The DPO advises management on data protection, participates in impact assessments, informs and trains staff, monitors compliance with the Law and internal policies including responsibilities, awareness, training and audits, cooperates with and is the contact point for the Commissioner, and has regard to risk. The DPO is chosen for certified professional qualities, in particular expert knowledge of data protection law and practice, may be staff or under a service contract, and may hold other duties that do not conflict. The controller or processor must publish the DPO's contact details and communicate them to the Commissioner; data subjects may contact the DPO on all matters. The DPO must be involved properly and in good time, given the resources needed, kept bound by secrecy, receive no instructions on the tasks, not be dismissed or penalised for performing them, and report directly to the highest management level. DPOs may form a network coordinated with the Commissioner.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.