Skip to content

"GDPR Certification" under Article 42 vs. Certificate of Attendance: The Difference

Provimedia Redaktion 6 min read 10 July 2026 2 views
Datenschutz & DSGVO
"GDPR Certification" under Article 42 vs. Certificate of Attendance: The Difference
Illustrative image · AI-generated

A "GDPR certification" in the legal sense (Article 42 GDPR) is a voluntary, demanding assessment procedure that only accredited certification bodies are allowed to carry out, and that usually covers the processing operations or technical measures of a company. A certificate of attendance for a training course is something different: it confirms that an individual person completed a training course, comparable to a seminar attendance record. Both are useful, but neither replaces the other.

By the Provimedia editorial team · As of: July 2026 · This article is general information, not legal advice.

What is a "GDPR certification" under Article 42?

Article 42 GDPR provides that member states, supervisory authorities, the European Data Protection Board, and the Commission encourage the establishment of data protection certification mechanisms, seals, and marks. Such a certification is issued by a certification body under Article 43 GDPR based on approved criteria, and confirms that the processing operations of a controller or processor comply with the requirements of the GDPR. The certification is issued for a maximum of three years and can be renewed under the same conditions (Article 42(7) GDPR).

Who is actually allowed to certify?

Not every provider is allowed to call itself a "certification body." Only bodies that have previously been formally accredited may issue certifications under Article 42. In Germany, this task is carried out by the German accreditation body (Deutsche Akkreditierungsstelle, DAkkS) together with the competent independent data protection supervisory authorities under Section 39 of the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG). Accreditation confirms that the body is technically capable of correctly carrying out a certification procedure.

What is a certificate of attendance for a training course?

A certificate of attendance is a document that confirms: this person completed a specific training course at a specific point in time. In substance, this is comparable to an attendance record for a webinar, seminar, or internal workshop. It says something about the individual training of a person, not about an accredited audit of a company's entire data protection organization. Anyone who blurs this distinction risks a misleading advertising claim.

Still, a certificate of attendance is not a blank piece of paper: it is exactly the documented, dated evidence that the accountability principle (Article 5(2) GDPR) and the DPO task of "awareness raising and training" (Article 39(1)(b) GDPR) require, as one building block, not as a replacement for a company certification.

Article 42 certification vs. certificate of attendance compared

FeatureGDPR certification (Article 42)Training certificate of attendance
SubjectProcessing operations/technical and organizational measures of a company or productTraining of an individual person
Who issues it?Accredited certification body (DAkkS + supervisory authority, Section 39 BDSG)The training provider itself
ProcedureFormal audit based on approved criteriaCompletion of a learning program or an exam
Validity periodMax. 3 years (Article 42(7) GDPR)Not time-limited, but the content can become outdated
Legal statusOfficially recognized assessment procedurePrivate training record, not an official certification

Why does the difference matter for you?

Two reasons. First, legal precision: anyone who advertises a training certificate of attendance as a "GDPR certification" or even as a "certified data protection officer" is conflating two different legal instruments, which can be misleading. Second, practical value: an honestly labeled certificate of attendance loses none of its worth as a result. It remains exactly the evidence that Article 5(2) and Article 39(1)(b) GDPR require for employee awareness raising, just correctly categorized.

How do you recognize a trustworthy training offer?

Because the market for data protection training is hard to navigate, a quick check helps before you book an offer for your team:

  • Clear terminology: A trustworthy provider calls its product a "certificate of attendance" or "training record," not a "GDPR certification" or "accredited certification."
  • No false promises: A single employee training session does not make a company "GDPR certified" or "AI Act compliant"; trustworthy providers phrase this accordingly cautiously.
  • Traceable content: The training should name specific articles of the GDPR, not just promise "data protection knowledge" in general terms.
  • Documented, dated evidence: For the accountability principle, what counts is a certificate with a date, name, and content, not a verbal assurance.

These criteria protect you twice over: against a misleading advertising claim from the provider, and against evidence that would not hold up before a supervisory authority if it came to that.

Frequently asked questions (FAQ)

Is my training certificate a GDPR certification under Article 42?

No. A certificate of attendance confirms that a person completed a training course. A certification under Article 42 GDPR is a formal audit procedure for a company's processing operations carried out by an accredited body.

Who is officially allowed to certify under Article 42 GDPR?

Only certification bodies that have previously been formally accredited, in Germany by the DAkkS together with the competent supervisory authorities (Section 39 BDSG).

So what does a certificate of attendance actually get me?

It is a dated, individual record that a person received data protection training, a recognized building block of the accountability principle (Article 5(2) GDPR), not a statement about a company's overall compliance.

Does employee training make my company "GDPR certified"?

No. Training improves your ability to demonstrate compliance and reduces risk, but it does not replace a certification under Article 42 GDPR or individual legal advice on your company's overall compliance.

Do you want the honest, documented training record for your team? Our GDPR fundamentals training with certificate of attendance can be booked online, honestly named for what it is: a dated training record per person, not a certification under Article 42. You can read more about the evidence building blocks of the accountability principle in our article Accountability under the GDPR.

Sources

  • Regulation (EU) 2016/679 (GDPR), Article 5(2), Article 39(1)(b), Article 42, Article 43: eur-lex.europa.eu
  • Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG), Section 39 (accreditation of certification bodies): gesetze-im-internet.de
  • Federal Commissioner for Data Protection and Freedom of Information (Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit, BfDI), certification: bfdi.bund.de
  • North Rhine-Westphalia State Commissioner for Data Protection and Freedom of Information (Landesbeauftragte für Datenschutz und Informationsfreiheit NRW, LDI NRW), accreditation/certification: ldi.nrw.de

Share this article

Stay up to date

Get the latest articles, insights and industry updates straight to your inbox.

Unsubscribe at any time. See our privacy policy.

Decide for yourself what Google shows you

Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.

Add provimedia.de to my preferred sources

Bereit für den dokumentierten Schulungsnachweis?

Die DSGVO-Grundlagenschulung für Ihr Team – online, in rund 90 Minuten, mit datiertem Teilnahmezertifikat je Person.