Catalogue · Certification track

    The GDPR-CARPA criteria index

    GDPR-CARPA (CNPD, Luxembourg, GDPR Art. 42, v2.0) is the only GDPR certification criteria set a European supervisory authority has adopted under GDPR Art. 42. This index maps every criterion onto the course that teaches it — including the ones not written yet.

    70
    Criteria
    30
    Subjects
    2
    Available now
    4
    Coming soon
    24
    Planned

    SECTION I · Accountability and governance

    controllers and processors · 18 criteria

    • 1.1The target of evaluation

      The system and interface inventory, and a data-flow diagram down to manual steps, transformations and printouts.

      I-0

      Coming soon

      Records of Processing Activities · GDPR & AI Act Operations

      one lesson — partly — the ToE inventory sits beside the register

    • 1.2Policies and procedures

      Management's accountability measures, the ten topics a policy set must cover, and the review that revalidates even the unchanged ones.

      I-1 · I-2 · I-3

      Planned

      Governance · Accountability & Certification

      one lesson — new course 01

    • 1.3The record of processing activities

      Content for controller and for processor, then the management review that certifies completeness and accuracy.

      I-4 · I-5 · I-6 · I-7

      Coming soon

      Records of Processing Activities · GDPR & AI Act Operations

      in depth — three courses · eighteen modules · in build

    • 1.4Facilitating data subjects' rights

      The accessible contact point, identification and minimisation, one month with a reasoned extension to three, refusals that carry the complaint route.

      I-8 · I-9

      Planned

      Governance · Accountability & Certification

      one lesson — new course 01

    • 1.5The data protection officer

      Designation and publication, the competence floor and its training substitutes, protected position, and the three-year audit plan.

      I-10 · I-11 · I-12 · I-13

      Planned

      Governance · Accountability & Certification

      one lesson — new course 01

    • 1.6Data breaches

      The documented method for deciding whether an event qualifies, the register, notification content, and the processor's duty inside 72 hours.

      I-14 · I-15

      Coming soon

      Personal Data Breach · GDPR & AI Act Operations

      in depth — seven lessons · GDPR Art. 33–34

    • 1.7Awareness and competencies

      Competence defined per processing activity, annual training for staff and externals, documented participation, written commitments.

      I-16 · I-17

      Planned

      Governance · Accountability & Certification

      one lesson — new course 01

    SECTION II-a · Lawfulness, transparency and rights

    controllers · 18 criteria

    • 2.1Identifying and reviewing a legal basis

      Necessity against the purpose, the conditions the law attaches, and the annual re-test of the basis itself.

      II-a-1 · II-a-2

      Planned

      Lawfulness, transparency and rights · Accountability & Certification

      one lesson — new course 02

    • 2.2The five bases other than consent

      Contract, legal obligation, vital interest, public interest, legitimate interest — each with the assessment CARPA names.

      II-a-4 · II-a-5 · II-a-6 · II-a-7 · II-a-8

      Planned

      Lawfulness, transparency and rights · Accountability & Certification

      one lesson — new course 02

    • 2.3Consent

      Freely given, specific, informed, unambiguous; explicit where required; the record kept unaltered; withdrawal as easy as giving.

      II-a-3

      Available now

      Structured Consent · Structured Consent

      in depth — Structured Consent 01–02 · 06 Studio · ISO/IEC TS 27560

    • 2.4Special categories

      The prohibition first, then the ten Article 9(2) routes one at a time, each with its own assessment and safeguards.

      II-a-9

      Planned

      Lawfulness, transparency and rights · Accountability & Certification

      one lesson — new course 02

    • 2.5Objection, restriction, automated decisions

      When each right arises, the compelling-grounds analysis, restriction without deletion, and qualified human intervention.

      II-a-10 · II-a-11 · II-a-12

      Planned

      Lawfulness, transparency and rights · Accountability & Certification

      one lesson — new course 02

    • 2.6Transparency

      The direct-collection list, the indirect list with its exceptions, and keeping information current as processing changes.

      II-a-13 · II-a-14 · II-a-15

      Available now

      Structured Consent · Structured Consent

      in depth — Structured Consent 03–05 · ISO/IEC 29184

    • 2.7Access, portability and transfers

      The structured retrieval process, the rights-of-others assessment, format choice, and the transfer-mechanism analysis with annual revalidation.

      II-a-16 · II-a-17 · II-a-18

      Planned

      Lawfulness, transparency and rights · Accountability & Certification

      one lesson — new course 02

    SECTION II-b–f · Data quality, storage and security

    controllers · 21 criteria

    • 3.1Purpose limitation and minimisation

      Purpose quality, compatibility of further processing, and the field-by-field necessity record.

      II-b-1 · II-b-2 · II-c-1 · II-c-2

      Planned

      Data quality, storage and security · Accountability & Certification

      one lesson — new course 03

    • 3.2Accuracy and rectification

      Source reliability assessed by method, annual verification of data held, and rectification propagated to every recipient.

      II-d-1 · II-d-2 · II-d-3

      Planned

      Data quality, storage and security · Accountability & Certification

      one lesson — new course 03

    • 3.3Storage limitation and erasure

      Retention derived from law or a documented assessment; deletion and anonymisation tested annually, backups and logs included.

      II-e-1 · II-e-2 · II-e-3

      Planned

      Data quality, storage and security · Accountability & Certification

      one lesson — new course 03

    • 3.4Security: risk analysis and treatment

      The named organisational and technical checklist, impact and probability on rights and freedoms, and accepted risks documented.

      II-f-1 · II-f-2 · II-f-3

      Planned

      Data quality, storage and security · Accountability & Certification

      one lesson — new course 03

    • 3.5Audit and follow-up

      The independent annual audit, the three-year audit plan and its documented method, and the correction cycle.

      II-f-4 · II-f-5

      Planned

      Data quality, storage and security · Accountability & Certification

      one lesson — new course 03

    • 3.6DPIA and prior consultation

      The documented decision either way, the four required contents, the view of data subjects, and consultation on residual high risk.

      II-f-6 · II-f-7

      Coming soon

      Data Protection Impact Assessment · GDPR & AI Act Operations

      in depth — seven lessons · GDPR Art. 35–36

    • 3.7Outsourcing

      Sufficiency assessed before and during, the nine contract stipulations, joint procedures, and annual independent monitoring.

      II-f-8 · II-f-9 · II-f-10 · II-f-11

      Planned

      Data quality, storage and security · Accountability & Certification

      one lesson — new course 03

    SECTION III · The processor's obligations

    processors · 13 criteria

    • 4.1The contract and documented instructions

      What the contract must set out, the annual review testing instructions against actual processing, and processing under law without instruction.

      III-1 · III-2 · III-3 · III-4

      Planned

      The processor's obligations · Accountability & Certification

      one lesson — new course 04

    • 4.2Security

      The controller's risk analysis and treatment, but with method and accepted risks validated by the contractual partner.

      III-5 · III-6 · III-7

      Planned

      The processor's obligations · Accountability & Certification

      one lesson — new course 04

    • 4.3Audit and follow-up

      The independent audit, the partner's agreed involvement, and reports to both managements.

      III-8 · III-9

      Planned

      The processor's obligations · Accountability & Certification

      one lesson — new course 04

    • 4.4Subcontracting

      Proving the sub-processor offers the same guarantees, prior written authorisation, and a chain contract with identical obligations.

      III-10 · III-11

      Planned

      The processor's obligations · Accountability & Certification

      one lesson — new course 04

    • 4.5Transfers and the end of service

      The transfer-mechanism analysis validated before processing starts, and return or deletion at the end, copies included.

      III-12 · III-13

      Planned

      The processor's obligations · Accountability & Certification

      one lesson — new course 04

    THE MECHANISM · How certification is examined

    the audit itself — no criteria numbers · 0 criteria

    • 5.1Eligibility and the target of evaluation

      The exclusions, the maturity self-assessment, and a meaningful ToE described across its four levels: legal context, business function, applications, infrastructure.

      Planned

      The certification mechanism · Accountability & Certification

      one lesson — new course 05 · first to publish

    • 5.2ISAE 3000 and what the auditor tests

      A type 2 reasonable-assurance report over a past period of six to twelve months: design and implementation, then operating effectiveness.

      Planned

      The certification mechanism · Accountability & Certification

      one lesson — new course 05

    • 5.3Nonconformities and the decision

      Major against minor, and their asymmetry: a major finding in Section I rejects the application; in Sections II or III it removes one activity from scope.

      Planned

      The certification mechanism · Accountability & Certification

      one lesson — new course 05

    • 5.4The certificate

      Validity tied to the audited period, renewal at each anniversary to a three-year maximum, changes to report, scope reduction, withdrawal, and the seal.

      Planned

      The certification mechanism · Accountability & Certification

      one lesson — new course 05

    BEYOND THE CRITERIA · What CARPA does not reach

    taught anyway — not counted in the thirty

    • —AI Act conformity

      Risk classification, provider and deployer obligations, technical documentation, and the interface with the GDPR. CARPA excludes AI Act conformity entirely — and excludes most Article 10 data from certification.

      Coming soon

      AI Act Compliance · GDPR & AI Act Operations

      in depth — EQF 7 · Regulation (EU) 2024/1689

    • —Machine-readable documentation

      Records, receipts and notices to ISO/IEC TS 27560 and ISO/IEC 29184, and registers a machine can validate. CARPA asks for documentation; it does not ask for it to be structured.

      Available now

      Structured Consent · Structured Consent

      in depth — the catalogue's own thesis

    Read this first

    KROG does not certify entities.

    A GDPR-CARPA certificate is issued by an accredited certification body under CNPD supervision, and only entities established in Luxembourg are eligible. These courses prepare the people who build and defend the documentation the criteria require. Outside Luxembourg they are accountability training held to the only GDPR criteria a European authority has actually adopted — which is a stronger reference point than the Regulation alone, not a weaker one.

    The criteria are versioned, and they do not cover everything.

    The mechanism is at v2.0 (July 2023) and the CNPD keeps the criteria under review, so every course card and every certificate we issue carries the criteria version it was written and earned under. CARPA does not certify the security of processing, and it excludes most Article 10 data — so it is a floor for accountability, not a substitute for it.