Codes of conduct
Codes of conduct are voluntary sets of rules drawn up by associations or other bodies representing categories of controllers or processors to specify the application of the GDPR in their sector, approved by the competent supervisory authority and, for codes covering several Member States, by the EDPB and the European Commission (Art. 40). Art. 40(2) lists topics a code may address, including fair and transparent processing, legitimate interests, collection and pseudonymisation, information to the public and data subjects, rights, protection of children, security, breach notification, international transfers and dispute resolution. Compliance is monitored by an accredited monitoring body (Art. 41).
Adherence to an approved code has legal effects: it may be used to demonstrate compliance with controller obligations (Art. 24(3)), processor guarantees (Art. 28(5)) and security (Art. 32(3)); it is taken into account in DPIAs (Art. 35(8)) and when setting fines (Art. 83(2)(j)); and a code approved with binding and enforceable commitments by third-country recipients can serve as an appropriate safeguard for transfers under Art. 46(2)(e), as clarified by EDPB Guidelines 04/2021. The EDPB has approved transnational codes for cloud infrastructure and cloud service providers (the EU Cloud CoC and CISPE), which many life sciences vendors adhere to.
For health and research, several national codes exist or are under development, for example on health research in the Netherlands and on hospital data processing in France, and the European Health Data Space and the Commission's Code of Conduct on secondary use of health data initiative aim to give sponsors and data holders sector-specific reference rules. Codes complement rather than replace legal obligations; a sponsor can use a vendor's adherence to the EU Cloud CoC as evidence in its vendor assessment, but still needs a DPA, a TIA where relevant and its own DPIA.
