EDCA-P03 · Governed by EDCA-STD-02
Data Protection Certification
An assessment of the lawfulness, transparency and accountability of personal data processing, including data subject rights, international transfers and retention practice.
Scope of assessment
The scope is agreed in writing before the assessment begins and is printed on the certificate. A certificate says nothing outside its scope.
- Processing activities carried out by the organisation
- Personal data categories and the data subjects concerned
- Processors, sub-processors and transfer mechanisms
- Rights handling and complaint procedures
What is examined
Each area below is assessed against the requirements of EDCA-STD-02, Data Protection and Privacy, version 2.0.
- Records of processing and lawful basis
- Transparency information provided to data subjects
- Data subject rights procedures and response times
- Data protection by design and by default
- International transfers and safeguards
- Retention schedule and erasure in practice
Programme particulars
- Programme code
- EDCA-P03
- Governing standard
- EDCA-STD-02 — Data Protection and Privacy, version 2.0, issued 12 March 2026
- Levels available
-
Level II — EDCA Security Verified
Level III — EDCA Advanced Compliance
Level IV — EDCA Trusted Technology - Typical duration
- Eight to twelve weeks from application to decision.
- Surveillance
- As required by the level held. See level requirements.
Evidence normally requested
The list is indicative. The evidence request issued after the preliminary assessment is specific to the agreed scope.
- Records of processing activities
- Privacy notices and consent mechanisms
- Data processing agreements with processors
- Transfer impact assessments where applicable
- Rights request log and retention schedule
Apply for Data Protection Certification
Submitting an application costs nothing and commits you to nothing. The Agency will confirm eligibility, propose a scope and issue a fee schedule before any assessment work begins.