The organisation appoints a privacy senior official or executive with the authority, mission, accountability and resources to coordinate, develop and implement privacy requirements and manage privacy risk through the organisation-wide program. The GC discussion notes the official is appointed by the head of the institution, may be called the chief privacy officer, and sits on the data governance committee and the committee on data and information. No enhancements. Deployed organisation-wide in the medium profile.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.