Framework overlap

Does China Personal Information Protection Law (PIPL) cover Connecticut Data Privacy Act (CTDPA)?

You hold China Personal Information Protection Law (PIPL) and have been told to do Connecticut Data Privacy Act (CTDPA). Here is how much overlaps, control by control.

50% of Connecticut Data Privacy Act (CTDPA) you already have

China Personal Information Protection Law (PIPL) already covers about 50% of Connecticut Data Privacy Act (CTDPA), leaving 13 of 26 controls as genuinely new work.

Already covered 0 Likely covered 13 New work 13

No control in China Personal Information Protection Law (PIPL) maps directly to one in Connecticut Data Privacy Act (CTDPA). Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in China Personal Information Protection Law (PIPL) reaches these. This is the list to scope.

CTDPA-42-516-EXEMPT
Entity and Data Exemptions
CTDPA-42-518-AUTHAGENT
Authorized Agents
CTDPA-42-518-CORRECT
Right to Correct
CTDPA-42-518-PORT
Right to Data Portability
CTDPA-42-518-RESPONSE
Response Timeline and Appeal
CTDPA-42-518-UOOM
Universal Opt-Out Mechanism
CTDPA-42-520-NONDISCRIM
Non-Discrimination
CTDPA-42-520-PRIVNOTICE
Privacy Notice
CTDPA-42-520-SECURITY
Reasonable Security Practices
CTDPA-42-521-DEIDENT
De-identified and Pseudonymous Data
CTDPA-42-525-AGENFORCE
Exclusive Attorney General Enforcement
CTDPA-42-525-CURE
Cure Period (Sunset 31 Dec 2024)
CTDPA-42-525-GEOFENCE
Geofencing Prohibition Near Health Facilities (PA 23-56)
Show the 13 you already have
CTDPA-42-516
Applicability Thresholds
CTDPA-42-518-ACCESS
Right to Confirm and Access
CTDPA-42-518-DELETE
Right to Delete
CTDPA-42-518-OPTOUT
Right to Opt Out
CTDPA-42-520-CHILDREN
Children's and Minors' Data
CTDPA-42-520-CONSENTREVOKE
Consent and Revocation (No Dark Patterns)
CTDPA-42-520-PURPLIMIT
Purpose Limitation and Data Minimization
CTDPA-42-520-SALEDISC
Sale and Targeted-Advertising Disclosure
CTDPA-42-520-SECONDARY
No Secondary Use Without Consent
CTDPA-42-520-SENSITIVE
Sensitive Data Opt-In Consent
CTDPA-42-521-PROCESSOR
Processor Obligations and Contracts
CTDPA-42-522-DPA
Data Protection Assessments
CTDPA-42-525-CHD
Consumer Health Data (PA 23-56)

How this is calculated

Already covered means a mapping runs from a control in China Personal Information Protection Law (PIPL) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition