Organisations that carry out data protection certifications in accordance with Article 13 FADP (certification bodies) must be accredited. Accreditation is governed by the Accreditation and Designation Ordinance of 17 June 1996 2 (AccDO), unless the present Ordinance provides otherwise.
Separate accreditation is required in each case for the certification of:
- the organisational structure and the procedure (management systems) in connection with data processing;
- products, in particular data processing systems or programs and hardware, as well as services and processes in connection with data processing.
The certification bodies must have established organisational regulations and an established certification procedure (certification programme).
The minimum qualification requirements for the staff who carry out data protection certifications are set out in the Annex. The certification bodies must prove that they have staff who are qualified in accordance with these criteria.