Framework overlap

Does Azure Security Benchmark cover Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018)?

You hold Azure Security Benchmark and have been told to do Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018). Here is how much overlaps, control by control.

63% of Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) you already have

Azure Security Benchmark already covers about 63% of Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018), leaving 3 of 8 controls as genuinely new work.

Already covered 4 Likely covered 1 New work 3

What is genuinely new work

Nothing in Azure Security Benchmark reaches these. This is the list to scope.

ICELAND-Act90-Chap1-Scope-Definitions-EEA-GDPR-Personuvernd
Iceland Act No. 90/2018 - Chapter I Scope + Definitions + EEA Agreement + GDPR Application + Personuvernd Authority
ICELAND-Act90-Chap2-Principles-LawfulBasis-Consent-Sensitive-Criminal
Iceland Act 90/2018 - Chapter II Principles + Lawful Basis + Consent + Special Categories + Criminal Data (Articles 8-13)
ICELAND-Act90-Sectoral-Employment-Children-DirectMarketing-AutomatedDecisions-Cookies
Iceland Act 90/2018 - Sectoral - Employment + Children + Direct Marketing + Automated Decisions + Cookies + Cybersecurity
Show the 5 you already have
ICELAND-Act90-Chap3-Transparency-DataSubjectRights-Access-Rectification-Erasure
Iceland Act 90/2018 - Chapter III Transparency + Data Subject Rights (Articles 14-23) - Access + Rectification + Erasure + Portability + Object + Automated Decisions
ICELAND-Act90-Chap4-ControllerObligations-PrivacyByDesign-Processor-RoPA-DPO
Iceland Act 90/2018 - Chapter IV Controller Obligations + Privacy by Design + Processor + RoPA + DPO (Articles 24-26 + 35)
ICELAND-Act90-Chap4-Security-BreachNotification-DPIA-Personuvernd-72hr
Iceland Act 90/2018 - Chapter IV Security of Processing + Breach Notification + DPIA (Articles 27-29)
ICELAND-Act90-Chap6-Personuvernd-Enforcement-AdminFines-AAB-Appeals-CriminalPenalties
Iceland Act 90/2018 - Chapter VI Personuvernd Authority + Investigation + Administrative Fines + Penal Code Section 228 + Court Appeals
ICELAND-Act90-Chap5-CrossBorder-EEA-AdequacyDecisions-SCC-BCR
Iceland Act 90/2018 - Chapter V Cross-Border Transfer of Personal Data + EEA + Adequacy + SCCs + BCRs + Article 30 Privacy Policy

How this is calculated

Already covered means a mapping runs from a control in Azure Security Benchmark to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition