63% of Privacy Act 2020 you already have
ISO 13485 already covers about 63% of Privacy Act 2020, leaving
3 of 8 controls as genuinely new work.
Already covered 3
Likely covered 2
New work 3
What is genuinely new work
Nothing in ISO 13485 reaches these. This is the list to scope.
NZPRV-1IPP 1-4 Purpose, Source, Collection from Subject, Manner of Collection
NZPRV-3IPP 6-8 Access, Correction, Accuracy
NZPRV-4IPP 9-10 Retention, Limits on Use
Show the 5 you already have
NZPRV-2IPP 5 Storage and Security of Personal Information
NZPRV-6IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
NZPRV-8Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training
NZPRV-5IPP 11-12 Disclosure, Cross-Border Disclosure (Schedule 8)
NZPRV-7Notifiable Privacy Breach Scheme
How this is calculated
Already covered means a mapping runs from a control in ISO 13485 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition