GDPR in plain Language
The information contained in this site is provided for informational purposes only, and should not be construed as legal advice on any subject matter. You should not act or refrain from acting on the basis of any content included on this site without seeking legal or other professional advice

Article 42 - Certification
Who can authorize an organization to meet regulatory requirements?
The immediate answer, as far as I know (in the day I am writing this) there are no certificates, stamps and certifications recognized by the regulation today, neither for individuals nor for organizations.
If you have found one, it is great news!. You should, in any case, read the terms of use and make sure who authorized the certifiers.
The regulation encourages the definition of such a stamp, especially for small and medium organizations. It calls on the various countries to ratify such a framework.
This will not replace coercive legal contracts such as an information transfer agreement to foreign countries.
Moreover, certificates, stamps and other amulets will not remove the responsibility from you in any way if a gap will exist between the expectations of the law and what you are actually doing.
It will be possible to issue such certificates for a period of up to three years, after which they will expire.
Im this context, I would like to recommend all of you to certify you organization to ISO 27701. This is (yet) not recognized as a valid GDPR certification as required by this verse, but it is (as far as I know) as close as it gets these days. You can see here that the French Data Protection authority (CNIL) is recommending using this standard.