Explanatory note:
The requirements below aim to ensure that the proposals for monitoring are operationally feasible, by specifically outlining the monitoring process and demonstrating how it will deliver the code’s monitoring mechanism.
The monitoring body will need to demonstrate to the AP established procedures, structures and resources to assess the eligibility of controllers/processors to apply the code, monitor compliance with the code and to carry out periodic reviews of the code’s operation.
Monitoring procedures must take into account the risk raised by the data processing, complaints received and the expected number and size of code members. These procedures could lead to the publication of monitoring information including audit or summary reports or periodic outcomes reporting of findings.
The monitoring body shall apply the corrective measures and penalties as defined in the code of conduct.
Requirements:
The monitoring body shall demonstrate that they have a procedure to check prior to joining the eligibility of members to comply with the code, for example, their processing of personal data falls within the scope of the relevant code of conduct.
The monitoring body shall provide evidence of upfront, ad hoc and regular procedures to monitor the compliance of members within a clear timeframe such as, procedures providing for audit plans to be carried out over a definite period and on the basis of predetermined criteria.
The monitoring body shall demonstrate that they have a procedure to provide compliance monitoring to be carried out over a defined period taking into account such things as: the complexity and risks involved, the expected number and size of code members, geographical scope and complaints received.
The monitoring body shall demonstrate that their audit or review procedures define the criteria to be assessed, the type of assessment to be used and a procedure to document the findings. Review procedures can include such things as: audits, inspections, reporting and the use of self-monitoring reports or questionnaires.
The monitoring body shall demonstrate that they have a procedure for the investigation, identification and management of code member infringements to the code and additional controls to ensure appropriate action is taken to remedy such infringements as set out in the relevant code of conduct.
The monitoring body shall be responsible for the management of all information obtained or created during the monitoring process. The monitoring body shall ensure that personnel will keep all information obtained or created during the performance of their tasks confidential, unless they are required to disclose or are exempt by law.
Artikel 3
Established procedures and structures
Onderdeel van NL accreditation requirements for GDPR code of conduct monitoring bodies· Privacy
Deze tekst geldt sinds 10 maart 2021