top of page
Image by Ian Schneider

CERTIFICATION

What is certification?

Art 42 of the UK GDPR provides for the creation of official certification schemes that will be recognised by the local Supervisory Authority (in this case the Information Commissioner's Office).

ICO REQUIREMENTS

  1. UK GDPR - The standard must meet all UK GDPR requirements.

  2. SCOPE - The standard must have a defined scope that relates to a specific processing activity.

  3. PRACTICAL - formulated in such a way that they are clear and allow practical application.

  4. AUDITABLE - objectives must be specified along with how they can be achieved so as to demonstrate compliance.

  5. RELEVANT - to the target audience.

  6. INTEROPERABLE - with other standards such as ISO 27001.

  7. SCALABLE - for use by different sized organisations.

Further ICO guidance on the benefits of certification can be found here.

 

LOCS:23 SCOPE

The primary processing activities within the scope of this standard are:

  • Processing of Personal Data in the Client File

  • Ensuring protection of Client data when shared

 (the full scope can be seen in the LOCS:23 Standard).​

SCHEME REVIEW

The Certification Scheme has a scheme review process designed to ensure the overall integrity and relevance is maintained. You can see more here


COMPLAINTS

If you wish to make a complaint regarding the Certification Scheme you can see the complaints and appeals process here


CERTIFICATION BODIES

For more information on the Certification Body operating requirements click here
Business Conference

The Official Certification Mark

Specifies Certification Body

Cert Mark Controller.png

QR code links back to CB website to validate certification

Specifies Data Controller or

Data Processor

The Official Certification Mark can only be awarded by a UKAS accredited Certification Body and is the only Mark that signifies LOCS:23 Certification as either a Data Controller or Data Processor.
 
All Certified organisations will be automatically published in a publicly available register accessible both here and by using the QR code on a Certification Mark.
 
It is highly recommended that clients check the validity of Certification before relying on it.
 
The Certification Mark is valid for 3 years from date of issue

The LOCS logo may be used for other purposes but the official Certification Mark will always follow the format of the above example and display the following:

 
  • Name or logo of Certification Body making award
  • Name of Certified organisation
  • Certified Organisation's corporate address
  • Certification Status (Controller or Processor)
  • Date of issue
  • Validation QR code (enables look up of Certification register)
​​
If an organisation claims to be certified but does not have a Certification Mark in this format you are advised to check the Certification register and if in doubt or to report any misuse contact info@locs23.com
Use of the Certification Mark is closely monitored. Inappropriate or fraudulent use may result in legal action.

Certification Options

Organisations can Certify as a Data Controller or a Data Processor

LOCS2 Controller.png

Suitable for:

  • Law firms

  • Barristers

  • In-house Council

LOCS2 Processor.png

Suitable for:

  • Tech providers

  • Service Providers

  • Chambers

Working from Home

Ecosystem Options

LOCS2 AI.png

Approved Implementors are experts in the LOCS standard, have full knowledge of the LOCS audit and can assist firms with their certification preparation.

LOCS2 QC.png

Qualified Consultancies are organisations that have two or more Approved Implementors.

LOCS2 solution.png

An Approved Solution is a product or service that has demonstrated it meets one or more of the LOCS controls and can assist a firm with its certification

Original on Transparent_edited_edited_edited.png

A LOCS Practitioner has passed a knowledge test that covers

  • Data Protection fundamentals

  • InfoSec fundamentals

  • LOCS:23 fundamentals

To preserve the integrity of the LOCS programme, the ICO and UKAS require that public registers be kept of certified organisations

ARE YOU READY FOR CERTIFICATION?
Find out with our free on-line assessment tool
assessment.png

FREE consultation


Want to know how the certification works and the potential benefits?


Request a 30 minute Teams meeting here

Original on Transparent.png

BE YOUR FIRM'S LOCS EXPERT

 

The LOCS Practitioner course is a deeper dive into the LOCS standard, how to apply it within the organisation and ultimately prepare for certification.

Candidates receive a LOCS Practitioner Certificate on completion

AI PP.png

UNDERSTAND THE DATA PROTECTION REQUIREMENTS FOR AI

 

The AI Privacy Practitioner course is for anyone involved with AI projects.

Understanding the data protection obligations is critical to ensuring individuals are protected and breaches are avoided.

Candidates receive an AI Privacy Practitioner Certificate on completion

HR PP.png

UNDERSTAND THE DATA PROTECTION FUNDAMENTALS IN AN HR CONTEXT

 

The HR Privacy Practitioner course covers core areas of GDPR compliance when recruiting, managing employee health data, monitoring employees and using AI.

Candidates receive an HR Privacy  Practitioner Certificate on completion

© 2024 by 2twenty4 Consulting Ltd

  • LinkedIn Social Icon
bottom of page