Framework overlap

Does ISO 27018 cover Law No. 172-13 on the Protection of Personal Data?

You hold ISO 27018 and have been told to do Law No. 172-13 on the Protection of Personal Data. Here is how much overlaps, control by control.

63% of Law No. 172-13 on the Protection of Personal Data you already have

ISO 27018 already covers about 63% of Law No. 172-13 on the Protection of Personal Data, leaving 3 of 8 controls as genuinely new work.

Already covered 0 Likely covered 5 New work 3

No control in ISO 27018 maps directly to one in Law No. 172-13 on the Protection of Personal Data. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in ISO 27018 reaches these. This is the list to scope.

DOM172-Database-Registration-Article-30-Credit-Information-Bureaus-SIC-Superintendencia-Bancos-Healthcare-Sector
Dominican Republic Law 172-13 Database Registration + Credit Information Bureaus + SIC + Superintendencia de Bancos
DOM172-Scope-Ley172-13-13December2013-Effective15December2013-Constitution-Article-44-Habeas-Data-Superintendencia-Bancos
Dominican Republic Law 172-13 Scope + 13 December 2013 + Constitution Article 44 + Habeas Data
DOM172-Sensitive-Personal-Data-Confidentiality-Duty-Articles-9-12-Special-Categories-Health-Genetic-Religious-Political
Dominican Republic Law 172-13 Sensitive Data + Confidentiality + Articles 9-12 + Special Categories
Show the 5 you already have
DOM172-Cross-Border-Transfer-Article-80-Vendor-Processor-Management-Marketing-Direct-Communications-Article-23-24-26
Dominican Republic Law 172-13 Cross-Border Transfer + Vendor Management + Marketing + Articles 23-24-26-80
DOM172-Data-Subject-ARCO-Rights-Habeas-Data-Action-Constitutional-Article-70-Access-Rectification-Cancellation-Opposition
Dominican Republic Law 172-13 ARCO Rights + Habeas Data Action + Constitutional Article 70
DOM172-Lawful-Basis-Consent-Notice-Information-Duty-Articles-4-12-Quality-Principle-Purpose-Limitation-Minimisation
Dominican Republic Law 172-13 Lawful Basis + Consent + Notice + Information Duty + Articles 4-12
DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22
Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification
DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation
Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness

How this is calculated

Already covered means a mapping runs from a control in ISO 27018 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition