GDPR
What is GDPR?
General Data Protection Regulation - EU regulation on data protection and privacy for all individuals within the European Union and European Economic Area. It comprises 40 controls organised across 4 domains, published by European Union, and applies in the European Union.
How GDPR maps to other frameworks
All 40 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 4 domains GDPR groups its controls into
Frameworks that share controls with GDPR
Each of these has at least one control mapped to a control in GDPR. The number is how many GDPR controls are shared, counted from the mapping graph.
ISO 27701:2019
33 shared controlsAICPA Privacy Management Framework (PMF)
30 shared controlsNIST SP 800-53 Rev 5
27 shared controlsAPEC Cross-Border Privacy Rules (CBPR) System
24 shared controlsAPPI
24 shared controlsChina Personal Information Protection Law (PIPL)
24 shared controlsAustralia Consumer Data Right - Banking (CDR)
22 shared controlsAustralia My Health Records Act 2012
22 shared controlsWhere GDPR overlaps with the standards you already hold
Implementation guides for frameworks that overlap GDPR
Step-by-step implementation of GDPR
More GDPR comparisons
Analysis of GDPR
Training that covers GDPR
Where to get trained on GDPR
4 courses in the catalogue cover GDPR directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
What GDPR means in your sector
What GDPR means for your job
Questions people ask about GDPR
What is GDPR?
How many controls does GDPR have?
Where does GDPR apply?
What frameworks does GDPR map to?
How do I get started with GDPR compliance?
Query GDPR programmatically
GDPR, its 40 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
GDPR API reference and MCP config →What GDPR requires, control by control
Each page carries the requirement text for one GDPR control and what an assessor expects to see as evidence.
- GDPR-ART-10 Processing of personal data relating to criminal convictions
- GDPR-ART-11 Processing which does not require identification
- GDPR-ART-12 Transparent information, communication and modalities for rights
- GDPR-ART-13 Information to be provided where personal data are collected
- GDPR-ART-14 Information where personal data have not been obtained from the data subject
- GDPR-ART-15 Right of access by the data subject
- GDPR-ART-16 Right to rectification
- GDPR-ART-17 Right to erasure (right to be forgotten)
- GDPR-ART-18 Right to restriction of processing
- GDPR-ART-19 Notification obligation regarding rectification, erasure or restriction
How much of another standard GDPR already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- APEC Cross-Border Privacy Rules (CBPR) System to GDPR crosswalk
- APPI to GDPR crosswalk
- Australia Consumer Data Right - Banking (CDR) to GDPR crosswalk
- Australia My Health Records Act 2012 to GDPR crosswalk
- GDPR to Australian Privacy Principles (APPs) crosswalk
- C5 (Germany) to GDPR crosswalk
- CCPA/CPRA to GDPR crosswalk
- Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 to GDPR crosswalk
How ready are you for GDPR?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.