
Code of Conduct: Definition, Principles, and Examples (5, 6, 7)
Few things shape an organization’s culture as quietly as its code of conduct — the set of rules that tells everyone, from new hires to the C-suite, what counts as acceptable behavior. These documents translate broad ethical values into daily decisions, and in some sectors, they carry legal weight.
Typical number of principles in a code of conduct: 5 or 7 ·
Example organizations with published codes: PwC, RICS, IoD ·
Year of latest update (IoD): 2024 ·
Number of codes highlighted by Ethisphere: 5 ·
GDPR-related codes of conduct: Voluntary sets of rules
Quick snapshot
- Codes of conduct are voluntary or mandatory sets of rules. (European Commission)
- GDPR Article 40 encourages codes of conduct for data protection. (GDPR Text)
- A code of conduct conveys an organization’s commitment to responsible practice. (Portuguese MFA)
- GDPR Article 40 came into force in 2018, and codes of conduct continue to be developed and approved. (GDPR Text)
- IoD updated its guidance in 2024. (GDPR Text)
- More sector-specific codes expected under GDPR — especially for SMEs. (European Commission)
- Increased use of codes as evidence of compliance with regulations. (Bird & Bird)
Five key facts about codes of conduct, each drawn from authoritative sources.
| Fact | Detail |
|---|---|
| Definition | Set of rules outlining norms, responsibilities, and proper practices (European Commission) |
| Common principle counts | 5, 6, or 7 (i-SCOOP) |
| Sectors using codes | Corporate, professional, governmental, data protection (Portuguese MFA) |
| Latest update (IoD) | 2024 |
| Notable example | EU GDPR codes of conduct (Bird & Bird) |
What is a code of conduct?
A code of conduct is a written document that lays down the behavioral expectations and responsibilities of an organization’s members. It goes beyond a simple list of do’s and don’ts — it articulates the values and standards that guide decision-making. The European Commission notes that such codes can be voluntary tools used to demonstrate compliance with data protection rules, while the GDPR Text describes Article 40 as encouraging the drawing up of codes to contribute to the proper application of the Regulation.
A code of conduct is not a feel-good poster — it is the operating manual for how an organization puts its ethics into action. For regulated sectors like data processing, it can also serve as a shield in enforcement actions.
Key elements of a code of conduct
- Scope: who it applies to and when
- Core principles: often 5, 6, or 7 principles
- Specific rules: concrete guidance on topics like confidentiality, conflicts of interest, and data handling
- Enforcement mechanisms: reporting channels, disciplinary actions
The European Commission emphasizes that codes of conduct and certification can be used as evidence of compliance with applicable data protection rules and principles. This turns a voluntary document into a compliance asset.
Purpose and benefits
Codes of conduct serve multiple purposes: they set a clear standard for behavior, protect the organization from legal risks, and build trust with stakeholders. A code that is well-drafted and enforced can reduce misconduct and provide a framework for ethical decision-making. The Bird & Bird analysis lists areas such as fair and transparent processing, legitimate interests, and breach notification as typical topics covered in GDPR codes of conduct.
The implication: A code of conduct serves as both an ethical compass and a compliance instrument, bridging values and regulatory requirements in a single document.
What are the 5 codes of conduct?
Not all codes use five principles, but several well-known frameworks and examples follow this number. The Bird & Bird guide notes that expected guidance areas for GDPR codes include legitimate interest, pseudonymisation, and security measures — often grouped under five thematic headings.
Common 5-principle frameworks
Professional bodies sometimes adopt a five-principle structure. The RICS Rules of Conduct, for example, are built around five principles, as noted in their professional standards literature. While we cannot link to their document here, the pattern is consistent: a concise set of high-level commitments that are then detailed through supporting rules.
Five principles may seem simple, but the devil is in the interpretation. Without specific guidance on each principle, a code can become too vague to enforce. That is why the GDPR code-of-conduct framework explicitly mentions the specific features of various processing sectors and SME needs (GDPR Text).
The i-SCOOP analysis describes the seven key principles of GDPR (lawfulness, fairness, transparency; purpose limitation; data minimisation; storage limitation; accuracy; integrity and confidentiality; accountability). Some organizations map their code to five of these, while others include all seven.
What are the 6 codes of conduct?
Six-principle codes are less common than five or seven, but they appear in certain professional and sector-specific contexts. For instance, some corporate codes of conduct group their values into six pillars: integrity, respect, accountability, transparency, fairness, and responsibility.
Article 40 of the GDPR lists ten areas that codes may specify, but associations are free to combine them into fewer principles. A six-principle structure might merge pseudonymisation with security measures, or split accountability into separate points.
In practice, the number of principles matters less than the clarity and enforceability of each. A six-principle code that is well-communicated can be more effective than a ten-principle one that is ignored.
What are the 7 code of conduct principles?
Seven principles is a popular structure, in part because of the Nolan Principles in UK public life. The i-SCOOP overview lists seven GDPR principles, which have been adapted into codes of conduct by many data controllers.
Common 7-principle frameworks
In the data protection realm, the seven GDPR principles — lawfulness, fairness and transparency; purpose limitation; data minimisation; storage limitation; accuracy; integrity and confidentiality; accountability — form a natural backbone for a code of conduct. The Portuguese Ministry of Foreign Affairs published a Code of Conduct for the Protection of Personal Data that explicitly includes purpose limitation, data minimization, storage limitation, and traceability of access, mirroring several of these principles.
A seven-principle code gives regulators a straightforward way to check compliance. When the principles align with regulatory requirements (as in GDPR), the code becomes more than an ethics guideline — it becomes a compliance tool. The Bird & Bird analysis confirms that GDPR codes of conduct can cover legitimate interests, pseudonymisation, minor protection, and dispute resolution among others.
The pattern: Aligning a code’s principles with regulatory frameworks transforms it from a voluntary guideline into a demonstrable compliance asset that regulators can evaluate systematically.
What are examples of code of conduct?
Real-world examples show how codes of conduct vary across sectors. Below are four types, each with a concrete illustration.
Corporate examples
Large corporations often publish their codes publicly. While we cannot provide a direct link for every company, the European Commission notes that companies may adhere to national or transnational GDPR codes of conduct prepared by business associations.
Professional examples
Professional bodies such as the Royal Institution of Chartered Surveyors (RICS) have codes that can be legally binding for members. Their Rules of Conduct contain five principles, each with detailed mandatory requirements.
Governmental examples
The Portuguese Ministry of Foreign Affairs code is a strong example from the public sector. It outlines principles and guidelines governing staff actions regarding personal data, including deletion of data not strictly necessary and traceability of access.
GDPR codes of conduct
Under GDPR Article 40, associations can draft codes covering fair and transparent processing, legitimate interests, collection of personal data, pseudonymisation, public information, data subject rights, children’s data, security, breach notification, and dispute resolution. The Bird & Bird guide provides a specialist summary of expected guidance areas.
The implication: Examples across sectors demonstrate that specificity and enforcement determine a code’s effectiveness more than its principle count or origin.
What’s clear and what’s not
Confirmed facts
- Codes of conduct are voluntary or mandatory sets of rules (European Commission).
- GDPR Article 40 encourages codes of conduct and lists topics they may specify (GDPR Text).
- Codes can be used as evidence of compliance with data protection rules (i-SCOOP).
- The Portuguese MFA has a published code that includes purpose limitation and data minimization (Portuguese MFA).
What’s unclear
- The exact number of principles varies by organization; not all codes follow a specific count.
- Whether a code is legally binding depends on sector, jurisdiction, and enforcement mechanisms.
- How consistently codes are audited and updated is not standardized across industries.
- The effectiveness of a code depends more on enforcement than on the number of principles it contains.
Perspectives on codes of conduct
A code of conduct is an articulation of the standards that govern an organisation’s conduct.
— Institute of Directors, 2024 guidance
The Code of Conduct is the foundational document that broadly establishes the expectations for behavior.
— Ethisphere, annual ethics review
Both perspectives underline the same truth: a code of conduct sets the stage for everything else. Without a clear code, organizations lack a consistent benchmark for behavior. The Bird & Bird analysis reinforces that codes are not just ethical documents but also practical compliance tools.
Summary
Codes of conduct are not optional extras for organizations that care about ethics — they are mandatory operational frameworks in many sectors. For data controllers under GDPR, the path is clear: adopt a code that reflects the seven principles, ensure it is approved by the competent authority, and use it as living evidence of compliance. For organizations in the EU, the European Commission provides guidance on using codes as compliance tools. The choice is straightforward: invest in a well-structured code now, or face the consequences of an undefined culture and regulatory scrutiny later.
Related reading: Code of conduct principles, examples, classification, sectors, corporate, professional, governmental, GDPR · GDPR codes of conduct and certification as evidence of compliance
gdpr.algolia.com, sriw.de, egba.eu, gdprwise.eu, gdpr-info.eu, datacomplyone.eu
For a detailed breakdown of the five key principles of a code of conduct, five key principles of a code of conduct offers practical examples from leading organizations.
Frequently asked questions
Why is a code of conduct important?
A code of conduct sets clear expectations for behavior, reduces legal risk, and builds trust with stakeholders. Under GDPR, it can also serve as evidence of compliance (European Commission).
How do I create a code of conduct for my organization?
Start by identifying the principles that align with your values and regulatory requirements. Consult guidelines like GDPR Article 40, then draft specific rules covering the areas relevant to your sector. Involve stakeholders and have the code approved by competent authorities if needed (GDPR Text).
What is the difference between a code of conduct and a code of ethics?
A code of conduct is specific and behavioral, outlining do’s and don’ts. A code of ethics is broader and aspirational, stating core values and principles. Many organizations have both, with the code of conduct providing the actionable rules for everyday situations.
Are codes of conduct legally binding?
It depends. Professional codes (e.g., for doctors, surveyors) can be legally enforceable through licensing bodies. Corporate codes are generally internal policies, but breaching them can lead to disciplinary actions or legal consequences if they incorporate regulatory requirements (e.g., GDPR codes).
What happens if an employee violates the code of conduct?
Consequences range from a verbal warning to termination, depending on the severity. For codes aligned with regulations (e.g., data protection), violations may also trigger regulatory penalties. The code should outline reporting channels and disciplinary procedures explicitly.
How often should a code of conduct be reviewed?
Best practice is to review annually and update whenever regulations change or after a significant incident. The IoD updated its guidance in 2024, reflecting the need for ongoing relevance. Regular training and communication are equally important.