Code of Conduct on Data Protection for Research (GDPR Article 40)
Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Art.40 Research Code: Data Subject Rights and Transparency
Provide transparency to participants and uphold data-subject rights, applying any Article 89(2) derogations only where rights would render the research impossible or seriously impair it, with conditions.
- Participant information notices
- Rights-request handling procedure
- Documented basis for any Art.89(2) derogation
- Blanket derogation from rights without conditions
- No participant information
Art.40 Research Code: Governance, Monitoring and Enforcement (Art.41)
Define how controllers/processors adhere to the code, the binding commitments they make, and the public register of adherents.
- Adherence application + binding-commitment records
- Public register of adherents
- Adherence not documented/binding
Submit the code to the competent supervisory authority (and EDPB for transnational codes) for approval, registration and publication.
- Submission + approval records from the supervisory authority/EDPB
- Registration/publication evidence
- Code applied before approval
- No SA/EDPB submission
The monitoring body conducts periodic reviews/audits of adherents' compliance with the code.
- Monitoring-body audit schedule + reports
- Adherent compliance-review records
- No periodic compliance review
Provide mechanisms for handling complaints about infringements of the code by adherents.
- Complaint-handling procedure of the monitoring body
- Complaint records and outcomes
- No complaint mechanism
Designate a code owner (association/body representing research controllers/processors) responsible for the code's development and governance.
- Code-owner charter
- Governance structure for the code
- No accountable code owner
Designate an accredited monitoring body with the requisite expertise, independence and procedures to monitor compliance (mandatory for private-sector codes).
- Monitoring-body accreditation
- Independence + expertise evidence
- Monitoring procedures
- No accredited monitoring body
- Monitoring body not independent
Review and update the code to reflect legal, regulatory and sector developments, with SA/EDPB re-approval of amendments.
- Code review cycle
- Amendment + re-approval records
- Code not maintained/updated
The monitoring body can take action against adherents that infringe the code (suspension/exclusion) and inform the supervisory authority.
- Sanction/suspension procedure
- Records of actions taken + SA notification
- No enforcement against non-compliant adherents
Provide training and awareness to adherents' personnel on the code's commitments and research data-protection practices.
- Training materials + completion records for the code
- No training on the code
Art.40 Research Code: Research Safeguards (Art.89)
Define when research data is anonymised (irreversibly non-identifiable) and therefore outside GDPR, with a robust re-identification-risk assessment.
- Anonymisation criteria + re-identification risk assessment
- Anonymisation claimed but data re-identifiable
Conduct DPIAs for high-risk research processing and define when a DPIA is required for research projects.
- DPIA records for high-risk research
- DPIA trigger criteria for research projects
- No DPIA for high-risk research
Apply pseudonymisation as a default safeguard for research data where the purpose can be achieved without identifiers, with key separation and access controls.
- Pseudonymisation methodology + key-separation controls
- Assessment that purposes cannot be met with further-minimised data
- Identifiers retained without justification
- No key separation
Set storage-limitation and archival rules for research data, permitting longer retention for research subject to Article 89 safeguards.
- Retention/archival schedule for research datasets
- Justification for extended research retention with safeguards
- Indefinite retention without safeguards
Art.40 Research Code: Scope and Lawful Basis
Where consent is used, meet GDPR consent conditions; broad consent to areas of research is permitted where consistent with ethical standards and recognised purposes, with the ability to consent to parts.
- Consent records meeting Art.7 conditions
- Broad-consent framework aligned to recognised research purposes
- Bundled consent
- Broad consent without granular options
Establish the lawful basis for research processing (e.g. public interest/legitimate interest or consent) and the Article 9(2)(j) condition for special-category data, subject to Article 89 safeguards.
- Lawful-basis determination per research activity
- Article 9(2)(j) condition + Member State law basis for special-category data
- Reliance on consent where another basis applies
- No special-category condition documented
Define the categories of research processing the code covers (controllers/processors, data categories, research purposes) so adherence scope is clear.
- Documented scope of research processing covered by the code
- Register of adhering controllers/processors
- Scope undefined or broader than the code permits
Art.40 Research Code: Security and Breach
Maintain breach detection, notification to the supervisory authority and affected participants, and remediation for research data.
- Breach response + notification procedure
- Breach log
- No breach notification path for research data
Art.40 Research Code: Transfers and Processors
Govern processors handling research data via Article 28 contracts and oversight.
- Article 28 data-processing agreements
- Processor oversight/audit records
- No DPA with research processors
Define safeguards for transferring research data outside the EEA (adequacy, SCCs, or the code itself as a transfer tool under Art.40(3)).
- Transfer mechanism per recipient (adequacy/SCC/code)
- Transfer impact assessment
- Transfers without an Art.44-49 mechanism
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Code of Conduct on Data Protection for Research (GDPR Article 40) framework page.