75% of Minnesota Consumer Data Privacy Act you already have
ISO 27043 already covers about 75% of Minnesota Consumer Data Privacy Act, leaving
2 of 8 controls as genuinely new work.
Already covered 2
Likely covered 4
New work 2
What is genuinely new work
Nothing in ISO 27043 reaches these. This is the list to scope.
MN-CDPA-Privacy-Notice-Section-325O-05-Categories-Purposes-Rights-Email-Online-Mechanism-AppealMinnesota CDPA Privacy Notice + Section 325O.05 + Categories + Purposes + Rights + Email + Online + Appeal
MN-CDPA-Scope-HF-1367-Chapter-325O-Walz-24-May-2024-Effective-31-July-2025-AG-Ellison-100K-25K-ThresholdMinnesota CDPA Scope + HF 1367 + Chapter 325O + Walz + 24 May 2024 + Effective 31 July 2025 + AG Ellison + 100K/25K
Show the 6 you already have
MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-TrainingMinnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training
MN-CDPA-Universal-Opt-Out-GPC-Sensitive-Data-Section-325O-02-Consumer-Health-Data-Children-Known-Child-TransgenderMinnesota CDPA Universal Opt-Out + GPC + Sensitive + Section 325O.02 + Consumer Health Data + Children + Known Child + Transgender
MN-CDPA-Consumer-Rights-Section-325O-04-Access-Correct-Delete-Portability-List-Third-Parties-Opt-Out-Appeal-AIQUEST-ProfileMinnesota CDPA Consumer Rights + Section 325O.04 + Access + Correct + Delete + Portability + List of Third Parties + Opt-Out + Appeal + AI Question Profile
MN-CDPA-Data-Privacy-Assessment-DPIA-Section-325O-07-Sensitive-Targeted-Sale-Profiling-AI-Consumer-HealthMinnesota CDPA DPIA + Section 325O.07 + Sensitive + Targeted + Sale + Profiling + AI + Consumer Health
MN-CDPA-Enforcement-AG-Ellison-Section-325O-10-USD-7500-Per-Violation-Data-Broker-Registration-325O-13-Sunset-25-Jan-2026Minnesota CDPA Enforcement + AG Ellison + Section 325O.10 + USD 7,500 Per Violation + Data Broker Registration + Sunset 25 January 2026
MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-IdentificationMinnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification
How this is calculated
Already covered means a mapping runs from a control in ISO 27043 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition