The controller must be able to prove it has implemented mechanisms to comply with the principles, rights and obligations of the Act, using applicable rules and optionally standards, good practices, self- and co-regulation, codes, certifications and seals; it is accountable to data subjects and to the Authority, and must evaluate and review its mechanisms continuously to improve their effectiveness. The Reglamento requires appropriate measures both when choosing the means and during processing, weighing the state of the art (which must be continuously assessed), implementation costs (including time and people; inability to pay is no excuse, subject to proportionality with the volume processed and economic capacity), the nature, scope, context and purposes, and the likelihood and severity of risks; measures must be reviewed and updated, and compliance may be demonstrated with key performance indicators such as risk levels, complaint reduction or response times.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.