50% of Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) you already have
ISO/IEC 23894:2023 already covers about 50% of Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018), leaving
4 of 8 controls as genuinely new work.
Already covered 0
Likely covered 4
New work 4
No control in ISO/IEC 23894:2023
maps directly to one in Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018). Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in ISO/IEC 23894:2023 reaches these. This is the list to scope.
ICELAND-Act90-Chap1-Scope-Definitions-EEA-GDPR-PersonuverndIceland Act No. 90/2018 - Chapter I Scope + Definitions + EEA Agreement + GDPR Application + Personuvernd Authority
ICELAND-Act90-Chap2-Principles-LawfulBasis-Consent-Sensitive-CriminalIceland Act 90/2018 - Chapter II Principles + Lawful Basis + Consent + Special Categories + Criminal Data (Articles 8-13)
ICELAND-Act90-Chap6-Personuvernd-Enforcement-AdminFines-AAB-Appeals-CriminalPenaltiesIceland Act 90/2018 - Chapter VI Personuvernd Authority + Investigation + Administrative Fines + Penal Code Section 228 + Court Appeals
ICELAND-Act90-Sectoral-Employment-Children-DirectMarketing-AutomatedDecisions-CookiesIceland Act 90/2018 - Sectoral - Employment + Children + Direct Marketing + Automated Decisions + Cookies + Cybersecurity
Show the 4 you already have
ICELAND-Act90-Chap3-Transparency-DataSubjectRights-Access-Rectification-ErasureIceland Act 90/2018 - Chapter III Transparency + Data Subject Rights (Articles 14-23) - Access + Rectification + Erasure + Portability + Object + Automated Decisions
ICELAND-Act90-Chap4-ControllerObligations-PrivacyByDesign-Processor-RoPA-DPOIceland Act 90/2018 - Chapter IV Controller Obligations + Privacy by Design + Processor + RoPA + DPO (Articles 24-26 + 35)
ICELAND-Act90-Chap4-Security-BreachNotification-DPIA-Personuvernd-72hrIceland Act 90/2018 - Chapter IV Security of Processing + Breach Notification + DPIA (Articles 27-29)
ICELAND-Act90-Chap5-CrossBorder-EEA-AdequacyDecisions-SCC-BCRIceland Act 90/2018 - Chapter V Cross-Border Transfer of Personal Data + EEA + Adequacy + SCCs + BCRs + Article 30 Privacy Policy
How this is calculated
Already covered means a mapping runs from a control in ISO/IEC 23894:2023 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition