Framework overlap

Does Code of Conduct on Data Protection for Research (GDPR Article 40) cover Chile Personal Data Protection Law (Law No. 21.719)?

You hold Code of Conduct on Data Protection for Research (GDPR Article 40) and have been told to do Chile Personal Data Protection Law (Law No. 21.719). Here is how much overlaps, control by control.

47% of Chile Personal Data Protection Law (Law No. 21.719) you already have

Code of Conduct on Data Protection for Research (GDPR Article 40) already covers about 47% of Chile Personal Data Protection Law (Law No. 21.719), leaving 16 of 30 controls as genuinely new work.

Already covered 0 Likely covered 14 New work 16

No control in Code of Conduct on Data Protection for Research (GDPR Article 40) maps directly to one in Chile Personal Data Protection Law (Law No. 21.719). Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in Code of Conduct on Data Protection for Research (GDPR Article 40) reaches these. This is the list to scope.

CL21719-A14quater
Privacy by Design and by Default (Art. 14 quater)
CL21719-A14ter
Lawfulness Documentation and Transparency (Art. 14 ter)
CL21719-A15bis
Records of Processing Activities (Art. 15 bis)
CL21719-A17
Credit and Financial Data (Art. 17-18)
CL21719-A26
Certification and Compliance Models (Art. 26)
CL21719-A36
Personal Data Protection Agency (Art. 30/36)
CL21719-A45
Sanctions Regime (Art. 34 quinquies / Art. 45)
CL21719-A49
Data Protection Officer (Art. 49)
CL21719-A50
Effective Date and Transition
CL21719-A5a
Right of Access (Art. 5 lit a)
CL21719-A5b
Right of Rectification (Art. 5 lit b)
CL21719-A5c
Right of Cancellation/Erasure (Art. 5 lit c)
CL21719-A5d
Right of Opposition (Art. 5 lit d)
CL21719-A5e
Right of Portability (Art. 5 lit e)
CL21719-A8bis
Rights Regarding Automated Decisions (Art. 8 bis)
CL21719-A8ter
Right to Block Processing (Art. 8 ter)
Show the 14 you already have
CL21719-A12
Lawful Bases for Processing (Art. 12)
CL21719-A14
Consent (Art. 13-14)
CL21719-A14quinquies
Security of Processing (Art. 14 quinquies)
CL21719-A14sexies
Breach Notification (Art. 14 sexies)
CL21719-A15
Processor Obligations and Contracts (Art. 15)
CL21719-A15ter
Data Protection Impact Assessment (Art. 15 ter)
CL21719-A16
Sensitive Personal Data (Art. 16)
CL21719-A16bis
Health Data (Art. 16 bis)
CL21719-A16quater
Children's Data (Art. 16 quater)
CL21719-A16ter
Biometric Data (Art. 16 ter)
CL21719-A27
International Data Transfers (Art. 27-28 bis)
CL21719-A28
Adequacy Determinations (Art. 28)
CL21719-A3
Definitions and Scope (Art. 1-3)
CL21719-A4
Principles of Processing (Art. 3-4)

How this is calculated

Already covered means a mapping runs from a control in Code of Conduct on Data Protection for Research (GDPR Article 40) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition