Skip to content

Evidence request lists

Code of Conduct on Data Protection for Research (GDPR Article 40)

Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Art.40 Research Code: Data Subject Rights and Transparency

RDCOC-RIG-01
Data Subject Rights and Information in Research

Provide transparency to participants and uphold data-subject rights, applying any Article 89(2) derogations only where rights would render the research impossible or seriously impair it, with conditions.

Artefacts an auditor will ask for
  • Participant information notices
  • Rights-request handling procedure
  • Documented basis for any Art.89(2) derogation
Where this commonly fails
  • Blanket derogation from rights without conditions
  • No participant information

Art.40 Research Code: Governance, Monitoring and Enforcement (Art.41)

RDCOC-ADH-01
Adherence Procedures

Define how controllers/processors adhere to the code, the binding commitments they make, and the public register of adherents.

Artefacts an auditor will ask for
  • Adherence application + binding-commitment records
  • Public register of adherents
Where this commonly fails
  • Adherence not documented/binding
RDCOC-APP-01
Supervisory Authority / EDPB Approval

Submit the code to the competent supervisory authority (and EDPB for transnational codes) for approval, registration and publication.

Artefacts an auditor will ask for
  • Submission + approval records from the supervisory authority/EDPB
  • Registration/publication evidence
Where this commonly fails
  • Code applied before approval
  • No SA/EDPB submission
RDCOC-AUD-01
Audits and Compliance Reviews

The monitoring body conducts periodic reviews/audits of adherents' compliance with the code.

Artefacts an auditor will ask for
  • Monitoring-body audit schedule + reports
  • Adherent compliance-review records
Where this commonly fails
  • No periodic compliance review
RDCOC-COM-01
Complaint Handling

Provide mechanisms for handling complaints about infringements of the code by adherents.

Artefacts an auditor will ask for
  • Complaint-handling procedure of the monitoring body
  • Complaint records and outcomes
Where this commonly fails
  • No complaint mechanism
RDCOC-GOV-01
Code Owner and Governance

Designate a code owner (association/body representing research controllers/processors) responsible for the code's development and governance.

Artefacts an auditor will ask for
  • Code-owner charter
  • Governance structure for the code
Where this commonly fails
  • No accountable code owner
RDCOC-MON-01
Accredited Monitoring Body

Designate an accredited monitoring body with the requisite expertise, independence and procedures to monitor compliance (mandatory for private-sector codes).

Artefacts an auditor will ask for
  • Monitoring-body accreditation
  • Independence + expertise evidence
  • Monitoring procedures
Where this commonly fails
  • No accredited monitoring body
  • Monitoring body not independent
RDCOC-REV-01
Periodic Review and Update

Review and update the code to reflect legal, regulatory and sector developments, with SA/EDPB re-approval of amendments.

Artefacts an auditor will ask for
  • Code review cycle
  • Amendment + re-approval records
Where this commonly fails
  • Code not maintained/updated
RDCOC-SAN-01
Sanctions and Suspension

The monitoring body can take action against adherents that infringe the code (suspension/exclusion) and inform the supervisory authority.

Artefacts an auditor will ask for
  • Sanction/suspension procedure
  • Records of actions taken + SA notification
Where this commonly fails
  • No enforcement against non-compliant adherents
RDCOC-TRN-01
Training and Awareness

Provide training and awareness to adherents' personnel on the code's commitments and research data-protection practices.

Artefacts an auditor will ask for
  • Training materials + completion records for the code
Where this commonly fails
  • No training on the code

Art.40 Research Code: Research Safeguards (Art.89)

RDCOC-ANO-01
Anonymisation Criteria

Define when research data is anonymised (irreversibly non-identifiable) and therefore outside GDPR, with a robust re-identification-risk assessment.

Artefacts an auditor will ask for
  • Anonymisation criteria + re-identification risk assessment
Where this commonly fails
  • Anonymisation claimed but data re-identifiable
RDCOC-DPI-01
Data Protection Impact Assessments

Conduct DPIAs for high-risk research processing and define when a DPIA is required for research projects.

Artefacts an auditor will ask for
  • DPIA records for high-risk research
  • DPIA trigger criteria for research projects
Where this commonly fails
  • No DPIA for high-risk research
RDCOC-PSE-01
Pseudonymisation Standards

Apply pseudonymisation as a default safeguard for research data where the purpose can be achieved without identifiers, with key separation and access controls.

Artefacts an auditor will ask for
  • Pseudonymisation methodology + key-separation controls
  • Assessment that purposes cannot be met with further-minimised data
Where this commonly fails
  • Identifiers retained without justification
  • No key separation
RDCOC-RET-01
Retention and Archival

Set storage-limitation and archival rules for research data, permitting longer retention for research subject to Article 89 safeguards.

Artefacts an auditor will ask for
  • Retention/archival schedule for research datasets
  • Justification for extended research retention with safeguards
Where this commonly fails
  • Indefinite retention without safeguards

Art.40 Research Code: Scope and Lawful Basis

RDCOC-CON-01
Consent and Broad Consent

Where consent is used, meet GDPR consent conditions; broad consent to areas of research is permitted where consistent with ethical standards and recognised purposes, with the ability to consent to parts.

Artefacts an auditor will ask for
  • Consent records meeting Art.7 conditions
  • Broad-consent framework aligned to recognised research purposes
Where this commonly fails
  • Bundled consent
  • Broad consent without granular options
RDCOC-LAW-01
Lawful Basis for Research

Establish the lawful basis for research processing (e.g. public interest/legitimate interest or consent) and the Article 9(2)(j) condition for special-category data, subject to Article 89 safeguards.

Artefacts an auditor will ask for
  • Lawful-basis determination per research activity
  • Article 9(2)(j) condition + Member State law basis for special-category data
Where this commonly fails
  • Reliance on consent where another basis applies
  • No special-category condition documented
RDCOC-SCO-01
Scope of Processing Activities

Define the categories of research processing the code covers (controllers/processors, data categories, research purposes) so adherence scope is clear.

Artefacts an auditor will ask for
  • Documented scope of research processing covered by the code
  • Register of adhering controllers/processors
Where this commonly fails
  • Scope undefined or broader than the code permits

Art.40 Research Code: Security and Breach

RDCOC-BRE-01
Breach Notification Procedures

Maintain breach detection, notification to the supervisory authority and affected participants, and remediation for research data.

Artefacts an auditor will ask for
  • Breach response + notification procedure
  • Breach log
Where this commonly fails
  • No breach notification path for research data

Art.40 Research Code: Transfers and Processors

RDCOC-PRO-01
Processor Engagements

Govern processors handling research data via Article 28 contracts and oversight.

Artefacts an auditor will ask for
  • Article 28 data-processing agreements
  • Processor oversight/audit records
Where this commonly fails
  • No DPA with research processors
RDCOC-TRA-01
International Data Transfers

Define safeguards for transferring research data outside the EEA (adequacy, SCCs, or the code itself as a transfer tool under Art.40(3)).

Artefacts an auditor will ask for
  • Transfer mechanism per recipient (adequacy/SCC/code)
  • Transfer impact assessment
Where this commonly fails
  • Transfers without an Art.44-49 mechanism
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Code of Conduct on Data Protection for Research (GDPR Article 40) framework page.