Skip to content

GDPRISO 27001 crosswalk

A control-by-control mapping between General Data Protection Regulation (EU 2016/679) and ISO/IEC 27001:2022. 6 mappings.

GDPRISO 27001RelationshipNotes
Art. 25
Data protection by design and by default
A.5.1
Policies for information security
RelatedCurated
Gouvernance et politique de sécurité
Art. 30
Records of processing activities
A.5.9
Inventory of information and other associated assets
RelatedCurated
Inventaire des actifs et des données
Art. 32
Security of processing
A.8.24
Use of cryptography
PartialCurated
Cryptographie et protection des données
Art. 32
Security of processing
A.8.13
Information backup
RelatedCurated
Sauvegarde et restauration
Art. 33
Notification of a personal data breach to the supervisory authority
A.5.24
Information security incident management planning and preparation
RelatedCurated
Réponse aux incidents et notification des violations
Art. 33
Notification of a personal data breach to the supervisory authority
A.5.26
Response to information security incidents
RelatedCurated
Réponse aux incidents et notification des violations

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.