Framework overlap

Does Act on the Implementation of the General Data Protection Regulation (OG 42/2018) cover Canadian PIPEDA?

You hold Act on the Implementation of the General Data Protection Regulation (OG 42/2018) and have been told to do Canadian PIPEDA. Here is how much overlaps, control by control.

52% of Canadian PIPEDA you already have

Act on the Implementation of the General Data Protection Regulation (OG 42/2018) already covers about 52% of Canadian PIPEDA, leaving 15 of 31 controls as genuinely new work.

Already covered 0 Likely covered 16 New work 15

No control in Act on the Implementation of the General Data Protection Regulation (OG 42/2018) maps directly to one in Canadian PIPEDA. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in Act on the Implementation of the General Data Protection Regulation (OG 42/2018) reaches these. This is the list to scope.

PIPEDA-10.1
Report of Breach to the Commissioner
PIPEDA-10.1(6)
Real Risk of Significant Harm Assessment
PIPEDA-10.1-ind
Notification of Breach to Individuals
PIPEDA-10.2
Notification to Other Organizations
PIPEDA-10.3
Records of Breaches
PIPEDA-11
Filing of Complaints with the Commissioner
PIPEDA-4.1.3
Accountability for Transfers to Third Parties
PIPEDA-4.1.4
Policies and Practices (Privacy Management Program)
PIPEDA-4.10
Principle 10 - Challenging Compliance
PIPEDA-4.8
Principle 8 - Openness
PIPEDA-4.8.2
Required Openness Information
PIPEDA-4.9
Principle 9 - Individual Access
PIPEDA-4.9.4
Access Response Timelines
PIPEDA-4.9.5
Correction and Notation
PIPEDA-7.3
Disclosure for Prospective Business Transaction
Show the 16 you already have
PIPEDA-4.1
Principle 1 - Accountability
PIPEDA-4.2
Principle 2 - Identifying Purposes
PIPEDA-4.2.4
New Purpose Requires New Consent
PIPEDA-4.3
Principle 3 - Consent
PIPEDA-4.3.4
Form of Consent Calibrated to Sensitivity
PIPEDA-4.3.8
Withdrawal of Consent
PIPEDA-4.4
Principle 4 - Limiting Collection
PIPEDA-4.5
Principle 5 - Limiting Use, Disclosure and Retention
PIPEDA-4.5.3
Secure Destruction and Retention
PIPEDA-4.6
Principle 6 - Accuracy
PIPEDA-4.7
Principle 7 - Safeguards
PIPEDA-4.7.3
Categories of Safeguards
PIPEDA-4.7.4
Employee Awareness of Safeguards
PIPEDA-5(3)
Appropriate Purposes
PIPEDA-6.1
Valid Consent
PIPEDA-7
Collection, Use and Disclosure Without Consent

How this is calculated

Already covered means a mapping runs from a control in Act on the Implementation of the General Data Protection Regulation (OG 42/2018) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition