GDPR Certified? What GDPR and AI Act Claims Really Prove
GDPR certified and AI Act certification claims explained: scope, approval, three-year validity, continuing responsibility, conformity and CE marking.

Quick Answer: GDPR certification is voluntary, time-limited and tied to a defined processing scope; it never removes controller or processor responsibility. AI Act conformity assessment is a different legal mechanism for relevant systems, with CE marking for high-risk AI. A defensible claim states the scheme, scope, issuer, validity and regime without implying blanket approval.
Summary in a mind map
GDPR Certified? What GDPR and AI Act Claims Prove │ ├─ GDPR certification │ ├─ Voluntary and tied to processing scope │ ├─ Approved criteria and authorised issuer │ └─ Maximum three-year validity │ ├─ Responsibility remains │ ├─ Controller or processor still accountable │ └─ Certificate is evidence, not immunity │ ├─ AI Act route │ ├─ Conformity assessment for relevant systems │ ├─ CE marking communicates conformity │ └─ It is not a quality award │ └─ Defensible claim ├─ Name regime, scheme, scope and issuer ├─ Show current status and validity └─ Never blend separate legal mechanisms
GDPR certification covers processing, not a whole company
Article 42 creates data-protection certification mechanisms, seals and marks for demonstrating compliance of processing operations with the GDPR. It does not create an unrestricted status called “GDPR certified company”. The certified object and approved criteria define what the certificate can support.
Certification is voluntary and must be available through a transparent process.1 Voluntary does not mean informal. An Article 42 scheme sits within the accreditation and criteria-approval structure of Articles 42 and 43. A consultancy's private badge may be useful evidence in another context, but it is not transformed into a GDPR certification by its wording.
Scope is the first fact a buyer should request. It may cover a service, a family of processing operations or a defined controller or processor activity. Other departments, systems or legal duties may remain outside. A precise statement therefore names what was assessed instead of applying the result to everything the organisation does.
| Claim | What it can properly mean | What it cannot mean |
|---|---|---|
| Certified processing operation | Defined scope met approved criteria | Every company activity complies |
| European Data Protection Seal | Criteria approved through the EU mechanism | Regulator guarantees every decision |
| Private privacy assessment | Evidence under its own method | Article 42 status without accreditation |
| Supplier certificate | A current certificate for named scope | Responsibility transfers to the supplier |
Criteria approval and certificate issuance are separate
The EDPB explains that certification is issued by accredited certification bodies or data-protection authorities and may lead to a European Data Protection Seal where criteria are approved following an EDPB opinion.3 The system separates criteria, accreditation and issuance so a marketing department cannot declare its own standard official.
Guidelines 1/2018 provide the EDPB's final guidance on certification and identifying certification criteria under Articles 42 and 43.4 Criteria must be capable of consistent assessment. They should identify the processing, relevant legal requirements and evidence needed for a certification decision.
A buyer should therefore ask four questions: what scheme is used, who approved the criteria, who issued the certificate and what processing falls within scope? If one answer is missing, the claim may still describe a private assessment, but it should not be represented as an Article 42 certification.
Validity is limited and can end early
Article 42(7) sets a maximum period of three years. Renewal is possible under the same conditions where the requirements continue to be met. Certification must be withdrawn when its criteria are not, or are no longer, satisfied.1
The maximum period is not a promise that every certificate lasts three years. Scheme rules can require a shorter term, surveillance or reassessment after changes. A major change to processing can also affect scope or continuing conformity before the printed expiry date.
Marketing controls should therefore store issuer, scheme, scope, issue date, expiry and status. Claims should be removed or updated promptly when a certificate expires, is suspended or is withdrawn. A static website logo without ownership and review date is a predictable source of misleading statements.
Responsibility remains with controllers and processors
Article 42(4) is explicit: certification does not reduce the responsibility of the controller or processor for compliance.1 The organisation still determines how each GDPR duty applies and must be able to demonstrate its decisions.
Certification can strengthen evidence. It can show that specified processing met approved criteria at the assessment point. It cannot decide a new purpose introduced after certification, guarantee every employee action or answer whether an unrelated system has a lawful basis.
The distinction matters in procurement. A controller cannot rely on a processor's certificate as a complete substitute for due diligence and contractual controls. The certificate should inform the assessment, while scope gaps, current status and the controller's own responsibilities remain visible.
AI Act conformity assessment follows a different route
The AI Act does not use GDPR certification as its general conformity mechanism. Relevant high-risk systems undergo the conformity-assessment route specified by the Act, with the applicable route depending on classification and product context. The assessment tests conformity with legal requirements for the system; it is not a broad corporate award.
CE marking communicates conformity after the applicable procedure. Article 48(3) requires the CE marking for high-risk AI systems to be affixed visibly, legibly and indelibly. Where that is not possible or warranted, it may be placed on packaging or accompanying documentation, as appropriate.2
CE marking should not be described as proof that an AI system is always correct, unbiased or safe in every deployment. Operators still need to use a system according to instructions and fulfil their own duties. A system's conformity also does not certify the buyer's entire governance programme.
| Question | GDPR certification | AI Act conformity assessment |
|---|---|---|
| Object | Defined processing operations | Relevant AI system and applicable requirements |
| Voluntary? | Yes under Article 42 | Required where the Act's route applies |
| Visible sign | Scheme certificate, seal or mark | CE marking for high-risk AI |
| Responsibility after assessment | Controller or processor remains responsible | Economic operator and deployer duties remain |
Separate the regimes before making claims
A company can encounter both regimes in one service. Personal-data processing may fall within a GDPR certification scope, while an AI system may follow an AI Act conformity route. The assessments have different legal objects, criteria and consequences. One does not automatically satisfy the other.
The AI governance comparison helps place the regimes side by side. AI literacy under Article 4 explains a separate organisational duty. A supplier review can use the EU AI Act vendor questionnaire without turning an answer into certification.
For UK businesses, geography also matters. UK GDPR arrangements and EU GDPR mechanisms should not be conflated merely because the standards share origins. An EU-market AI system may still face the EU AI Act even where the provider is in the UK. The claim should identify the relevant legal regime.
Build a claim-evidence register
A reliable claim begins with its exact proposed wording. The register then records regime, scheme, scope, issuer, criteria approval, validity, owner and supporting document. Marketing cannot publish until each field supports the sentence.
In words, the tree branches like this: if the claim concerns processing under Article 42, verify approved criteria and an authorised issuer. If it concerns a high-risk AI system, follow the applicable conformity-assessment route and CE-marking rules. If neither route applies, describe the private assessment accurately without official certification language.
Evidence should be reviewed when processing, products or schemes change. A claim owner checks expiry dates and withdrawal notices. Procurement staff should retain the certificate and its scope, not only a supplier's webpage screenshot.
Marketing claims that overreach
“Fully GDPR certified” hides scope and wrongly suggests comprehensive legal approval. “EU-approved AI” can imply a regulator endorsement that CE marking does not provide. “Certified secure and unbiased” combines qualities that may not have been assessed. These formulations should be replaced with factual statements.
A better sentence names the scheme and certified operation, followed by current validity. For AI Act statements, specify that the system has completed the applicable conformity-assessment route and carries CE marking, if true. Do not merge that statement with claims about accuracy or suitability for every intended use.
The article on Article 50 transparency illustrates another distinction: transparency duties can apply even where a system is not described by a certification claim. Compliance remains a set of specific duties and records, not a single badge.
Worked example: one supplier, three different claims
A software supplier processes customer-support recordings and also sells an AI quality-monitoring tool. Its website proposes three statements: “GDPR certified”, “EU-approved AI” and “independently security assessed”. The statements appear similar, yet each rests on a different evidence path.
The supplier holds a current Article 42 certificate for a defined processing operation involving storage and retrieval of support recordings. The scope excludes the AI evaluation layer and several new integrations. The accurate claim names the certification scheme, issuer, certified processing operation and validity. It does not describe the entire company or every product as certified.
The AI tool is classified as high-risk for one intended use and has completed the applicable conformity assessment. The provider may make the required CE-related conformity statement, but “EU-approved AI” is misleading because it suggests discretionary regulator endorsement. The corrected wording identifies the system and applicable conformity status without adding promises about accuracy, fairness or suitability for every deployment.
The security review is a private assessment under a commercial methodology. It may provide valuable evidence, but it is neither an Article 42 certification nor the AI Act conformity route. The claim therefore says exactly who performed the assessment, what scope was tested and when. It avoids official seals and legal language the review cannot support.
Procurement then checks how the claims interact. The GDPR certificate supports due diligence for the named processing scope but does not transfer the customer's controller duties. The conformity evidence supports the AI system's route but does not certify the customer's deployment. The security report informs technical risk assessment but does not replace either legal mechanism.
Finally, the supplier creates an expiry control. The website owner receives alerts before certificate expiry, product management owns conformity changes and security owns reassessment dates. If scope, status or evidence changes, the public sentence changes with it. This worked example turns three attractive badges into three bounded, verifiable statements.
Buyer checks that preserve the limits
A buyer should obtain the certificate itself, not only a logo in a proposal. The review records the legal mechanism, certified object, scheme, issuer, issue date, expiry and current status. It then maps the supplier service being purchased against the stated scope. A certificate for one hosting region or processing operation may not cover the contracted configuration.
The buyer should also test relevant exclusions. Sub-processors, optional integrations, new AI features and customer-configured workflows can sit beyond the certified boundary. Those gaps do not automatically make the supplier unsuitable. They identify where ordinary due diligence, contract controls and direct evidence remain necessary.
For AI Act conformity, the buyer matches the exact system, version and intended purpose. Instructions and the declaration of conformity should agree with how the buyer plans to deploy the system. A material local change or off-label use can undermine the relevance of the provider's assessment and create different responsibilities.
Evidence belongs in a review cycle. Procurement owns the initial collection, the service owner watches scope changes and compliance tracks expiry or withdrawal. The organisation records what the evidence supports and, equally, what it does not. This prevents a valid but narrow certificate from becoming a permanent substitute for supplier oversight.
The review should also compare the certificate's named legal entity with the contracting supplier, because group branding can make evidence issued to one subsidiary appear to cover another. Where scope references annexes or technical schedules, those documents must be retained with the certificate; without them, the buyer may be unable to identify covered services, locations and exclusions. Any translation of the claim should preserve these limits rather than shortening them into an unqualified badge. A supplier that cannot provide current scope evidence should be assessed on the available facts, not credited with an assumed certification.
When this guide cannot validate a claim
This guide cannot confirm the accreditation, scope or status of a particular certificate. Those facts require the scheme documents and issuer's current register. It also cannot determine the correct AI Act conformity route without classification and product facts.
Words such as “assured”, “verified” and “validated” may still mislead depending on context. A legal and technical review should examine the whole presentation, including logos, footnotes and omissions. A technically true fragment can create a false overall impression.
What to do next
Inventory every certification, seal, conformity and approval claim. Attach the supporting scope and current status, then rewrite or remove anything broader than the evidence. For the next EU AI Act documentation step, use the EU AI Act Documentation Pack.
Frequently asked questions
Can a company call itself GDPR certified?
A GDPR certification covers specified processing operations against approved criteria; it is not a blanket declaration that an entire company complies with every GDPR duty. Any claim should name the scheme, certification body, certified scope and validity. Broad wording such as “fully GDPR certified” is likely to conceal limits that matter.
Who can issue a GDPR certification?
Certification may be issued by an accredited certification body or, where the applicable framework provides, a competent supervisory authority. Criteria require approval through the GDPR system. ISO-style certificates or private compliance badges do not become Article 42 certifications merely because they address privacy or use similar terminology.
How long does GDPR certification last?
Article 42(7) sets a maximum certification period of three years. Renewal is possible where the criteria continue to be met. Certification must be withdrawn if the criteria are no longer satisfied. Marketing should therefore show current status and expiry rather than presenting an old certificate as permanent proof.
Does certification remove controller responsibility?
No. Article 42(4) expressly says certification does not reduce the controller's or processor's responsibility for compliance. Certification can provide evidence about a defined processing scope, but the organisation still owns lawful processing, transparency, security, rights handling and all other duties that apply to its role.
Is CE marking an AI Act quality award?
No. For a high-risk AI system, CE marking communicates conformity with applicable requirements following the required conformity-assessment route. Article 48 requires the mark to be visible, legible and indelible, with alternatives for packaging or documentation where appropriate. It does not mean every output is accurate or risk-free.
Which certification marketing claims should be avoided?
Avoid claims that omit scope, imply regulator endorsement, promise complete GDPR compliance, treat CE marking as an optional excellence badge or suggest certification transfers legal responsibility. Claims should be specific, current and verifiable. Where two regimes are involved, describe GDPR certification and AI Act conformity assessment separately rather than blending them.
Frequently Asked Questions
Can a company call itself GDPR certified?
Who can issue a GDPR certification?
How long does GDPR certification last?
Does certification remove controller responsibility?
Is CE marking an AI Act quality award?
Which certification marketing claims should be avoided?
Sources
- 1.Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · 2016
- 2.Regulation (EU) 2024/1689 — consolidated text — EUR-Lex · 2026
- 3.Certification — European Data Protection Board · 2026
- 4.Guidelines 1/2018 on certification and identifying certification criteria — European Data Protection Board · 2019
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.