// Privacy
General Data Protection Regulation Compliance Software
EU data protection regulation governing personal data of EU residents.
Framework at a glance
Short name
GDPR
Version
2018
Category
Privacy
Controls
87
What GDPR covers
87 controls across 52 domains — every one tracked, owned and evidenced in Cyber Horizon.
Lawful Basis
1 controls- A.5.1 Lawfulness of processing
Data Management
2 controls- A.5.2 Purpose limitation
- A.5.3 Data minimisation
Data Quality
1 controls- A.5.4 Accuracy
Retention
2 controls- A.5.5 Storage limitation
- A.24.13 Retention schedule
Security
1 controls- A.5.6 Integrity and confidentiality
Governance
5 controls- A.5.7 Accountability
- A.13.2 Data Protection Officer appointment
- A.13.3 DPO tasks
- A.21.1 EU representative appointment
- A.24.10 Privacy in procurement
Consent
2 controls- A.6.1 Consent
- A.22.1 Cookie and tracking consent
Contracts
3 controls- A.6.2 Contract performance
- A.15.2 Data processing agreements
- A.24.4 Data sharing agreements
Legal
1 controls- A.6.3 Legal obligation
Special Cases
2 controls- A.6.4 Vital interests
- A.24.11 Research data governance
Public Sector
1 controls- A.6.5 Public task
Legitimate Interests
1 controls- A.6.6 Legitimate interests
Consent Management
2 controls- A.7.1 Conditions for consent
- A.7.2 Withdrawing consent
Children's Data
1 controls- A.8.1 Child's consent for information society services
Sensitive Data
2 controls- A.9.1 Processing of special categories
- A.9.2 Processing criminal convictions
Privacy by Design
1 controls- A.10.1 Privacy by design
Privacy Notice
5 controls- A.12.1 Transparent information
- A.12.2 Information provided on collection
- A.12.3 Information to be provided where obtained indirectly
- A.23.1 Privacy notice completeness
- A.23.2 Layered privacy notices
Access
1 controls- A.12.4 Right of access
Rectification
1 controls- A.12.5 Right to rectification
Erasure
1 controls- A.12.6 Right to erasure
Restriction
1 controls- A.12.7 Right to restriction
Portability
1 controls- A.12.8 Data portability
Objection
1 controls- A.12.9 Right to object
Automated Decisions
1 controls- A.12.10 Automated decision-making
Documentation
7 controls- A.13.1 Records of processing (ROPA)
- A.16.4 Breach documentation
- A.24.8 Sensitive data mapping
- A.24.9 Data flow mapping
- A.24.19 Privacy impact register
Risk Assessment
1 controls- A.13.4 Data Protection Impact Assessment
Regulatory
4 controls- A.13.5 Prior consultation
- A.18.1 Supervisory authority cooperation
- A.18.2 Consistency mechanism
- A.19.1 One-stop-shop mechanism
Security Controls
2 controls- A.14.1 Security of processing
- A.14.3 Ongoing confidentiality
Cryptography
2 controls- A.14.2 Pseudonymisation and encryption
- A.24.15 Encryption key management
Business Continuity
1 controls- A.14.4 Data availability and resilience
Testing
1 controls- A.14.5 Regular testing and evaluation
Third-Party
3 controls- A.15.1 Processor contracts
- A.15.3 Sub-processor authorisation
- A.15.4 Processor audit rights
Incident Management
1 controls- A.16.1 Breach detection
Notification
3 controls- A.16.2 Controller breach notification to SA
- A.16.3 Individual breach notification
- A.24.24 Cross-border incident notification
Data Transfers
5 controls- A.17.1 Adequacy decisions
- A.17.2 Standard contractual clauses
- A.17.3 Binding corporate rules
- A.17.4 Transfer impact assessments
- A.17.5 Codes of conduct and certification
Data Subject Rights
1 controls- A.20.1 Right to lodge complaint
Marketing
1 controls- A.22.2 Email marketing consent
Automated Processing
1 controls- A.22.3 Profiling transparency
Awareness
1 controls- A.24.1 Staff privacy training
Incidents
1 controls- A.24.2 Privacy incident response plan
Vendors
1 controls- A.24.3 Vendor management programme
Management
1 controls- A.24.5 Privacy governance structure
Risk
1 controls- A.24.6 Privacy risk register
Audit
1 controls- A.24.7 Annual privacy review
Anonymisation
1 controls- A.24.12 Anonymisation standards
Disposal
1 controls- A.24.14 Secure disposal
Logging
1 controls- A.24.16 Access logs for PII
Vulnerability Management
1 controls- A.24.17 Vulnerability management for PII systems
DSR Management
1 controls- A.24.18 Data subject request tracking
Children
1 controls- A.24.20 Children age verification
Certification
1 controls- A.24.23 Privacy seal and certification
Reporting
1 controls- A.24.25 Accountability reporting
How Cyber Horizon automates GDPR
Every GDPR control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is General Data Protection Regulation?
EU data protection regulation governing personal data of EU residents.
How many controls does General Data Protection Regulation have?
General Data Protection Regulation (2018) has 87 controls in Cyber Horizon's catalogue, organised across 52 domains.
How does Cyber Horizon help with General Data Protection Regulation?
Cyber Horizon maps General Data Protection Regulation into a shared control library alongside every other framework you run, so evidence collected once counts towards GDPR and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More Privacy frameworks
See GDPR mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of GDPR in Cyber Horizon.