GDPR to CCPA/CPRA control mapping
GDPR and CCPA/CPRA both map to 50 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.
- Shared NIST 800-53 controls
- 50
- GDPR controls involved
- 46
- CCPA/CPRA controls involved
- 222
- NIST 800-53 families touched
- 20
How this pairing is derived
Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored GDPR to CCPA/CPRA crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.
Shared controls in full
| NIST 800-53 control | Family | GDPR controls | CCPA/CPRA controls |
|---|---|---|---|
| AC-1Policy and Procedures | ACAccess Control | Art 24.2 | 7123(b)(1), 7123(c)(1), 7123(c)(3), 7123(c)(3)(C) |
| AC-2(7)Privileged User Accounts | ACAccess Control | Art 32.4 | 7123(c)(3)(A), 7123(c)(3)(A)(i), 7123(c)(3)(A)(ii), 7123(c)(3)(A)(iii), 7123(c)(3)(B) |
| AC-3(14)Individual Access | ACAccess Control | Art 12.3, Art 12.5, Art 12.6, Art 15.1, Art 15.2, Art 15.3, Art 15.4, Art 16, Art 17.1, Art 18.1 | 7020(a), 7020(b), 7020(c), 7020(d), 7020(e), 7020(f), 7020(f)(1), 7020(f)(2), 7022(b), 7023(c), 7023(d)(1), 7024(g), 7024(h), 7024(j), 7027(d), 7027(e) |
| AT-1Policy and Procedures | ATAwareness and Training | Art 24.2 | 7123(b)(1), 7123(c)(12) |
| AU-1Policy and Procedures | AUAudit and Accountability | Art 24.2 | 7123(b)(1), 7123(c)(7) |
| CA-1Policy and Procedures | CAAssessment, Authorization, and Monitoring | Art 24.2 | 7123(b)(1), 7123(c)(4)(C) |
| CA-7Continuous Monitoring | CAAssessment, Authorization, and Monitoring | Art 32.1 | 7122(a)(3), 7122(f) |
| CA-7(1)Independent Assessment | CAAssessment, Authorization, and Monitoring | Art 32.1 | 7122(a)(2), 7122(a)(3), 7122(f) |
| CM-1Policy and Procedures | CMConfiguration Management | Art 24.2 | 7123(b)(1), 7123(c)(11), 7123(c)(4)(B), 7123(c)(5) |
| CP-1Policy and Procedures | CPContingency Planning | Art 24.2, Art 32.1 | 7123(b)(1), 7123(c)(18) |
| CP-2Contingency Plan | CPContingency Planning | Art 32.1 | 7123(c)(18) |
| CP-10System Recovery and Reconstitution | CPContingency Planning | Art 32.1 | 7123(c)(18) |
| IA-1Policy and Procedures | IAIdentification and Authentication | Art 24.2 | 7123(b)(1), 7123(c)(1), 7123(c)(3), 7123(c)(3)(C) |
| IR-1Policy and Procedures | IRIncident Response | Art 24.2 | 7123(b)(1), 7123(c)(17), 7123(c)(17)(B) |
| IR-4(3)Continuity of Operations | IRIncident Response | Art 32.1 | 7123(c)(17)(A), 7123(c)(18) |
| MA-1Policy and Procedures | MAMaintenance | Art 24.2 | 7123(b)(1) |
| PE-1Policy and Procedures | PEPhysical and Environmental Protection | Art 24.2 | 7123(b)(1), 7123(c)(3)(D) |
| PL-1Policy and Procedures | PLPlanning | Art 24.2 | 7013(h), 7022(d), 7023(e), 7050(b), 7072(b), 7123(b)(1), 7123(b)(3), 7123(c)(14), 7200(a), 7200(b) |
| RA-1Policy and Procedures | RARisk Assessment | Art 24.2, Art 32.2 | 7123(b)(1) |
| RA-8Privacy Impact Assessments | RARisk Assessment | Art 35.1, Art 35.11, Art 35.3, Art 35.7, Art 35.8, Art 35.9, Art 36.1 | 7152(a), 7152(a)(1), 7152(a)(2), 7152(a)(3), 7152(a)(3)(A), 7152(a)(3)(B), 7152(a)(3)(C), 7152(a)(3)(D), 7152(a)(3)(E), 7152(a)(3)(F), 7152(a)(3)(G), 7152(a)(3)(G)(i), 7152(a)(3)(G)(ii), 7152(a)(4), 7152(a)(5), 7152(a)(5)(A), 7152(a)(5)(B), 7152(a)(5)(C), 7152(a)(5)(D), 7152(a)(5)(E), 7152(a)(5)(F), 7152(a)(5)(G), 7152(a)(5)(H), 7152(a)(6), 7152(a)(6)(A), 7152(a)(6)(A)(i), 7152(a)(6)(A)(ii), 7152(a)(6)(A)(iii), 7152(a)(6)(A)(iv), 7152(a)(7), 7152(a)(8), 7152(a)(9), 7154(a), 7155(a), 7156(a), 7156(b) |
| SA-1Policy and Procedures | SASystem and Services Acquisition | Art 24.2 | 7123(b)(1), 7123(c)(14) |
| SC-1Policy and Procedures | SCSystem and Communications Protection | Art 24.2 | 7123(b)(1), 7123(c)(5)(B), 7123(c)(8), 7123(c)(8)(A) |
| SC-8(1)Cryptographic Protection | SCSystem and Communications Protection | Art 32.1 | 7123(c)(2) |
| SC-8(2)Pre- and Post-transmission Handling | SCSystem and Communications Protection | Art 32.1 | 7123(c)(2) |
| SC-13Cryptographic Protection | SCSystem and Communications Protection | Art 32.1 | 7123(c)(2) |
| SI-1Policy and Procedures | SISystem and Information Integrity | Art 24.2 | 7123(b)(1), 7123(c)(5)(B) |
| SI-7(6)Cryptographic Protection | SISystem and Information Integrity | Art 32.1 | 7123(c)(2) |
| SI-12Information Management and Retention | SISystem and Information Integrity | Art 5.1 | 7122(g), 7123(c)(16), 7155(c) |
| SI-18(4)Individual Requests | SISystem and Information Integrity | Art 12.3, Art 12.5, Art 12.6, Art 15.1, Art 15.2, Art 15.3, Art 15.4, Art 16, Art 17.1, Art 18.1 | 7020(a), 7020(b), 7020(c), 7020(d), 7020(e), 7020(f), 7020(f)(1), 7020(f)(2), 7022(b), 7023(a), 7023(b), 7023(c), 7023(d)(1), 7023(d)(2), 7024(g), 7024(h), 7024(j), 7027(d), 7027(e) |
| MP-1Policy and Procedures | MPMedia Protection | Art 24.2 | 7123(b)(1) |
| PS-1Policy and Procedures | PSPersonnel Security | Art 24.2 | 7123(b)(1) |
| PS-2Position Risk Designation | PSPersonnel Security | Art 32.4 | 7123(c)(3)(B) |
| PM-1Information Security Program Plan | PMProgram Management | Art 24.2 | 7123(b)(1) |
| PM-8Critical Infrastructure Plan | PMProgram Management | Art 32.1 | 7013(h), 7022(d), 7023(e), 7050(b), 7072(b), 7123(b)(3), 7123(c)(18), 7200(a), 7200(b) |
| PM-13Security and Privacy Workforce | PMProgram Management | Art 32.4 | 7123(c)(12) |
| PM-14Testing, Training, and Monitoring | PMProgram Management | Art 32.1 | 7122(a)(3), 7122(f) |
| PM-18Privacy Program Plan | PMProgram Management | Art 12.2, Art 5.1, Art 9.1 | 7002(a) |
| PM-20(1)Privacy Policies on Websites, Applications, and Digital Services | PMProgram Management | Art 12.7, Art 13.1, Art 13.2, Art 13.3, Art 14.1, Art 14.2, Art 14.3, Art 14.4, Art 14.5 | 7002(b)(5), 7003(a), 7004(a)(1), 7010(a), 7011(a), 7011(b), 7011(c), 7011(d), 7011(e), 7011(e)(1), 7011(e)(1)(A), 7011(e)(1)(B), 7011(e)(1)(C), 7011(e)(1)(D), 7011(e)(1)(E), 7011(e)(1)(F), 7011(e)(1)(G), 7011(e)(1)(H), 7011(e)(1)(I), 7011(e)(1)(J), 7011(e)(2), 7011(e)(2)(A), 7011(e)(2)(B), 7011(e)(2)(C), 7011(e)(2)(D), 7011(e)(2)(E), 7011(e)(2)(F), 7011(e)(2)(G), 7011(e)(2)(H), 7011(e)(3), 7011(e)(3)(A), 7011(e)(3)(B), 7011(e)(3)(C), 7011(e)(3)(D), 7011(e)(3)(E), 7011(e)(3)(F), 7011(e)(3)(G), 7011(e)(3)(H), 7011(e)(3)(I), 7011(e)(3)(J), 7011(e)(4), 7011(e)(5), 7012(f), 7012(g)(1), 7013(c), 7013(e), 7013(e)(1), 7013(e)(2), 7013(e)(3), 7013(g)(2), 7014(b), 7014(c), 7014(d), 7014(e)(1), 7014(e)(2), 7014(e)(3), 7014(g)(1), 7014(g)(2), 7014(h), 7025(g)(2), 7025(g)(2)(A), 7025(g)(2)(B), 7025(g)(2)(C), 7025(g)(2)(D), 7072(a) |
| PM-24Data Integrity Board | PMProgram Management | Art 5.1 | 7023(c) |
| PM-26Complaint Management | PMProgram Management | Art 12.4 | 7021(a), 7021(b), 7022(e), 7022(f), 7022(f)(1), 7023(a), 7023(d)(1), 7023(d)(2)(A), 7023(d)(2)(B), 7023(d)(2)(C), 7023(d)(2)(D), 7023(f)(1), 7023(f)(2), 7023(f)(3), 7023(f)(4), 7023(i), 7023(j), 7023(k), 7024(c), 7024(c)(1), 7024(c)(2), 7024(c)(3), 7024(c)(4), 7024(d), 7024(d)(1), 7024(d)(2), 7024(e), 7024(e)(1), 7024(e)(2), 7024(k), 7024(k)(1), 7024(k)(2), 7024(k)(3), 7024(k)(4), 7024(k)(5), 7024(k)(6), 7027(h), 7027(k) |
| PM-29Risk Management Program Leadership Roles | PMProgram Management | Art 32.2 | 7123(b)(3) |
| PT-1Policy and Procedures | PTPII Processing and Transparency | Art 12.2, Art 24.2, Art 5.1, Art 9.1 | 7002(a), 7123(b)(1), 7123(c)(5)(B) |
| PT-2Authority to Process Personally Identifiable Information | PTPII Processing and Transparency | Art 10, Art 5.1, Art 8.1, Art 9.2, Art 9.3 | 7002(f), 7023(d)(3), 7026(f), 7026(f)(1), 7027(a) |
| PT-3Personally Identifiable Information Processing Purposes | PTPII Processing and Transparency | Art 13.1, Art 14.1 | 7002(a)(1), 7002(a)(2), 7002(b)(4), 7027(m) |
| PT-4Consent | PTPII Processing and Transparency | Art 21.1, Art 21.2, Art 21.3, Art 21.4, Art 21.5, Art 21.6, Art 7.1, Art 7.2, Art 9.2 | 7002(e), 7010(b), 7012(a), 7012(b), 7012(c), 7012(d), 7012(e), 7012(e)(1), 7012(e)(2), 7012(e)(3), 7012(e)(4), 7012(e)(5), 7012(e)(6), 7027(c), 7027(d) |
| PT-5Privacy Notice | PTPII Processing and Transparency | Art 12.7, Art 13.1, Art 13.2, Art 13.3, Art 14.1, Art 14.2, Art 14.3, Art 14.4, Art 14.5 | 7002(b)(5), 7003(a), 7004(a)(1), 7010(a), 7011(a), 7011(b), 7011(c), 7011(d), 7011(e), 7011(e)(1), 7011(e)(1)(A), 7011(e)(1)(B), 7011(e)(1)(C), 7011(e)(1)(D), 7011(e)(1)(E), 7011(e)(1)(F), 7011(e)(1)(G), 7011(e)(1)(H), 7011(e)(1)(I), 7011(e)(1)(J), 7011(e)(2), 7011(e)(2)(A), 7011(e)(2)(B), 7011(e)(2)(C), 7011(e)(2)(D), 7011(e)(2)(E), 7011(e)(2)(F), 7011(e)(2)(G), 7011(e)(2)(H), 7011(e)(3), 7011(e)(3)(A), 7011(e)(3)(B), 7011(e)(3)(C), 7011(e)(3)(D), 7011(e)(3)(E), 7011(e)(3)(F), 7011(e)(3)(G), 7011(e)(3)(H), 7011(e)(3)(I), 7011(e)(3)(J), 7011(e)(4), 7011(e)(5), 7012(f), 7012(g)(1), 7013(c), 7013(e), 7013(e)(1), 7013(e)(2), 7013(e)(3), 7013(g)(2), 7014(b), 7014(c), 7014(d), 7014(e)(1), 7014(e)(2), 7014(e)(3), 7014(g)(1), 7014(g)(2), 7014(h), 7025(g)(2), 7025(g)(2)(A), 7025(g)(2)(B), 7025(g)(2)(C), 7025(g)(2)(D), 7072(a) |
| PT-7Specific Categories of Personally Identifiable Information | PTPII Processing and Transparency | Art 13.1, Art 14.1 | 7023(d)(3), 7024(j), 7024(l), 7026(f), 7026(f)(1), 7027(a) |
| PT-7(1)Social Security Numbers | PTPII Processing and Transparency | Art 13.1, Art 14.1 | 7024(j), 7024(l) |
| PT-7(2)First Amendment Information | PTPII Processing and Transparency | Art 13.1, Art 14.1 | 7024(j), 7024(l) |
| SR-1Policy and Procedures | SRSupply Chain Risk Management | Art 24.2 | 7024(l), 7052(a), 7123(b)(1), 7123(c)(15) |
Source and method
Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.
Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.
Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.