50% of Chile Personal Data Protection Law (Law No. 21.719) you already have
AICPA Privacy Management Framework (PMF) already covers about 50% of Chile Personal Data Protection Law (Law No. 21.719), leaving
15 of 30 controls as genuinely new work.
Already covered 0
Likely covered 15
New work 15
No control in AICPA Privacy Management Framework (PMF)
maps directly to one in Chile Personal Data Protection Law (Law No. 21.719). Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in AICPA Privacy Management Framework (PMF) reaches these. This is the list to scope.
CL21719-A14terLawfulness Documentation and Transparency (Art. 14 ter)
CL21719-A15bisRecords of Processing Activities (Art. 15 bis)
CL21719-A17Credit and Financial Data (Art. 17-18)
CL21719-A26Certification and Compliance Models (Art. 26)
CL21719-A36Personal Data Protection Agency (Art. 30/36)
CL21719-A45Sanctions Regime (Art. 34 quinquies / Art. 45)
CL21719-A49Data Protection Officer (Art. 49)
CL21719-A50Effective Date and Transition
CL21719-A5aRight of Access (Art. 5 lit a)
CL21719-A5bRight of Rectification (Art. 5 lit b)
CL21719-A5cRight of Cancellation/Erasure (Art. 5 lit c)
CL21719-A5dRight of Opposition (Art. 5 lit d)
CL21719-A5eRight of Portability (Art. 5 lit e)
CL21719-A8bisRights Regarding Automated Decisions (Art. 8 bis)
CL21719-A8terRight to Block Processing (Art. 8 ter)
Show the 15 you already have
CL21719-A12Lawful Bases for Processing (Art. 12)
CL21719-A14Consent (Art. 13-14)
CL21719-A14quaterPrivacy by Design and by Default (Art. 14 quater)
CL21719-A14quinquiesSecurity of Processing (Art. 14 quinquies)
CL21719-A14sexiesBreach Notification (Art. 14 sexies)
CL21719-A15Processor Obligations and Contracts (Art. 15)
CL21719-A15terData Protection Impact Assessment (Art. 15 ter)
CL21719-A16Sensitive Personal Data (Art. 16)
CL21719-A16bisHealth Data (Art. 16 bis)
CL21719-A16quaterChildren's Data (Art. 16 quater)
CL21719-A16terBiometric Data (Art. 16 ter)
CL21719-A27International Data Transfers (Art. 27-28 bis)
CL21719-A28Adequacy Determinations (Art. 28)
CL21719-A3Definitions and Scope (Art. 1-3)
CL21719-A4Principles of Processing (Art. 3-4)
How this is calculated
Already covered means a mapping runs from a control in AICPA Privacy Management Framework (PMF) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition