  • How does Europrivacy address domain and technology specific risks for data subjects?
  • How can Europrivacy assess a large diversity of data processing in an adequate and reliable manner?
  • What is Interprivacy?
  • What is Europrivacy?
  • How can I learn how to use Europrivacy?
  • What are Europrivacy Official Partners, Implementers, and Auditors?
  • What resources are available for Europrivacy?
  • What are the advantages of the Welcome Pack?
  • Can applicants from outside the EU and EEA receive a Europrivacy certificate? 
  • What is the scope and purpose of Europrivacy certification?
  • How does Europrivacy solve the dilemma between universal versus specialised certification scheme models?
  • What value does Europrivacy bring for data subjects?
View Categories
  • Home
  • FAQs

Public FAQs

  • What value does Europrivacy bring for data controllers and processors?
  • How does Europrivacy compare to other certification schemes?
  • How does Europrivacy guarantee uniformity, consistency, and homogeneity in its certifications?
  • How does Europrivacy address domain and technology specific risks for data subjects?
  • How can Europrivacy assess a large diversity of data processing in an adequate and reliable manner?
  • What is Interprivacy?
  • What is Europrivacy?
  • How can I learn how to use Europrivacy?
  • What are Europrivacy Official Partners, Implementers, and Auditors?
  • What resources are available for Europrivacy?
  • What are the advantages of the Welcome Pack?
  • Can applicants from outside the EU and EEA receive a Europrivacy certificate? 
  • What is the scope and purpose of Europrivacy certification?
  • How does Europrivacy solve the dilemma between universal versus specialised certification scheme models?
  • What value does Europrivacy bring for data subjects?

Policies

  • Cookie & Privacy Policy
  • Terms & Conditions

Useful links

  • Main Europrivacy Website
  • Europrivacy Online Academy
  • Privacy Pact

Services

Europrivacy delivers gap analysis and certification of compliance with the European General Data Protection Regulation (GDPR). The Europrivacy Community provides comprehensive resources to enable Europrivacy experts and partners to assess and certify the compliance of data processing activities with the GDPR and national regulations.

© Copyright 2020 ECCP & Archimede Solutions. All rights reserved

This website is subject to Terms of Use. It minimizes the use of cookies to those that are needed for a good user experience on the website or required for delivering services, such as online payments. Find more on our Privacy and Cookies Policy.

Europrivacy Community
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and enabling your purchases and subscriptions. No user monitoring or analytics are performed.

Strictly Necessary Cookies

Strictly Necessary Cookies should be enabled at all times so that we can save your preferences for cookie settings.

Functionality Cookies are used to allow the website to provide personalized features. These cookies do not track a user's browsing activity and cannot be used to directly identify a visitor

Name: PHPSESSID
Provider: PHP module in server
Description: An auto-generated session cookie that is used to store and identify a user's session ID to manage user session on the website.
Duration: Until the expiration/deletion of the session in the browser history/when all the browser windows are closed.

Cookie Policy

More information about our Cookie Policy