🏛️ Context of the EDPB Opinion
On April 15, 2026, the European Data Protection Board (EDPB) issued Opinion 15/2026 specifically assessing whether the Europrivacy certification criteria can be used as a transfer mechanism under Articles 42 and 46 GDPR.
This initiative was first reviewed and submitted by the Luxembourg supervisory authority (CNPD), acting as lead authority, before being assessed at EU level under the GDPR consistency mechanism. This process ensures that the scheme is recognized across the EU as a European Data Protection Seal, rather than a purely national initiative.
Unlike Opinion 14/2026, which focuses on certification as a European Data Protection Seal, Opinion 15/2026 specifically evaluates certification in the context of international data transfers.
The Opinion comes in the broader context of post-Schrems II transfer constraints, where organizations must rely on adequacy decisions or tools such as Standard Contractual Clauses (SCCs) combined with Transfer Impact Assessments (TIAs) and supplementary measures.
✔️ What does certification as a tool for transfer mean?
The GDPR allows certification to be used as a transfer mechanism (Article 46(2)(f)), but this possibility had remained largely theoretical.
The EDPB now confirms that Europrivacy certification, when specifically approved for transfers, can serve as an appropriate safeguard under Article 46 GDPR, for situations where there is no adequacy decision for the destination country, provided strict conditions are met.
In practical terms, using certification for transfers means:
• An EEA exporter (a controller/processor subject to the GDPR) may rely on a data importer’s certification as an “appropriate safeguard” for an international transfer only if:
o the certification is specifically approved for transfer purposes, and
o it is accompanied by the importer’s binding and enforceable commitments to apply those safeguards (including commitments linked to data subject rights).
Certification therefore operates as:
• a pre-audited and standardized compliance framework, and
• a transfer mechanism when combined with contractual commitments.
However, the EDPB makes it clear that: “Certification is not a standalone solution and does not remove the need for contractual and accountability measures.”
📋 Criteria for approval
The EDPB assessed whether the certification criteria ensure a level of protection essentially equivalent to the GDPR.
At a high level, the scheme requires that certified entities:
• Comply with core GDPR principles (lawfulness, purpose limitation, minimization);
• ensure the effective exercise of data subject rights;
• implement appropriate technical and organizational measures;
• manage data breaches and risks;
• map and control data flows and onward transfers;
• assess the impact of third-country laws on Data Protection.
A notable requirement is that: “transfers may only start once certification is granted and validated.” This reflects a shift toward ensuring compliance in advance, by integrating transfer safeguards directly into the certification process.
🔍 A central issue: third-country laws and risk assessment
A major takeaway from the Opinion is that the assessment of third-country laws and practices remains at the core of the transfer analysis.
Certified organizations must:
• assess whether local laws (e.g. access by public authorities) undermine Data Protection;
• implement supplementary measures where necessary;
• suspend or stop transfers if adequate protection cannot be ensured.
In other words: The logic of the TIA is not removed but it is integrated into the certification framework.
🔄 The role of the exporter: no “plug-and-play” solution
A key practical takeaway is that EU exporters cannot rely blindly on certification.
They must:
• verify that the certification is valid and not expired;
• ensure it covers the specific transfer and processing scope (i.e. the certified “Target of Evaluation”);
• reflect the mechanism in their contractual arrangements;
• inform data subjects of the safeguards used.
This confirms that certification under Opinion 15/2026 operates as a complementary safeguard, not a replacement for exporter due diligence obligations.
A further limitation is that the scheme does not cover joint controllership scenarios. This is not due to the number of importers, but to the nature of certification itself: it requires a single entity to fully control and guarantee the certified processing.
Certification reduces the need to repeatedly build and assess transfer safeguards from scratch, but it does not eliminate the exporter’s responsibility to verify that those safeguards are appropriate.
🤝 Potential benefits
If widely adopted, certification could:
• provide a standardized and scalable alternative to SCCs;
• reduce duplication of TIAs across multiple transfers;
• increase transparency and trust;
• offer a competitive advantage for certified organizations.
For sectors such as Clinical Research, this could theoretically:
• streamline transfers between EU sites and non-EU sponsors;
• simplify global data governance.
🔒 Practical limitations
However, several constraints limit its immediate impact:
• Scope limitation: certification applies only to a defined processing activity (not an entire organization);
• Operational complexity: audits, governance, and continuous compliance are required;
• Legal commitments: importers must accept strong obligations, including EU oversight and enforceable rights;
• Exporter due diligence remains necessary.
In practice, certification reorganizes transfer compliance but does not eliminate it.
💡 Conclusion: a promising but still emerging tool
The EDPB’s approval of Europrivacy as a transfer tool marks an important evolution in the GDPR transfer landscape.
It introduces a more structured and standardized approach to international transfers, which could be particularly valuable for organizations managing multiple cross-border data flows.
However, in practice:
• certification is complex to obtain and maintain;
• it applies only to specific processing scopes;
• it requires strong governance and legal commitments.
As a result, existing tools such as:
• adequacy decisions (e.g. EU-US Data Privacy Framework), and
• SCCs
will likely remain dominant in the short term.
🧬 Clinical Trials perspective
For Clinical Research stakeholders (sponsors, CROs, vendors), this mechanism is particularly relevant given the systematic transfer of sensitive Health Data from EU sites to global sponsors.
In theory, certification could streamline these transfers by reducing the need for repeated SCCs and TIAs across studies.
In practice, however, its limited scope (processing-based), operational complexity, and reliance on strict governance mean that it is unlikely to replace existing transfer tools in the near term.
At MyData-TRUST, we closely monitor developments in Data Protection and Data Privacy and support sponsors, CROs, and organizations across the Life Sciences sector with practical, tailored advice on their data processing activities. If you would like to discuss how these developments may affect your operations, please feel free to get in touch.
Author: Nicolas André