CROSSWALKS

GAISSF to GDPR Crosswalk

Public crosswalk publication mapping GAISSF v1.0 to GDPR, with scope, method, limitations and traceability.

1. Executive Summary

This crosswalk contains 188 outcome-based control-to-article mapping records covering all 59 GAISSF controls and 58 operationally material GDPR provisions. It supports privacy engineering, evidence reuse, gap analysis and governance planning. It does not establish GDPR compliance.

3. Mapping Methodology

Mappings compare intended outcomes, implementation capabilities and evidence. Relationship codes are SP (strong partial), P (partial) and S (supporting). Confidence is rated independently. Similar terminology alone is insufficient. Reverse coverage records identify residual legal and procedural work.

4. Key Alignment Areas

  • Article 5 principles and accountability

  • Article 25 data protection by design and by default

  • Article 30 records of processing activities

  • Article 32 security of processing

  • Articles 33-34 personal data breach response

  • Article 35 data protection impact assessment

  • Article 22 automated decision-making and profiling

  • Articles 44-49 international transfers

5. Material Gaps

  • Lawful basis and consent validity

  • Controller, joint-controller and processor allocation

  • Data-subject request fulfilment and statutory deadlines

  • Article 22 applicability and meaningful safeguards

  • Cross-border transfer mechanism and transfer impact assessment

  • DPO independence and regulator-facing obligations

  • National-law variations and sector overlays

6. Notably Absent

The analysis did not find any basis to claim that GAISSF certification constitutes GDPR certification, that technical security controls establish lawful processing, that a crosswalk replaces a DPIA, or that mapping demonstrates compliance with data-subject rights, international-transfer rules, or supervisory requirements.

7. Article Coverage Register

Art. Title Mapped controls Coverage
1 Subject-matter and objectives 0 Not Addressed
2 Material scope 0 Not Addressed
3 Territorial scope 0 Not Addressed
4 Definitions 0 Not Addressed
5 Principles relating to processing of personal data 11 Substantially Addressed
6 Lawfulness of processing 3 Partially Addressed
7 Conditions for consent 0 Not Addressed
8 Conditions applicable to child's consent in relation to information society services 5 Substantially Addressed
9 Processing of special categories of personal data 1 Indirectly Supported
10 Processing of personal data relating to criminal convictions and offences 0 Not Addressed
11 Processing which does not require identification 1 Indirectly Supported
12 Transparent information, communication and modalities for exercise of data subject rights 0 Not Addressed
13 Information to be provided where personal data are collected from the data subject 0 Not Addressed
14 Information to be provided where personal data have not been obtained from the data subject 1 Indirectly Supported
15 Right of access by the data subject 0 Not Addressed
16 Right to rectification 0 Not Addressed
17 Right to erasure (right to be forgotten) 1 Indirectly Supported
18 Right to restriction of processing 0 Not Addressed
19 Notification obligation regarding rectification or erasure of personal data or restriction of processing 0 Not Addressed
20 Right to data portability 0 Not Addressed
21 Right to object 0 Not Addressed
22 Automated individual decision-making, including profiling 12 Substantially Addressed
23 Restrictions 0 Not Addressed
24 Responsibility of the controller 14 Substantially Addressed
25 Data protection by design and by default 13 Substantially Addressed
26 Joint controllers 0 Not Addressed
27 Representatives of controllers or processors not established in the Union 0 Not Addressed
28 Processor 5 Substantially Addressed
29 Processing under the authority of the controller or processor 0 Not Addressed
30 Records of processing activities 1 Indirectly Supported
31 Cooperation with the supervisory authority 1 Indirectly Supported
32 Security of processing 22 Substantially Addressed
33 Notification of a personal data breach to the supervisory authority 14 Substantially Addressed
34 Communication of a personal data breach to the data subject 17 Substantially Addressed
35 Data protection impact assessment 8 Substantially Addressed
36 Prior consultation 4 Partially Addressed
37 Designation of the data protection officer 0 Not Addressed
38 Position of the data protection officer 0 Not Addressed
39 Tasks of the data protection officer 8 Substantially Addressed
40 Codes of conduct 0 Not Addressed
41 Monitoring of approved codes of conduct 3 Partially Addressed
42 Certification 2 Partially Addressed
43 Certification bodies 0 Not Addressed
44 General principle for transfers 7 Substantially Addressed
45 Transfers on the basis of an adequacy decision 7 Substantially Addressed
46 Transfers subject to appropriate safeguards 8 Substantially Addressed
47 Binding corporate rules 1 Indirectly Supported
48 Transfers or disclosures not authorised by Union law 0 Not Addressed
49 Derogations for specific situations 2 Partially Addressed
50 International cooperation for the protection of personal data 0 Not Addressed
77 Right to lodge a complaint with a supervisory authority 0 Not Addressed
78 Right to an effective judicial remedy against a supervisory authority 0 Not Addressed
79 Right to an effective judicial remedy against a controller or processor 0 Not Addressed
80 Representation of data subjects 0 Not Addressed
81 Suspension of proceedings 0 Not Addressed
82 Right to compensation and liability 10 Substantially Addressed
83 General conditions for imposing administrative fines 3 Partially Addressed
84 Penalties 3 Partially Addressed

Annex A — Complete GAISSF-to-GDPR Mapping Register

Controlled Publication. The table below shows a representative sample (6 of 188 total records). The complete control-by-control mapping register — full requirement-level traceability, evidence guidance and machine-readable export — is a Controlled Publication. Contact ODA3 Institute for access.
Record GAISSF GDPR Rel. Confidence Rationale / Residual Gap
CRO030-MAP-0001 D1-CTL-01 Art. 14 — Information to be provided where personal data have not been obtained from the data subject P Medium GAISSF D1-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 14. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation. Article 14 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.
CRO030-MAP-0002 D1-CTL-01 Art. 5 — Principles relating to processing of personal data P Medium GAISSF D1-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 5. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation. Article 5 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.
CRO030-MAP-0003 D1-CTL-01 Art. 32 — Security of processing P Medium GAISSF D1-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation. Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.
CRO030-MAP-0004 D1-CTL-01 Art. 44 — General principle for transfers S Medium GAISSF D1-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 44. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation. Article 44 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.
CRO030-MAP-0005 D1-CTL-02 Art. 32 — Security of processing P Medium GAISSF D1-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation. Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.
CRO030-MAP-0006 D1-CTL-02 Art. 34 — Communication of a personal data breach to the data subject S Medium GAISSF D1-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation. Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.

Annex B — Source Register

Source Role Status
GAISSF-NOR-001 v1.0 Framework and conformance baseline Normative
GAISSF-NOR-004 v1.0 Authoritative 59-control catalogue Normative
Regulation (EU) 2016/679 Primary legal baseline Binding regulation
EDPB guidance Interpretive implementation guidance Non-legislative guidance
CJEU and national decisions Legal interpretation and enforcement context Separate review required

Limitations and Reliance Notice

  • Mapping does not establish GDPR compliance.

  • GAISSF controls cannot determine lawful basis, controller/processor status, territorial scope, or validity of consent.

  • EDPB guidance, CJEU case law and national supervisory practice require separate review.

  • National laws may supplement the GDPR in permitted areas.

  • Evidence of control design is not evidence of operating effectiveness or lawful processing.

© 2026 ODA3 Pvt Ltd. Published by ODA3 Institute. Third-party laws, names and marks remain the property of their respective owners. No endorsement or legal opinion is implied.