Cross-Framework Mapping

GDPRvsISO 27001:2022

See exactly how GDPR controls map to ISO 27001:2022. Pre-computed mappings, identified gaps, and coverage analysis.

79
Controls Mapped
0
Gaps Found
45%
Coverage

According to the TheArtOfService Compliance Knowledge Graph:

GDPR maps to ISO 27001:2022 with 45% coverage across 20 directly mapped controls. Analysis of 44 GDPR controls identifies 24 compliance gaps — primarily concentrated in Chapter III - Rights of the Data Subject.

Source: TheArtOfService Knowledge Graph | 44 controls analysed | 693 frameworks | 820K+ cross-framework mappings

Control Mappings

Showing 20 of 79 mapped controls across 3 domains. Sign up to explore all 820K+ mappings across 693 frameworks.

Chapter III - Rights of the Data Subject(5 mappings)

Art. 19Consent Management Controls
ISO27001-A.5.34Personal data and privacy safeguards
GDPR-Art.15Right of access by the data subject
ISO27001-A.5.34Personal data and privacy safeguards
GDPR-Art.17Right to erasure (right to be forgotten)2 targets
ISO27001-A.7.14Secure decommissioning and media sanitisation
ISO27001-A.8.10Controlled data removal and purging
GDPR-Art.19Notification obligation regarding rectification, erasure or restriction
ISO27001-A.5.34Personal data and privacy safeguards

Chapter II - Principles(4 mappings)

GDPR-Art.10Processing of personal data relating to criminal convictions
ISO27001-A.5.34Personal data and privacy safeguards
GDPR-Art.11Processing which does not require identification
ISO27001-A.5.34Personal data and privacy safeguards
GDPR-Art.5Principles relating to processing of personal data
ISO27001-A.5.33Records retention and integrity
GDPR-Art.9Processing of special categories of personal data
ISO27001-A.5.34Personal data and privacy safeguards

Chapter IV - Controller and Processor(11 mappings)

GDPR-Art.24Responsibility of the controller6 targets
ISO27001-A.5.1Information security policy management
ISO27001-A.5.18Access entitlement provisioning and review
ISO27001-A.5.2Security roles and accountability assignments
ISO27001-A.5.31Legal and regulatory obligation tracking
ISO27001-A.5.4Management accountability for security
ISO27001-ISMS-6.1Cl. 6.1 Information security risk assessment — planning actions to address risks and opportunities in the ISMS
GDPR-Art.25Data protection by design and by default5 targets
ISO27001-A.5.18Access entitlement provisioning and review
ISO27001-A.5.8Security integration in project delivery
ISO27001-A.8.11Sensitive data obfuscation techniques
ISO27001-A.8.19Controlled software deployment to production
ISO27001-A.8.27Secure architecture and design principles

+59 more mappings

Plus AI-powered gap analysis, compliance advisory, PDF exports, and cross-mapping for all 693 frameworks.

Create Free Account →

Free forever — no credit card required

Stop Paying Consultants to Read Spreadsheets

AI-powered compliance intelligence across 693 frameworks — at a fraction of consulting costs.

$0/forever

Free

  • 693 framework browser
  • Cross-framework mappings (820K+)
  • 824 compliance assessments
  • 3 AI queries & searches per day
Get Started Free
Recommended
$49/month

Professional

  • Unlimited AI Compliance Advisory
  • Unlimited full-text search
  • Framework self-assessment
  • PDF, Excel & CSV exports
Start 7-Day Free Trial →

What are the key differences between GDPR and ISO 27001:2022?

GDPR has 44 controls across its framework, while ISO 27001:2022 covers 95 controls. Direct mapping analysis identifies 20 overlapping controls (45% coverage). The frameworks diverge most significantly in Chapter III - Rights of the Data Subject, where 13 GDPR controls have no direct ISO 27001:2022 equivalent.

How many controls map between GDPR and ISO 27001:2022?

Of 44 total GDPR controls, 20 map directly to ISO 27001:2022 controls — representing 45% coverage. The remaining 24 controls represent compliance gaps requiring additional documentation or compensating controls to satisfy both frameworks simultaneously.

What are the compliance gaps when mapping GDPR to ISO 27001:2022?

24 GDPR controls have no direct equivalent in ISO 27001:2022. The highest concentration of gaps is in Chapter III - Rights of the Data Subject with 13 unmapped controls. These gaps represent areas where additional controls, policies, or documentation must be created to achieve compliance with both frameworks.

Which control domains have the most gaps between GDPR and ISO 27001:2022?

The domain with the highest gap count is Chapter III - Rights of the Data Subject (13 gaps). Export the full domain-by-domain gap breakdown via the Professional tier to generate a prioritised remediation roadmap.

This platform provides educational compliance tools, not legal, regulatory, or professional compliance advice. Cross-framework mappings are AI-assisted interpretations and do not reproduce or replace official standards. Framework names and trademarks belong to their respective owners. Consult qualified professionals for your specific compliance requirements. See our Terms of Service.