Australiaglobal Daily Report English (AU)
Australiaglobal.net Australiaglobal Daily Report
Blog Business Local Politics Tech World

Code of Conduct: Definition, Principles, and Examples (5, 6, 7)

Lachlan Oliver Thompson Smith • 2026-07-29 • Reviewed by Sofia Lindberg

Few things shape an organization’s culture as quietly as its code of conduct — the set of rules that tells everyone, from new hires to the C-suite, what counts as acceptable behavior. These documents translate broad ethical values into daily decisions, and in some sectors, they carry legal weight.

Typical number of principles in a code of conduct: 5 or 7 ·
Example organizations with published codes: PwC, RICS, IoD ·
Year of latest update (IoD): 2024 ·
Number of codes highlighted by Ethisphere: 5 ·
GDPR-related codes of conduct: Voluntary sets of rules

Quick snapshot

1Confirmed facts
  • Codes of conduct are voluntary or mandatory sets of rules. (European Commission)
  • GDPR Article 40 encourages codes of conduct for data protection. (GDPR Text)
  • A code of conduct conveys an organization’s commitment to responsible practice. (Portuguese MFA)
2What’s unclear
  • Exact number of principles varies by organization; not all codes follow a specific count. (i-SCOOP)
  • Whether a code is legally binding depends on sector and jurisdiction. (GDPR Text)
  • Exact enforcement and auditing processes vary by code and are not standardized across industries. (i-SCOOP)
3Timeline signal
  • GDPR Article 40 came into force in 2018, and codes of conduct continue to be developed and approved. (GDPR Text)
  • IoD updated its guidance in 2024. (GDPR Text)
4What’s next
  • More sector-specific codes expected under GDPR — especially for SMEs. (European Commission)
  • Increased use of codes as evidence of compliance with regulations. (Bird & Bird)

Five key facts about codes of conduct, each drawn from authoritative sources.

Fact Detail
Definition Set of rules outlining norms, responsibilities, and proper practices (European Commission)
Common principle counts 5, 6, or 7 (i-SCOOP)
Sectors using codes Corporate, professional, governmental, data protection (Portuguese MFA)
Latest update (IoD) 2024
Notable example EU GDPR codes of conduct (Bird & Bird)

What is a code of conduct?

A code of conduct is a written document that lays down the behavioral expectations and responsibilities of an organization’s members. It goes beyond a simple list of do’s and don’ts — it articulates the values and standards that guide decision-making. The European Commission notes that such codes can be voluntary tools used to demonstrate compliance with data protection rules, while the GDPR Text describes Article 40 as encouraging the drawing up of codes to contribute to the proper application of the Regulation.

The upshot

A code of conduct is not a feel-good poster — it is the operating manual for how an organization puts its ethics into action. For regulated sectors like data processing, it can also serve as a shield in enforcement actions.

Key elements of a code of conduct

  • Scope: who it applies to and when
  • Core principles: often 5, 6, or 7 principles
  • Specific rules: concrete guidance on topics like confidentiality, conflicts of interest, and data handling
  • Enforcement mechanisms: reporting channels, disciplinary actions

The European Commission emphasizes that codes of conduct and certification can be used as evidence of compliance with applicable data protection rules and principles. This turns a voluntary document into a compliance asset.

Purpose and benefits

Codes of conduct serve multiple purposes: they set a clear standard for behavior, protect the organization from legal risks, and build trust with stakeholders. A code that is well-drafted and enforced can reduce misconduct and provide a framework for ethical decision-making. The Bird & Bird analysis lists areas such as fair and transparent processing, legitimate interests, and breach notification as typical topics covered in GDPR codes of conduct.

Bottom line: A code of conduct is the bridge between abstract ethical principles and concrete daily behavior. For data controllers, it is also a demonstrable commitment to GDPR compliance.

The implication: A code of conduct serves as both an ethical compass and a compliance instrument, bridging values and regulatory requirements in a single document.

What are the 5 codes of conduct?

Not all codes use five principles, but several well-known frameworks and examples follow this number. The Bird & Bird guide notes that expected guidance areas for GDPR codes include legitimate interest, pseudonymisation, and security measures — often grouped under five thematic headings.

Common 5-principle frameworks

Professional bodies sometimes adopt a five-principle structure. The RICS Rules of Conduct, for example, are built around five principles, as noted in their professional standards literature. While we cannot link to their document here, the pattern is consistent: a concise set of high-level commitments that are then detailed through supporting rules.

The catch

Five principles may seem simple, but the devil is in the interpretation. Without specific guidance on each principle, a code can become too vague to enforce. That is why the GDPR code-of-conduct framework explicitly mentions the specific features of various processing sectors and SME needs (GDPR Text).

The i-SCOOP analysis describes the seven key principles of GDPR (lawfulness, fairness, transparency; purpose limitation; data minimisation; storage limitation; accuracy; integrity and confidentiality; accountability). Some organizations map their code to five of these, while others include all seven.

What are the 6 codes of conduct?

Six-principle codes are less common than five or seven, but they appear in certain professional and sector-specific contexts. For instance, some corporate codes of conduct group their values into six pillars: integrity, respect, accountability, transparency, fairness, and responsibility.

Article 40 of the GDPR lists ten areas that codes may specify, but associations are free to combine them into fewer principles. A six-principle structure might merge pseudonymisation with security measures, or split accountability into separate points.

In practice, the number of principles matters less than the clarity and enforceability of each. A six-principle code that is well-communicated can be more effective than a ten-principle one that is ignored.

What are the 7 code of conduct principles?

Seven principles is a popular structure, in part because of the Nolan Principles in UK public life. The i-SCOOP overview lists seven GDPR principles, which have been adapted into codes of conduct by many data controllers.

Common 7-principle frameworks

In the data protection realm, the seven GDPR principles — lawfulness, fairness and transparency; purpose limitation; data minimisation; storage limitation; accuracy; integrity and confidentiality; accountability — form a natural backbone for a code of conduct. The Portuguese Ministry of Foreign Affairs published a Code of Conduct for the Protection of Personal Data that explicitly includes purpose limitation, data minimization, storage limitation, and traceability of access, mirroring several of these principles.

Why this matters

A seven-principle code gives regulators a straightforward way to check compliance. When the principles align with regulatory requirements (as in GDPR), the code becomes more than an ethics guideline — it becomes a compliance tool. The Bird & Bird analysis confirms that GDPR codes of conduct can cover legitimate interests, pseudonymisation, minor protection, and dispute resolution among others.

The pattern: Aligning a code’s principles with regulatory frameworks transforms it from a voluntary guideline into a demonstrable compliance asset that regulators can evaluate systematically.

What are examples of code of conduct?

Real-world examples show how codes of conduct vary across sectors. Below are four types, each with a concrete illustration.

Corporate examples

Large corporations often publish their codes publicly. While we cannot provide a direct link for every company, the European Commission notes that companies may adhere to national or transnational GDPR codes of conduct prepared by business associations.

Professional examples

Professional bodies such as the Royal Institution of Chartered Surveyors (RICS) have codes that can be legally binding for members. Their Rules of Conduct contain five principles, each with detailed mandatory requirements.

Governmental examples

The Portuguese Ministry of Foreign Affairs code is a strong example from the public sector. It outlines principles and guidelines governing staff actions regarding personal data, including deletion of data not strictly necessary and traceability of access.

GDPR codes of conduct

Under GDPR Article 40, associations can draft codes covering fair and transparent processing, legitimate interests, collection of personal data, pseudonymisation, public information, data subject rights, children’s data, security, breach notification, and dispute resolution. The Bird & Bird guide provides a specialist summary of expected guidance areas.

Bottom line: Whether corporate, professional, governmental, or GDPR-specific, a code of conduct matters most when it is specific, enforced, and tied to real consequences. Actors in highly regulated sectors should prioritize alignment with legal frameworks such as GDPR.

The implication: Examples across sectors demonstrate that specificity and enforcement determine a code’s effectiveness more than its principle count or origin.

What’s clear and what’s not

Confirmed facts

  • Codes of conduct are voluntary or mandatory sets of rules (European Commission).
  • GDPR Article 40 encourages codes of conduct and lists topics they may specify (GDPR Text).
  • Codes can be used as evidence of compliance with data protection rules (i-SCOOP).
  • The Portuguese MFA has a published code that includes purpose limitation and data minimization (Portuguese MFA).

What’s unclear

  • The exact number of principles varies by organization; not all codes follow a specific count.
  • Whether a code is legally binding depends on sector, jurisdiction, and enforcement mechanisms.
  • How consistently codes are audited and updated is not standardized across industries.
  • The effectiveness of a code depends more on enforcement than on the number of principles it contains.

Perspectives on codes of conduct

A code of conduct is an articulation of the standards that govern an organisation’s conduct.

— Institute of Directors, 2024 guidance

The Code of Conduct is the foundational document that broadly establishes the expectations for behavior.

— Ethisphere, annual ethics review

Both perspectives underline the same truth: a code of conduct sets the stage for everything else. Without a clear code, organizations lack a consistent benchmark for behavior. The Bird & Bird analysis reinforces that codes are not just ethical documents but also practical compliance tools.

Summary

Codes of conduct are not optional extras for organizations that care about ethics — they are mandatory operational frameworks in many sectors. For data controllers under GDPR, the path is clear: adopt a code that reflects the seven principles, ensure it is approved by the competent authority, and use it as living evidence of compliance. For organizations in the EU, the European Commission provides guidance on using codes as compliance tools. The choice is straightforward: invest in a well-structured code now, or face the consequences of an undefined culture and regulatory scrutiny later.

Related reading: Code of conduct principles, examples, classification, sectors, corporate, professional, governmental, GDPR · GDPR codes of conduct and certification as evidence of compliance

For a detailed breakdown of the five key principles of a code of conduct, five key principles of a code of conduct offers practical examples from leading organizations.

Frequently asked questions

Why is a code of conduct important?

A code of conduct sets clear expectations for behavior, reduces legal risk, and builds trust with stakeholders. Under GDPR, it can also serve as evidence of compliance (European Commission).

How do I create a code of conduct for my organization?

Start by identifying the principles that align with your values and regulatory requirements. Consult guidelines like GDPR Article 40, then draft specific rules covering the areas relevant to your sector. Involve stakeholders and have the code approved by competent authorities if needed (GDPR Text).

What is the difference between a code of conduct and a code of ethics?

A code of conduct is specific and behavioral, outlining do’s and don’ts. A code of ethics is broader and aspirational, stating core values and principles. Many organizations have both, with the code of conduct providing the actionable rules for everyday situations.

Are codes of conduct legally binding?

It depends. Professional codes (e.g., for doctors, surveyors) can be legally enforceable through licensing bodies. Corporate codes are generally internal policies, but breaching them can lead to disciplinary actions or legal consequences if they incorporate regulatory requirements (e.g., GDPR codes).

What happens if an employee violates the code of conduct?

Consequences range from a verbal warning to termination, depending on the severity. For codes aligned with regulations (e.g., data protection), violations may also trigger regulatory penalties. The code should outline reporting channels and disciplinary procedures explicitly.

How often should a code of conduct be reviewed?

Best practice is to review annually and update whenever regulations change or after a significant incident. The IoD updated its guidance in 2024, reflecting the need for ongoing relevance. Regular training and communication are equally important.



Lachlan Oliver Thompson Smith

About the author

Lachlan Oliver Thompson Smith

Coverage is updated through the day with transparent source checks.