45% of Cayman Islands Data Protection Act 2017 (DPA) you already have
AICPA Privacy Management Framework (PMF) already covers about 45% of Cayman Islands Data Protection Act 2017 (DPA), leaving
12 of 22 controls as genuinely new work.
Already covered 0
Likely covered 10
New work 12
No control in AICPA Privacy Management Framework (PMF)
maps directly to one in Cayman Islands Data Protection Act 2017 (DPA). Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in AICPA Privacy Management Framework (PMF) reaches these. This is the list to scope.
CAYDPA-P6Sixth Principle - Rights of Data Subjects
CAYDPA-Sch3Schedule 3 - Conditions for Processing Sensitive Personal Data
CAYDPA-s10Right to Stop Processing Likely to Cause Damage or Distress (s.10)
CAYDPA-s11Right to Stop Processing for Direct Marketing (s.11)
CAYDPA-s12Rights in Relation to Automated Decision-Making (s.12)
CAYDPA-s14Rectification, Blocking, Erasure or Destruction (s.14)
CAYDPA-s18National Security Exemption (s.18)
CAYDPA-s31Exemptions by Regulations (s.31)
CAYDPA-s43Complaints to the Ombudsman (s.43)
CAYDPA-s47Right to Seek Judicial Review (s.47)
CAYDPA-s55Power of the Ombudsman to Impose Monetary Penalty (s.55)
CAYDPA-s8Fundamental Rights of Access to Personal Data (s.8)
Show the 10 you already have
CAYDPA-P1First Principle - Fair and Lawful Processing
CAYDPA-P2Second Principle - Purpose Limitation
CAYDPA-P3Third Principle - Adequate, Relevant and Not Excessive
CAYDPA-P4Fourth Principle - Accuracy
CAYDPA-P5Fifth Principle - Storage Limitation
CAYDPA-P7Seventh Principle - Security
CAYDPA-P8Eighth Principle - International Transfer
CAYDPA-Sch2Schedule 2 - Conditions for Processing (General Personal Data)
CAYDPA-Sch4Schedule 4 - Transfers to Which the Eighth Principle Does Not Apply
CAYDPA-s16Personal Data Breach Notification (s.16)
How this is calculated
Already covered means a mapping runs from a control in AICPA Privacy Management Framework (PMF) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition