Section 149(4)
DPA 2018
Data Protection Act 2018 · United Kingdom
The third type of failure is where a person who is a certification provider— does not meet the requirements for accreditation, has failed, or is failing, to comply with an obligation under Article 42 or 43 of the UK GDPR (certification of controllers and processors), or has failed, or is failing, to comply with any other provision of the UK GDPR (whether in the person's capacity as a certification provider or otherwise).
← 3 · All articles · 5 →
Source: legislation.gov.uk · retrieved 2026-09-04