The rapid adoption of smart-city technologies had increased dependence on interconnected digital infrastructure, creating significant cybersecurity, privacy, and regulatory challenges. This study examined the alignment between cybersecurity engineering controls and data-protection requirements in smart-city environments. A quantitative research design was adopted using primary data collected through a structured questionnaire from professionals involved in cybersecurity, information technology, engineering, data protection, and smart-city management. The collected data were analyzed using descriptive statistics, Cronbach’s alpha, Pearson correlation, and multiple regression analysis. The findings indicated that cybersecurity engineering controls, including encryption, authentication, access control, network security, monitoring, and vulnerability management, had a significant positive relationship with data-protection practices and regulatory compliance. Data-protection practices also demonstrated a significant positive relationship with regulatory compliance, indicating that technical safeguards alone were insufficient to achieve comprehensive compliance. The study further established that integrating privacy-by-design principles, data minimization, accountability, retention management, and continuous compliance monitoring strengthened the effectiveness of cybersecurity controls. Based on these findings, an integrated framework was proposed to align engineering controls with data-protection requirements throughout the smart-city lifecycle. The study contributed practical and theoretical insights for improving cybersecurity resilience, privacy protection, regulatory compliance, and public trust in smart-city infrastructures