# CRO-030 — GAISSF–GDPR Mapping v1.0 > Status: Publication Candidate This crosswalk maps 59 GAISSF controls to 58 operationally material GDPR provisions through 188 outcome-based records. It does not establish GDPR compliance. ## Source baseline - GAISSF-NOR-001 and GAISSF-NOR-004 v1.0 - Regulation (EU) 2016/679 - Verification date: 29 June 2026 ## Article coverage | Article | Title | Mapped controls | Coverage | |---:|---|---:|---| | 1 | Subject-matter and objectives | 0 | Not Addressed | | 2 | Material scope | 0 | Not Addressed | | 3 | Territorial scope | 0 | Not Addressed | | 4 | Definitions | 0 | Not Addressed | | 5 | Principles relating to processing of personal data | 11 | Substantially Addressed | | 6 | Lawfulness of processing | 3 | Partially Addressed | | 7 | Conditions for consent | 0 | Not Addressed | | 8 | Conditions applicable to child's consent in relation to information society services | 5 | Substantially Addressed | | 9 | Processing of special categories of personal data | 1 | Indirectly Supported | | 10 | Processing of personal data relating to criminal convictions and offences | 0 | Not Addressed | | 11 | Processing which does not require identification | 1 | Indirectly Supported | | 12 | Transparent information, communication and modalities for exercise of data subject rights | 0 | Not Addressed | | 13 | Information to be provided where personal data are collected from the data subject | 0 | Not Addressed | | 14 | Information to be provided where personal data have not been obtained from the data subject | 1 | Indirectly Supported | | 15 | Right of access by the data subject | 0 | Not Addressed | | 16 | Right to rectification | 0 | Not Addressed | | 17 | Right to erasure (right to be forgotten) | 1 | Indirectly Supported | | 18 | Right to restriction of processing | 0 | Not Addressed | | 19 | Notification obligation regarding rectification or erasure of personal data or restriction of processing | 0 | Not Addressed | | 20 | Right to data portability | 0 | Not Addressed | | 21 | Right to object | 0 | Not Addressed | | 22 | Automated individual decision-making, including profiling | 12 | Substantially Addressed | | 23 | Restrictions | 0 | Not Addressed | | 24 | Responsibility of the controller | 14 | Substantially Addressed | | 25 | Data protection by design and by default | 13 | Substantially Addressed | | 26 | Joint controllers | 0 | Not Addressed | | 27 | Representatives of controllers or processors not established in the Union | 0 | Not Addressed | | 28 | Processor | 5 | Substantially Addressed | | 29 | Processing under the authority of the controller or processor | 0 | Not Addressed | | 30 | Records of processing activities | 1 | Indirectly Supported | | 31 | Cooperation with the supervisory authority | 1 | Indirectly Supported | | 32 | Security of processing | 22 | Substantially Addressed | | 33 | Notification of a personal data breach to the supervisory authority | 14 | Substantially Addressed | | 34 | Communication of a personal data breach to the data subject | 17 | Substantially Addressed | | 35 | Data protection impact assessment | 8 | Substantially Addressed | | 36 | Prior consultation | 4 | Partially Addressed | | 37 | Designation of the data protection officer | 0 | Not Addressed | | 38 | Position of the data protection officer | 0 | Not Addressed | | 39 | Tasks of the data protection officer | 8 | Substantially Addressed | | 40 | Codes of conduct | 0 | Not Addressed | | 41 | Monitoring of approved codes of conduct | 3 | Partially Addressed | | 42 | Certification | 2 | Partially Addressed | | 43 | Certification bodies | 0 | Not Addressed | | 44 | General principle for transfers | 7 | Substantially Addressed | | 45 | Transfers on the basis of an adequacy decision | 7 | Substantially Addressed | | 46 | Transfers subject to appropriate safeguards | 8 | Substantially Addressed | | 47 | Binding corporate rules | 1 | Indirectly Supported | | 48 | Transfers or disclosures not authorised by Union law | 0 | Not Addressed | | 49 | Derogations for specific situations | 2 | Partially Addressed | | 50 | International cooperation for the protection of personal data | 0 | Not Addressed | | 77 | Right to lodge a complaint with a supervisory authority | 0 | Not Addressed | | 78 | Right to an effective judicial remedy against a supervisory authority | 0 | Not Addressed | | 79 | Right to an effective judicial remedy against a controller or processor | 0 | Not Addressed | | 80 | Representation of data subjects | 0 | Not Addressed | | 81 | Suspension of proceedings | 0 | Not Addressed | | 82 | Right to compensation and liability | 10 | Substantially Addressed | | 83 | General conditions for imposing administrative fines | 3 | Partially Addressed | | 84 | Penalties | 3 | Partially Addressed | ## Limitations - Mapping does not establish GDPR compliance. - GAISSF controls cannot determine lawful basis, controller/processor status, territorial scope, or validity of consent. - EDPB guidance, CJEU case law and national supervisory practice require separate review. - National laws may supplement the GDPR in permitted areas. - Evidence of control design is not evidence of operating effectiveness or lawful processing. ## Notably Absent No GDPR certification, automatic compliance, regulator endorsement, lawful-basis determination, or DPIA substitution is claimed.