Framework overlap

Does NIST AI Risk Management Framework (AI RMF 1.0) cover Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019)?

You hold NIST AI Risk Management Framework (AI RMF 1.0) and have been told to do Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019). Here is how much overlaps, control by control.

12% of Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) you already have

NIST AI Risk Management Framework (AI RMF 1.0) already covers about 12% of Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019), leaving 22 of 25 controls as genuinely new work.

Already covered 1 Likely covered 2 New work 22

What is genuinely new work

Nothing in NIST AI Risk Management Framework (AI RMF 1.0) reaches these. This is the list to scope.

EPDPA-2
Specifications for Application (§2)
EPDPA-3
Application of Administrative Procedure Act (§3)
EST-IKS-§1
Scope of regulation of the Act
EST-IKS-§10
Processing of personal data in connection with violation of an obligation
EST-IKS-§11
Processing of personal data in public places (CCTV)
EST-IKS-§12-13
Application of the Law Enforcement chapter and terms
EST-IKS-§2
Specifications for application of the Act and Regulation (EU) 2016/679
EST-IKS-§22-28
Rights of data subjects in law enforcement processing
EST-IKS-§29-39
Obligations of controllers and processors in law enforcement processing
EST-IKS-§3
Application of the Administrative Procedure Act
EST-IKS-§4
Processing for journalistic purposes (GDPR Art.85 derogation)
EST-IKS-§40-42
Data Protection Specialist for law enforcement processing
EST-IKS-§43-45
Security measures and breach notification in law enforcement processing
EST-IKS-§46-50
Transmission of personal data to third countries and international organisations
EST-IKS-§5
Processing for academic, artistic and literary expression
EST-IKS-§51-55
Formation of the Estonian Data Protection Inspectorate and Head appointment
EST-IKS-§56-61
Exercise of state and administrative supervision by the Inspectorate
EST-IKS-§62-73
Violations, proceedings and penalties
EST-IKS-§7
Processing for archiving in the public interest
EST-IKS-§74-76
Register, repeal and entry into force
EST-IKS-§8
Processing of children's personal data for information society services
EST-IKS-§9
Processing of personal data after death of the data subject
Show the 3 you already have
EPDPA-1
Scope of Regulation (§1)
EST-IKS-§14-21
Principles of processing by law enforcement authorities
EST-IKS-§6
Processing for scientific and historical research and official statistics

How this is calculated

Already covered means a mapping runs from a control in NIST AI Risk Management Framework (AI RMF 1.0) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair · Today's edition