The Belgian DPA approves the first EU-wide GDPR Code of Conduct

News type
Legal news

On 20 May 2021, the Belgian Data Protection Authority (“Belgian DPA”) approved the EU Cloud Code of Conduct for cloud service providers (“EU Cloud CoC”).

Article 40 of the GDPR provides the possibility of adopting such codes of conduct. It allows associations and other bodies representing categories of data controllers or data processors to draft codes of conduct for the purpose of specifying the application of the GDPR. The EU Cloud CoC is the first transnational code of conduct since the adoption of the GDPR.

The EU Cloud CoC was founded in 2017. On 19 May 2021, the European Data Protection Board (“EDPB”) issued a positive opinion, allowing the Belgian DPA as the lead data protection authority to approve its first ever transnational code of conduct on 20 May 2021.

In its decision, the Belgian DPA underlines the importance of codes of conduct as voluntary accountability tools to tailor data protection rules to the specificities of the data processing activities in a particular sector. It also reaffirms its commitment to encourage associations and bodies representing a sector to develop codes of conduct.

The objective of the EU Cloud CoC is to translate the requirements of the GDPR into a practical implementation for IaaS, PaaS and SaaS providers. It contains three levels of compliance for which cloud service providers can apply, making it a useful tool both for larger players and for SMEs.

The EU Cloud CoC also translates the requirements of Article 28 of the GDPR. As stated in Recital 81 and Article 28(5) of the GDPR, adherence by a data processor to an approved code of conduct may be used as an element by which to demonstrate sufficient data protection guarantees as referred to in Articles 28(1) and 28(5) of the GDPR. The EU Cloud CoC is not, however, to be used in the context of international transfers of personal data.

In accordance with article 41 of the GDPR, a code of conduct such as the EU Cloud CoC must be monitored by an accredited monitoring body. SCOPE Europe was accredited by the Belgian DPA and will be in charge of ensuring compliance of members with the provisions of the EU Cloud CoC. It may also take actions, including sanctions, in case of infringement of the provisions of the EU Cloud CoC.

The EU Cloud CoC is already operational for cloud service providers wishing to join. 

Please contact Karel Janssens for further information regarding the above and/or for general legal advice relating to privacy and data protection.
 

Practice areas