UK GDPR certification: Articles 42 and 43, and how it differs from ISO 27001
UK GDPR certification bodies are accredited by “the UK national accreditation body named in accordance with Regulation (EC) No 765/2008 of the European Parliament and of the Council in accordance with EN-ISO/IEC 17065/2012 and with the additional requirements established by the Commissioner” — Article 43(1)(b). ISO 27001 certification bodies are accredited to ISO/IEC 17021-1.
“GDPR certification” is used loosely for courses, badges and ISO certificates. In UK law it means one specific thing: certification under Article 42, against criteria the Information Commissioner has approved, by a body accredited under Article 43. This page sets out that framework from the legislation and the ICO's guidance, and where ISO 27001 sits beside it.
UK GDPR certification and ISO 27001 certification, side by side
| UK GDPR certification (Art. 42) | ISO 27001 certification | |
|---|---|---|
| Legal basis | UK GDPR Articles 42 and 43 | None — a voluntary international standard |
| Who writes the criteria | Scheme owners; the ICO approves them | ISO and IEC (ISO/IEC 27001) |
| What is certified | “Certification will relate to specific personal data processing operations that take place in a product, process or service offered by a controller or processor.” | An organisation's information security management system, within a stated scope |
| Certification bodies accredited to | EN-ISO/IEC 17065 (by UKAS, with ICO requirements) | ISO/IEC 17021-1 (with ISO/IEC 27006 for ISMS) |
| Named in UK GDPR as a way to demonstrate | Articles 25(3), 28(5), 32(3), 46(2)(f) | Not named |
| Maximum certificate term | Three years (Article 42(7)) | Three-year cycle with annual surveillance |
| Public register | ICO register of approved schemes; UKAS register of accredited bodies | Certification body and accreditation records |
| Can it certify a person? | No — controllers and processors only | No — organisations only |
What UK GDPR certification is
“Certification is a way for an organisation to demonstrate compliance with UK GDPR. Certification scheme criteria will be approved by the ICO and can cover a specific issue or be more general.” And what it applies to: “Certification will relate to specific personal data processing operations that take place in a product, process or service offered by a controller or processor.”
That second sentence is the practical difference from ISO 27001. An Article 42 certificate is about particular processing operations in a product, process or service. An ISO 27001 certificate is about the management system that governs information security across a scope.
What the law says it can be used for
The ICO lists the places UK GDPR names certification as a means to:
- demonstrate compliance with the provisions on data protection by design and by default (Article 25(3))
- demonstrate that you have appropriate technical and organisational measures to ensure data security (Article 32(3))
- to support transfers of personal data to third countries or international organisations (Article 46(2)(f))
Article 28(5) adds a fourth for processors: “Adherence of a processor to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as a means of demonstrating sufficient guarantees as referred to in paragraphs 1 and 4 of this Article.” See Article 28.
What it is not
- “A certification pursuant to this Article does not reduce the responsibility of the controller or the processor for compliance with this Regulation”
- “Certification can only be issued to data controllers and processors and cannot therefore be used to certify individuals, for example data protection officers.”
- “Applying for certification is voluntary.”
Who does what
The ICO describes the framework in six parts:
- us publishing accreditation requirements for certification bodies to meet
- the UK’s national accreditation body, UKAS, accrediting certification bodies and maintaining a public register
- us approving and publishing certification criteria
- accredited certification bodies issuing certification against those criteria
- controllers and processors applying for certification and using it to demonstrate compliance
- the ICO maintaining a public register of approved certification schemes
How certification bodies are accredited
Article 43(1) allows accreditation by the Commissioner, by the UK national accreditation body, or both; for the latter it is “the UK national accreditation body named in accordance with Regulation (EC) No 765/2008 of the European Parliament and of the Council in accordance with EN-ISO/IEC 17065/2012 and with the additional requirements established by the Commissioner”. The body must have:
| It must have | |
|---|---|
| a | demonstrated their independence and expertise in relation to the subject-matter of the certification to the satisfaction of the Commissioner |
| b | undertaken to respect the criteria referred to in Article 42(5) and approved by the Commissioner which is competent pursuant to Article 55 or 56 or by the Board pursuant to Article 63 |
| c | established procedures for the issuing, periodic review and withdrawal of data protection certification, seals and marks |
| d | established procedures and structures to handle complaints about infringements of the certification or the manner in which the certification has been, or is being, implemented by the controller or processor, and to make those procedures and structures transparent to data subjects and the public |
| e | demonstrated, to the satisfaction of the Commissioner, that their tasks and duties do not result in a conflict of interests |
“The accreditation shall be issued for a maximum period of five years and may be renewed on the same conditions provided that the certification body meets the requirements set out in this Article.”
How long a certificate lasts
“Certification shall be issued to a controller or processor for a maximum period of three years and may be renewed, under the same conditions, provided that the relevant criteria continue to be met.” Compare ISO 27001, where the three-year cycle is kept alive by annual surveillance audits under the certification body rules.
Where ISO 27001 fits
ISO/IEC 27001 is written by ISO and IEC, not approved by the ICO, and certified by bodies accredited to ISO/IEC 17021-1 — the management system certification standard — rather than ISO/IEC 17065. Those are two of the separate certification routes listed in the conformity assessment standards:
| What is certified | Standard | Scope |
|---|---|---|
| Management system certification | ISO/IEC 17021-1 | Requirements for bodies providing audit and certification of management systems |
| Product, process and service certification | ISO/IEC 17065 | Requirements for bodies certifying products, processes and services |
So an ISO 27001 certificate is not an Article 42 certification merely because it is accredited. The two are connected in one direction: the ICO says scheme criteria must be “interoperable with other standards, for example ISO standards”. An organisation with an ISO 27001 management system has much of the evidence an Article 42 audit of a security-related scheme would look at — that is our reading, not a statement in either text.
Check the register before relying on a scheme
“It is important that you check carefully that the code or certification scheme has been approved by the ICO.” The register also notes that approvals are under review following the Data (Use and Access) Act. We could not read its entries in a form we could quote, so we name no schemes here.
We do not certify, audit or give legal advice, and are paid the same fixed fee per enquiry whichever firm you use. The law is quoted from legislation.gov.uk and the guidance from ico.org.uk.
Where this fits
Common questions
Is there an official GDPR certification in the UK?
Yes: certification under UK GDPR Article 42. “Certification is a way for an organisation to demonstrate compliance with UK GDPR. Certification scheme criteria will be approved by the ICO and can cover a specific issue or be more general.” Schemes are listed on the ICO's register of approved certification schemes, and certification bodies are accredited by UKAS.
Is ISO 27001 a GDPR certification?
Not in the Article 42 sense. An Article 42 certification is issued against criteria the ICO has approved, by a body accredited to ISO/IEC 17065. ISO 27001 certification is issued against an ISO standard by a body accredited to ISO/IEC 17021-1. The ICO says approved criteria should be “interoperable with other standards, for example ISO standards” — related, but not the same thing.
How long does UK GDPR certification last?
“Certification shall be issued to a controller or processor for a maximum period of three years and may be renewed, under the same conditions, provided that the relevant criteria continue to be met.”
Is UK GDPR certification mandatory?
No. “Applying for certification is voluntary.” UK GDPR Article 42(3) says the same: certification shall be voluntary and available via a process that is transparent.
Does certification make us compliant?
No. “A certification pursuant to this Article does not reduce the responsibility of the controller or the processor for compliance with this Regulation” It is a means of demonstrating compliance for the processing it covers, not a transfer of responsibility.
Can a data protection officer be GDPR certified?
Not under Article 42. “Certification can only be issued to data controllers and processors and cannot therefore be used to certify individuals, for example data protection officers.” Courses that call themselves GDPR certification for individuals are something else.
Has the Data (Use and Access) Act changed certification?
The ICO updated its certification guide on 13 February 2026 to reflect the Act, and its register carries a notice: “Approval of the certification schemes in this register remain valid. However, due to the Data (Use and Access) Act coming into law on 19 June 2025, they are under review and may be subject to change.”
Sources cited on this page
- UK GDPR (Regulation (EU) 2016/679 as retained), legislation.gov.uk, Articles 32 and 42
- UK GDPR Article 43 (Certification bodies), legislation.gov.uk
- ICO, Certification schemes: a guide (updated 13 February 2026)
- ICO, Certification schemes register
- UK GDPR Article 28 (Processor), legislation.gov.uk
- ISO/CASCO, Conformity assessment bodies and the standards that govern each type
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
A customer asked for GDPR certification?
Say exactly what they asked for. It may mean an ISO 27001 certificate, a security questionnaire, or both.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.