Skip to content

    GDPR to CCPA/CPRA control mapping

    GDPR and CCPA/CPRA both map to 50 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.

    Shared NIST 800-53 controls
    50
    GDPR controls involved
    46
    CCPA/CPRA controls involved
    222
    NIST 800-53 families touched
    20

    How this pairing is derived

    Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored GDPR to CCPA/CPRA crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls mapped by both GDPR and CCPA/CPRA, with the controls on each side that map to them.
    NIST 800-53 controlFamilyGDPR controlsCCPA/CPRA controls
    AC-1Policy and ProceduresACAccess ControlArt 24.27123(b)(1), 7123(c)(1), 7123(c)(3), 7123(c)(3)(C)
    AC-2(7)Privileged User AccountsACAccess ControlArt 32.47123(c)(3)(A), 7123(c)(3)(A)(i), 7123(c)(3)(A)(ii), 7123(c)(3)(A)(iii), 7123(c)(3)(B)
    AC-3(14)Individual AccessACAccess ControlArt 12.3, Art 12.5, Art 12.6, Art 15.1, Art 15.2, Art 15.3, Art 15.4, Art 16, Art 17.1, Art 18.17020(a), 7020(b), 7020(c), 7020(d), 7020(e), 7020(f), 7020(f)(1), 7020(f)(2), 7022(b), 7023(c), 7023(d)(1), 7024(g), 7024(h), 7024(j), 7027(d), 7027(e)
    AT-1Policy and ProceduresATAwareness and TrainingArt 24.27123(b)(1), 7123(c)(12)
    AU-1Policy and ProceduresAUAudit and AccountabilityArt 24.27123(b)(1), 7123(c)(7)
    CA-1Policy and ProceduresCAAssessment, Authorization, and MonitoringArt 24.27123(b)(1), 7123(c)(4)(C)
    CA-7Continuous MonitoringCAAssessment, Authorization, and MonitoringArt 32.17122(a)(3), 7122(f)
    CA-7(1)Independent AssessmentCAAssessment, Authorization, and MonitoringArt 32.17122(a)(2), 7122(a)(3), 7122(f)
    CM-1Policy and ProceduresCMConfiguration ManagementArt 24.27123(b)(1), 7123(c)(11), 7123(c)(4)(B), 7123(c)(5)
    CP-1Policy and ProceduresCPContingency PlanningArt 24.2, Art 32.17123(b)(1), 7123(c)(18)
    CP-2Contingency PlanCPContingency PlanningArt 32.17123(c)(18)
    CP-10System Recovery and ReconstitutionCPContingency PlanningArt 32.17123(c)(18)
    IA-1Policy and ProceduresIAIdentification and AuthenticationArt 24.27123(b)(1), 7123(c)(1), 7123(c)(3), 7123(c)(3)(C)
    IR-1Policy and ProceduresIRIncident ResponseArt 24.27123(b)(1), 7123(c)(17), 7123(c)(17)(B)
    IR-4(3)Continuity of OperationsIRIncident ResponseArt 32.17123(c)(17)(A), 7123(c)(18)
    MA-1Policy and ProceduresMAMaintenanceArt 24.27123(b)(1)
    PE-1Policy and ProceduresPEPhysical and Environmental ProtectionArt 24.27123(b)(1), 7123(c)(3)(D)
    PL-1Policy and ProceduresPLPlanningArt 24.27013(h), 7022(d), 7023(e), 7050(b), 7072(b), 7123(b)(1), 7123(b)(3), 7123(c)(14), 7200(a), 7200(b)
    RA-1Policy and ProceduresRARisk AssessmentArt 24.2, Art 32.27123(b)(1)
    RA-8Privacy Impact AssessmentsRARisk AssessmentArt 35.1, Art 35.11, Art 35.3, Art 35.7, Art 35.8, Art 35.9, Art 36.17152(a), 7152(a)(1), 7152(a)(2), 7152(a)(3), 7152(a)(3)(A), 7152(a)(3)(B), 7152(a)(3)(C), 7152(a)(3)(D), 7152(a)(3)(E), 7152(a)(3)(F), 7152(a)(3)(G), 7152(a)(3)(G)(i), 7152(a)(3)(G)(ii), 7152(a)(4), 7152(a)(5), 7152(a)(5)(A), 7152(a)(5)(B), 7152(a)(5)(C), 7152(a)(5)(D), 7152(a)(5)(E), 7152(a)(5)(F), 7152(a)(5)(G), 7152(a)(5)(H), 7152(a)(6), 7152(a)(6)(A), 7152(a)(6)(A)(i), 7152(a)(6)(A)(ii), 7152(a)(6)(A)(iii), 7152(a)(6)(A)(iv), 7152(a)(7), 7152(a)(8), 7152(a)(9), 7154(a), 7155(a), 7156(a), 7156(b)
    SA-1Policy and ProceduresSASystem and Services AcquisitionArt 24.27123(b)(1), 7123(c)(14)
    SC-1Policy and ProceduresSCSystem and Communications ProtectionArt 24.27123(b)(1), 7123(c)(5)(B), 7123(c)(8), 7123(c)(8)(A)
    SC-8(1)Cryptographic ProtectionSCSystem and Communications ProtectionArt 32.17123(c)(2)
    SC-8(2)Pre- and Post-transmission HandlingSCSystem and Communications ProtectionArt 32.17123(c)(2)
    SC-13Cryptographic ProtectionSCSystem and Communications ProtectionArt 32.17123(c)(2)
    SI-1Policy and ProceduresSISystem and Information IntegrityArt 24.27123(b)(1), 7123(c)(5)(B)
    SI-7(6)Cryptographic ProtectionSISystem and Information IntegrityArt 32.17123(c)(2)
    SI-12Information Management and RetentionSISystem and Information IntegrityArt 5.17122(g), 7123(c)(16), 7155(c)
    SI-18(4)Individual RequestsSISystem and Information IntegrityArt 12.3, Art 12.5, Art 12.6, Art 15.1, Art 15.2, Art 15.3, Art 15.4, Art 16, Art 17.1, Art 18.17020(a), 7020(b), 7020(c), 7020(d), 7020(e), 7020(f), 7020(f)(1), 7020(f)(2), 7022(b), 7023(a), 7023(b), 7023(c), 7023(d)(1), 7023(d)(2), 7024(g), 7024(h), 7024(j), 7027(d), 7027(e)
    MP-1Policy and ProceduresMPMedia ProtectionArt 24.27123(b)(1)
    PS-1Policy and ProceduresPSPersonnel SecurityArt 24.27123(b)(1)
    PS-2Position Risk DesignationPSPersonnel SecurityArt 32.47123(c)(3)(B)
    PM-1Information Security Program PlanPMProgram ManagementArt 24.27123(b)(1)
    PM-8Critical Infrastructure PlanPMProgram ManagementArt 32.17013(h), 7022(d), 7023(e), 7050(b), 7072(b), 7123(b)(3), 7123(c)(18), 7200(a), 7200(b)
    PM-13Security and Privacy WorkforcePMProgram ManagementArt 32.47123(c)(12)
    PM-14Testing, Training, and MonitoringPMProgram ManagementArt 32.17122(a)(3), 7122(f)
    PM-18Privacy Program PlanPMProgram ManagementArt 12.2, Art 5.1, Art 9.17002(a)
    PM-20(1)Privacy Policies on Websites, Applications, and Digital ServicesPMProgram ManagementArt 12.7, Art 13.1, Art 13.2, Art 13.3, Art 14.1, Art 14.2, Art 14.3, Art 14.4, Art 14.57002(b)(5), 7003(a), 7004(a)(1), 7010(a), 7011(a), 7011(b), 7011(c), 7011(d), 7011(e), 7011(e)(1), 7011(e)(1)(A), 7011(e)(1)(B), 7011(e)(1)(C), 7011(e)(1)(D), 7011(e)(1)(E), 7011(e)(1)(F), 7011(e)(1)(G), 7011(e)(1)(H), 7011(e)(1)(I), 7011(e)(1)(J), 7011(e)(2), 7011(e)(2)(A), 7011(e)(2)(B), 7011(e)(2)(C), 7011(e)(2)(D), 7011(e)(2)(E), 7011(e)(2)(F), 7011(e)(2)(G), 7011(e)(2)(H), 7011(e)(3), 7011(e)(3)(A), 7011(e)(3)(B), 7011(e)(3)(C), 7011(e)(3)(D), 7011(e)(3)(E), 7011(e)(3)(F), 7011(e)(3)(G), 7011(e)(3)(H), 7011(e)(3)(I), 7011(e)(3)(J), 7011(e)(4), 7011(e)(5), 7012(f), 7012(g)(1), 7013(c), 7013(e), 7013(e)(1), 7013(e)(2), 7013(e)(3), 7013(g)(2), 7014(b), 7014(c), 7014(d), 7014(e)(1), 7014(e)(2), 7014(e)(3), 7014(g)(1), 7014(g)(2), 7014(h), 7025(g)(2), 7025(g)(2)(A), 7025(g)(2)(B), 7025(g)(2)(C), 7025(g)(2)(D), 7072(a)
    PM-24Data Integrity BoardPMProgram ManagementArt 5.17023(c)
    PM-26Complaint ManagementPMProgram ManagementArt 12.47021(a), 7021(b), 7022(e), 7022(f), 7022(f)(1), 7023(a), 7023(d)(1), 7023(d)(2)(A), 7023(d)(2)(B), 7023(d)(2)(C), 7023(d)(2)(D), 7023(f)(1), 7023(f)(2), 7023(f)(3), 7023(f)(4), 7023(i), 7023(j), 7023(k), 7024(c), 7024(c)(1), 7024(c)(2), 7024(c)(3), 7024(c)(4), 7024(d), 7024(d)(1), 7024(d)(2), 7024(e), 7024(e)(1), 7024(e)(2), 7024(k), 7024(k)(1), 7024(k)(2), 7024(k)(3), 7024(k)(4), 7024(k)(5), 7024(k)(6), 7027(h), 7027(k)
    PM-29Risk Management Program Leadership RolesPMProgram ManagementArt 32.27123(b)(3)
    PT-1Policy and ProceduresPTPII Processing and TransparencyArt 12.2, Art 24.2, Art 5.1, Art 9.17002(a), 7123(b)(1), 7123(c)(5)(B)
    PT-2Authority to Process Personally Identifiable InformationPTPII Processing and TransparencyArt 10, Art 5.1, Art 8.1, Art 9.2, Art 9.37002(f), 7023(d)(3), 7026(f), 7026(f)(1), 7027(a)
    PT-3Personally Identifiable Information Processing PurposesPTPII Processing and TransparencyArt 13.1, Art 14.17002(a)(1), 7002(a)(2), 7002(b)(4), 7027(m)
    PT-4ConsentPTPII Processing and TransparencyArt 21.1, Art 21.2, Art 21.3, Art 21.4, Art 21.5, Art 21.6, Art 7.1, Art 7.2, Art 9.27002(e), 7010(b), 7012(a), 7012(b), 7012(c), 7012(d), 7012(e), 7012(e)(1), 7012(e)(2), 7012(e)(3), 7012(e)(4), 7012(e)(5), 7012(e)(6), 7027(c), 7027(d)
    PT-5Privacy NoticePTPII Processing and TransparencyArt 12.7, Art 13.1, Art 13.2, Art 13.3, Art 14.1, Art 14.2, Art 14.3, Art 14.4, Art 14.57002(b)(5), 7003(a), 7004(a)(1), 7010(a), 7011(a), 7011(b), 7011(c), 7011(d), 7011(e), 7011(e)(1), 7011(e)(1)(A), 7011(e)(1)(B), 7011(e)(1)(C), 7011(e)(1)(D), 7011(e)(1)(E), 7011(e)(1)(F), 7011(e)(1)(G), 7011(e)(1)(H), 7011(e)(1)(I), 7011(e)(1)(J), 7011(e)(2), 7011(e)(2)(A), 7011(e)(2)(B), 7011(e)(2)(C), 7011(e)(2)(D), 7011(e)(2)(E), 7011(e)(2)(F), 7011(e)(2)(G), 7011(e)(2)(H), 7011(e)(3), 7011(e)(3)(A), 7011(e)(3)(B), 7011(e)(3)(C), 7011(e)(3)(D), 7011(e)(3)(E), 7011(e)(3)(F), 7011(e)(3)(G), 7011(e)(3)(H), 7011(e)(3)(I), 7011(e)(3)(J), 7011(e)(4), 7011(e)(5), 7012(f), 7012(g)(1), 7013(c), 7013(e), 7013(e)(1), 7013(e)(2), 7013(e)(3), 7013(g)(2), 7014(b), 7014(c), 7014(d), 7014(e)(1), 7014(e)(2), 7014(e)(3), 7014(g)(1), 7014(g)(2), 7014(h), 7025(g)(2), 7025(g)(2)(A), 7025(g)(2)(B), 7025(g)(2)(C), 7025(g)(2)(D), 7072(a)
    PT-7Specific Categories of Personally Identifiable InformationPTPII Processing and TransparencyArt 13.1, Art 14.17023(d)(3), 7024(j), 7024(l), 7026(f), 7026(f)(1), 7027(a)
    PT-7(1)Social Security NumbersPTPII Processing and TransparencyArt 13.1, Art 14.17024(j), 7024(l)
    PT-7(2)First Amendment InformationPTPII Processing and TransparencyArt 13.1, Art 14.17024(j), 7024(l)
    SR-1Policy and ProceduresSRSupply Chain Risk ManagementArt 24.27024(l), 7052(a), 7123(b)(1), 7123(c)(15)

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.