Regulation

EU GDPR

EU GDPR — General Data Protection Regulation

16 requirements · 15 connected unified controls

Open EU GDPR in the map
Version
Regulation (EU) 2016/679
Published
2016-05-04
Effective
2018-05-25
Amendments
none

Requirements and control mappings

“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.

EU GDPR

RequirementUnified control and mapping
GDPR-Art5Principles relating to processing of personal data
UC-GOV-26 — Enforce personal-data processing principles and minimizationPartial

Remaining requirement: operational enforcement of principles sits in data-protection, retention, and security controls

GDPR-Art6Lawfulness of processing
GDPR-Art7Conditions for consent
GDPR-Art9Processing of special categories of data
GDPR-Art12-14Transparency and information to data subjects
UC-DATA-05 — Provide privacy notices and transparency to data subjectsPartial

Remaining requirement: controller/DPO identity, complaint right, transfer info, automated-decision disclosures, Art 14 source omitted

GDPR-Art15-22Data subject rights (access, rectification, erasure, portability, objection, automated decisions)
UC-DATA-08 — Execute deletion and other rights requests within deadlinesPartial

Remaining requirement: Art 22 standing automated-decision prohibition and Art 19 recipient notification exceed request handling

GDPR-Art24Responsibility of the controller
UC-GOV-25 — Operate a privacy program with accountable leadershipPartial

Remaining requirement: implementing operational technical and organisational protection measures across all processing

GDPR-Art25Data protection by design and by default
UC-CONFIG-04 — Build security and privacy into software design and upkeepPartial

Remaining requirement: Art.25(2) data-protection-by-default applies organization-wide beyond software design; this control covers the by-design engineering arm

GDPR-Art28Processor obligations and data processing agreements
GDPR-Art30Records of processing activities (RoPA)
GDPR-Art32Security of processing
UC-ACCESS-05 — Enforce approved authorizations for information and functionsPartial

Remaining requirement: also requires encryption, resilience, and effectiveness testing addressed in other domains

GDPR-Art33Notification of a personal data breach to the supervisory authority
GDPR-Art34Communication of a breach to the data subject
GDPR-Art35Data protection impact assessment (DPIA)
GDPR-Art37-39Designation and tasks of the Data Protection Officer
UC-GOV-25 — Operate a privacy program with accountable leadershipPartial

Remaining requirement: DPO contact details must be published and communicated to the supervisory authority

GDPR-Art44-49International transfers of personal data