Taking account of the nature, scope, context and purposes of processing and the risks to rights and freedoms, the controller must implement appropriate technical and organisational measures to ensure, and be able to demonstrate, that processing complies with the Law, reviewing and updating them where needed; these include data protection by design and by default under Article 23. The controller should consider designating a data protection officer even outside the Article 33 cases where its processing presents other significant risk factors. Adherence to an approved code of conduct or certification may help demonstrate compliance. Controllers and processors must cooperate with the Commissioner on request.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.