Framework overlap

Does China Personal Information Protection Law (PIPL) cover EU Data Governance Act (DGA)?

You hold China Personal Information Protection Law (PIPL) and have been told to do EU Data Governance Act (DGA). Here is how much overlaps, control by control.

21% of EU Data Governance Act (DGA) you already have

China Personal Information Protection Law (PIPL) already covers about 21% of EU Data Governance Act (DGA), leaving 15 of 19 controls as genuinely new work.

Already covered 0 Likely covered 4 New work 15

No control in China Personal Information Protection Law (PIPL) maps directly to one in EU Data Governance Act (DGA). Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in China Personal Information Protection Law (PIPL) reaches these. This is the list to scope.

DGA-Art.1
Subject matter and scope (Article 1)
DGA-Art.10_11
Data intermediation services and notification (Articles 10-11)
DGA-Art.12
Conditions for providing data intermediation services (Article 12)
DGA-Art.13_14_15
Competent authorities, monitoring and exceptions (Articles 13-15)
DGA-Art.16_17
Data altruism national arrangements and public registers (Articles 16-17)
DGA-Art.18_19
Registration requirements and procedure (Articles 18-19)
DGA-Art.2
Definitions (Article 2)
DGA-Art.22
Rulebook (Article 22)
DGA-Art.26_27_28
Competent authority requirements, complaint and judicial remedy (Articles 26-28)
DGA-Art.29_30
European Data Innovation Board (Articles 29-30)
DGA-Art.32_33
Delegation and committee procedure (Articles 32-33)
DGA-Art.34
Penalties (Article 34)
DGA-Art.35_36_37_38
Evaluation, amendment of (EU) 2018/1724, transitional arrangements and entry into force (Articles 35-38)
DGA-Art.3_4
Categories of public-sector data and prohibition of exclusive arrangements (Articles 3-4)
DGA-Art.7_8_9
Competent bodies, single information points and re-use request procedure (Articles 7-9)
Show the 4 you already have
DGA-Art.20_21
Transparency and safeguarding requirements (Articles 20-21)
DGA-Art.23_24_25
Competent authority + monitoring + European Data Altruism Consent Form (Articles 23-25)
DGA-Art.31
International access and transfer (Article 31)
DGA-Art.5_6
Conditions for re-use and fees (Articles 5-6)

How this is calculated

Already covered means a mapping runs from a control in China Personal Information Protection Law (PIPL) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition