Catalogue · Certification track
The GDPR-CARPA criteria index
GDPR-CARPA (CNPD, Luxembourg, GDPR Art. 42, v2.0) is the only GDPR certification criteria set a European supervisory authority has adopted under GDPR Art. 42. This index maps every criterion onto the course that teaches it — including the ones not written yet.
- 70
- Criteria
- 30
- Subjects
- 2
- Available now
- 4
- Coming soon
- 24
- Planned
SECTION I · Accountability and governance
controllers and processors · 18 criteria
1.1The target of evaluation
The system and interface inventory, and a data-flow diagram down to manual steps, transformations and printouts.
I-0
Coming soonRecords of Processing Activities · GDPR & AI Act Operations
one lesson — partly — the ToE inventory sits beside the register
1.2Policies and procedures
Management's accountability measures, the ten topics a policy set must cover, and the review that revalidates even the unchanged ones.
I-1 · I-2 · I-3
PlannedGovernance · Accountability & Certification
one lesson — new course 01
1.3The record of processing activities
Content for controller and for processor, then the management review that certifies completeness and accuracy.
I-4 · I-5 · I-6 · I-7
Coming soonRecords of Processing Activities · GDPR & AI Act Operations
in depth — three courses · eighteen modules · in build
1.4Facilitating data subjects' rights
The accessible contact point, identification and minimisation, one month with a reasoned extension to three, refusals that carry the complaint route.
I-8 · I-9
PlannedGovernance · Accountability & Certification
one lesson — new course 01
1.5The data protection officer
Designation and publication, the competence floor and its training substitutes, protected position, and the three-year audit plan.
I-10 · I-11 · I-12 · I-13
PlannedGovernance · Accountability & Certification
one lesson — new course 01
1.6Data breaches
The documented method for deciding whether an event qualifies, the register, notification content, and the processor's duty inside 72 hours.
I-14 · I-15
Coming soonPersonal Data Breach · GDPR & AI Act Operations
in depth — seven lessons · GDPR Art. 33–34
1.7Awareness and competencies
Competence defined per processing activity, annual training for staff and externals, documented participation, written commitments.
I-16 · I-17
PlannedGovernance · Accountability & Certification
one lesson — new course 01
SECTION II-a · Lawfulness, transparency and rights
controllers · 18 criteria
2.1Identifying and reviewing a legal basis
Necessity against the purpose, the conditions the law attaches, and the annual re-test of the basis itself.
II-a-1 · II-a-2
PlannedLawfulness, transparency and rights · Accountability & Certification
one lesson — new course 02
2.2The five bases other than consent
Contract, legal obligation, vital interest, public interest, legitimate interest — each with the assessment CARPA names.
II-a-4 · II-a-5 · II-a-6 · II-a-7 · II-a-8
PlannedLawfulness, transparency and rights · Accountability & Certification
one lesson — new course 02
2.3Consent
Freely given, specific, informed, unambiguous; explicit where required; the record kept unaltered; withdrawal as easy as giving.
II-a-3
Available nowStructured Consent · Structured Consent
in depth — Structured Consent 01–02 · 06 Studio · ISO/IEC TS 27560
2.4Special categories
The prohibition first, then the ten Article 9(2) routes one at a time, each with its own assessment and safeguards.
II-a-9
PlannedLawfulness, transparency and rights · Accountability & Certification
one lesson — new course 02
2.5Objection, restriction, automated decisions
When each right arises, the compelling-grounds analysis, restriction without deletion, and qualified human intervention.
II-a-10 · II-a-11 · II-a-12
PlannedLawfulness, transparency and rights · Accountability & Certification
one lesson — new course 02
2.6Transparency
The direct-collection list, the indirect list with its exceptions, and keeping information current as processing changes.
II-a-13 · II-a-14 · II-a-15
Available nowStructured Consent · Structured Consent
in depth — Structured Consent 03–05 · ISO/IEC 29184
2.7Access, portability and transfers
The structured retrieval process, the rights-of-others assessment, format choice, and the transfer-mechanism analysis with annual revalidation.
II-a-16 · II-a-17 · II-a-18
PlannedLawfulness, transparency and rights · Accountability & Certification
one lesson — new course 02
SECTION II-b–f · Data quality, storage and security
controllers · 21 criteria
3.1Purpose limitation and minimisation
Purpose quality, compatibility of further processing, and the field-by-field necessity record.
II-b-1 · II-b-2 · II-c-1 · II-c-2
PlannedData quality, storage and security · Accountability & Certification
one lesson — new course 03
3.2Accuracy and rectification
Source reliability assessed by method, annual verification of data held, and rectification propagated to every recipient.
II-d-1 · II-d-2 · II-d-3
PlannedData quality, storage and security · Accountability & Certification
one lesson — new course 03
3.3Storage limitation and erasure
Retention derived from law or a documented assessment; deletion and anonymisation tested annually, backups and logs included.
II-e-1 · II-e-2 · II-e-3
PlannedData quality, storage and security · Accountability & Certification
one lesson — new course 03
3.4Security: risk analysis and treatment
The named organisational and technical checklist, impact and probability on rights and freedoms, and accepted risks documented.
II-f-1 · II-f-2 · II-f-3
PlannedData quality, storage and security · Accountability & Certification
one lesson — new course 03
3.5Audit and follow-up
The independent annual audit, the three-year audit plan and its documented method, and the correction cycle.
II-f-4 · II-f-5
PlannedData quality, storage and security · Accountability & Certification
one lesson — new course 03
3.6DPIA and prior consultation
The documented decision either way, the four required contents, the view of data subjects, and consultation on residual high risk.
II-f-6 · II-f-7
Coming soonData Protection Impact Assessment · GDPR & AI Act Operations
in depth — seven lessons · GDPR Art. 35–36
3.7Outsourcing
Sufficiency assessed before and during, the nine contract stipulations, joint procedures, and annual independent monitoring.
II-f-8 · II-f-9 · II-f-10 · II-f-11
PlannedData quality, storage and security · Accountability & Certification
one lesson — new course 03
SECTION III · The processor's obligations
processors · 13 criteria
4.1The contract and documented instructions
What the contract must set out, the annual review testing instructions against actual processing, and processing under law without instruction.
III-1 · III-2 · III-3 · III-4
PlannedThe processor's obligations · Accountability & Certification
one lesson — new course 04
4.2Security
The controller's risk analysis and treatment, but with method and accepted risks validated by the contractual partner.
III-5 · III-6 · III-7
PlannedThe processor's obligations · Accountability & Certification
one lesson — new course 04
4.3Audit and follow-up
The independent audit, the partner's agreed involvement, and reports to both managements.
III-8 · III-9
PlannedThe processor's obligations · Accountability & Certification
one lesson — new course 04
4.4Subcontracting
Proving the sub-processor offers the same guarantees, prior written authorisation, and a chain contract with identical obligations.
III-10 · III-11
PlannedThe processor's obligations · Accountability & Certification
one lesson — new course 04
4.5Transfers and the end of service
The transfer-mechanism analysis validated before processing starts, and return or deletion at the end, copies included.
III-12 · III-13
PlannedThe processor's obligations · Accountability & Certification
one lesson — new course 04
THE MECHANISM · How certification is examined
the audit itself — no criteria numbers · 0 criteria
5.1Eligibility and the target of evaluation
The exclusions, the maturity self-assessment, and a meaningful ToE described across its four levels: legal context, business function, applications, infrastructure.
PlannedThe certification mechanism · Accountability & Certification
one lesson — new course 05 · first to publish
5.2ISAE 3000 and what the auditor tests
A type 2 reasonable-assurance report over a past period of six to twelve months: design and implementation, then operating effectiveness.
PlannedThe certification mechanism · Accountability & Certification
one lesson — new course 05
5.3Nonconformities and the decision
Major against minor, and their asymmetry: a major finding in Section I rejects the application; in Sections II or III it removes one activity from scope.
PlannedThe certification mechanism · Accountability & Certification
one lesson — new course 05
5.4The certificate
Validity tied to the audited period, renewal at each anniversary to a three-year maximum, changes to report, scope reduction, withdrawal, and the seal.
PlannedThe certification mechanism · Accountability & Certification
one lesson — new course 05
BEYOND THE CRITERIA · What CARPA does not reach
taught anyway — not counted in the thirty
—AI Act conformity
Risk classification, provider and deployer obligations, technical documentation, and the interface with the GDPR. CARPA excludes AI Act conformity entirely — and excludes most Article 10 data from certification.
Coming soonAI Act Compliance · GDPR & AI Act Operations
in depth — EQF 7 · Regulation (EU) 2024/1689
—Machine-readable documentation
Records, receipts and notices to ISO/IEC TS 27560 and ISO/IEC 29184, and registers a machine can validate. CARPA asks for documentation; it does not ask for it to be structured.
Read this first
KROG does not certify entities.
A GDPR-CARPA certificate is issued by an accredited certification body under CNPD supervision, and only entities established in Luxembourg are eligible. These courses prepare the people who build and defend the documentation the criteria require. Outside Luxembourg they are accountability training held to the only GDPR criteria a European authority has actually adopted — which is a stronger reference point than the Regulation alone, not a weaker one.
The criteria are versioned, and they do not cover everything.
The mechanism is at v2.0 (July 2023) and the CNPD keeps the criteria under review, so every course card and every certificate we issue carries the criteria version it was written and earned under. CARPA does not certify the security of processing, and it excludes most Article 10 data — so it is a floor for accountability, not a substitute for it.