The organisation implements a process for receiving and responding to complaints, concerns and questions about its security and privacy practices, with easy public mechanisms, the information needed to file, tracking so complaints are addressed within a set time, and acknowledgement and response within set times. The GC discussion requires informing individuals of their right to complain, including to the Privacy Commissioner, preparing for Commissioner investigations, and reporting complaint trends in the annual report. No enhancements. Deployed organisation-wide in the medium profile.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.