Framework overlap

Does BSI IT-Grundschutz cover Indiana Consumer Data Protection Act?

You hold BSI IT-Grundschutz and have been told to do Indiana Consumer Data Protection Act. Here is how much overlaps, control by control.

75% of Indiana Consumer Data Protection Act you already have

BSI IT-Grundschutz already covers about 75% of Indiana Consumer Data Protection Act, leaving 2 of 8 controls as genuinely new work.

Already covered 2 Likely covered 4 New work 2

What is genuinely new work

Nothing in BSI IT-Grundschutz reaches these. This is the list to scope.

INCDPA-Coord-USStatePrivacy-VCDPA-CPA-CTDPA-CCPA-Federal-FTC-DPDP-GDPR-International
Indiana CDPA Coordination - US State Privacy Laws (Virginia/Colorado/Connecticut/Utah/Texas/Iowa+) + Federal Sectoral (HIPAA/GLBA/FCRA/FERPA/COPPA) + FTC Section 5 + GDPR + India D
INCDPA-Scope-SEA5-2023-Effective-1Jan2026-IC-24-15-Applicability-100K-25K-50pct-Exemptions
Indiana CDPA Scope + Senate Enrolled Act 5 of 2023 + Effective 1 January 2026 + IC 24-15 + Applicability Thresholds + Exemptions GLBA/HIPAA/FCRA/FERPA + B2B/Employee Carve-Outs
Show the 6 you already have
INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation
Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification
INCDPA-SensitiveData-Children-Consent-COPPA-DataProtectionAssessment-DPIA
Indiana CDPA Sensitive Data + Consent for Sensitive Categories + Children Under 13 + COPPA Coordination + Data Protection Assessment (DPA) + High-Risk Processing
INCDPA-ConsumerRights-Access-Correction-Deletion-Portability-OptOut-TargetedAd-Sale-Profiling-Appeal-45Day
Indiana CDPA Consumer Rights - Access + Correction + Deletion + Portability + Opt-Out of Targeted Advertising/Sale/Profiling + 45-Day Response + 45-Day Extension + Authorised Agent
INCDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Transparency-LawfulBasis
Indiana CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Transparency + Lawful Basis + Reasonable + Adequate + Relevant + Limited to What is
INCDPA-Enforcement-30DayCure-AttorneyGeneralOnly-NoPrivateRight-CivilPenalties-7500-PerViolation
Indiana CDPA Enforcement - Attorney General Exclusive + 30-Day Cure Period + No Private Right of Action + Civil Penalties Up to USD 7500 Per Violation + Investigation + Compliance
INCDPA-Processor-Contracts-DPA-Subprocessor-Audit-Confidentiality-EndOfContract
Indiana CDPA Processor Contracts - Data Processing Agreement (DPA) + Required Provisions + Subprocessor Approval + Confidentiality + End of Contract Deletion + Audit Rights + Assis

How this is calculated

Already covered means a mapping runs from a control in BSI IT-Grundschutz to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition