Skip navigation

Panel Recap Bitkom PCO26: Collaborative Enforcement of Cross-Border Data Protection Certifications and Codes of Conduct

SCOPE EuropeNews

SCOPE Europe had the pleasure of participating in a panel at this year's Bitkom Privacy Conference, “Collaborative Enforcement of Cross-Border Data Protection Certifications and Codes of Conduct” – exploring how GDPR codes of conduct and certifications can provide credible, practical and scalable frameworks for organisations operating across borders.

The discussion brought together Alain Herrmann, Commissioner at the Luxembourg National Commission for Data Protection (CNPD); Gabriela Mercuri, Managing Director at SCOPE Europe; and Prof. Dr. Sebastian Lins, Professor for Information Systems at the University of Kassel, with the conversation moderated by Elena Kouremenou, Policy Officer for Data Privacy at Bitkom. Drawing on perspectives from a national data protection authority, an accredited Monitoring Body and academic research, the panellists explored what makes these accountability tools effective in practice - from the design of the underlying framework to the mechanisms needed to verify compliance and build trust.

A key theme was the importance of credibility and workability. Under Article 40 of the GDPR, a code of conduct should address the specific challenges of a particular processing context or sector and translate GDPR principles into practical, accessible requirements that organisations can implement. But guidance alone is not enough: without an appropriate and proportionate oversight mechanism, codes and certifications risk becoming little more than self-declarations, limiting their ability to provide meaningful assurance and legal certainty.

SCOPE Europe also highlighted how the practical challenges can vary significantly depending on the context of a particular code. Drawing on its experience as the accredited Monitoring Body of both the EU Cloud Code of Conduct and the Dutch Data Pro Code, SCOPE Europe pointed to the very different risks, technologies, data volumes and organisational profiles covered by these frameworks. This illustrates why codes and monitoring schemes need to remain sufficiently flexible to reflect the specific circumstances of the organisations they serve.

The discussion ultimately highlighted that successful codes of conduct and certifications require both sides of the equation: a credible, workable and proportionate framework and oversight mechanism, as well as a meaningful reason for organisations to invest in implementing it. When these elements come together, codes can effectively become practical accountability tools that are broadly adopted and genuinely create robust data protection standards.

We are grateful to the speakers and moderator for their contributions and look forward to continuing the conversation on how codes of conduct and certifications can support greater trust and cross-border consistency in the privacy sphere. Click here to watch the full discussion now available on YouTube.

Image_BitkomPrivacyConference2026.png