Skip to content

GDPRGLBA crosswalk

A control-by-control mapping between General Data Protection Regulation (EU 2016/679) and GLBA Safeguards Rule (16 CFR Part 314). 3 mappings.

GDPRGLBARelationshipNotes
Art. 25
Data protection by design and by default
§314.4(a)
Designate a qualified individual
RelatedCurated
Governance & security policy
Art. 32
Security of processing
§314.4(c)(3)
Encryption of customer information
PartialCurated
Cryptography & data protection
Art. 33
Notification of a personal data breach to the supervisory authority
§314.4(h)
Incident response plan
RelatedCurated
Incident response & breach notification

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.