SCHEDULES

SCHEDULE 6The applied GDPR and the applied Chapter 2

PART 1Modifications to the GDPR

Section 5 of Chapter IV of the GDPR (controller and processor: codes of conduct and certification)

31

In Article 40 (codes of conduct)—

(a)

in paragraph 1, for “The Member States, the supervisory authorities, the Board and the Commission shall” substitute “ The Commissioner must ”;

(b)

omit paragraph 3;

(c)

in paragraph 6, omit “, and where the code of conduct concerned does not relate to processing activities in several Member States”;

(d)

omit paragraphs 7 to 11.

32

In Article 41 (monitoring of approved codes of conduct), omit paragraph 3.

33

In Article 42 (certification)—

(a)

in paragraph 1—

(i)

for “The Member States, the supervisory authorities, the Board and the Commission” substitute “ The Commissioner ”;

(ii)

omit “, in particular at Union level,”;

(b)

omit paragraph 2;

(c)

in paragraph 5, omit “or by the Board pursuant to Article 63. Where the criteria are approved by the Board, this may result in a common certification, the European Data Protection Seal”;

(d)

omit paragraph 8.

34

In Article 43 (certification bodies)—

(a)

in paragraph 1, in the second sentence, for “Member States shall ensure that those certification bodies are” substitute “ Those certification bodies must be ”;

(b)

in paragraph 2, in point (b), omit “or by the Board pursuant to Article 63”;

(c)

in paragraph 3, omit “or by the Board pursuant to Article 63”;

(d)

in paragraph 6, omit the second and third sentences;

(e)

omit paragraphs 8 and 9.