Article 40 of the GDPR: Codes of Conduct

Article 40 of the GDPR: Codes of Conduct

Article 40 of the GDPR Explained

Professional associations, representative bodies or stakeholders in a given sector may draw up codes of conduct aimed at:

  • Clarifying data protection obligations in a specific context;
  • Specifying the application of the principles of the GDPR (e.g., information, consent, security, etc.);
  • Proposing concrete solutions for compliance (information formats, tools, procedures, etc.).

These codes may be submitted for validation by the supervisory authority (e.g., the French supervisory authority) and may even be recognised at European level.

Why is this article important for your GDPR compliance?

Codes of conduct serve as a framework of good practices recognised by the authorities. Adhering to them or drawing inspiration from them helps to strengthen your compliance, particularly in sectors where regulation may seem complex or difficult to interpret.

How to Comply with Article 40 of the GDPR?

  • Identify whether a code of conduct exists in your sector or for your type of activity;
  • Study its content and adapt your procedures accordingly;
  • Consider joining a supporting organisation or developing one with other stakeholders;
  • Take into account the recommendations from codes validated by the French supervisory authority or the EDPB.

Examples of Application of GDPR Article 40

  • A group of hospitals defines a code of conduct to govern access to health data;
  • E-commerce companies agree on best practices regarding cookies and targeted advertising;
  • An association of construction SMEs implements a simplified guide compliant with the GDPR for its members.

Related Resources

Accelerate your compliance in a few clicks

With our all-in-one solution, you can accelerate and ensure your compliance with ease:

  • Automate your compliance with our GDPR software
  • Supported or outsourced by our DPO experts
  • Train your teams with our GDPR e-learning course

Request a demo with an expert

Assess your situation in 15 minutes with our free, no-obligation GDPR self-assessment.

GDPR: Self-assess now