Certification · Last verified
GDPR-Certified Assurance Report-based Processing Activities
GDPR-CARPA is a GDPR Article 42 certification scheme created and run directly by Luxembourg's data protection authority, the CNPD. The certificate runs three years and requires a successful full audit every year to keep it; CNPD approves the certification bodies itself, without a separate accreditation body.
- Class
- Certification
- Owner
- Commission Nationale pour la Protection des Données (CNPD), Luxembourg
- Who asks for it
- Voluntary
- Last verified
What it is
GDPR-CARPA stands for GDPR-Certified Assurance Report-based Processing Activities, a certification scheme under Article 42 of the GDPR.
"To date, the CNPD is the only European supervisory authority to have itself developed a certification scheme under the GDPR." CNPD's own page also describes it as "the first and only certification scheme under the RGPD [GDPR]."
"A certificate is valid for 3 years, subject to a successful annual full audit."
"Approval is granted by the CNPD under Article 15 of the Act of 1 August 2018" — the certification bodies that issue GDPR-CARPA certificates are approved directly by CNPD, not by a separate national accreditation body.
"CNPD can only issue approvals to organisations established on Luxembourg territory."
Who owns it
CNPD, Luxembourg's data protection authority, designed the scheme and is the only body that approves the certification bodies allowed to issue GDPR-CARPA certificates.
Who assesses it
Certification bodies approved by CNPD under Article 15 of the 1 August 2018 Act carry out the assessments and annual audits; CNPD approves only organisations established in Luxembourg.
Sources
- CNPD — GDPR-CARPA certification scheme ↗ — accessed
- CNPD — Approval of certification bodies ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.