"GDPR Certification" under Article 42 vs. Certificate of Attendance: The Difference

A "GDPR certification" in the legal sense (Article 42 GDPR) is a voluntary, demanding assessment procedure that only accredited certification bodies are allowed to carry out, and that usually covers the processing operations or technical measures of a company. A certificate of attendance for a training course is something different: it confirms that an individual person completed a training course, comparable to a seminar attendance record. Both are useful, but neither replaces the other.
By the Provimedia editorial team · As of: July 2026 · This article is general information, not legal advice.
What is a "GDPR certification" under Article 42?
Article 42 GDPR provides that member states, supervisory authorities, the European Data Protection Board, and the Commission encourage the establishment of data protection certification mechanisms, seals, and marks. Such a certification is issued by a certification body under Article 43 GDPR based on approved criteria, and confirms that the processing operations of a controller or processor comply with the requirements of the GDPR. The certification is issued for a maximum of three years and can be renewed under the same conditions (Article 42(7) GDPR).
Who is actually allowed to certify?
Not every provider is allowed to call itself a "certification body." Only bodies that have previously been formally accredited may issue certifications under Article 42. In Germany, this task is carried out by the German accreditation body (Deutsche Akkreditierungsstelle, DAkkS) together with the competent independent data protection supervisory authorities under Section 39 of the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG). Accreditation confirms that the body is technically capable of correctly carrying out a certification procedure.
What is a certificate of attendance for a training course?
A certificate of attendance is a document that confirms: this person completed a specific training course at a specific point in time. In substance, this is comparable to an attendance record for a webinar, seminar, or internal workshop. It says something about the individual training of a person, not about an accredited audit of a company's entire data protection organization. Anyone who blurs this distinction risks a misleading advertising claim.
Still, a certificate of attendance is not a blank piece of paper: it is exactly the documented, dated evidence that the accountability principle (Article 5(2) GDPR) and the DPO task of "awareness raising and training" (Article 39(1)(b) GDPR) require, as one building block, not as a replacement for a company certification.
Article 42 certification vs. certificate of attendance compared
| Feature | GDPR certification (Article 42) | Training certificate of attendance |
|---|---|---|
| Subject | Processing operations/technical and organizational measures of a company or product | Training of an individual person |
| Who issues it? | Accredited certification body (DAkkS + supervisory authority, Section 39 BDSG) | The training provider itself |
| Procedure | Formal audit based on approved criteria | Completion of a learning program or an exam |
| Validity period | Max. 3 years (Article 42(7) GDPR) | Not time-limited, but the content can become outdated |
| Legal status | Officially recognized assessment procedure | Private training record, not an official certification |
Why does the difference matter for you?
Two reasons. First, legal precision: anyone who advertises a training certificate of attendance as a "GDPR certification" or even as a "certified data protection officer" is conflating two different legal instruments, which can be misleading. Second, practical value: an honestly labeled certificate of attendance loses none of its worth as a result. It remains exactly the evidence that Article 5(2) and Article 39(1)(b) GDPR require for employee awareness raising, just correctly categorized.
How do you recognize a trustworthy training offer?
Because the market for data protection training is hard to navigate, a quick check helps before you book an offer for your team:
- Clear terminology: A trustworthy provider calls its product a "certificate of attendance" or "training record," not a "GDPR certification" or "accredited certification."
- No false promises: A single employee training session does not make a company "GDPR certified" or "AI Act compliant"; trustworthy providers phrase this accordingly cautiously.
- Traceable content: The training should name specific articles of the GDPR, not just promise "data protection knowledge" in general terms.
- Documented, dated evidence: For the accountability principle, what counts is a certificate with a date, name, and content, not a verbal assurance.
These criteria protect you twice over: against a misleading advertising claim from the provider, and against evidence that would not hold up before a supervisory authority if it came to that.
Frequently asked questions (FAQ)
Is my training certificate a GDPR certification under Article 42?
No. A certificate of attendance confirms that a person completed a training course. A certification under Article 42 GDPR is a formal audit procedure for a company's processing operations carried out by an accredited body.
Who is officially allowed to certify under Article 42 GDPR?
Only certification bodies that have previously been formally accredited, in Germany by the DAkkS together with the competent supervisory authorities (Section 39 BDSG).
So what does a certificate of attendance actually get me?
It is a dated, individual record that a person received data protection training, a recognized building block of the accountability principle (Article 5(2) GDPR), not a statement about a company's overall compliance.
Does employee training make my company "GDPR certified"?
No. Training improves your ability to demonstrate compliance and reduces risk, but it does not replace a certification under Article 42 GDPR or individual legal advice on your company's overall compliance.
Do you want the honest, documented training record for your team? Our GDPR fundamentals training with certificate of attendance can be booked online, honestly named for what it is: a dated training record per person, not a certification under Article 42. You can read more about the evidence building blocks of the accountability principle in our article Accountability under the GDPR.
Sources
- Regulation (EU) 2016/679 (GDPR), Article 5(2), Article 39(1)(b), Article 42, Article 43: eur-lex.europa.eu
- Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG), Section 39 (accreditation of certification bodies): gesetze-im-internet.de
- Federal Commissioner for Data Protection and Freedom of Information (Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit, BfDI), certification: bfdi.bund.de
- North Rhine-Westphalia State Commissioner for Data Protection and Freedom of Information (Landesbeauftragte für Datenschutz und Informationsfreiheit NRW, LDI NRW), accreditation/certification: ldi.nrw.de
Share this article
Stay up to date
Get the latest articles, insights and industry updates straight to your inbox.
Decide for yourself what Google shows you
Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.
Add provimedia.de to my preferred sourcesRelated articles
More articles you might find interesting.
Phishing and Social Engineering: How Your Employees Can Spot an Attack
Phishing, spear phishing, CEO fraud, and smishing target people, not systems. The warning signs a phishing employee training should teach, and why a successful attack quickly turns into a reportable data breach.
GDPR Fines: Real Cases from Germany and What Companies Can Learn from Them
Four real GDPR fine cases from Germany show how authorities calculate the amount, and that courts can also significantly reduce them afterward.
Information Security Training vs. GDPR Training: What Companies Actually Need
Information security protects systems and information, data protection protects people and their data. The difference, the overlap under Art. 32 GDPR, and what the new NIS2 training duty means for management boards.
Bereit für den dokumentierten Schulungsnachweis?
Die DSGVO-Grundlagenschulung für Ihr Team – online, in rund 90 Minuten, mit datiertem Teilnahmezertifikat je Person.