50% of Connecticut Data Privacy Act (CTDPA) you already have
China Personal Information Protection Law (PIPL) already covers about 50% of Connecticut Data Privacy Act (CTDPA), leaving
13 of 26 controls as genuinely new work.
Already covered 0
Likely covered 13
New work 13
No control in China Personal Information Protection Law (PIPL)
maps directly to one in Connecticut Data Privacy Act (CTDPA). Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in China Personal Information Protection Law (PIPL) reaches these. This is the list to scope.
CTDPA-42-516-EXEMPTEntity and Data Exemptions
CTDPA-42-518-AUTHAGENTAuthorized Agents
CTDPA-42-518-CORRECTRight to Correct
CTDPA-42-518-PORTRight to Data Portability
CTDPA-42-518-RESPONSEResponse Timeline and Appeal
CTDPA-42-518-UOOMUniversal Opt-Out Mechanism
CTDPA-42-520-NONDISCRIMNon-Discrimination
CTDPA-42-520-PRIVNOTICEPrivacy Notice
CTDPA-42-520-SECURITYReasonable Security Practices
CTDPA-42-521-DEIDENTDe-identified and Pseudonymous Data
CTDPA-42-525-AGENFORCEExclusive Attorney General Enforcement
CTDPA-42-525-CURECure Period (Sunset 31 Dec 2024)
CTDPA-42-525-GEOFENCEGeofencing Prohibition Near Health Facilities (PA 23-56)
Show the 13 you already have
CTDPA-42-516Applicability Thresholds
CTDPA-42-518-ACCESSRight to Confirm and Access
CTDPA-42-518-DELETERight to Delete
CTDPA-42-518-OPTOUTRight to Opt Out
CTDPA-42-520-CHILDRENChildren's and Minors' Data
CTDPA-42-520-CONSENTREVOKEConsent and Revocation (No Dark Patterns)
CTDPA-42-520-PURPLIMITPurpose Limitation and Data Minimization
CTDPA-42-520-SALEDISCSale and Targeted-Advertising Disclosure
CTDPA-42-520-SECONDARYNo Secondary Use Without Consent
CTDPA-42-520-SENSITIVESensitive Data Opt-In Consent
CTDPA-42-521-PROCESSORProcessor Obligations and Contracts
CTDPA-42-522-DPAData Protection Assessments
CTDPA-42-525-CHDConsumer Health Data (PA 23-56)
How this is calculated
Already covered means a mapping runs from a control in China Personal Information Protection Law (PIPL) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition