4.3 Policy Compliance Measurement & Gap Analysis
Key Takeaways
- Gap analysis compares current-state controls against applicable laws, internal policies, and accepted frameworks (GDPR accountability, ISO 27701, NIST Privacy Framework) to identify remediation needs
- A compliance gap measures deviation from a mandatory requirement; a risk gap measures exposure where no explicit requirement exists but harm is foreseeable
- The gap-analysis process flows: identify requirement, assess current state, score the gap, prioritize remediation, and track closure through re-measurement
- Gap outputs feed the privacy program roadmap, budget requests, and board-level reporting on maturity and residual risk
- Continuous compliance measurement uses metrics (e.g., DSAR timeliness, training completion, incident closure) rather than one-time snapshots
From Inventory to Action
Once data is inventoried and flows are mapped, the privacy manager must answer: where do our controls fall short of what the law, our own policies, or accepted frameworks require? That question is answered by gap analysis — the structured comparison of current state against a defined target state. The CIPM Body of Knowledge treats gap analysis as a core III.A competency because it converts descriptive artifacts (inventories, flow maps) into a prioritized remediation plan.
Compliance Gap vs. Risk Gap
A frequent exam distinction:
- Compliance gap — current state falls short of a mandatory requirement (a law, regulation, contract, or binding internal policy). Example: retaining customer data for 7 years when a 3-year retention policy is in place.
- Risk gap — current state is not mandated by any explicit requirement, but exposes the organization to foreseeable harm. Example: storing sensitive data unencrypted where no law explicitly requires encryption, but breach risk makes it prudent.
Both belong in a gap register, but they are prioritized differently. Compliance gaps carry legal or contractual consequences; risk gaps carry business and reputational consequences. A mature program closes compliance gaps first, then uses risk acceptance or mitigation for risk gaps that cannot be eliminated.
The Gap-Analysis Process
A repeatable gap-analysis workflow has five stages:
- Identify the requirement — select a law (e.g., GDPR Art. 32 security), an internal policy (e.g., "all laptops encrypted"), or a framework control (e.g., ISO 27701 6.12.1).
- Assess current state — collect evidence from the inventory, flow maps, control testing, and stakeholder interviews.
- Score the gap — apply a consistent scale (often 0 = no control, 1 = ad hoc, 2 = documented, 3 = implemented, 4 = monitored, 5 = optimized — the CMMI-style maturity ladder).
- Prioritize remediation — rank by legal exposure, data sensitivity, affected data-subject volume, and effort to remediate.
- Track closure — assign owners, set target dates, and re-measure at agreed intervals; closure is verified, not self-reported.
Gap-Analysis Matrix
A gap register is usually rendered as a matrix so the program owner and auditors can see status at a glance:
| Ref | Requirement | Source | Current State | Maturity (0–5) | Gap Severity | Owner | Target Date |
|---|---|---|---|---|---|---|---|
| G-01 | Encrypt personal data at rest | GDPR Art. 32(1)(a); internal policy SEC-04 | Database encrypted; backups pending | 3 | High | CISO | 2026-11-30 |
| G-02 | Record all sub-processors in DPA | GDPR Art. 28(2) | 4 of 7 vendors listed | 2 | Medium | Procurement Lead | 2026-10-15 |
| G-03 | DPIA for new analytics pipeline | GDPR Art. 35 | DPIA started, not signed off | 2 | High | DPO | 2026-09-30 |
| G-04 | Annual privacy training completion | Internal policy HR-12 | 78% completion | 3 | Low | HRBP | 2026-12-31 |
| G-05 | Cross-border transfer assessment | GDPR Art. 44–49; SCC 2021 Clause 14 | TIA missing for US vendor | 1 | High | Privacy Counsel | 2026-09-15 |
Frameworks as the Target State
When an organization lacks an internal policy baseline, accepted frameworks supply the target state:
- ISO/IEC 27701 — extends ISO 27001 with a Privacy Information Management System (PIMS); defines controller- and processor-specific controls.
- NIST Privacy Framework — a flexible, voluntary framework organized around Identify, Govern, Control, Communicate, and Protect functions.
- GDPR accountability principle (Art. 5(2)) — requires demonstrable compliance, not just compliance; the ROPA, DPIAs, and records of consent are the evidence.
- CCPA/CPRA, LGPD, PIPL — jurisdictional requirements that may exceed or differ from GDPR (e.g., PIPL's separate consent for sensitive data, CPRA's 12-month DSAR deadline for collected categories).
Frameworks harmonize language across jurisdictions, but the gap analysis must always anchor on the binding law first; frameworks fill in where law is silent.
Continuous Compliance Measurement
A single gap snapshot decays quickly. Mature programs instrument ongoing compliance metrics so trends surface before they become incidents:
- DSAR fulfillment rate within statutory deadline (target ≥ 95%).
- Privacy training completion rate by role.
- Vendor DPIA/DPA coverage percentage.
- Incident detection-to-notification time vs. the 72-hour GDPR Art. 33 window.
- Percentage of new processing activities with DPIA before launch.
These metrics feed dashboards reviewed monthly by the privacy steering committee and quarterly by the board. A declining trend is itself a gap, even if every individual control passes.
Worked Scenario: Healthcare SaaS Vendor
A healthcare SaaS company runs a gap analysis against HIPAA, GDPR (it has EU hospital clients), and ISO 27701. The matrix reveals: (1) Business Associate Agreements are missing for two sub-processors — a compliance gap under HIPAA §164.308(b)(1); (2) The EU client data is processed in a US data center relying on SCCs without a transfer impact assessment — a compliance gap under Schrems II; (3) Employee laptops lack full-disk encryption — a risk gap under ISO 27701 6.12.1 because no law explicitly mandates it but breach harm is high. The privacy manager prioritizes the BAA and TIA gaps as High severity with 30-day target dates, and routes the encryption gap to the CISO as a 90-day remediation. Closure is verified by re-testing each control rather than accepting vendor self-attestation.
Outputs Feed the Program Roadmap
Gap-analysis results are the spine of the privacy program roadmap. Each High-severity gap becomes a funded initiative with an owner, budget, and milestone. Medium and Low gaps enter a backlog for the next planning cycle. Without this linkage, gap analysis becomes shelfware — the most common failure mode the exam tests.
During a gap analysis, a privacy manager identifies that employee laptops store personal data without full-disk encryption. No applicable law explicitly mandates encryption for laptops, but breach risk is significant. How should this be classified?
Which sequence correctly orders the gap-analysis process?
A regulator asks an organization to demonstrate compliance with GDPR's accountability principle (Art. 5(2)). Which set of artifacts most directly satisfies that request?