Cybersecurity Policy Report, Views on GDPR Certification Criteria Published by EDPB, (Apr 16, 2025)
By R. Jason Howard, J.D.
The European Data Protection Board (EDPB) has published an opinion on the draft decision by the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), concerning the submission of certification criteria under the European Union’s General Data Protection Regulation (GDPR) by French legal entity Lexing.
In the opinion, the EDPB concludes that the Lexing certification does not provide adequate safeguards for international data transfers. The EDPB recommended actions that the CNIL could take, including requiring further details on GDPR compliance, defining ‘anonymization,’ and addressing various GDPR articles such as consent, data protection by design, and the rights of data subjects.
Pursuant to the GDPR, CNIL shall communicate its response to the EDPB concerning whether it will amend or maintain its draft decision by electronic means within two weeks of receiving the opinion.
CNIL is also required under the GDPR to make the Lexing certification criteria public and in an easily accessible form which should be transmitted to the EDPB for inclusion in the public register of certification mechanisms and data protection seals.
News: InternationalLegislation DataPrivacy GDPR