GAISSF to GDPR Crosswalk
Public crosswalk publication mapping GAISSF v1.0 to GDPR, with scope, method, limitations and traceability.
1. Executive Summary
This crosswalk contains 188 outcome-based control-to-article mapping records covering all 59 GAISSF controls and 58 operationally material GDPR provisions. It supports privacy engineering, evidence reuse, gap analysis and governance planning. It does not establish GDPR compliance.
2. Scope and Legal Baseline
The primary legal source is Regulation (EU) 2016/679. EDPB guidelines, CJEU judgments, national law and supervisory practice may affect interpretation and implementation but are not silently merged into the article text. Articles outside the operational mapping scope remain legally relevant where applicable.
3. Mapping Methodology
Mappings compare intended outcomes, implementation capabilities and evidence. Relationship codes are SP (strong partial), P (partial) and S (supporting). Confidence is rated independently. Similar terminology alone is insufficient. Reverse coverage records identify residual legal and procedural work.
4. Key Alignment Areas
Article 5 principles and accountability
Article 25 data protection by design and by default
Article 30 records of processing activities
Article 32 security of processing
Articles 33-34 personal data breach response
Article 35 data protection impact assessment
Article 22 automated decision-making and profiling
Articles 44-49 international transfers
5. Material Gaps
Lawful basis and consent validity
Controller, joint-controller and processor allocation
Data-subject request fulfilment and statutory deadlines
Article 22 applicability and meaningful safeguards
Cross-border transfer mechanism and transfer impact assessment
DPO independence and regulator-facing obligations
National-law variations and sector overlays
6. Notably Absent
The analysis did not find any basis to claim that GAISSF certification constitutes GDPR certification, that technical security controls establish lawful processing, that a crosswalk replaces a DPIA, or that mapping demonstrates compliance with data-subject rights, international-transfer rules, or supervisory requirements.
7. Article Coverage Register
| Art. | Title | Mapped controls | Coverage |
|---|---|---|---|
| 1 | Subject-matter and objectives | 0 | Not Addressed |
| 2 | Material scope | 0 | Not Addressed |
| 3 | Territorial scope | 0 | Not Addressed |
| 4 | Definitions | 0 | Not Addressed |
| 5 | Principles relating to processing of personal data | 11 | Substantially Addressed |
| 6 | Lawfulness of processing | 3 | Partially Addressed |
| 7 | Conditions for consent | 0 | Not Addressed |
| 8 | Conditions applicable to child's consent in relation to information society services | 5 | Substantially Addressed |
| 9 | Processing of special categories of personal data | 1 | Indirectly Supported |
| 10 | Processing of personal data relating to criminal convictions and offences | 0 | Not Addressed |
| 11 | Processing which does not require identification | 1 | Indirectly Supported |
| 12 | Transparent information, communication and modalities for exercise of data subject rights | 0 | Not Addressed |
| 13 | Information to be provided where personal data are collected from the data subject | 0 | Not Addressed |
| 14 | Information to be provided where personal data have not been obtained from the data subject | 1 | Indirectly Supported |
| 15 | Right of access by the data subject | 0 | Not Addressed |
| 16 | Right to rectification | 0 | Not Addressed |
| 17 | Right to erasure (right to be forgotten) | 1 | Indirectly Supported |
| 18 | Right to restriction of processing | 0 | Not Addressed |
| 19 | Notification obligation regarding rectification or erasure of personal data or restriction of processing | 0 | Not Addressed |
| 20 | Right to data portability | 0 | Not Addressed |
| 21 | Right to object | 0 | Not Addressed |
| 22 | Automated individual decision-making, including profiling | 12 | Substantially Addressed |
| 23 | Restrictions | 0 | Not Addressed |
| 24 | Responsibility of the controller | 14 | Substantially Addressed |
| 25 | Data protection by design and by default | 13 | Substantially Addressed |
| 26 | Joint controllers | 0 | Not Addressed |
| 27 | Representatives of controllers or processors not established in the Union | 0 | Not Addressed |
| 28 | Processor | 5 | Substantially Addressed |
| 29 | Processing under the authority of the controller or processor | 0 | Not Addressed |
| 30 | Records of processing activities | 1 | Indirectly Supported |
| 31 | Cooperation with the supervisory authority | 1 | Indirectly Supported |
| 32 | Security of processing | 22 | Substantially Addressed |
| 33 | Notification of a personal data breach to the supervisory authority | 14 | Substantially Addressed |
| 34 | Communication of a personal data breach to the data subject | 17 | Substantially Addressed |
| 35 | Data protection impact assessment | 8 | Substantially Addressed |
| 36 | Prior consultation | 4 | Partially Addressed |
| 37 | Designation of the data protection officer | 0 | Not Addressed |
| 38 | Position of the data protection officer | 0 | Not Addressed |
| 39 | Tasks of the data protection officer | 8 | Substantially Addressed |
| 40 | Codes of conduct | 0 | Not Addressed |
| 41 | Monitoring of approved codes of conduct | 3 | Partially Addressed |
| 42 | Certification | 2 | Partially Addressed |
| 43 | Certification bodies | 0 | Not Addressed |
| 44 | General principle for transfers | 7 | Substantially Addressed |
| 45 | Transfers on the basis of an adequacy decision | 7 | Substantially Addressed |
| 46 | Transfers subject to appropriate safeguards | 8 | Substantially Addressed |
| 47 | Binding corporate rules | 1 | Indirectly Supported |
| 48 | Transfers or disclosures not authorised by Union law | 0 | Not Addressed |
| 49 | Derogations for specific situations | 2 | Partially Addressed |
| 50 | International cooperation for the protection of personal data | 0 | Not Addressed |
| 77 | Right to lodge a complaint with a supervisory authority | 0 | Not Addressed |
| 78 | Right to an effective judicial remedy against a supervisory authority | 0 | Not Addressed |
| 79 | Right to an effective judicial remedy against a controller or processor | 0 | Not Addressed |
| 80 | Representation of data subjects | 0 | Not Addressed |
| 81 | Suspension of proceedings | 0 | Not Addressed |
| 82 | Right to compensation and liability | 10 | Substantially Addressed |
| 83 | General conditions for imposing administrative fines | 3 | Partially Addressed |
| 84 | Penalties | 3 | Partially Addressed |
Annex A — Complete GAISSF-to-GDPR Mapping Register
| Record | GAISSF | GDPR | Rel. | Confidence | Rationale / Residual Gap |
|---|---|---|---|---|---|
| CRO030-MAP-0001 | D1-CTL-01 | Art. 14 — Information to be provided where personal data have not been obtained from the data subject | P | Medium | GAISSF D1-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 14. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation. Article 14 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control. |
| CRO030-MAP-0002 | D1-CTL-01 | Art. 5 — Principles relating to processing of personal data | P | Medium | GAISSF D1-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 5. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation. Article 5 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control. |
| CRO030-MAP-0003 | D1-CTL-01 | Art. 32 — Security of processing | P | Medium | GAISSF D1-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation. Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control. |
| CRO030-MAP-0004 | D1-CTL-01 | Art. 44 — General principle for transfers | S | Medium | GAISSF D1-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 44. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation. Article 44 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control. |
| CRO030-MAP-0005 | D1-CTL-02 | Art. 32 — Security of processing | P | Medium | GAISSF D1-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation. Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control. |
| CRO030-MAP-0006 | D1-CTL-02 | Art. 34 — Communication of a personal data breach to the data subject | S | Medium | GAISSF D1-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation. Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control. |
Annex B — Source Register
| Source | Role | Status |
|---|---|---|
| GAISSF-NOR-001 v1.0 | Framework and conformance baseline | Normative |
| GAISSF-NOR-004 v1.0 | Authoritative 59-control catalogue | Normative |
| Regulation (EU) 2016/679 | Primary legal baseline | Binding regulation |
| EDPB guidance | Interpretive implementation guidance | Non-legislative guidance |
| CJEU and national decisions | Legal interpretation and enforcement context | Separate review required |
Limitations and Reliance Notice
Mapping does not establish GDPR compliance.
GAISSF controls cannot determine lawful basis, controller/processor status, territorial scope, or validity of consent.
EDPB guidance, CJEU case law and national supervisory practice require separate review.
National laws may supplement the GDPR in permitted areas.
Evidence of control design is not evidence of operating effectiveness or lawful processing.
© 2026 ODA3 Pvt Ltd. Published by ODA3 Institute. Third-party laws, names and marks remain the property of their respective owners. No endorsement or legal opinion is implied.