GDPR Compliance | BC 5701 Certification
With the new BC 5701 privacy certification, you can visibly demonstrate your organizationโs compliance with personal data protection regulations.
Questions?
Talk to our experts
BC 5701
The BC5701 standard outlines a set of criteria, procedures, and measures that provide organizations with guidance to align the processing of personal data with GDPR regulations. Applying the standard means that, as a data controller or processor, you can have the handling of personal data assessed by an external expert. This provides greater certainty that GDPR compliance is demonstrably well managed. BC 5701 was approved by the Dutch Data Protection Authority in September 2023 and published in the Official Gazette.
- We make privacy practical and natural, ensuring that your organization becomes GDPR compliant
- Demonstrable and verifiable compliance
- BC 5701: standard in the field of GDPR
- The applied standard provides assurance regarding the correct handling of personal data for the individuals involved.
What does the BC 5701 standard entail?
Other services
In recent years, organizations have implemented various processes for GDPR compliance. However, due to the many open standards, it is unclear when it is truly sufficient. The introduction of BC 5701 means you now have a standard approved by the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) on how to interpret and apply the GDPR.
A privacy certificate serves not only an internal but primarily an external function. With the BC 5701 certificate, you demonstrate outwardly that the privacy interests of individuals are well protected. The organizationโs processes have been objectively assessed and verified. This makes it clear to everyone that the requirements of the GDPR have been correctly implemented.
Ultimately, the greatest benefit of the BC 5701 standard is that it allows organizations to comply with the GDPR in an objective manner. The standard ensures demonstrable compliance and gives individuals confidence that their personal data is well protected.
What does the process look like if I choose a BC 5701 specialist from The Privacy Cooperation?
Free consultation
Click on โSchedule a consultationโ to schedule an appointment with a consultant within two business days. Our consultants can provide an answer to your initial questions within 30 minutes.
Let's get to work together
Our consultant will gather more information if necessary to gain a better understanding. After visiting your location, they will formulate a proposal for the next steps.
All details sorted.
Once we agree on what needs to be done, you will receive a quote from us for the work to be carried out.
We will work with you and for you.
Our consultant works according to the action plan and is monitored by The Privacy Cooperation and a certified BC 5701 implementation professional.
Final assessment
We are working towards obtaining the Brand Compliance certification for your organization. If improvements are needed after an audit, we will address them until the certificate is obtained.
BC5701
What value can this privacy certification add to your organization?
Privacy
Certainty about how privacy is safeguarded in your organization
Demonstrability
Good start to talks with regulators
USP
Competitive advantage within your industry
Future-oriented
Future advantage in tendering procedures
Questions?
Talk to our experts!BC 5701 in a broader context
Questions?
Talk to our experts!In July 2023, the European Court of Justice ruled that Meta/Facebook misinterpreted a part of the GDPR. The ongoing lawsuits against Meta demonstrate that organizations can avoid the risks of fines by objectively reviewing the requirements and standards of the GDPR. With certification, independent auditors assess the organizationโs approach, and mandatory recertifications take place. This prevents privacy protection from being implemented incorrectly or insufficiently.
Organizations can decide whether to apply BC 5701 as a voluntary standard or go through the formal certification process. Similar to the ISO 27001 standard for information security, some organizations may choose to follow BC 5701 without applying for certification, possibly due to the annual costs associated with certification.
By applying the BC 5701 methodology, an organization demonstrates to itself, the regulator, and stakeholders that it has taken serious steps toward GDPR compliance. Additionally, there is the potential benefit of governments requesting the BC 5701 certificate in procurement procedures. Certification could then become a unique selling point.
The long-term benefits far outweigh the short-term investments required for certification. The certification process places significant emphasis on staff training and awareness, meaning privacy and information security eventually become part of daily operations, and employees become unconsciously competent in the subject. This truly gives the topic substance.
Any uncertainties?
Frequently Asked Questions
Read the most frequently asked questions below. If your question is not listed, you can always reach us by phone at +31 6 58832812 or by email at Info@ThePrivacyCoOperation.nl.
I am not sure whether privacy is properly implemented within my organization. How can my organization qualify for BC 5701 certification?
The level of maturity in the field of privacy can be determined using a model developed by the Center for Information Security and Privacy (CIP). Certification against BC 5701 is possible from CIP maturity level 3 onwards.
Does obtaining the BC 5701 certificate mean that my organization as a whole can be considered privacy compliant?
The BC 5701 certificate can be issued for a single independent processing of personal data (= the object of certification). All branches of the processing that is eligible for certification, both within and outside your organization, are assessed. Because processing within an organization can only be compliant if a certain system is in place (processes and procedures to properly apply privacy within processing), certification of one processing operation provides a picture of compliance within your organization.
How long does the entire process take (from determining the maturity level to certification by Brand Compliance)?
A maturity level assessment with an appropriate action plan for achieving certification is normally completed within two months. It is difficult to estimate in advance how much time it will take to bring your organization up to the required level. This depends on the size of the organization, its national or international branches, and (unfortunately) also the availability of suitable privacy and information security specialists.
What is the level of expertise of the privacy and information security specialists who will be working for my organization?
The Privacy CoOperation works exclusively with privacy and information security specialists who have at least three years of experience with GDPR implementation programs at various companies. It is also important to note that the specialists have followed training courses tailored to their work. Furthermore, a BC 5701 implementation program is always led and supervised by a BC 5701 implementation professional.

Sign up here for the monthly newsletter
Our newsletter is carefully compiled each month from reports from regulators and developments in case law and legislation. By subscribing, you can stay up to date with all the latest trends.
