Framework overlap

Does Act on the Implementation of the General Data Protection Regulation (OG 42/2018) cover AICPA Privacy Management Framework (PMF)?

You hold Act on the Implementation of the General Data Protection Regulation (OG 42/2018) and have been told to do AICPA Privacy Management Framework (PMF). Here is how much overlaps, control by control.

58% of AICPA Privacy Management Framework (PMF) you already have

Act on the Implementation of the General Data Protection Regulation (OG 42/2018) already covers about 58% of AICPA Privacy Management Framework (PMF), leaving 11 of 26 controls as genuinely new work.

Already covered 0 Likely covered 15 New work 11

No control in Act on the Implementation of the General Data Protection Regulation (OG 42/2018) maps directly to one in AICPA Privacy Management Framework (PMF). Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in Act on the Implementation of the General Data Protection Regulation (OG 42/2018) reaches these. This is the list to scope.

PMF-A.1
Individual Access Rights
PMF-A.2
Access Request Process
PMF-AN.1
Privacy Notice
PMF-AN.3
Privacy Agreements
PMF-D.1
Third-Party Disclosure Controls
PMF-D.2
Third-Party Agreements
PMF-D.3
Onward Transfer Accountability
PMF-M.2
Privacy Policies and Procedures
PMF-M.4
Privacy Incident Management
PMF-ME.1
Privacy Program Monitoring
PMF-URD.3
Secure Disposal
Show the 15 you already have
PMF-AN.2
Purpose Specification
PMF-CC.1
Lawful and Fair Collection
PMF-CC.2
Collection Limitation
PMF-CC.3
Consent Mechanisms
PMF-DI.1
Data Accuracy
PMF-DI.2
Data Quality Processes
PMF-M.1
Privacy Program Governance
PMF-M.3
Privacy Risk Assessment
PMF-ME.2
Complaint Handling
PMF-ME.3
Enforcement and Remediation
PMF-SP.1
Information Security Program
PMF-SP.2
Security Safeguards
PMF-SP.3
Security Testing and Monitoring
PMF-URD.1
Use Limitation
PMF-URD.2
Retention Periods

How this is calculated

Already covered means a mapping runs from a control in Act on the Implementation of the General Data Protection Regulation (OG 42/2018) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition