Main site ↗

Docs / GAISSF™ / Crosswalk

GAISSF™ to GDPR Crosswalk

ID GAISSF-CRO-030 Framework GAISSF™ Type Crosswalk

Download PDF Document record

Read this first. A crosswalk records a documented correspondence under stated criteria. It does not establish compliance, equivalence, endorsement or certification.
What it coversThis crosswalk contains 188 outcome-based control-to-article mapping records covering all 59 GAISSF controls and 58 operationally material GDPR provisions. It supports privacy engineering, evidence reuse, gap analysis and governance planning.
Scope and limitsMapping does not establish GDPR compliance. GAISSF controls cannot determine lawful basis, controller/processor status, territorial scope, or validity of consent.
Edition mappedRegulation (EU) 2016/679 (GDPR)

Revision history

Date (as stated)EventWhat changed
2026PublicationPublished as v1.0Source: Page metadata (/crosswalks/cro-030-gdpr/)
06 October 2026Document revisionDraft for Publication issued, public and in full; independent crosswalk review openSource: GAISSF-CRO-030_GAISSF-GDPR-Mapping_v1.0.pdf
7 October 2026File correctionMapping register: GAISSF-NOR-001 and NOR-004 relabelled "Published normative source" (were "Internal controlled source")Source: GAISSF-CRO-030_GAISSF-GDPR_Mapping_Register_v1.0.xlsx
7 October 2026File correctionWebsite summary: list of publication files now names the files published here (PDF, XLSX, JSON); DOCX and Markdown entries removed (document date unchanged)Source: GAISSF-CRO-030_GAISSF-GDPR_Website-Summary_v1.0.pdf

Website record last updated 7 October 2026. This is the web page, not the document.

More from GAISSF™

SEC-047GAISSF™ Telecommunications Sector Implementation Guide
NOR-001GAISSF™ Framework Standard
NOR-002GAISSF™ Executive Summary
NOR-003GAISSF™ Quick Start Guide
Cite this document
ODA3 Institute. GAISSF™ to GDPR Crosswalk (GAISSF-CRO-030), v1.0. Published 29 June 2026. docs.oda3.org/documents/cro-030/

Report a correction or ask about this publication