Conformité et contrats · Luxembourg

GDPR-CARPA: understanding the scope of GDPR certification

A certification must be read together with its scope, issuing body and validity. It does not constitute a general guarantee covering all of a company’s activities.

GDPR-CARPA : comprendre la portée d’une certification RGPD : Distinguer certification et conformité quotidienne, Lire le certificat plutôt que le seul logo, Préparer le dossier interne
Schéma de lecture : les points de décision de ce guide.

Data protection begins with a very practical question: who receives which information and for what reason? In an accounting firm, accounting and payroll documents require a clear organisation, from initial submission to archiving.

Key takeaway

The CNPD states that certification does not reduce the liability of the controller or the processor. Check exactly what is certified.

The framework to check

The roles of controller and processor are determined according to the processing operations actually carried out. They do not follow solely from the name of the contract. Retention periods, security, information and individuals’ rights must be examined for each purpose.

Distinguishing certification from day-to-day compliance

GDPR-CARPA is a certification mechanism presented by the CNPD. It is based on criteria and an assessment procedure. A company considering this process must first identify the relevant processing operations and organisation.

The acronym does not replace the record of processing activities, the organisation of rights, access management or security measures. Certification can support a demonstration within its scope; it does not permit other obligations to be ignored.

Request the certificate and identify the entity, covered operations, period and certification body. Check the body's status with the CNPD and the public information relating to the certificate.

Do not confuse GDPR certification with information security certification or a simple contractual commitment. Each serves a different purpose. When selecting a payroll or accounting provider, compare the certified scope with the service actually purchased.

Preparing the internal file

Map the data: employees, customers, suppliers, beneficial owners and identity documents. Identify access rights, periods, recipients and any transfers. The roles of controller and processor must be defined according to the operations actually carried out.

Check contracts, incident procedures, backups and arrangements for responding to requests. A procedure must be usable by teams, not merely available in a document. Keep evidence of its implementation and of the controls performed.

Including the approach in the choice of an accounting firm

Ask how documents are transmitted, who can consult them and how your data will be returned at the end of the engagement. Payroll data require particular attention to the separation of access rights.

A relevant certification may be one element in the selection file, alongside contracts, technical measures and the ability to explain procedures. It must not become a commercial formula substituted for these checks.

Turning the promise of certification into verifiable questions

When you receive a certificate, first compare the name of the entity with that of the contracting party. Then identify the covered processing operations and the stated limitations. A payroll service, a document platform and another company in the same group must not be considered covered without reading the scope.

Ask for the certificate reference, its period and the arrangements for checking its status. The mechanism presented by the CNPD distinguishes the certification of processing operations from the accreditation of assessment bodies. You must therefore check the right document for the right question. A logo in a commercial presentation does not provide this level of detail.

Prepare an example of processing that concerns you: submission of variables, production of the payslip, making it available and retention. At each stage, identify access rights, tools and processors. The guide to data exchanges with an accounting firm details this day-to-day organisation; certification must be compared with this practical operation.

Keeping controls active between two assessments

An access withdrawal procedure must work when an employee leaves. An incident procedure must make it possible to know whom to notify and what information to gather. To test your organisation, use a fictional scenario and record the decisions, internal deadlines and areas of uncertainty. Avoid exposing real data solely to demonstrate a process.

Keep control evidence: access reviews, approvals, request tracking and corrections. This is not about accumulating documents without using them, but about being able to explain what was checked, by whom and with what result. If a tool or provider changes, identify the affected processing operations and the documents to be reviewed.

The guide to accounting digitalisation helps prepare the testing of new tools and their return. For payroll data, the payroll variables schedule must also specify authorised persons. The approach becomes useful when each rule is reflected in actual work. Ask the provider how a major change will be assessed in relation to the certified scope, rather than assuming that the certificate automatically extends to the new service.

Reading a certificate in relation to the service purchased
PointCheckLimitation to avoid
EntityName of the holder and contracting partyExtending the certificate to an entire group
ScopeRelevant processing operations and servicesTreating a logo as general coverage
StatusReference, period and verificationRelying on an old isolated copy
OperationControls and changes monitoredConfusing a written procedure with actual implementation

Let us consider a practical case

Fictional educational example, intended to explain the reasoning.

A company sends payroll variables through a shared mailbox accessible to its entire team. Before changing software, it must limit access to what is genuinely needed, define an appropriate channel and know who validates the information. It then reviews the contracts and processors of the selected service. The control is not limited to requesting a “GDPR compliant” statement: it concerns access rights, uses and evidence that can be checked.

Points to prepare

  • Scope and entity of the certificate identified.
  • Body and validity checked.
  • Processing operations, access rights and processors listed.
  • Procedures implemented and evidence retained.

Frequently asked questions

Does certification automatically cover the entire company?

Its scope must be read in the certificate. It must not be extended to processing operations that are not included in it.

Does an ISO logo prove GDPR-CARPA certification?

No. Certifications do not have the same purpose; check the exact certificate and its issuing body.

Useful terms in this guide

Questions to ask the professional

  • Which roles and responsibilities are documented?
  • Who can access payroll data and how are rights withdrawn?

To clarify the scope of your request, also consult our accounting section.

And for your situation?

To assess a provider, bring a description of the data and the expected service. Ask them to link their commitments and any certifications to the processing operations actually offered, with clearly defined access rights, data return and incident procedure. Search our directory for the professional suited to your needs, then ask them for a detailed engagement and quote.

Sources and verification

References consulted on 20 September 2026. Official procedures specify the applicable conditions and exceptions.

This guide explains a general process. The applicable rules depend on your situation; it does not constitute personalised advice. Report a correction.

Your next step

A specific need deserves the right contact

Accounting, taxation, company formation or payroll: prepare your questions, then search the directory for the professional who can review your situation. Check their assignments and status before entrusting them with your file.

Find a professional