Certifications to Safeguard Data Protection Standards? How Superficial Internalization Thwarts the Plan

Danylak, Philipp 1; Brecker, Kathrin 1; Lins, Sebastian 1; Sunyaev, Ali 1
1 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)


The EU General Data Protection Regulation (GDPR) proposes certifications issued by independent and accredited certification bodies to demonstrate compliance with data protection standards in Articles 42 and 43. Beyond demonstrating regulatory compliance, certifications are a valuable means to tackle current challenges in data governance. First, certifications can serve as a global mechanism for decentralized self-regulation [1]. Competitive pressure may motivate companies to adopt data governance and protection standards and undergo corresponding certifications, even if they are not explicitly mandated by governmental regulations [2–4]. Second, certifications can help reduce the asymmetric power distribution between individuals and companies by creating transparency about data processing practices and enabling individuals to make better-informed decisions [5]. Finally, certifications provide organizations with guidance on how to fulfill the requirements imposed by the GDPR and achieve efficient data governance by clarifying the specific requirements an organization needs to fulfill and recommending best practices on how to implement the requirements into the organization’s processes [5]. ... mehr

Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Publikationstyp Poster
Publikationsdatum 13.10.2022
Sprache Englisch
Identifikator KITopen-ID: 1000151588
Veranstaltung Forum Privatheit (2022), Berlin, Deutschland, 13.10.2022 – 14.10.2022
Schlagwörter data protection, GDPR, certification, internalization

Volltext §
DOI: 10.5445/IR/1000151588
Veröffentlicht am 18.10.2022
