{
  "meta": {
    "document_id": "GAISSF-CRO-030",
    "title": "GAISSF-GDPR Mapping",
    "version": "1.0",
    "status": "Draft for Publication",
    "publication_date": "29 June 2026",
    "publisher": "ODA3 Institute",
    "legal_entity": "ODA3 Pvt Ltd",
    "gaissf_baseline": "GAISSF v1.0, 59 controls",
    "external_baseline": "Regulation (EU) 2016/679",
    "external_application_date": "25 May 2018",
    "verification_date": "29 June 2026",
    "scope": "Operationally material GDPR articles 1-50 and 77-84; EDPB guidance is informative interpretation, not merged into the legal text."
  },
  "controls": [
    {
      "id": "D1-CTL-01",
      "title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-02",
      "title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-03",
      "title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-04",
      "title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-05",
      "title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-06",
      "title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-07",
      "title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-08",
      "title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-09",
      "title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-01",
      "title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-02",
      "title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-03",
      "title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-04",
      "title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-05",
      "title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-06",
      "title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-01",
      "title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-02",
      "title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-03",
      "title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-04",
      "title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-05",
      "title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-06",
      "title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-07",
      "title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-01",
      "title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-02",
      "title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-03",
      "title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-04",
      "title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-05",
      "title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-06",
      "title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-07",
      "title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-01",
      "title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-02",
      "title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-03",
      "title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-04",
      "title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-05",
      "title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-06",
      "title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-01",
      "title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-02",
      "title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-03",
      "title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-04",
      "title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-05",
      "title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-06",
      "title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-07",
      "title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D7-CTL-H01",
      "title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes"
    },
    {
      "id": "D7-CTL-H02",
      "title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes"
    },
    {
      "id": "D7-CTL-H03",
      "title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes"
    },
    {
      "id": "D7-CTL-H04",
      "title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes"
    },
    {
      "id": "D7-CTL-H05",
      "title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes"
    },
    {
      "id": "D8-CTL-01",
      "title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes"
    },
    {
      "id": "D8-CTL-02",
      "title": "ISO 42001 GAP ANALYSIS",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes"
    },
    {
      "id": "D8-CTL-03",
      "title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes"
    },
    {
      "id": "D8-CTL-04",
      "title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes"
    },
    {
      "id": "D8-CTL-05",
      "title": "NIST SP 800-218A COMPLIANCE CHECK",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes"
    },
    {
      "id": "D9-CTL-01",
      "title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-02",
      "title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-03",
      "title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-04",
      "title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-05",
      "title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-06",
      "title": "ACTUATOR COMMAND VERIFICATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-07",
      "title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    }
  ],
  "articles": [
    {
      "article": 1,
      "title": "Subject-matter and objectives",
      "chapter": "I - General provisions"
    },
    {
      "article": 2,
      "title": "Material scope",
      "chapter": "I - General provisions"
    },
    {
      "article": 3,
      "title": "Territorial scope",
      "chapter": "I - General provisions"
    },
    {
      "article": 4,
      "title": "Definitions",
      "chapter": "I - General provisions"
    },
    {
      "article": 5,
      "title": "Principles relating to processing of personal data",
      "chapter": "II - Principles"
    },
    {
      "article": 6,
      "title": "Lawfulness of processing",
      "chapter": "II - Principles"
    },
    {
      "article": 7,
      "title": "Conditions for consent",
      "chapter": "II - Principles"
    },
    {
      "article": 8,
      "title": "Conditions applicable to child's consent in relation to information society services",
      "chapter": "II - Principles"
    },
    {
      "article": 9,
      "title": "Processing of special categories of personal data",
      "chapter": "II - Principles"
    },
    {
      "article": 10,
      "title": "Processing of personal data relating to criminal convictions and offences",
      "chapter": "II - Principles"
    },
    {
      "article": 11,
      "title": "Processing which does not require identification",
      "chapter": "II - Principles"
    },
    {
      "article": 12,
      "title": "Transparent information, communication and modalities for exercise of data subject rights",
      "chapter": "III - Rights of the data subject"
    },
    {
      "article": 13,
      "title": "Information to be provided where personal data are collected from the data subject",
      "chapter": "III - Rights of the data subject"
    },
    {
      "article": 14,
      "title": "Information to be provided where personal data have not been obtained from the data subject",
      "chapter": "III - Rights of the data subject"
    },
    {
      "article": 15,
      "title": "Right of access by the data subject",
      "chapter": "III - Rights of the data subject"
    },
    {
      "article": 16,
      "title": "Right to rectification",
      "chapter": "III - Rights of the data subject"
    },
    {
      "article": 17,
      "title": "Right to erasure (right to be forgotten)",
      "chapter": "III - Rights of the data subject"
    },
    {
      "article": 18,
      "title": "Right to restriction of processing",
      "chapter": "III - Rights of the data subject"
    },
    {
      "article": 19,
      "title": "Notification obligation regarding rectification or erasure of personal data or restriction of processing",
      "chapter": "III - Rights of the data subject"
    },
    {
      "article": 20,
      "title": "Right to data portability",
      "chapter": "III - Rights of the data subject"
    },
    {
      "article": 21,
      "title": "Right to object",
      "chapter": "III - Rights of the data subject"
    },
    {
      "article": 22,
      "title": "Automated individual decision-making, including profiling",
      "chapter": "III - Rights of the data subject"
    },
    {
      "article": 23,
      "title": "Restrictions",
      "chapter": "III - Rights of the data subject"
    },
    {
      "article": 24,
      "title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 25,
      "title": "Data protection by design and by default",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 26,
      "title": "Joint controllers",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 27,
      "title": "Representatives of controllers or processors not established in the Union",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 28,
      "title": "Processor",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 29,
      "title": "Processing under the authority of the controller or processor",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 30,
      "title": "Records of processing activities",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 31,
      "title": "Cooperation with the supervisory authority",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 32,
      "title": "Security of processing",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 33,
      "title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 34,
      "title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 35,
      "title": "Data protection impact assessment",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 36,
      "title": "Prior consultation",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 37,
      "title": "Designation of the data protection officer",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 38,
      "title": "Position of the data protection officer",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 39,
      "title": "Tasks of the data protection officer",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 40,
      "title": "Codes of conduct",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 41,
      "title": "Monitoring of approved codes of conduct",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 42,
      "title": "Certification",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 43,
      "title": "Certification bodies",
      "chapter": "IV - Controller and processor"
    },
    {
      "article": 44,
      "title": "General principle for transfers",
      "chapter": "V - Transfers to third countries or international organisations"
    },
    {
      "article": 45,
      "title": "Transfers on the basis of an adequacy decision",
      "chapter": "V - Transfers to third countries or international organisations"
    },
    {
      "article": 46,
      "title": "Transfers subject to appropriate safeguards",
      "chapter": "V - Transfers to third countries or international organisations"
    },
    {
      "article": 47,
      "title": "Binding corporate rules",
      "chapter": "V - Transfers to third countries or international organisations"
    },
    {
      "article": 48,
      "title": "Transfers or disclosures not authorised by Union law",
      "chapter": "V - Transfers to third countries or international organisations"
    },
    {
      "article": 49,
      "title": "Derogations for specific situations",
      "chapter": "V - Transfers to third countries or international organisations"
    },
    {
      "article": 50,
      "title": "International cooperation for the protection of personal data",
      "chapter": "V - Transfers to third countries or international organisations"
    },
    {
      "article": 77,
      "title": "Right to lodge a complaint with a supervisory authority",
      "chapter": "VIII - Remedies, liability and penalties"
    },
    {
      "article": 78,
      "title": "Right to an effective judicial remedy against a supervisory authority",
      "chapter": "VIII - Remedies, liability and penalties"
    },
    {
      "article": 79,
      "title": "Right to an effective judicial remedy against a controller or processor",
      "chapter": "VIII - Remedies, liability and penalties"
    },
    {
      "article": 80,
      "title": "Representation of data subjects",
      "chapter": "VIII - Remedies, liability and penalties"
    },
    {
      "article": 81,
      "title": "Suspension of proceedings",
      "chapter": "VIII - Remedies, liability and penalties"
    },
    {
      "article": 82,
      "title": "Right to compensation and liability",
      "chapter": "VIII - Remedies, liability and penalties"
    },
    {
      "article": 83,
      "title": "General conditions for imposing administrative fines",
      "chapter": "VIII - Remedies, liability and penalties"
    },
    {
      "article": 84,
      "title": "Penalties",
      "chapter": "VIII - Remedies, liability and penalties"
    }
  ],
  "mappings": [
    {
      "record_id": "GAISSF-CRO030-MAP-0001",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 14,
      "article_title": "Information to be provided where personal data have not been obtained from the data subject",
      "chapter": "III - Rights of the data subject",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 14. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 14 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0002",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 5,
      "article_title": "Principles relating to processing of personal data",
      "chapter": "II - Principles",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 5. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 5 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0003",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0004",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 44,
      "article_title": "General principle for transfers",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 44. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 44 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0005",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0006",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0007",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 33,
      "article_title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 33. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 33 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0008",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 25,
      "article_title": "Data protection by design and by default",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 25. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 25 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0009",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0010",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 5,
      "article_title": "Principles relating to processing of personal data",
      "chapter": "II - Principles",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 5. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 5 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0011",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0012",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 33,
      "article_title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 33. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 33 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0013",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0014",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0015",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 33,
      "article_title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 33. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 33 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0016",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 25,
      "article_title": "Data protection by design and by default",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 25. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 25 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0017",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0018",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0019",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 33,
      "article_title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 33. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 33 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0020",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 25,
      "article_title": "Data protection by design and by default",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 25. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 25 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0021",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0022",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0023",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 33,
      "article_title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 33. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 33 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0024",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 25,
      "article_title": "Data protection by design and by default",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 25. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 25 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0025",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0026",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 5,
      "article_title": "Principles relating to processing of personal data",
      "chapter": "II - Principles",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 5. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 5 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0027",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0028",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 33,
      "article_title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 33. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 33 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0029",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-08 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0030",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 35,
      "article_title": "Data protection impact assessment",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-08 provides technical or governance capability relevant to the outcome addressed by GDPR Article 35. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 35 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0031",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-08 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0032",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 33,
      "article_title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-08 provides technical or governance capability relevant to the outcome addressed by GDPR Article 33. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 33 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0033",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0034",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 41,
      "article_title": "Monitoring of approved codes of conduct",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides technical or governance capability relevant to the outcome addressed by GDPR Article 41. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 41 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0035",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 39,
      "article_title": "Tasks of the data protection officer",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides technical or governance capability relevant to the outcome addressed by GDPR Article 39. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 39 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0036",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0037",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0038",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 25,
      "article_title": "Data protection by design and by default",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 25. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 25 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0039",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0040",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 33,
      "article_title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 33. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 33 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0041",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0042",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 25,
      "article_title": "Data protection by design and by default",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 25. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 25 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0043",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0044",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 33,
      "article_title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 33. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 33 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0045",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0046",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 25,
      "article_title": "Data protection by design and by default",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 25. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 25 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0047",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 39,
      "article_title": "Tasks of the data protection officer",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 39. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 39 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0048",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0049",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0050",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 25,
      "article_title": "Data protection by design and by default",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 25. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 25 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0051",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0052",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 33,
      "article_title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 33. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 33 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0053",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0054",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 25,
      "article_title": "Data protection by design and by default",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 25. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 25 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0055",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0056",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 33,
      "article_title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 33. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 33 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0057",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0058",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 25,
      "article_title": "Data protection by design and by default",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 25. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 25 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0059",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0060",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 33,
      "article_title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 33. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 33 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0061",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 82,
      "article_title": "Right to compensation and liability",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 82. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 82 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0062",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0063",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 46,
      "article_title": "Transfers subject to appropriate safeguards",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 46. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 46 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0064",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0065",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0066",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 25,
      "article_title": "Data protection by design and by default",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 25. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 25 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0067",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 24,
      "article_title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 24. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 24 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0068",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 35,
      "article_title": "Data protection impact assessment",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 35. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 35 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0069",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 82,
      "article_title": "Right to compensation and liability",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 82. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 82 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0070",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0071",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 8,
      "article_title": "Conditions applicable to child's consent in relation to information society services",
      "chapter": "II - Principles",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 8. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 8 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0072",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 24,
      "article_title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 24. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 24 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0073",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 82,
      "article_title": "Right to compensation and liability",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 82. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 82 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0074",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 35,
      "article_title": "Data protection impact assessment",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 35. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 35 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0075",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0076",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 25,
      "article_title": "Data protection by design and by default",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 25. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 25 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0077",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 17,
      "article_title": "Right to erasure (right to be forgotten)",
      "chapter": "III - Rights of the data subject",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 17. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 17 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0078",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 6,
      "article_title": "Lawfulness of processing",
      "chapter": "II - Principles",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 6. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 6 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0079",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 5,
      "article_title": "Principles relating to processing of personal data",
      "chapter": "II - Principles",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 5. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 5 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0080",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 46,
      "article_title": "Transfers subject to appropriate safeguards",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 46. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 46 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0081",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 44,
      "article_title": "General principle for transfers",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 44. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 44 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0082",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 45,
      "article_title": "Transfers on the basis of an adequacy decision",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 45. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 45 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0083",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 28,
      "article_title": "Processor",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 28. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 28 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0084",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 46,
      "article_title": "Transfers subject to appropriate safeguards",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 46. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 46 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0085",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 45,
      "article_title": "Transfers on the basis of an adequacy decision",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 45. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 45 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0086",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 44,
      "article_title": "General principle for transfers",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 44. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 44 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0087",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 28,
      "article_title": "Processor",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 28. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 28 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0088",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 46,
      "article_title": "Transfers subject to appropriate safeguards",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 46. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 46 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0089",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 45,
      "article_title": "Transfers on the basis of an adequacy decision",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 45. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 45 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0090",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 44,
      "article_title": "General principle for transfers",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 44. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 44 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0091",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 28,
      "article_title": "Processor",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 28. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 28 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0092",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 46,
      "article_title": "Transfers subject to appropriate safeguards",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 46. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 46 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0093",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 45,
      "article_title": "Transfers on the basis of an adequacy decision",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 45. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 45 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0094",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 44,
      "article_title": "General principle for transfers",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 44. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 44 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0095",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0096",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 46,
      "article_title": "Transfers subject to appropriate safeguards",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D4-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 46. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 46 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0097",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 44,
      "article_title": "General principle for transfers",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 44. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 44 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0098",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 28,
      "article_title": "Processor",
      "chapter": "IV - Controller and processor",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 28. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 28 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0099",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 45,
      "article_title": "Transfers on the basis of an adequacy decision",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 45. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 45 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0100",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 47,
      "article_title": "Binding corporate rules",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 47. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 47 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0101",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 46,
      "article_title": "Transfers subject to appropriate safeguards",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 46. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 46 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0102",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 49,
      "article_title": "Derogations for specific situations",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 49. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 49 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0103",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 45,
      "article_title": "Transfers on the basis of an adequacy decision",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 45. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 45 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0104",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 46,
      "article_title": "Transfers subject to appropriate safeguards",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 46. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 46 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0105",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 45,
      "article_title": "Transfers on the basis of an adequacy decision",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 45. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 45 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0106",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 44,
      "article_title": "General principle for transfers",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 44. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 44 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0107",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 28,
      "article_title": "Processor",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 28. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 28 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0108",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 22,
      "article_title": "Automated individual decision-making, including profiling",
      "chapter": "III - Rights of the data subject",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 22. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 22 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0109",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 8,
      "article_title": "Conditions applicable to child's consent in relation to information society services",
      "chapter": "II - Principles",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 8. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 8 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0110",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 35,
      "article_title": "Data protection impact assessment",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 35. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 35 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0111",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 5,
      "article_title": "Principles relating to processing of personal data",
      "chapter": "II - Principles",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 5. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 5 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0112",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 22,
      "article_title": "Automated individual decision-making, including profiling",
      "chapter": "III - Rights of the data subject",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 22. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 22 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0113",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0114",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 8,
      "article_title": "Conditions applicable to child's consent in relation to information society services",
      "chapter": "II - Principles",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 8. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 8 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0115",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 5,
      "article_title": "Principles relating to processing of personal data",
      "chapter": "II - Principles",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 5. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 5 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0116",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 22,
      "article_title": "Automated individual decision-making, including profiling",
      "chapter": "III - Rights of the data subject",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 22. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 22 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0117",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 8,
      "article_title": "Conditions applicable to child's consent in relation to information society services",
      "chapter": "II - Principles",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 8. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 8 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0118",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 5,
      "article_title": "Principles relating to processing of personal data",
      "chapter": "II - Principles",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 5. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 5 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0119",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 22,
      "article_title": "Automated individual decision-making, including profiling",
      "chapter": "III - Rights of the data subject",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 22. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 22 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0120",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 32. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 32 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0121",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 8,
      "article_title": "Conditions applicable to child's consent in relation to information society services",
      "chapter": "II - Principles",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 8. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 8 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0122",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 5,
      "article_title": "Principles relating to processing of personal data",
      "chapter": "II - Principles",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 5. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 5 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0123",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 25,
      "article_title": "Data protection by design and by default",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 25. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 25 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0124",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 35,
      "article_title": "Data protection impact assessment",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 35. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 35 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0125",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 22,
      "article_title": "Automated individual decision-making, including profiling",
      "chapter": "III - Rights of the data subject",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 22. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 22 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0126",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 11,
      "article_title": "Processing which does not require identification",
      "chapter": "II - Principles",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 11. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 11 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0127",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 35,
      "article_title": "Data protection impact assessment",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 35. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 35 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0128",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 22,
      "article_title": "Automated individual decision-making, including profiling",
      "chapter": "III - Rights of the data subject",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 22. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 22 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0129",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 9,
      "article_title": "Processing of special categories of personal data",
      "chapter": "II - Principles",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 9. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 9 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0130",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 5,
      "article_title": "Principles relating to processing of personal data",
      "chapter": "II - Principles",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 5. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 5 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0131",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 82,
      "article_title": "Right to compensation and liability",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D6-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 82. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 82 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0132",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 24,
      "article_title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D6-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 24. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 24 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0133",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 36,
      "article_title": "Prior consultation",
      "chapter": "IV - Controller and processor",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 36. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 36 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0134",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 39,
      "article_title": "Tasks of the data protection officer",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 39. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 39 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0135",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 39,
      "article_title": "Tasks of the data protection officer",
      "chapter": "IV - Controller and processor",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 39. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 39 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0136",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 24,
      "article_title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 24. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 24 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0137",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 82,
      "article_title": "Right to compensation and liability",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 82. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 82 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0138",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 41,
      "article_title": "Monitoring of approved codes of conduct",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 41. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 41 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0139",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 24,
      "article_title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 24. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 24 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0140",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 82,
      "article_title": "Right to compensation and liability",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 82. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 82 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0141",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 36,
      "article_title": "Prior consultation",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 36. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 36 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0142",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 31,
      "article_title": "Cooperation with the supervisory authority",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 31. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 31 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0143",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 24,
      "article_title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 24. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 24 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0144",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 84,
      "article_title": "Penalties",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 84. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 84 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0145",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 83,
      "article_title": "General conditions for imposing administrative fines",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 83. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 83 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0146",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 82,
      "article_title": "Right to compensation and liability",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 82. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 82 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0147",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 39,
      "article_title": "Tasks of the data protection officer",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 39. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 39 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0148",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 24,
      "article_title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 24. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 24 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0149",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 84,
      "article_title": "Penalties",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 84. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 84 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0150",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 83,
      "article_title": "General conditions for imposing administrative fines",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 83. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 83 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0151",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 24,
      "article_title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D6-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 24. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 24 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0152",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 82,
      "article_title": "Right to compensation and liability",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 82. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 82 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0153",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 39,
      "article_title": "Tasks of the data protection officer",
      "chapter": "IV - Controller and processor",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 39. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 39 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0154",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 36,
      "article_title": "Prior consultation",
      "chapter": "IV - Controller and processor",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 36. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 36 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0155",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 24,
      "article_title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 24. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 24 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0156",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 84,
      "article_title": "Penalties",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 84. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 84 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0157",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 83,
      "article_title": "General conditions for imposing administrative fines",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 83. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 83 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0158",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 82,
      "article_title": "Right to compensation and liability",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D6-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 82. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 82 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0159",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 22,
      "article_title": "Automated individual decision-making, including profiling",
      "chapter": "III - Rights of the data subject",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 22. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 22 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0160",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 22,
      "article_title": "Automated individual decision-making, including profiling",
      "chapter": "III - Rights of the data subject",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 22. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 22 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0161",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 39,
      "article_title": "Tasks of the data protection officer",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 39. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 39 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0162",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 22,
      "article_title": "Automated individual decision-making, including profiling",
      "chapter": "III - Rights of the data subject",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 22. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 22 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0163",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 22,
      "article_title": "Automated individual decision-making, including profiling",
      "chapter": "III - Rights of the data subject",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 22. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 22 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0164",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 22,
      "article_title": "Automated individual decision-making, including profiling",
      "chapter": "III - Rights of the data subject",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 22. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 22 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0165",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 82,
      "article_title": "Right to compensation and liability",
      "chapter": "VIII - Remedies, liability and penalties",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 82. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 82 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0166",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 49,
      "article_title": "Derogations for specific situations",
      "chapter": "V - Transfers to third countries or international organisations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 49. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 49 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0167",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 42,
      "article_title": "Certification",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 42. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 42 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0168",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 36,
      "article_title": "Prior consultation",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 36. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 36 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0169",
      "gaissf_id": "D8-CTL-02",
      "gaissf_title": "ISO 42001 GAP ANALYSIS",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 24,
      "article_title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 24. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 24 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0170",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 30,
      "article_title": "Records of processing activities",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 30. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 30 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0171",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 6,
      "article_title": "Lawfulness of processing",
      "chapter": "II - Principles",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 6. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 6 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0172",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 5,
      "article_title": "Principles relating to processing of personal data",
      "chapter": "II - Principles",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 5. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 5 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0173",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 33,
      "article_title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 33. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 33 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0174",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0175",
      "gaissf_id": "D8-CTL-05",
      "gaissf_title": "NIST SP 800-218A COMPLIANCE CHECK",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 6,
      "article_title": "Lawfulness of processing",
      "chapter": "II - Principles",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 6. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 6 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0176",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 24,
      "article_title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-01 provides technical or governance capability relevant to the outcome addressed by GDPR Article 24. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 24 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0177",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 35,
      "article_title": "Data protection impact assessment",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-02 provides technical or governance capability relevant to the outcome addressed by GDPR Article 35. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 35 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0178",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 24,
      "article_title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-03 provides technical or governance capability relevant to the outcome addressed by GDPR Article 24. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 24 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0179",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 24,
      "article_title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-04 provides technical or governance capability relevant to the outcome addressed by GDPR Article 24. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 24 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0180",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 5,
      "article_title": "Principles relating to processing of personal data",
      "chapter": "II - Principles",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 5. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 5 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0181",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 22,
      "article_title": "Automated individual decision-making, including profiling",
      "chapter": "III - Rights of the data subject",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 22. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 22 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0182",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 41,
      "article_title": "Monitoring of approved codes of conduct",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 41. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 41 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0183",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 39,
      "article_title": "Tasks of the data protection officer",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-05 provides technical or governance capability relevant to the outcome addressed by GDPR Article 39. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 39 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0184",
      "gaissf_id": "D9-CTL-06",
      "gaissf_title": "ACTUATOR COMMAND VERIFICATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 24,
      "article_title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-06 provides technical or governance capability relevant to the outcome addressed by GDPR Article 24. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 24 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0185",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 33,
      "article_title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 33. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 33 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0186",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 42,
      "article_title": "Certification",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 42. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 42 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0187",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 35,
      "article_title": "Data protection impact assessment",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 35. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 35 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    },
    {
      "record_id": "GAISSF-CRO030-MAP-0188",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-07 provides technical or governance capability relevant to the outcome addressed by GDPR Article 34. The relationship is outcome-based and does not establish the required lawful basis, actor status, data-subject procedure, or supervisory interpretation.",
      "residual_gap": "Article 34 requires processing-context analysis, controller/processor accountability, and legal evidence beyond implementation of this GAISSF control.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "gdpr_source": "Regulation (EU) 2016/679"
    }
  ],
  "reverse": [
    {
      "article": 1,
      "article_title": "Subject-matter and objectives",
      "chapter": "I - General provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 2,
      "article_title": "Material scope",
      "chapter": "I - General provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 3,
      "article_title": "Territorial scope",
      "chapter": "I - General provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 4,
      "article_title": "Definitions",
      "chapter": "I - General provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 5,
      "article_title": "Principles relating to processing of personal data",
      "chapter": "II - Principles",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-03",
        "D1-CTL-07",
        "D3-CTL-07",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-06",
        "D8-CTL-03",
        "D9-CTL-05"
      ],
      "mapped_count": 11,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 6,
      "article_title": "Lawfulness of processing",
      "chapter": "II - Principles",
      "mapped_controls": [
        "D3-CTL-07",
        "D8-CTL-03",
        "D8-CTL-05"
      ],
      "mapped_count": 3,
      "coverage_status": "Partially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 7,
      "article_title": "Conditions for consent",
      "chapter": "II - Principles",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 8,
      "article_title": "Conditions applicable to child's consent in relation to information society services",
      "chapter": "II - Principles",
      "mapped_controls": [
        "D3-CTL-04",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04"
      ],
      "mapped_count": 5,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 9,
      "article_title": "Processing of special categories of personal data",
      "chapter": "II - Principles",
      "mapped_controls": [
        "D5-CTL-06"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 10,
      "article_title": "Processing of personal data relating to criminal convictions and offences",
      "chapter": "II - Principles",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 11,
      "article_title": "Processing which does not require identification",
      "chapter": "II - Principles",
      "mapped_controls": [
        "D5-CTL-05"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 12,
      "article_title": "Transparent information, communication and modalities for exercise of data subject rights",
      "chapter": "III - Rights of the data subject",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 13,
      "article_title": "Information to be provided where personal data are collected from the data subject",
      "chapter": "III - Rights of the data subject",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 14,
      "article_title": "Information to be provided where personal data have not been obtained from the data subject",
      "chapter": "III - Rights of the data subject",
      "mapped_controls": [
        "D1-CTL-01"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 15,
      "article_title": "Right of access by the data subject",
      "chapter": "III - Rights of the data subject",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 16,
      "article_title": "Right to rectification",
      "chapter": "III - Rights of the data subject",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 17,
      "article_title": "Right to erasure (right to be forgotten)",
      "chapter": "III - Rights of the data subject",
      "mapped_controls": [
        "D3-CTL-07"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 18,
      "article_title": "Right to restriction of processing",
      "chapter": "III - Rights of the data subject",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 19,
      "article_title": "Notification obligation regarding rectification or erasure of personal data or restriction of processing",
      "chapter": "III - Rights of the data subject",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 20,
      "article_title": "Right to data portability",
      "chapter": "III - Rights of the data subject",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 21,
      "article_title": "Right to object",
      "chapter": "III - Rights of the data subject",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 22,
      "article_title": "Automated individual decision-making, including profiling",
      "chapter": "III - Rights of the data subject",
      "mapped_controls": [
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06",
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H03",
        "D7-CTL-H04",
        "D7-CTL-H05",
        "D9-CTL-05"
      ],
      "mapped_count": 12,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 23,
      "article_title": "Restrictions",
      "chapter": "III - Rights of the data subject",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 24,
      "article_title": "Responsibility of the controller",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [
        "D3-CTL-03",
        "D3-CTL-05",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-06",
        "D6-CTL-07",
        "D8-CTL-02",
        "D9-CTL-01",
        "D9-CTL-03",
        "D9-CTL-04",
        "D9-CTL-06"
      ],
      "mapped_count": 14,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 25,
      "article_title": "Data protection by design and by default",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [
        "D1-CTL-02",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-02",
        "D3-CTL-06",
        "D5-CTL-05"
      ],
      "mapped_count": 13,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 26,
      "article_title": "Joint controllers",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 27,
      "article_title": "Representatives of controllers or processors not established in the Union",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 28,
      "article_title": "Processor",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-05",
        "D4-CTL-07"
      ],
      "mapped_count": 5,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 29,
      "article_title": "Processing under the authority of the controller or processor",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 30,
      "article_title": "Records of processing activities",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [
        "D8-CTL-03"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 31,
      "article_title": "Cooperation with the supervisory authority",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [
        "D6-CTL-03"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 32,
      "article_title": "Security of processing",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-04",
        "D3-CTL-06",
        "D4-CTL-04",
        "D5-CTL-02",
        "D5-CTL-04"
      ],
      "mapped_count": 22,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 33,
      "article_title": "Notification of a personal data breach to the supervisory authority",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D8-CTL-04",
        "D9-CTL-07"
      ],
      "mapped_count": 14,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 34,
      "article_title": "Communication of a personal data breach to the data subject",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-02",
        "D8-CTL-04",
        "D9-CTL-07"
      ],
      "mapped_count": 17,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 35,
      "article_title": "Data protection impact assessment",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [
        "D1-CTL-08",
        "D3-CTL-04",
        "D3-CTL-06",
        "D5-CTL-01",
        "D5-CTL-05",
        "D5-CTL-06",
        "D9-CTL-02",
        "D9-CTL-07"
      ],
      "mapped_count": 8,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 36,
      "article_title": "Prior consultation",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [
        "D6-CTL-01",
        "D6-CTL-03",
        "D6-CTL-06",
        "D8-CTL-01"
      ],
      "mapped_count": 4,
      "coverage_status": "Partially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 37,
      "article_title": "Designation of the data protection officer",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 38,
      "article_title": "Position of the data protection officer",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 39,
      "article_title": "Tasks of the data protection officer",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [
        "D1-CTL-09",
        "D2-CTL-03",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-05",
        "D6-CTL-06",
        "D7-CTL-H02",
        "D9-CTL-05"
      ],
      "mapped_count": 8,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 40,
      "article_title": "Codes of conduct",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 41,
      "article_title": "Monitoring of approved codes of conduct",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [
        "D1-CTL-09",
        "D6-CTL-02",
        "D9-CTL-05"
      ],
      "mapped_count": 3,
      "coverage_status": "Partially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 42,
      "article_title": "Certification",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [
        "D8-CTL-01",
        "D9-CTL-07"
      ],
      "mapped_count": 2,
      "coverage_status": "Partially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 43,
      "article_title": "Certification bodies",
      "chapter": "IV - Controller and processor",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 44,
      "article_title": "General principle for transfers",
      "chapter": "V - Transfers to third countries or international organisations",
      "mapped_controls": [
        "D1-CTL-01",
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-07"
      ],
      "mapped_count": 7,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 45,
      "article_title": "Transfers on the basis of an adequacy decision",
      "chapter": "V - Transfers to third countries or international organisations",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07"
      ],
      "mapped_count": 7,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 46,
      "article_title": "Transfers subject to appropriate safeguards",
      "chapter": "V - Transfers to third countries or international organisations",
      "mapped_controls": [
        "D3-CTL-02",
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07"
      ],
      "mapped_count": 8,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 47,
      "article_title": "Binding corporate rules",
      "chapter": "V - Transfers to third countries or international organisations",
      "mapped_controls": [
        "D4-CTL-06"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 48,
      "article_title": "Transfers or disclosures not authorised by Union law",
      "chapter": "V - Transfers to third countries or international organisations",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 49,
      "article_title": "Derogations for specific situations",
      "chapter": "V - Transfers to third countries or international organisations",
      "mapped_controls": [
        "D4-CTL-06",
        "D8-CTL-01"
      ],
      "mapped_count": 2,
      "coverage_status": "Partially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 50,
      "article_title": "International cooperation for the protection of personal data",
      "chapter": "V - Transfers to third countries or international organisations",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 77,
      "article_title": "Right to lodge a complaint with a supervisory authority",
      "chapter": "VIII - Remedies, liability and penalties",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 78,
      "article_title": "Right to an effective judicial remedy against a supervisory authority",
      "chapter": "VIII - Remedies, liability and penalties",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 79,
      "article_title": "Right to an effective judicial remedy against a controller or processor",
      "chapter": "VIII - Remedies, liability and penalties",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 80,
      "article_title": "Representation of data subjects",
      "chapter": "VIII - Remedies, liability and penalties",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 81,
      "article_title": "Suspension of proceedings",
      "chapter": "VIII - Remedies, liability and penalties",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 82,
      "article_title": "Right to compensation and liability",
      "chapter": "VIII - Remedies, liability and penalties",
      "mapped_controls": [
        "D3-CTL-01",
        "D3-CTL-04",
        "D3-CTL-06",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-06",
        "D6-CTL-07",
        "D8-CTL-01"
      ],
      "mapped_count": 10,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 83,
      "article_title": "General conditions for imposing administrative fines",
      "chapter": "VIII - Remedies, liability and penalties",
      "mapped_controls": [
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-07"
      ],
      "mapped_count": 3,
      "coverage_status": "Partially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    },
    {
      "article": 84,
      "article_title": "Penalties",
      "chapter": "VIII - Remedies, liability and penalties",
      "mapped_controls": [
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-07"
      ],
      "mapped_count": 3,
      "coverage_status": "Partially Addressed",
      "residual_gap": "GAISSF does not by itself establish GDPR applicability, lawful basis, transparency content, rights-handling procedure, international-transfer mechanism, or regulator-facing compliance."
    }
  ],
  "limitations": [
    "Mapping does not establish GDPR compliance.",
    "GAISSF controls cannot determine lawful basis, controller/processor status, territorial scope, or validity of consent.",
    "EDPB guidance, CJEU case law and national supervisory practice require separate review.",
    "National laws may supplement the GDPR in permitted areas.",
    "Evidence of control design is not evidence of operating effectiveness or lawful processing."
  ]
}
