Back to Frameworks

Code of Conduct on Data Protection for Research (GDPR Article 40)

European Union
v2022
6 domains
20 controls

Represents the GDPR Article 40 code-of-conduct mechanism applied to the scientific-research sector. There is no single EDPB-approved transnational research code; the controls capture what such a code must contain under GDPR Articles 40 (codes of conduct), 41 (accredited monitoring bodies) and 89 (safeguards and derogations for scientific research), informed by EDPB guidance. Sectoral codes exist (e.g. clinical-research and biobanking codes).

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Art.40 Research Code: Data Subject Rights and Transparency

1 controls
Controls in the Art.40 Research Code: Data Subject Rights and Transparency domain of Code of Conduct on Data Protection for Research (GDPR Article 40)1 controls
CodeTitle
RDCOC-RIG-01Data Subject Rights and Information in Research

Art.40 Research Code: Governance, Monitoring and Enforcement (Art.41)

9 controls
Controls in the Art.40 Research Code: Governance, Monitoring and Enforcement (Art.41) domain of Code of Conduct on Data Protection for Research (GDPR Article 40)9 controls
CodeTitle
RDCOC-ADH-01Adherence Procedures
RDCOC-APP-01Supervisory Authority / EDPB Approval
RDCOC-AUD-01Audits and Compliance Reviews
RDCOC-COM-01Complaint Handling
RDCOC-GOV-01Code Owner and Governance
RDCOC-MON-01Accredited Monitoring Body
RDCOC-REV-01Periodic Review and Update
RDCOC-SAN-01Sanctions and Suspension
RDCOC-TRN-01Training and Awareness

Art.40 Research Code: Research Safeguards (Art.89)

4 controls
Controls in the Art.40 Research Code: Research Safeguards (Art.89) domain of Code of Conduct on Data Protection for Research (GDPR Article 40)4 controls
CodeTitle
RDCOC-ANO-01Anonymisation Criteria
RDCOC-DPI-01Data Protection Impact Assessments
RDCOC-PSE-01Pseudonymisation Standards
RDCOC-RET-01Retention and Archival

Art.40 Research Code: Scope and Lawful Basis

3 controls
Controls in the Art.40 Research Code: Scope and Lawful Basis domain of Code of Conduct on Data Protection for Research (GDPR Article 40)3 controls
CodeTitle
RDCOC-CON-01Consent and Broad Consent
RDCOC-LAW-01Lawful Basis for Research
RDCOC-SCO-01Scope of Processing Activities

Art.40 Research Code: Security and Breach

1 controls
Controls in the Art.40 Research Code: Security and Breach domain of Code of Conduct on Data Protection for Research (GDPR Article 40)1 controls
CodeTitle
RDCOC-BRE-01Breach Notification Procedures

Art.40 Research Code: Transfers and Processors

2 controls
Controls in the Art.40 Research Code: Transfers and Processors domain of Code of Conduct on Data Protection for Research (GDPR Article 40)2 controls
CodeTitle
RDCOC-PRO-01Processor Engagements
RDCOC-TRA-01International Data Transfers

Your Compliance Coverage

If you comply with Code of Conduct on Data Protection for Research (GDPR Article 40), you already cover:

Maps to 3 other frameworks

20 total controls
GDPR
10 source controls mapped|9 target controls covered
50%
ISO 37001:2016
1 source controls mapped|1 target controls covered
5%
ISO 13485:2016
1 source controls mapped|1 target controls covered
5%

Frequently Asked Questions

What is Code of Conduct on Data Protection for Research (GDPR Article 40)?

Code of Conduct on Data Protection for Research (GDPR Article 40) is a compliance framework from European Union with 6 domains and 20 controls. Represents the GDPR Article 40 code-of-conduct mechanism applied to the scientific-research sector. There is no single EDPB-approved transnational research code; the controls capture what such a code must contain under GDPR Articles 40 (codes of conduct), 41 (accredited monitoring bodies) and 89 (safeguards and derogations for scientific research), informed by EDPB guidance. Sectoral codes exist (e.g. clinical-research and biobanking codes). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Code of Conduct on Data Protection for Research (GDPR Article 40) have?

Code of Conduct on Data Protection for Research (GDPR Article 40) has 20 controls organised across 6 domains. The largest domains are Art.40 Research Code: Governance, Monitoring and Enforcement (Art.41) (9 controls), Art.40 Research Code: Research Safeguards (Art.89) (4 controls), Art.40 Research Code: Scope and Lawful Basis (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Code of Conduct on Data Protection for Research (GDPR Article 40) map to?

Code of Conduct on Data Protection for Research (GDPR Article 40) maps to 3 other compliance frameworks. The top mapping partners are GDPR (50% coverage), ISO 37001:2016 (5% coverage), ISO 13485:2016 (5% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with Code of Conduct on Data Protection for Research (GDPR Article 40) compliance?

Start your Code of Conduct on Data Protection for Research (GDPR Article 40) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Code of Conduct on Data Protection for Research (GDPR Article 40) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 20 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required