Code of Conduct on Data Protection for Research (GDPR Article 40)
The Code of Conduct on Data Protection for Research, adopted under GDPR Article 40 and endorsed by the European Data Protection Board (EDPB) in 2022, offers practical guidance for research organisations on GDPR‑compliant data handling. It defines lawful bases for research processing, outlines conditions for consent, clarifies the role of data protection impact assessments, sets out governance and accountability mechanisms, and provides sector‑specific recommendations for handling personal data in research contexts.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (21)
Adherence
| Code | Title |
|---|---|
| RDCOC-ADH-01 | Adherence Procedures |
Approval
| Code | Title |
|---|---|
| RDCOC-APP-01 | EDPB or Supervisory Authority Approval |
Approval and Monitoring
| Code | Title |
|---|---|
| Art. 40(5) | Draft code submission |
| Art. 40(6) | Supervisory authority approval |
| Art. 40(7) | Registration and publication |
Code Development and Governance
| Code | Title |
|---|---|
| Art. 40(1) | Encouragement of codes of conduct |
| Art. 40(2) | Sector-specific contributions |
| Art. 40(3) | Code preparation by associations |
Data Subject Rights
| Code | Title |
|---|---|
| RDCOC-RIG-01 | Data Subject Rights in Research |
Enforcement
| Code | Title |
|---|---|
| RDCOC-COM-01 | Complaint Handling |
| RDCOC-SAN-01 | Sanctions and Suspension |
Governance
| Code | Title |
|---|---|
| RDCOC-GOV-01 | Code Owner and Governance |
Incident Management
| Code | Title |
|---|---|
| RDCOC-BRE-01 | Breach Notification Procedures |
Lawful Basis
| Code | Title |
|---|---|
| RDCOC-CON-01 | Consent and Broad Consent |
| RDCOC-LAW-01 | Lawful Basis for Research |
Maintenance
| Code | Title |
|---|---|
| RDCOC-REV-01 | Periodic Review and Update |
Monitoring
| Code | Title |
|---|---|
| RDCOC-AUD-01 | Audits and Compliance Reviews |
| RDCOC-MON-01 | Monitoring Body |
Monitoring Bodies
| Code | Title |
|---|---|
| Art. 41(1) | Monitoring body requirement |
| Art. 41(2) | Accreditation of monitoring bodies |
| Art. 41(4) | Enforcement actions |
Research Data Specific Provisions
| Code | Title |
|---|---|
| Art. 40(2)(i) | Dispute resolution procedures |
| Art. 89(1) | Safeguards for scientific research processing |
| Art. 89(2) | Derogations for research |
Retention
| Code | Title |
|---|---|
| RDCOC-RET-01 | Retention and Archival |
Risk Management
| Code | Title |
|---|---|
| RDCOC-DPI-01 | Data Protection Impact Assessments |
Scope
| Code | Title |
|---|---|
| RDCOC-SCO-01 | Scope of Processing Activities |
Scope and Application Areas
| Code | Title |
|---|---|
| Art. 40(2)(a) | Fair and transparent processing |
| Art. 40(2)(b) | Legitimate interests of controllers |
| Art. 40(2)(c) | Collection of personal data |
| Art. 40(2)(d) | Pseudonymisation of personal data |
| Art. 40(2)(e) | Information to data subjects and authorities |
| Art. 40(2)(h) | Appropriate safeguards for data transfers |
Technical Measures
| Code | Title |
|---|---|
| RDCOC-ANO-01 | Anonymisation Criteria |
| RDCOC-PSE-01 | Pseudonymisation Standards |
Training
| Code | Title |
|---|---|
| RDCOC-TRN-01 | Training and Awareness |
Transfers
| Code | Title |
|---|---|
| RDCOC-TRA-01 | International Data Transfers |
Vendor Management
| Code | Title |
|---|---|
| RDCOC-PRO-01 | Processor Engagements |
Your Compliance Coverage
If you comply with Code of Conduct on Data Protection for Research (GDPR Article 40), you already cover:
Angola Personal Data Protection Law (Law No. 22/11)
18%
7 controls mapped
Compare →Digital Services Act (DSA) - Regulation (EU) 2022/2065
18%
7 controls mapped
Compare →Digital Services Act (Regulation (EU) 2022/2065 of the European Parliament and of the Council of 6 July 2022)
18%
7 controls mapped
Compare →+ 331 more: Chile Personal Data Protection Law (Law No. 21.719) (18%), North Macedonia Law on Personal Data Protection (2020) (18%)
See all 334 mapped frameworks ↓Maps to 334 other frameworks
Frequently Asked Questions
What is Code of Conduct on Data Protection for Research (GDPR Article 40)?
Code of Conduct on Data Protection for Research (GDPR Article 40) is a compliance framework from European Union with 21 domains and 38 controls. The Code of Conduct on Data Protection for Research, adopted under GDPR Article 40 and endorsed by the European Data Protection Board (EDPB) in 2022, offers practical guidance for research organisations on GDPR‑compliant data handling. It defines lawful bases for research processing, outlines conditions for consent, clarifies the role of data protection impact assessments, sets out governance and accountability mechanisms, and provides sector‑specific recommendations for handling personal data in research contexts. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Code of Conduct on Data Protection for Research (GDPR Article 40) have?
Code of Conduct on Data Protection for Research (GDPR Article 40) has 38 controls organised across 21 domains. The largest domains are Scope and Application Areas (6 controls), Approval and Monitoring (3 controls), Code Development and Governance (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Code of Conduct on Data Protection for Research (GDPR Article 40) map to?
Code of Conduct on Data Protection for Research (GDPR Article 40) maps to 334 other compliance frameworks. The top mapping partners are Angola Personal Data Protection Law (Law No. 22/11) (18% coverage), Digital Services Act (DSA) - Regulation (EU) 2022/2065 (18% coverage), Digital Services Act (Regulation (EU) 2022/2065 of the European Parliament and of the Council of 6 July 2022) (18% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Code of Conduct on Data Protection for Research (GDPR Article 40) compliance?
Start your Code of Conduct on Data Protection for Research (GDPR Article 40) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Code of Conduct on Data Protection for Research (GDPR Article 40) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 38 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 768 frameworks.
Get Started Free →Free forever — no credit card required