wetzoeker

1.1 — Legal and decision-making procedures NL accreditation requirements for GDPR code of conduct monitoring bodies

Legal and decision-making procedures

1.1.1 Legal and decision-making procedures

− The legal structure of the monitoring body, including its ownership, must shield the monitoring body from external influence with respect to the code owners and the code members. This might be demonstrated for example by submitting the following documents, the articles of incorporation (the set of formal documents filed with a government body to legally document the creation of a corporation) of the monitoring body and the articles of incorporation of the code owner and by demonstrating that the duration, or expiration of the mandate of the monitoring body is fixed in such a way as to prevent overdependence on a renewal or fear of losing the appointment, to an extent that adversely affects the independence in carrying out the monitoring activities by the monitoring body.

− The monitoring body shall demonstrate any legal and economic links that may exist between the monitoring body and the code owner or code members, as well as with regard to the profession, industry or sector to which the code applies.

− The monitoring body’s decision-making procedures must ensure that the decision process from the conception of a decision to its implementation must shield the monitoring body from undue influence. The independence and impartiality of the decision-making procedure might be demonstrated for example by submitting the organigram of the monitoring body and the code owner; a description of the decision-making process that also points out to the roles and prerogatives of all parties involved in the decision-making process associated to a decision making procedure.

− The monitoring body could be an internal or external body as long as evidence can be provided of adequate procedures and rules that allow monitoring of compliance with a code independently and without undue pressure or influence from the code owner or the code members.

1.1.2. The monitoring body shall demonstrate that it will act independently in its choice and application of its actions and sanctions. This could be evidenced by formal rules for appointment, terms of reference, powers and operation of any committees or personnel that may be involved with an internal monitoring body (such committees or personnel shall be free from any commercial, financial and other pressures that might influence decisions).

1.1.3. An internal monitoring body shall provide information concerning its relationship to its larger entity (in particular the code owner) and shall evidence its impartiality. This could be demonstrated with evidence that may include information barriers, separate reporting and separate operational and management functions.

1.1.4. The monitoring body shall demonstrate organisational independence, for example, an internal monitoring body may use different logos or names where appropriate, information barriers and separate reporting structures.

1.1.5. The monitoring body shall not provide any services to code members that would adversely affect its independence.

1.1.6. Any decisions made by the monitoring body related to its functions shall not be subject to approval by any other organisation, including the code owner.

Regeling
NL accreditation requirements for GDPR code of conduct monitoring bodies
Soort
ZBO-regeling
Geldend vanaf
10-03-2021
BWB-id
BWBR0044929
Versie
2021-03-10_0

In de hele regeling · Officiële tekst op wetten.overheid.nl