Croatia’s personal data protection agency, AZOP, has put out a practical explainer on GDPR certification. The tone is useful because this topic gets marketed into mush. A seal is not a gold star for the whole company. It is an independent check that named processing activities met named criteria, for a named period, on a named version of a product or service.
How the machine is supposed to work
A certification mechanism, often called a scheme, is the package: criteria, assessment method, and rules for issuing, watching, renewing, suspending, and pulling a certificate. The certificate is the output of that assessment. A mark or seal may be used only under that scheme’s rules.
In short: AZOP or the European Data Protection Board approves the criteria. The national accreditation body accredits the certification body. The accredited body evaluates the processing and issues the certificate. EDPB does not hand certificates to companies one by one.
Croatia still has no national mechanism approved under Article 42(5) and listed in the EDPB register. The Croatian Accreditation Agency has not accredited any body for Articles 42 and 43. You cannot get a Croatian national-scheme certificate today. That does not block a Croatian controller or processor from applying for a European Data Protection Seal through a body in another EU or EEA country, if that body is accredited for that exact seal, covers the processing you want assessed, and is allowed to work with organizations in Croatia. You do not need prior AZOP or HAA permission. You do not file with EDPB. You file with the certification body.
ISO/IEC 17065 accreditation by itself is not enough. Accreditation for another member state’s national scheme does not automatically let that body issue certificates that work as a European Seal in Croatia. Check the EDPB register for the words “European Data Protection Seal,” check the accreditation scope, and check whether Croatia is in that scope.
National scheme versus European Seal
AZOP draws a clean line. National criteria are approved by AZOP after an EDPB consistency opinion. They apply where those criteria were approved. They are not automatically good across the Union. They can reflect Croatian law and sector rules, and another country can later approve the same criteria.
A European Seal’s criteria are approved by EDPB. The point is Union-wide use and recognition. The scheme still has to say how national and sector rules get taken into account in each country where it runs. The certificate still comes from a body accredited for that Seal, not from the Board.
Neither flavor is a general “GDPR compliant company” stamp. Both are limited to subject, scope, version, and term on the piece of paper.
What you can certify
Article 42 certifies processing operations of controllers or processors. A product, service, process, or system can appear on the certificate only to the extent the related processing is defined. You might certify the processing inside one digital service, or only the login flow. The certificate has to say what was in scope and which version.
It does not automatically cover the rest of the firm, every processing activity, or the whole software stack. Do not advertise “fully GDPR compliant” off a seal that covers one module.
ISO/IEC 27001, ISO/IEC 27701, and DPO competency certificates are useful evidence of measures or skill. They are not Article 42 certificates unless they were issued under an approved mechanism by a body accredited for that mechanism.
What the paper actually proves
The applicant gave the certification body documents, evidence, and access to real practice sufficient to show the scheme’s criteria were met. That is compliance with those criteria, in that scope. It is not proof of complete, permanent compliance with every GDPR article.
The certificate does not shrink the controller’s or processor’s liability. It does not replace legal duties. It does not clip AZOP’s powers. A certified organization can still be investigated and sanctioned if the Regulation is breached.
Following an approved scheme can be one factor under Article 83(2)(j) when a fine is calculated. Holding a certificate does not guarantee a lighter penalty.
It can help demonstrate pieces of Articles 24, 25, 28, and 32. A processor certificate can be one element of the “sufficient guarantees” in Article 28. It does not replace a DPIA when you need one, a legal basis, notices, an Article 28 contract, or security measures.
Ordinary national certificates and European Seals are not, by themselves, a Chapter V transfer tool. Only a mechanism expressly approved for Article 46(2)(f), with binding enforceable commitments on the importer, can serve as an appropriate safeguard. Check the EDPB register for that specific approval.
How an organization actually gets one
Define the processing: purposes, controller and processor roles, systems, interfaces, recipients, processors, transfers. Pick a scheme that covers that type of processing and your role. Confirm it in the EDPB public register. Pick a body accredited for that scheme, not “a certifier” in the abstract. Ask about territorial scope, timeline, and fees. Fees follow complexity, readiness, and how much checking is required.
Hand over records of processing, legal bases, notices, processor contracts, risk and DPIA work, retention and deletion rules, TOMs, rights-handling, and breach procedures. The body reviews documents, talks to staff, may visit the site, and may run technical tests. If the criteria are met, it issues the certificate and then watches you for the life of it.
Maximum term is three years. Renewal is not automatic. AZOP’s additional accreditation requirements say surveillance should be risk-based and happen at least twice in the cycle. Tell the body promptly about material changes to purpose, methods, tech, data scope, processors, transfers, security, or law. If criteria fail, the certificate can be limited, suspended, or withdrawn. Accreditation of the body itself can last up to five years. That is a different clock from your certificate.
AZOP encourages schemes, approves national criteria after EDPB opinion, sets extra accreditation requirements, and can order that a certificate not be issued or be pulled. HAA accredits bodies to EN ISO/IEC 17065 plus AZOP’s extras. EDPB approves Seal criteria, opinions on national criteria, and the public register. The scheme owner maintains criteria and rules. The certification body assesses, decides, surveils, handles complaints, suspends or withdraws. You still own GDPR compliance.
A would-be certification body has to show expertise, independence, impartiality, no conflicts, a solid method, and a transparent complaint system. In Croatia the accreditation request goes to HAA under 17065 and AZOP’s additional requirements.
AZOP will not pick a commercial certifier for you. Use the EDPB register, the accreditor’s register, and the scheme owner’s official pages. To test a certificate in the wild, read the scheme name, exact scope, issue and expiry dates, the issuer, and whether that issuer is accredited for that scheme. Then check the body’s public register and the EDPB list.
The honest pitch is narrow. Certification turns GDPR duties into checkable requirements for a defined slice of processing and lets someone outside the company kick the tires. It does not buy you a quiet year with the supervisor, and it does not let marketing rewrite the scope line into a company-wide halo.